Privacy Policy
Last updated: 24 June 2026
This Privacy Policy explains how Shelfie ("Shelfie", "we", "us") collects, uses, discloses and protects personal information when you use the Shelfie platform — a retail point-of-sale, stock-management and field-service application for South African businesses. It is written with the Protection of Personal Information Act, 2013 ("POPIA") in mind. For a focused POPIA disclosure, see our POPIA Disclosure.
1. Who is responsible for your information
Shelfie acts in two distinct roles, and which role applies determines who is responsible for the information:
- As responsible party (controller). For the account and billing information of the business owners and staff who sign up for Shelfie, Shelfie is the responsible party and decides why and how that information is processed.
- As operator (processor). For the customer and transaction data that a business captures inside Shelfie — its own customers' names, contact details, orders, invoices and WhatsApp conversations — the business is the responsible party. Shelfie processes that data on the business's behalf, under its instructions, to provide the service. If you are a customer of a business that uses Shelfie, please direct data-subject requests to that business in the first instance.
2. Information we collect
2.1 Account and billing information (Shelfie as responsible party)
- Business owner and staff names, email addresses and roles.
- The owner's billing email and subscription/payment status.
- Authentication data (hashed passwords, session and device information, IP address and user-agent).
- Support correspondence you send us.
2.2 Customer and transaction data (Shelfie as operator for the business)
- The business's customer names, phone numbers, email addresses and physical/delivery addresses.
- WhatsApp messages exchanged between the business and its customers through the platform, including order conversations and attachments.
- Quotes, invoices, orders, payments and field-service job records.
- Product catalogue, stock levels and stock-movement history.
2.3 Technical information
- Log data, error reports and basic usage analytics needed to operate, secure and improve the service.
- Cookies strictly necessary for authentication and language preferences.
Shelfie does not store full card numbers. Card and EFT payments are handled by our payment providers on their own secure, PCI-DSS-compliant infrastructure (see section 5).
3. Why we process your information (lawful basis)
- To provide the service — performance of the contract between Shelfie and the business, and between the business and its customers.
- To bill and take payment — managing subscriptions and processing payments.
- To secure the service — authentication, fraud prevention and audit logging (legitimate interest).
- To support and improve the product — responding to queries and diagnosing faults.
- To meet legal obligations — e.g. tax and accounting record-keeping.
4. How long we keep it (retention)
We keep personal information only for as long as necessary for the purposes above or as required by law. A summary schedule:
| Category | Retention |
|---|---|
| Account & staff records | For the life of the account, then deleted or anonymised within 90 days of account closure (unless a longer legal period applies). |
| Customer, order, invoice & job records | Retained while the business's account is active; financial records kept for at least 5 years to meet tax/accounting obligations. |
| WhatsApp message history | Retained while the account is active to maintain the order conversation; deleted with the account. |
| Authentication & security logs | Typically up to 12 months. |
| Backups | Rolling backups expire on a short cycle; deleted records age out of backups as the cycle rotates. |
5. Third parties and sub-processors
We share information with a small set of service providers who process it on our behalf to run the platform. We require each to protect the information and use it only for the agreed purpose.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Paystack | Billing & collection of the Shelfie platform subscription | Owner billing email, subscription/payment details |
| iKhokha | Card & EFT payments made by a business's own customers | Payer name/email, payment amount and reference |
| Twilio | Sending and receiving WhatsApp messages | Customer phone numbers and message content |
| Hosting & backup provider | Application hosting, storage and encrypted backups | All platform data, at rest and in transit |
| Error-monitoring provider | Diagnosing faults and securing the service | Technical logs and limited request metadata |
Some of these providers, or their infrastructure and backups, may be located outside South Africa. See cross-border processing in our POPIA disclosure. We do not sell your personal information.
6. Your rights as a data subject
Under POPIA you have the right to:
- Be told whether we hold information about you, and to access it.
- Request correction or deletion of inaccurate, irrelevant, excessive or unlawfully obtained information.
- Object, on reasonable grounds, to the processing of your information.
- Object to direct marketing and withdraw any consent you have given.
- Lodge a complaint with the Information Regulator (South Africa).
To exercise these rights, contact our Information Officer (section 7). If your information was captured by a business that uses Shelfie, contact that business; we will assist them as their operator.
7. Information Officer & contact
Information Officer: [Name / role — to be completed before go-live]
Email: [privacy@shelfie.co.za — to be confirmed]
Postal address: [Registered business address — to be completed]
You may also contact the Information Regulator of South Africa (inforegulator.org.za).
8. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the platform or by email. The "Last updated" date above reflects the most recent revision.