Privacy Statement
At Sassy, we respect your privacy and are committed to protecting your personal information. This Privacy Statement explains what personal information we collect, why we collect it, how we use it, who we may share it with, and what rights you have under the Protection of Personal Information Act, 4 of 2013, also known as POPIA.
By using our website, creating an account, placing an order, contacting us, or interacting with us, you agree that we may process your personal information as described in this Privacy Statement.
1. Personal information we collect
We may collect personal information that you provide to us directly, including:
- your name and surname;
- your email address;
- your mobile number;
- your physical delivery or billing address;
- your date of birth, where required;
- your account login details;
- order, payment and delivery information;
- communication records when you contact us;
- product ratings, reviews or feedback you choose to submit; and
- any other information you choose to provide to us.
We may also collect limited technical information when you use our website, such as your device information, browser type, IP address, website activity, cookies and similar usage data.
We will only collect personal information that is reasonably necessary for a specific, lawful business purpose.
2. Why we collect and use your personal information
We collect and use your personal information to:
- create and manage your customer account;
- process your orders and payments;
- arrange delivery, collection, returns, exchanges and warranty claims;
- communicate with you about your orders, enquiries or account;
- provide customer support;
- improve our website, products, services and customer experience;
- prevent fraud, unauthorised transactions or misuse of our website;
- comply with legal, accounting, tax, regulatory and record-keeping obligations;
- send you marketing communications where permitted by law or where you have given the required consent; and
- manage product ratings, reviews, promotions and competitions.
We will not use your personal information for a purpose that is unrelated to the reason it was collected, unless the law allows us to do so or you have given us permission.
3. Direct marketing
We may send you marketing communications about our products, promotions, special offers, new features or services where you have consented to receive them or where the law allows us to contact you.
You may opt out of marketing communications at any time by using the unsubscribe option in the communication or by contacting us directly.
Where POPIA requires your consent for direct marketing, we will request that consent in a clear and accessible way. We will not treat your failure to opt out as consent where express consent is legally required.
4. Cookies and website tracking
Our website uses cookies and similar technologies to improve your browsing experience, remember your preferences, understand how our website is used, improve website functionality, and, where applicable, show more relevant advertising.
Some cookies are necessary for the website to work properly. Other cookies may be used for analytics, performance or marketing purposes.
You can manage or disable cookies in your browser settings. Please note that some website features may not work properly if certain cookies are disabled.
Where legally required, we will request your consent before using cookies or similar technologies that process personal information for marketing or tracking purposes.
5. When we share your personal information
We do not sell your personal information.
We may share your personal information only where necessary and lawful, including with:
- our employees, contractors and authorised service providers;
- payment processors and fraud-prevention service providers;
- courier, delivery and logistics partners;
- technology, hosting, website and IT service providers;
- marketing and communication service providers, where permitted by law;
- suppliers or manufacturers where their involvement is needed for a product query, return, repair or warranty claim;
- third-party sellers, where applicable, for order fulfilment or invoicing purposes;
- professional advisers, auditors, insurers or legal representatives;
- law enforcement, regulators, government authorities or courts where required by law; and
- any other party where you have given consent or where the law allows us to do so.
Where we use third-party service providers, we require them to protect your personal information and to process it only for the services they provide to us.
6. Cross-border transfers
Some of our service providers may be located outside South Africa or may store information on systems hosted outside South Africa.
Where your personal information is transferred outside South Africa, we will take reasonable steps to ensure that it is protected in line with POPIA. This may include using appropriate contractual safeguards or confirming that the recipient is subject to privacy protections that are substantially similar to POPIA.
7. How we protect your personal information
We take reasonable and appropriate technical and organisational measures to protect your personal information against loss, misuse, unauthorised access, unlawful processing, alteration, disclosure or destruction.
These measures may include access controls, secure systems, confidentiality obligations, staff awareness, service-provider controls, and other safeguards appropriate to the nature of the personal information we process.
Although we take reasonable steps to protect your personal information, no website, system or electronic transmission is completely secure. We therefore cannot guarantee absolute security, but we will act promptly where we become aware of any unauthorised access, use or disclosure of personal information.
8. How long we keep your personal information
We will not keep your personal information for longer than necessary for the purpose for which it was collected, unless:
- we are required or allowed by law to keep it for a longer period;
- we need it for lawful business, tax, accounting, warranty, fraud-prevention, dispute-resolution or record-keeping purposes; or
- you have consented to us keeping it for longer.
When we no longer need your personal information, we will securely delete, destroy, de-identify or restrict access to it, where appropriate.
9. Your rights
Under POPIA, you have the right to:
- ask what personal information we hold about you;
- request access to your personal information;
- ask us to correct or update inaccurate, incomplete or outdated personal information;
- ask us to delete or destroy personal information where we are no longer legally allowed to keep it;
- object to the processing of your personal information in certain circumstances;
- withdraw consent where we rely on consent to process your personal information;
- opt out of direct marketing; and
- submit a complaint to the Information Regulator if you believe your personal information has been processed unlawfully.
We may need to verify your identity before actioning certain requests.
10. Keeping your information accurate
Please help us keep your personal information accurate and up to date. If your personal information changes, please update your account details or contact us so that we can update our records.
11. Product ratings and reviews
If you submit a product rating, review or feedback, we may display or use that content on our website, in newsletters, on social media, or in other marketing material.
We may display your first name with your rating or review, but we will not display your surname, email address, mobile number or contact details unless you have clearly agreed to this.
Please do not include personal information, private information or information about other people in a product review.
12. Children’s personal information
Our website and products are not intended for use by children without the involvement of a parent or legal guardian.
We will not knowingly collect or process personal information of children where parental or guardian consent is required, unless we have the required consent or the law allows us to do so.
13. Links to third-party websites
Our website may contain links to third-party websites, platforms or services.
We are not responsible for the privacy practices, security or content of third-party websites. If you visit a third-party website, you should read that website’s privacy policy before providing any personal information.
14. Information Officer and privacy requests
If you have any questions about this Privacy Statement, or if you want to exercise your rights under POPIA, please contact our Information Officer or privacy contact:
Business name: Sassy
Information Officer / Privacy Contact: Willem
Email: admin@sassystylebeauty.co.za
Telephone: +27 761332337
Address: Krugersdorp, South Africa
We will review and respond to privacy requests within a reasonable time and in accordance with POPIA.
15. Complaints
If you believe that we have not handled your personal information lawfully, please contact us first so that we can try to resolve your concern.
You also have the right to submit a complaint to the Information Regulator of South Africa.
16. Updates to this Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in the law, our business, our website, or how we process personal information.
The latest version will be made available on our website and will apply from the date it is published.