Last updated: June 3, 2026
Mekoshi helps sellers create storefronts, buyers discover and pay for products, delivery workers accept delivery or shopping jobs, and teams manage seller-owned WhatsApp, Instagram, payment, delivery, and promotion workflows.
Mekoshi is preparing and maintaining its Ghana Data Protection Commission compliance posture under Ghana's Data Protection Act, 2012 (Act 843). We process personal data only for defined marketplace, delivery, payment, trust, safety, support, legal, and service-improvement purposes.
We collect account details, seller store details, buyer checkout details, product information, delivery and shopping-job details, payment references, support messages, marketing campaign settings, and operational logs needed to run the service.
When verification is required, we collect only the fields needed to review account trust, including email and phone verification status, Ghana Card reference data, profile or vehicle photos, and guided face-capture media. Ghana Card/NIA automated verification will be enabled only after the required provider credentials and approvals are in place. Until then, Ghana Card evidence may support manual review where appropriate.
Verification media is treated as private account data and is used for safety review, fraud prevention, account recovery, dispute handling, and regulatory readiness. Public marketplace views do not expose raw Ghana Card numbers, identity evidence, biometric media, payment credentials, or private support records.
When a seller connects WhatsApp or Instagram through Meta, we may receive Meta business account IDs, WhatsApp phone number IDs, Facebook Page IDs, Instagram professional account IDs, display names, message identifiers, inbound message payloads, message delivery statuses, and access tokens needed to send or receive seller-approved messages.
Meta access tokens are stored as server-side secret files outside the database. The database stores only the generated secret file name and account metadata needed to route messages to the correct seller.
For payments, we store transaction references, checkout amounts, service-fee records, payment method choices, payout preferences, and provider status updates. For delivery and shopping jobs, we store pickup, drop-off, offer, assignment, and completion details. For Mekoshi Boost, we store subscription tier, campaign targets, sponsored placement metrics, catalog feed exports, promotional links, and managed-campaign requests.
Managed Growth sellers may connect external ad providers such as Meta, Google, or TikTok. OAuth token bundles for those connections are encrypted and stored outside normal database fields. Mekoshi uses them only to prepare campaign drafts, export catalog feeds, or support seller-authorized advertising actions.
We use information to authenticate users, verify contact details, operate storefronts, process orders, initialize payments, estimate delivery, route customer updates, promote seller listings, generate catalog feeds, receive webhook events, protect accounts, investigate disputes or fraud signals, troubleshoot errors, and comply with legal or platform requirements.
We share information only with service providers needed to operate the platform, including payment processors, hosting providers, storage providers, delivery workflows, observability tools, messaging providers, Meta APIs when sellers connect their own WhatsApp or Instagram accounts, and ad providers when a seller explicitly connects and authorizes that provider. We require service providers to use personal data only for the services they provide to Mekoshi or the connected seller.
Mekoshi may use reputable hosting, payment, messaging, storage, analytics, and support providers in Ghana, other African regions, Europe, or other jurisdictions. Where personal data is hosted or processed outside Ghana, Mekoshi documents the processing country, purpose, vendor, and safeguards, and uses contractual, technical, and access-control protections designed to keep the data protected.
We keep account, store, order, payment, delivery, trust, messaging, verification, support, and promotion records only for as long as needed to provide the service, verify transactions, resolve disputes, preserve audit records, prevent fraud, and meet legal obligations. We separate active records from review or archive records where practical, and we delete, anonymize, or restrict records when they are no longer needed.
Meta users can request deletion through Meta's app controls. Meta sends deletion requests to our data deletion callback, and we record the request, disable matching WhatsApp or Instagram channel connections, remove stored token-file references, and provide a confirmation code and status page. For full Mekoshi account, seller, buyer, delivery-worker, payment-profile, verification, access, correction, consent withdrawal, objection, or promotion-data requests, use our privacy request form or contact privacy support from the email address on the account.
Open Data Deletion Instructions
You may ask Mekoshi to help you access, correct, delete, or restrict personal data, withdraw consent where consent is the basis for a specific use, object to marketing, or ask how your information is used. We verify account ownership before disclosing, changing, or deleting personal data, and some records may need to be retained for payments, disputes, fraud prevention, tax, accounting, legal, or safety obligations.
We use HTTPS, authenticated API routes, service-use verification gates, rate limiting, role-based access checks, private object storage for sensitive media, server-side secret files, encrypted external token bundles, webhook signature verification, restricted container mounts, payment payload redaction, and least-privilege operational practices to reduce unauthorized access, disclosure, alteration, or destruction risks.
We monitor critical service paths and maintain incident procedures for payment failure, downtime, security events, delivery failure, and data-protection events. If a personal-data incident requires notice, Mekoshi will assess the impact and notify affected users, partners, or regulators as required.
For privacy requests, email privacy@mekoshi.com. For support questions, email support@mekoshi.com.