1) Who we are (Responsible Party)
Responsible Party: The Dog Food App (Pty) Ltd
Registered in: South Africa
Registered address: PO BOX 313, Newlands 7735
Contact: privacy@thedogfoodapp.co.za
2) What we collect
We collect information in three ways: (a) provided by you; (b) collected automatically; (c) received from third parties.
Information you provide
Account details (name, email, phone number, password).
Delivery/ billing addresses.
Order history, preferences, wishlists, store credit/redemption details.
Communications with us (support chats, emails, reviews).
Pet profiles or notes you choose to save.
Consents and marketing preferences.
Payments
We do not store full card numbers. Payments are processed by our payment provider(s) (e.g., PayFast). They may provide us with limited information such as tokenised references, last 4 digits, and status (paid/failed/refunded).
Automatically collected
Device and app data (model, OS, app version, language, time zone).
Log and usage data (pages/screens viewed, buttons tapped, in-app events, crash reports).
IP address and general location; precise location only if you grant permission (for delivery or local offers).
Cookies and similar technologies on our website.
From third parties
Analytics and attribution partners (e.g., deep-link providers).
Delivery and fulfilment partners (status updates).
Identity or anti-fraud providers (when applicable).
We do not intentionally collect information about children (under 18). If you believe we have, please contact us to delete it or obtain the required consent of a competent person.
3) How we use your information (purposes & lawful bases)
We process personal information for the following purposes, relying on one or more lawful bases under POPIA:
Provide the Services & fulfil contracts: create/manage your account, process orders, deliver products, handle returns and support.
Payments: process and reconcile payments, store credits and refunds via our processors. (Contract; Legal obligation.)
Communications: send order updates, service messages, support responses. (Legitimate interests; Contract.)
Personalisation: remember preferences, recommend products. (Legitimate interests; Consent where required.)
Marketing: send promotions and offers via email/push/SMS when permitted. You can opt out anytime. (Consent; or Legitimate interests with opt-out.)
Security & fraud prevention: detect, prevent or investigate fraud, abuse or violations of terms. (Legitimate interests; Legal obligation.)
Analytics & improvement: monitor usage, fix bugs, improve performance and features. (Legitimate interests.)
Legal compliance: keep records required by tax, financial and consumer laws. (Legal obligation.)
Where we rely on consent, you may withdraw it at any time (this won’t affect processing already carried out).
4) Sharing your information
We share personal information only as necessary for the purposes above:
Service providers/Operators: hosting, customer support, analytics, push notifications, deep-link/short-link providers, delivery and payment processors (e.g., PayFast). They process information under written agreements and may not use it for their own purposes.
Business transfers: in a merger, acquisition or asset sale, subject to safeguards and notice.
Legal: to comply with law, enforce our terms, or protect rights, safety and property.
We do not sell your personal information.
5) Cross-border transfers
Some service providers are located outside South Africa. When we transfer information internationally, we use lawful mechanisms and safeguards consistent with POPIA (e.g., contractual clauses, processor undertakings, comparable protection in the recipient country). You can contact us for details of current safeguards.
6) Security
We use administrative, technical and organisational measures designed to protect personal information, including encryption in transit, access controls and regular monitoring. No method of transmission or storage is 100% secure; if we become aware of a material security compromise, we will take steps required by law to notify you and the Information Regulator when applicable.
7) Retention
We keep personal information only as long as needed for the purposes set out above, including:
Order and tax records: typically 5 years (or longer if law requires).
Account data: for the life of your account and a reasonable period after closure.
Logs/analytics: for operational periods necessary to analyse and improve the Services.
We then delete or irreversibly de-identify the data.
8) Your rights (POPIA)
You have the right to:
Access your personal information.
Correct inaccurate, irrelevant, excessive, out-of-date or incomplete information.
Delete information where POPIA allows (e.g., where we no longer need it or consent is withdrawn and no other lawful ground applies).
Object to certain processing (including direct marketing) and request restriction.
Withdraw consent at any time where processing is based on consent.
Complain to the Information Regulator (South Africa) if you believe your rights are infringed (see Section 12).