Privacy Policy

Last updated: 31 October 2025

1. Introduction

At Caarl, we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your data in compliance with the Protection of Personal Information Act (POPIA) and other applicable South African laws.

2. Information We Collect

We collect the following types of information:

Personal Information:

  • Name and surname
  • Email address
  • Phone number
  • Delivery address
  • Payment information (processed securely through Paystack)

Account Information:

  • Username and password (encrypted)
  • Order history
  • Wishlist and saved items
  • Product reviews and ratings

Technical Information:

  • IP address
  • Browser type and version
  • Device information
  • Cookies and similar technologies
  • Pages visited and time spent on site

3. How We Use Your Information

We use your information for the following purposes:

  • Processing and fulfilling your orders
  • Communicating with you about your orders and account
  • Providing customer support
  • Improving our website and services
  • Personalizing your shopping experience
  • Sending promotional emails (with your consent)
  • Preventing fraud and ensuring security
  • Complying with legal obligations

4. Cookies

We use cookies and similar technologies to enhance your experience on our website. Cookies are small text files stored on your device that help us:

  • Remember your preferences and settings
  • Keep you logged in to your account
  • Analyze website traffic and usage patterns
  • Provide personalized content and recommendations

You can control cookies through your browser settings. However, disabling cookies may affect your ability to use certain features of our website.

5. Information Sharing

We do not sell your personal information to third parties. We may share your information with:

  • Service Providers: Paystack (payment processing), Courier Guy and Pudo (delivery), Cloudinary (image hosting)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In the event of a merger, acquisition, or sale of assets

All third-party service providers are required to protect your information and use it only for the purposes we specify.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Secure Socket Layer (SSL) encryption for data transmission
  • Encrypted password storage
  • Regular security audits and updates
  • Access controls and authentication
  • Secure cloud storage with Supabase

However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights (POPIA Compliance)

Under the Protection of Personal Information Act, you have the right to:

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal information
  • Objection: Object to processing of your information
  • Portability: Request transfer of your data to another service
  • Withdraw Consent: Opt-out of marketing communications

To exercise these rights, please contact us at privacy@caarl.co.za

8. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations (e.g., tax records for 5 years)
  • Resolve disputes and enforce our agreements

When your information is no longer needed, we securely delete or anonymize it.

9. Children's Privacy

Our website is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. International Transfers

Your information may be transferred to and stored on servers located outside South Africa. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws.

11. Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email. Your continued use of our website after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:

  • Email: privacy@caarl.co.za
  • Phone: +27 XX XXX XXXX
  • Address: [Your Business Address]

Information Officer: [Name]
Email: info.officer@caarl.co.za