Who we are & how to contact us
SA Fashion Mall (Pty) Ltd is a company incorporated in the Republic of South Africa (company registration number 2026/582100/07). Registered address: Cape Town, South Africa.
Our Information Officer, appointed under POPIA s55, is Michael Jerome. You can reach the Information Officer at privacy@safashionmall.co.za. General privacy questions can go to the same address; POPIA subject-access and deletion requests should include a copy of your government-issued ID for verification.
Information we collect
- Account data — your name, email address, phone number, chosen password (hashed with bcrypt, never stored in plain text), primary and saved delivery addresses.
- Order data — the products, fabric rolls or custom-order briefs you buy; measurements you provide for custom garments (encrypted at rest); delivery address associated with each order; order chat messages.
- Seller KYC — for approved Sellers, we additionally collect a CIPC company registration document, a director SA-ID or valid passport, date of birth, residential address, banking details for payout, a studio-tour video, and 3–8 portfolio images. KYC identifier fields are encrypted at rest with AES-256-GCM.
- Technical & fraud-prevention data — the IP address you connect from, an approximate city/province derived from that IP (via ip-api.com, keyless), browser user-agent, device fingerprint (hashed), and the JWT session token stored in your browser’s localStorage.
- Consent state — the timestamp at which you acknowledged this policy, stored in localStorage under safm.consent.v1.
- Optional marketing data — if you opt in through the Inner Circle newsletter form, your email is stored in a separate newsletter_leads collection.
Why we process it (POPIA s11 justification)
- Performance of a contract — to provide the service you signed up for: matching Buyers to Sellers, processing payment, dispatching parcels, holding escrow.
- Legal obligation — to comply with the Consumer Protection Act, tax legislation, the Financial Intelligence Centre Act (FICA) for seller KYC, and law-enforcement requests.
- Legitimate interest — to prevent fraud, detect abuse, secure the Platform against attack, and audit administrator actions on sensitive data.
- Consent — for the newsletter, we rely exclusively on your explicit opt-in. You may withdraw at any time by clicking Unsubscribe in any newsletter email.
Who sees what
- Sellers see the Buyer name, delivery address, order metadata (and measurements for custom orders) only for orders placed with them specifically. Sellers do not see each other’s data.
- SA Fashion Mall administrators see order-level data for dispute resolution, verification review and fraud investigation. Access to decrypted KYC identifier fields is audit-logged with a signed-URL trail (retention 24 months).
- Third-party couriers receive the delivery name, address and phone number — the minimum needed to dispatch the parcel.
- At checkout, our secure third-party payment processor receives the amount, currency, order reference and email address. SAFM does not see raw card numbers, CVVs or online-banking credentials.
- We do NOT sell, rent or trade your personal information with anyone.
Third-party operators
- Amazon Web Services (AWS S3, eu-west-1 by default) — encrypted-at-rest storage for product images, KYC documents, tailor portfolios and Seller logos. Access via signed short-lived URLs only. Cross-border processing consent covered under POPIA s72 (Ireland has a valid GDPR framework; AWS operates under the standard contractual clauses).
- MongoDB Atlas — encrypted-at-rest primary datastore for all account, order and marketplace data. Data is hosted in a South African region where available; the fallback region is EU-West with SCCs applied.
- Payment services — provided by our secure third-party payment processor, a licensed South African payment services provider that handles card, EFT and instant-pay transactions on our behalf under its own privacy policy.
- Resend — transactional email delivery (welcome + verification, dispute updates, payout confirmations). Emails carry your name and order references only.
- ip-api.com — keyless IP → city/province lookup used for seller-registration fraud checks. The IP address is sent; no other data.
- OpenAI GPT-4o (via Emergent LLM key) — used server-side for image QC (verifying that Seller product images are on-topic) and admin AI Studio tools. No Buyer personal information is sent to OpenAI; only image URLs and Seller-provided listing text.
Every third party is bound to us by a written operator agreement obliging them to process the information only for the purposes we set, apply appropriate security safeguards, and notify us promptly of any personal-information breach.
