1. Who we are
Kayen Parts operates the kayenparts.com automotive parts marketplace. Product, partner, and copyright materials also use the name Kayen Parts Business. In this policy, both names refer to the same organisation that decides why and how personal data is processed on the Kayen Parts platform.
This site does not publish a company registration number, registered office, or data-protection registration number. Do not treat any other company name or address as ours unless we publish it here.
Privacy requests go to privacy@kayen.parts. Support requests go to support@kayen.parts. Security reports go to security@kayen.parts.
Kayen Parts is live for buyers and suppliers in Algeria. People outside Algeria, including in the United Kingdom, may visit the site, connect a business WhatsApp number, or otherwise send us personal data. Where UK GDPR and the UK Data Protection Act 2018 apply, we handle that personal data according to those rules. Local laws in other countries may also apply. This policy does not create rights that the law does not give you, and it does not claim that Kayen Parts has a UK establishment or an appointed representative unless we later publish one.
2. Scope
This policy covers personal data processed through kayenparts.com, the Kayen Parts web application, supplier and buyer accounts, phone sign-in, part requests, offers, fulfilment, in-product messages, business-document uploads, operational logs, and the WhatsApp Business Platform connection used to deliver verification codes and operate the Kayen WhatsApp Business account.
A shorter summary in English, French, and Arabic, and the on-device marketing-measurement choice, remain available at /site/privacy. If that summary and this page differ, this page is the privacy policy.
This policy does not cover websites, apps, or WhatsApp accounts that we do not operate.
3. Personal data we process
We process the categories below when you or your device provide them, when they are created by using the product, or when a messaging or infrastructure provider returns a status we need to run the service. We do not claim to collect information that the current product does not collect.
- Account data: phone number, email address when you give one, display name, full name, the original name we store for internal use, role (buyer, supplier, or operator), country code, verification flags, last login, and account identifiers created by our authentication service.
- Buyer data: part requests, vehicle details you enter (including brand, model, year, engine, fuel, and VIN when you provide a VIN), fulfilment preference, pickup or delivery addresses, accepted offers, order and fee records, issue or return records, and the privacy-protected name shown to suppliers.
- Supplier and business data: application details (name, store name, phone, email, wilaya, store address), company or store profile fields, registre de commerce (RC) number, NAE codes read from submitted documents, pickup locations, storefront photographs, terms-acceptance records (version, language, time), inventory or catalogue data you connect, and offer, routing, and sold-order records.
- Uploaded business documents: images or PDFs you upload for business verification, stored in a private bucket, plus file type, size, and storage path. Storefront photographs are stored so buyers can recognise a shop.
- Phone numbers and authentication data: the phone number used to sign in, hashed phone, IP, session, and user-agent values used to authorise and rate-limit one-time codes, dispatch records, provider message identifiers, and delivery status. The authentication service holds the short-lived verification code. Kayen application tables store hashed send records and delivery status, not the code itself.
- WhatsApp Business Platform and Meta Platform Data: described in section 6. This includes delivery receipts for codes we send, technical identifiers for the Kayen WhatsApp Business account, and, only with your permission, limited advertising measurement events.
- Communications: messages sent inside a request thread between buyer, supplier, and Kayen operations, plus emails we send about your account.
- Usage and security telemetry: page and search events that the product writes (including search query, language, user agent, and result counts when search analytics run), supplier view heartbeats on live requests, abuse and rate-limit records, Cloudflare Turnstile bot-check tokens, and hosting or function logs needed to keep the service up and investigate misuse. Some diagnostic events stay in the browser only.
- Approximate location derived from your IP or from an address or map pin you choose when you set a shop or delivery destination.
4. What we do not collect
The current product does not process card numbers or operate a card-payment gateway. Buyers pay accepted supplier amounts in Algerian dinars according to the live request flow.
We do not sell personal contact lists. We do not place advertising cookies of our own. We do not store inbound WhatsApp chat bodies, WhatsApp contact names, or WhatsApp address books. We do not send names, phone numbers, email addresses, store details, verification codes, account IDs, or form contents to Meta Pixel.
5. Purposes and lawful bases
Where UK GDPR applies, we rely on the bases below. For users outside the UK we use the same purposes. Other local lawful bases may also apply.
Contract (to provide the service you asked for): creating and securing your account, sending a one-time sign-in code, matching parts, running live requests and offers, recording accepted orders, showing a privacy-protected buyer name to suppliers, hosting in-product messages, and storing supplier verification documents you upload so we can review an application.
Legitimate interests (balanced against your rights): preventing OTP abuse and fraud, enforcing rate limits, keeping buyer and supplier data within ownership boundaries, recording that a supplier viewed a request, diagnosing outages, measuring search quality, and keeping security logs. You may object. We will stop unless we have a compelling reason or the law requires us to continue.
Consent: Meta Pixel advertising measurement on this device. You can refuse or withdraw that permission at any time from /site/privacy. Withdrawing consent does not affect sign-in or the marketplace.
Legal obligation: we may keep a limited record when a law that applies to us requires it, for example to handle a binding request from a competent authority. We do not list a retention statute that we have not implemented as a product rule.
6. Meta and WhatsApp Business Platform
Kayen Parts uses the WhatsApp Business Platform, operated by Meta Platforms, Inc. and its affiliates, for two distinct jobs.
First, sign-in. When you request a one-time code, we send that code to the phone number you entered over WhatsApp. Meta processes the destination number, the message, and delivery status so the code can be delivered. Our webhook reads delivery and failure statuses and writes the provider message identifier and status onto the hashed dispatch record. Inbound WhatsApp messages from users are acknowledged and are not stored. We do not operate a WhatsApp-to-SMS fallback.
