Legal

Privacy policy

Version 2026-07 · Last updated July 2026. Plain-language summary, this policy has not yet been reviewed by an admitted attorney. See the repository README before launch.

This policy explains how we handle your personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). If anything isn't clear, email info-officer@homecart.co.za.

Who is responsible for your data

Homecart (Pty) Ltd, a South African company, is the responsible party. We decide why and how your personal information is processed. Registered address: 12 Church Street, Cape Town, 8001.

Information Officer

What we collect

  • Order details: name, delivery address, email, phone.
  • Account details (if you sign up), email and a hashed password held by our authentication provider.
  • Communication: messages you send us and our replies.
  • Marketing preferences: whether you've opted in to email or WhatsApp updates, and when.
  • Technical data: IP address, browser type, device, and pages viewed, for security and to fix broken flows.
  • Cookies: see the Cookie policy for what each one does.

We ask for the minimum we need. Every optional field on our forms is labelled Optional.

Why we use it and on what lawful basis

  • To take, process and deliver your order: necessary to carry out our contract with you (POPIA s11(1)(b)).
  • To meet tax, accounting and consumer-protection obligations: legal obligation (s11(1)(c)).
  • To send you marketing emails or WhatsApp messages: only with your opt-in consent (s11(1)(a)), which you can withdraw any time.
  • Security, fraud prevention and debugging: our legitimate interest in running a safe service (s11(1)(f)), balanced against your rights.

Who we share it with (operators)

We use these operators under written contracts (POPIA s20/s21) that require them to protect your data and use it only for us:

  • Hosting & database: Supabase (operated by Supabase Inc., data hosted in an EU region).
  • Payment processing: our SA payment gateway (to be finalised before launch). We never see or store your card details.
  • Delivery: the courier that fulfils your order in your area.
  • Transactional email: our managed email provider, for order confirmations and receipts.
  • Analytics: Google Analytics 4 via Google Tag Manager, only after you consent.

Cross-border transfers (section 72)

Our hosting, email and analytics providers may process your data outside South Africa (primarily the EU and the USA). We rely on POPIA s72(1)(a): the recipient is subject to a law that upholds substantially similar principles, or to binding contractual obligations (Standard Contractual Clauses) that do so.

How long we keep it

DataRetention
Order and invoice records5 years from the tax year (SARS & consumer law).
Guest customer contact details (no order in 24 months)Anonymised automatically after 24 months.
Account holdersFor as long as the account is open; deleted within 30 days of your request unless we must retain records above.
Marketing subscriber listUntil you unsubscribe; consent record kept for 3 years after withdrawal as proof.
Consent log7 years, required to prove lawful basis under s11.
Website analytics events14 months.
Support messages2 years from last contact.

Your rights

  • Access a copy of the personal information we hold about you.
  • Correct anything that's wrong or out of date.
  • Delete your data where we're not required to keep it.
  • Object to direct marketing at any time (section 69, unsubscribe link in every marketing email, or use the form below).
  • Withdraw consent for anything we do on that basis, without affecting past lawful processing.
  • Complain to the Information Regulator if you think we've mishandled your data.

Exercise any of these rights using the data subject request form. We reply within 30 days.

Information Regulator

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: PAIAComplaints@inforegulator.org.za · POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za

Security

We take reasonable, appropriate technical and organisational safeguards (POPIA s19):

  • All traffic is served over HTTPS/TLS.
  • Card details are handled directly by the payment gateway, we never see or store them.
  • Access to the database is scoped by Row-Level Security on every table; staff access is least-privilege by role.
  • Admin sign-in uses our authentication provider; two-factor authentication is encouraged for all staff.
  • Every admin action that changes data is written to an audit log.
  • Passwords are never stored by us, they're hashed by our authentication provider.

Data breaches

If a breach happens and it's likely to cause harm, we'll notify the Information Regulator and affected people as soon as reasonably possible, as required by section 22.

Changes to this policy

We'll change this policy from time to time. The version number and date at the top change with every update. Material changes are announced by email to account holders.