Privacy notice
Last updated: . Version 2026-10-09.
Who we are
This notice explains how Vleis & Co. ("we", "us"), handles your personal information when you use our website and ordering service. We are the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA).
Our Information Officer is responsible for making sure we follow POPIA:
What we collect and whether you must give it
We only ask for what we need to take your order and deliver it. We do not have customer accounts. You can order as a guest.
| Information | When we collect it | Must you give it? |
|---|---|---|
| Name, email address and phone number | At checkout, on a special order request, when you report a problem, or when you send a privacy request | Yes for an order. We cannot take or deliver an order without them. |
| Delivery address, suburb and postcode | At checkout when you choose delivery | Yes for delivery. Not needed if you collect. |
| What you ordered, the delivery slot, the price and payment status | When you place an order | Yes |
| Order notes and special request details (for example the cut you want, the number of people, the date you need it) | When you choose to type them | No. Please do not put health or religious details in notes beyond what the order needs. |
| Photos and a description of a problem with an order | When you report a problem | No. Needed only if you want us to assess a claim. |
| Payment reference and result | From PayFast after you pay | Yes for online payment. We never see or store your card or bank login details. |
| Your consent choices, and a scrambled (hashed) version of your IP address | When you accept the terms, choose marketing, or use the cookie banner | Yes for the terms. Marketing and cookies are your choice. |
| Your IP address, briefly | When you submit a form, sign in or use the cookie banner, so we can limit abuse | Automatic |
| Privacy request details | When you send a request | Only if you make a request |
We do not knowingly collect special personal information such as religion, health or biometric information. If you tell us something like that in a note, we use it only to fill your order.
Why we use your information and our lawful basis
POPIA allows us to use personal information only when there is a lawful reason. These are ours:
| Purpose | Lawful basis |
|---|---|
| Take, price, prepare, deliver and refund your order, and tell you how it is going | Needed to carry out the contract with you |
| Take payment through PayFast and match payments to orders | Needed to carry out the contract with you |
| Issue tax invoices and keep financial records | Required by law (tax and VAT legislation) |
| Handle problems, claims, refunds and complaints | Contract, and our legitimate interest in resolving disputes |
| Trace a product and warn you if a batch is recalled | Required by food safety law, and your legitimate interest in being warned |
| Protect the website and prevent fraud and abuse, including rate limiting | Our legitimate interest in security |
| Answer privacy requests and keep proof of how we handled them | Required by law |
| Keep proof of the terms you accepted and your marketing and cookie choices | Our legitimate interest in showing we followed the rules |
| Send you offers and news by email | Your consent only (see Direct marketing below) |
| Analytics and marketing cookies | Your consent only. We do not use them today. |
We do not use your order information to market to you unless you opted in. We do not sell personal information. We do not make decisions about you by automated means that have legal effect on you.
Sending information outside South Africa
Our database provider, Neon, hosts our database on Amazon Web Services in the United States (US East, N. Virginia), because there is no South African region. Our website host and email provider may also process information in other countries, including the United States. Section 72 of POPIA allows this where the recipient is bound by law, a binding agreement or corporate rules that give substantially similar protection to POPIA, or where the transfer is needed to carry out your contract with us. We rely on each provider's data processing terms, which require that level of protection, and by placing an order you ask us to carry out the contract, which includes these transfers.
How long we keep it
We keep personal information only as long as we need it for the reason we collected it, or as long as the law requires. After that we delete or anonymise it.
| Information | How long |
|---|---|
| Orders, invoices, delivery details and payment references | 5 years from the date of the order (tax and VAT law requires at least 5). After that your name, email, phone and address are removed from the record by an automatic daily job. |
| Order notes | With the order record, 5 years |
| Special order requests and quotes | 5 years from the request, then deleted |
| Photos and details of problems and claims | 3 years from the claim, then deleted with the photo |
| Recall notices sent to you | 5 years from the recall, then deleted |
| Copies of emails we sent you (outbox) | 12 months, then the recipient address and message are removed |
| Consent records (terms, marketing, cookies) | 5 years from the date the choice was recorded, then deleted |
| Privacy requests and our replies | 3 years from the request, then deleted |
| Abuse-prevention records (IP address used for rate limiting) | 30 days |
| Your marketing opt-in | Until you withdraw it. Your withdrawal is then kept in the consent record above so we do not email you again. |
| Items stored in your own browser (cart, delivery choice and postcode, recent order references, cookie choice) | On your device until you clear them |
How we keep it safe
We take reasonable technical and organisational steps to protect personal information, as POPIA requires:
- Connections to the website are encrypted in transit, and the database is encrypted at rest by our host.
- Every database table is locked down so that only our server code can read it. Visitors cannot query it directly.
- Staff access to the admin area needs a password and a signed session that expires, with sign-in attempts limited.
- Staff changes are written to an audit log.
- We do not receive or store your card number. Payment happens on the PayFast page.
- Order tracking pages need a signed link or your email address, so one customer cannot open another customer's order.
- Our service providers are bound by written contracts to keep information confidential and secure.
Your rights
You have the right to:
- ask whether we hold personal information about you and get a copy of it;
- ask us to correct information that is wrong or out of date;
- ask us to delete information we no longer need or may not keep;
- object to us using your information for a purpose that relies on our legitimate interest;
- withdraw consent at any time, for example for marketing or non-essential cookies, without affecting what we did before you withdrew;
- complain to the Information Regulator.
To use these rights send a request through our privacy request form or write to the Information Officer above. We answer within 30 days and do not charge a fee. We will need to confirm that the request comes from you before we share or change anything. Some information, such as tax records, we must keep for the period in the retention table even if you ask us to delete it. We will tell you if that applies.
You can complain to the Information Regulator at [email protected] or through https://inforegulator.org.za. We would appreciate the chance to put things right first, so please also see our complaints process.
Direct marketing
We only send you marketing email if you tick the separate, unticked box at checkout or on a special request form that asks for it. That box is not required to order. Every marketing email has a one click unsubscribe link, and you can also use our privacy request form. Messages about your order, such as confirmations, delivery updates, refunds and recall notices, are not marketing and you will still receive them. We do not send marketing by SMS or WhatsApp.
Children
Our service is for people aged 18 and over. We do not knowingly collect information about children. If you think a child has given us personal information, tell us and we will delete it.
If something goes wrong
If we find that personal information has been accessed or acquired by someone who should not have it, we will notify the Information Regulator and the people affected as soon as reasonably possible, with enough detail for you to protect yourself. We keep a record of every incident and what we did about it.
Addendum for visitors in the EU and UK
We are a South African business. We sell in rand and deliver only in South Africa. We do not target customers in the European Union or the United Kingdom. If European or UK data protection law (the GDPR and the UK GDPR) nevertheless applies to you, this section applies as well.
- Our lawful bases are those in the table above: contract, legal obligation, legitimate interests and consent.
- You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. We answer within one month. Use the privacy request form.
- We transfer personal information to South Africa, which has no European adequacy decision, and to our providers under their data processing agreements and standard contractual clauses.
- You may complain to the data protection authority where you live, to the Information Commissioner's Office in the UK, or to the Information Regulator in South Africa.
- Cookies that are not strictly necessary are only set with your consent. Rejecting is as easy as accepting.
Changes to this notice
If we change this notice we update the date and version at the top. If the change is material, for example a new purpose, we will tell you before it applies to your information.