Second, the Kayen WhatsApp Business account. Kayen may connect its WhatsApp Business app number through Meta Embedded Signup so the official WhatsApp Business mobile app and the Cloud API can coexist. That flow processes Meta login data, a WhatsApp Business Account identifier, a phone-number identifier, and technical sync acknowledgements (including history, app-state, and message-echo field names). We acknowledge those webhooks. We do not persist WhatsApp message bodies, contact names, or chat history from coexistence sync into Kayen product tables. Operational logs may record field names, progress, or error codes, not message content.
Meta also provides an optional Pixel used only after you grant marketing permission. The Pixel may receive PageView, a supplier-landing ViewContent event, and a supplier-application SubmitApplication event that contains only a content name, a pending-review status, and an event identifier. Your consent choice is stored on this device until you change it. Kayen does not keep a separate advertising-report database. Meta applies its own retention to events it receives.
Meta handles WhatsApp and Pixel data under Meta terms and privacy policy. Meta may be a processor for delivery we instruct, and a controller for its own platform products. We do not control how Meta independently uses Platform Data.
If you want Kayen to delete Meta-related records we hold about you (for example a hashed OTP dispatch row or a marketing-consent flag on a device you control), use the user data deletion page or email us. Deleting data held by Meta itself may also require tools provided by Meta.
7. Processors and service providers
We use service providers to host and operate the product. They process personal data only as needed for the services below, except where they act as independent controllers (for example Meta for its own platform products).
- Supabase: authentication, database, and file storage, including private business-document and storefront buckets.
- Vercel: website hosting, serverless functions, and operational logs.
- Meta / WhatsApp Business Platform: verification-code delivery, WhatsApp account connection, webhook status, and optional Pixel measurement after consent.
- Cloudflare Turnstile: bot checks when you request a sign-in code.
- Google Maps and Places: resolving a shop or delivery address you choose.
- Vehicle catalogue and fitment sources used to check whether a part matches a vehicle. Those sources receive vehicle attributes needed for a lookup, not your account password or verification code.
8. Retention
We do not run a published automatic deletion clock for most account, order, or verification records. The product keeps data while the account or business record is active and while we still need it for the purpose that collected it.
One-time-code authorisation rows are marked to expire for reuse after two minutes. Rate-limit checks look back across recent hours. Hashed dispatch, abuse, and security records are kept so we can enforce those limits and investigate misuse. There is no automated purge job for those records today.
Browser marketing-consent and some diagnostic events stay on the device until you clear site data or change the choice.
When you make a verified deletion request, we delete or anonymise personal data we no longer need, as described in section 9. We may keep a limited record of the request itself and any data we must keep for an active dispute, security investigation, or a legal obligation that applies to us.
9. Deletion and closing an account
Kayen Parts does not currently offer a self-serve account-delete button. To request deletion of your personal data, email privacy@kayen.parts from a contact we can match to the account, or follow https://kayenparts.com/legal/user-data-deletion. Include the phone number or email on the account and whether you are a buyer or a supplier.
After we verify the request, we delete or anonymise account profile fields, authentication links, supplier application and verification files we no longer need, storefront images tied to that account, hashed OTP dispatch rows we can locate, in-product messages we no longer need, and marketing-consent records we store, unless a reason in section 8 applies.
Orders, fee calculations, and fulfilment records may be anonymised rather than fully erased when we still need a non-identifying commercial record. WhatsApp content held only by Meta is outside a Kayen deletion.
We aim to respond within one month of a verified request. That is a handling target, not a silent background job.
10. Security
We transmit the site over HTTPS. Authentication uses a phone one-time code rather than a password. OTP abuse controls store phone, IP, session, and user-agent values as hashes. Database policies separate buyer, supplier, and operator access. Business-verification documents sit in a private storage bucket. Buyer names shown to suppliers are privacy-protected (first name and last initial) while the original name is kept for internal use.
No method is perfect. If you believe personal data was exposed, email security@kayen.parts with a clear description and the time. Do not send secrets, session tokens, or production credentials.
11. International transfers
Kayen Parts serves Algeria from a web application whose hosting, database, messaging, and mapping providers may process data in the United Kingdom, the European Economic Area, the United States, or other countries where those providers operate.
When UK GDPR applies, we rely on the transfer tools those providers offer (for example the UK addendum to the European Commission standard contractual clauses, or an adequacy decision). We do not claim that every subprocessor location is inside Algeria.
12. Your rights
Where UK GDPR applies, you can ask us to access, correct, erase, or restrict personal data, object to legitimate-interest processing, withdraw marketing consent, and receive a copy of data you provided in a portable form where that right applies. You can also complain to the UK Information Commissioner Office (ICO) or to another competent authority that accepts complaints about us.
Users outside the UK may have similar rights under local law. We will honour a request we can verify, even if a specific statute does not apply, unless a legal exception does.
To use these rights, email privacy@kayen.parts. We may ask for enough information to find your account and confirm that you are the person making the request.
13. Children
Kayen Parts is intended for adults who can place or fulfil a marketplace transaction. We do not knowingly create accounts for children. If you believe a child has given us personal data, email us and we will delete it when we can verify the request.
14. Changes
This policy is effective from 3 September 2026 and was last updated on 3 September 2026. If we change it, we will update the last-updated date on this page. Continued use after a material change means the updated policy applies to later processing. We will not use this page to claim collection, retention, or deletion that the product does not do.
15. Contact
Data protection contact: privacy@kayen.parts.
Support: support@kayen.parts. Security: security@kayen.parts.
Postal and company-registration details are not published in the current Kayen Parts legal materials. Use email until we publish a registered address.
Related pages: https://kayenparts.com/legal/user-data-deletion and https://kayenparts.com/site/terms.