Privacy policy

Draft for legal review. This page is a placeholder structure only. It is not yet GreenLeafBaby's privacy policy and nothing on it is final.

1. Who we are

TODO(legal)Responsible party's registered name, registration number and address, and the Information Officer's contact details.

2. Personal information we collect

TODO(legal)Describe each category of personal information collected and whether supplying it is voluntary or mandatory.

Engineering notes for the reviewer

  • Waitlist (coming soon page): full name, email address, confirmation of being 18 or older, consent to this policy with a timestamp, and campaign (UTM) parameters from the link the visitor arrived on.
  • Age verification (full site): South African ID number and date of birth are checked in memory and are not stored or logged.
  • Vercel Web Analytics (production only) records cookieless, aggregated page views: page URL, referrer, country, browser, operating system and device type. It sets no cookies and does not identify individual visitors.
  • A signed cookie records successful age verification for 24 hours. The shopping cart is kept in the visitor's browser (localStorage) and is not sent to our servers.

3. Why we collect it

TODO(legal)The specific purposes for each category of information.

4. Lawful basis and consent

TODO(legal)The lawful basis for processing, how consent is obtained and recorded, and how it can be withdrawn.

5. Sharing and operators

TODO(legal)Which operators process information on our behalf (for example hosting and email providers) and any other recipients.

Engineering notes for the reviewer

  • Hosting and web analytics: Vercel.
  • Database: Supabase, hosted in the EU (Frankfurt, eu-central-1), so waitlist data is transferred outside South Africa. Only our server can read or write it. Email provider not chosen yet.

6. Cross-border transfers

TODO(legal)Whether information is transferred outside South Africa and the safeguards that apply.

7. How long we keep information

TODO(legal)Retention periods for each category and how information is destroyed.

8. Your rights

TODO(legal)Data subject rights (access, correction, deletion, objection) and how to exercise them.

9. Security

TODO(legal)A summary of the security safeguards in place and the process for notifying security compromises.

10. Children

TODO(legal)The position on personal information of children and minors.

11. Cookies and similar technologies

TODO(legal)Which cookies and browser storage are used and why.

12. Contact and complaints

TODO(legal)How to contact us about privacy, and the Information Regulator's details for complaints.

13. Changes to this policy

TODO(legal)How changes are communicated and the effective date.