Cross-border processing
Some of our operators (AWS, Resend, OpenAI) are located outside South Africa. In accordance with POPIA section 72, we only transfer personal information to jurisdictions that either (a) provide an adequate level of protection recognised by the Information Regulator, or (b) are contractually bound by binding rules substantially similar to POPIA. All our current operators are located in the European Union (governed by GDPR) or the United States (bound by standard contractual clauses). Where you place an order that requires an operator not on this list, we obtain your consent first.
How long we keep it (retention)
- Account records — for as long as your account is active, plus 2 years after closure to satisfy CPA record-keeping obligations.
- Order records (including tailor measurements) — 2 years post-completion; then anonymised.
- Bank / payout details — 5 years for tax compliance; then destroyed.
- Encrypted KYC identifier fields — for the life of the Seller account plus 3 years, per FICA record-keeping duties.
- Audit-log entries (admin access to KYC, dispute resolution decisions) — 5 years.
- Newsletter emails — until you unsubscribe; then destroyed.
- Purged accounts — email anonymised to a .local placeholder, account_status flipped to Purged; personally identifying fields (phone, address, sizing profile) are cleared immediately.
Your POPIA rights
- The right to be informed — the entirety of this policy is that right in action.
- The right of access — request a copy of everything we hold about you using GET /api/me/export (a self-service tool in your Account Profile), or by email. We answer within 30 calendar days.
- The right to correction — most fields are editable directly from /account/profile. Fields that require verification (email, phone) go through a confirm-code flow.
- The right to erasure — delete your account any time from Account Security. We honour deletion subject to open-order and legal retention obligations (bank details, tax records, audit log).
- The right to object to processing — for legitimate-interest processing (fraud analytics) you may object; we’ll assess and respond in writing.
- The right to withdraw consent — for newsletter (Unsubscribe link) and any other consent-based processing.
- The right to lodge a complaint — with the Information Regulator (South Africa), whose contact details are below.
Information Regulator (South Africa) — JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · inforegulator.org.za · POPIAComplaints@inforegulator.org.za.
Cookies & local storage
SA Fashion Mall does not use tracking cookies or third-party analytics scripts (no Google Analytics, no Facebook Pixel, no Hotjar). We use browser localStorage only for:
- Your JWT session token — required for you to stay signed in.
- The POPIA notice acknowledgement flag (safm.consent.v1).
- Short-lived UI preferences — last-viewed category, admin sidebar accordion state, the current admin/support tab.
- The offline vendor inventory queue — stock edits queued while offline are held in IndexedDB and sync on reconnect.
Clearing your browser storage signs you out and re-shows the privacy banner — nothing else is affected.
Security
- Passwords — one-way hashed with bcrypt (cost factor 12). We never see the plaintext.
- Session tokens — signed JWTs, short-lived (24 hours access, 30 days refresh); revocable server-side via /api/auth/logout.
- KYC identifier fields — SA-ID or passport, date of birth, residential address, phone — encrypted at rest with AES-256-GCM using an application-scoped key held outside the database.
- Transport — TLS 1.2+ enforced on all endpoints. HSTS enabled.
- Two-factor authentication — available for all roles; mandatory for Admin.
- Rate limiting — authentication, support ticket submission, custom-order brief submission, and other sensitive endpoints are rate-limited to defeat brute-force and spam.
- Audit logging — every admin access to encrypted KYC and every dispute resolution is written to an immutable audit log.
- Breach notification — in the event of a personal-information compromise, we notify the Information Regulator and affected data subjects as soon as reasonably possible, per POPIA s22.
Children
SA Fashion Mall is not directed at children under 18. We do not knowingly collect personal information from a child without the consent of a competent person (parent or guardian) as required by POPIA s34. If you believe we have collected such information, email privacy@safashionmall.co.za and we will delete it promptly.
Changes to this policy
Material changes are announced in-app with the updated “Last updated” date at the top of this page. Continued use of the Platform after the effective date is deemed acceptance. If a change materially reduces your rights, we’ll ask for explicit consent before applying it to your account.
