POPIA Disclosure
Last updated: 24 June 2026
This disclosure summarises how Shelfie processes personal information in line with the Protection of Personal Information Act, 2013 ("POPIA"). It supplements, and should be read with, our Privacy Policy, which describes in full what we collect, who we share it with, and your rights.
1. Roles under POPIA
- For Shelfie account and billing information, Shelfie is the responsible party.
- For the customer and transaction data a business captures inside Shelfie, the business is the responsible party and Shelfie is its operator, processing that data only on the business's documented instructions.
2. Lawful basis for processing
We process personal information on the following bases recognised by POPIA:
- Performance of a contract — to provide the Service to businesses and to enable businesses to serve their own customers.
- Compliance with a legal obligation — e.g. retaining financial records for tax and accounting purposes.
- Legitimate interests — securing the platform, preventing fraud and abuse, and maintaining audit logs, balanced against data subjects' rights.
- Consent — where consent is the appropriate basis (for example, certain direct communications), it is obtained and can be withdrawn.
3. Cross-border processing
Some of our sub-processors, and the infrastructure or backups they operate, may be located outside the Republic of South Africa. Where personal information is transferred across borders, we take steps consistent with section 72 of POPIA — relying on recipients being subject to laws or binding agreements that provide an adequate level of protection, on the transfer being necessary to perform the contract, or on consent where appropriate.
In particular, encrypted backups may be stored with a hosting/backup provider whose data centres are located outside South Africa. Backups are encrypted and access-controlled.
4. Sub-processors
We use a limited set of sub-processors (Paystack for subscription billing, iKhokha for customer payments, Twilio for WhatsApp messaging, and our hosting/backup and error-monitoring providers). The current list, with purposes and data involved, is maintained in our Privacy Policy.
5. Retention schedule
| Category | Retention |
|---|---|
| Account & staff records | Life of the account; deleted or anonymised within 90 days of closure unless law requires longer. |
| Customer, order, invoice & job records | While the account is active; financial records kept at least 5 years for tax/accounting compliance. |
| WhatsApp message history | While the account is active; deleted with the account. |
| Authentication & security logs | Up to 12 months. |
| Backups | Short rolling cycle; deleted records age out as the cycle rotates. |
6. Security measures
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and encryption of backups at rest.
- Hashed and salted passwords; no plaintext credential storage.
- Strict multi-tenant isolation so each business only sees its own data, enforced by access policies.
- Role-based access control for staff within a business.
- Rate limiting and abuse controls on public, token-gated endpoints.
- No storage of full card numbers — card and EFT handling is delegated to PCI-DSS-compliant payment providers.
- Audit logging of security-relevant events and error monitoring.
7. Data-subject participation
Data subjects may request access to, correction or deletion of their personal information, and may object to processing, as set out in our Privacy Policy. Requests relating to data captured by a business that uses Shelfie should be directed to that business; we will assist as their operator.
8. Information Officer & the Regulator
Information Officer: [Name / role — to be completed before go-live]
Email: [privacy@shelfie.co.za — to be confirmed]
You have the right to lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.