01 // TERMS OF SERVICE 02 // PRIVACY POLICY 03 // COOKIE POLICY
LEGAL DIRECTIVE // PRIVACY PROTOCOL

PRIVACY POLICY

CLIENT DATA & GOOGLE USER DATA GOVERNANCE LAST REVISED // SEPTEMBER 2026
01

APPLICATION IDENTITY & PLATFORM OVERVIEW

KOVENANT Apparel (accessible at https://kovenantapparel.com) is an independent luxury contemporary fashion brand and digital e-commerce storefront operating from Nairobi, Kenya. This Privacy Policy governs all client data collected via our website, digital store, and Google OAuth authentication services.

Browsing our catalog, inspecting garment specifications, and checking out is entirely public without requiring account registration. We believe in minimal data collection and maximum client privacy.

02

GOOGLE USER DATA ACCESSED & PURPOSE OF PROCESSING

When you choose to sign in using Google OAuth authentication, KOVENANT requests access only to basic profile information: your primary Google email address, display name, and profile avatar URL.

We process this Google user data strictly for the following purposes:

  • Client Profile Authentication: To verify your client identity securely without storing passwords.
  • Order Attribution & Receipts: To associate your garment purchases, sizing selections, and archive receipts with your verified email address.
  • Courier Dispatch & Delivery Tracking: To allow you to monitor your order fulfillment and domestic/international courier tracking in real-time.
  • Customer Service: To verify ownership of previous orders when assisting with sizing exchanges or delivery coordination.
03

GOOGLE API SERVICES USER DATA POLICY // LIMITED USE DISCLOSURE

KOVENANT strictly complies with all Google API Services User Data Policies.

Limited Use Disclosure: KOVENANT's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not transfer or disclose Google user data to generalized artificial intelligence models, machine learning algorithms, or external model training platforms.

04

NON-DISCLOSURE & ZERO SALE OF USER DATA

KOVENANT does not sell, rent, lease, or monetize customer data under any circumstances. We never trade, license, or transfer Google user data or client information to third-party data brokers, advertising exchanges, marketing networks, or external commercial organizations.

05

PAYMENT SECURITY & FINANCIAL ENCRYPTION

We do not store, view, or process raw credit card numbers or M-PESA PINs on our servers. All transactions are securely routed through PCI-DSS Level 1 certified payment infrastructure (Paystack) and Safaricom Daraja M-PESA API servers over TLS 1.3 encrypted HTTPS channels.

06

DATA STORAGE, RETENTION & SECURITY

User profile information and order logs are securely stored in Google Firebase Authentication and Google Cloud Firestore. Data is protected with end-to-end TLS 1.3 encryption in transit and AES-256 encryption at rest. Access to administrative order records is strictly restricted to verified cryptographic root keys.

07

USER DATA DELETION & ACCOUNT REMOVAL MECHANISM

Clients retain full ownership of their personal information and have the right to request deletion of their profile, order logs, and account at any time.

How to Request Data Deletion: Send an email to privacy@kovenantapparel.com or support@kovenantapparel.com with the subject line "Account & Data Deletion Request", or message our verified WhatsApp concierge at +254 114 873 377. Upon verification, all user profile records, Google OAuth tokens, and historical logs will be permanently and irrevocably purged from our database within thirty (30) days.
08

ORGANIZATION CONTACT INFORMATION

For questions or notices regarding this Privacy Policy or our Google OAuth integration, contact KOVENANT Headquarters:

Organization: KOVENANT Apparel
Headquarters: Nairobi, Kenya
Privacy Desk: privacy@kovenantapparel.com
Support Desk: support@kovenantapparel.com
Direct Line / WhatsApp: +254 114 873 377
Website: https://kovenantapparel.com