This policy explains how Todae (TODAE, “we”, “us”) processes your personal information when you browse our store, request a quote, place an order, contact us, or use any related service. We are the responsible party for that information under POPIA.
1. Who we are & our Information Officer
TODAE (registration number 2026/563609/07), trading as Todae, of 52 Berrydel Avenue, Somerset West, Cape Town, Western Cape, 7130.
Our appointed Information Officer is [Information Officer name — to be appointed]. You can reach the Information Officer for any privacy question, request or complaint at info@todae.net.
2. The personal information we collect
Depending on how you use the store, we may process:
- Identity & contact information — your name, email address, phone number and, for businesses, company name and VAT/registration number.
- Order & delivery information — delivery and billing addresses, the items you buy, order history and your chosen customer type (e.g. installer, integrator, end-customer).
- Payment information — payment method and transaction references. Card details are entered directly with our payment gateway and are never stored on our systems.
- Returns & warranty information — the details and any photographs you submit when you log a return or warranty claim.
- Support & communications — messages you send us and our replies.
- Technical information — device, browser and approximate location (from your network) used to keep the site secure and, where you have consented, to measure how the store is used. Our shopping analytics use a random session token that does not identify you personally.
We do not seek to collect special personal information (such as health or biometric data) through the store.
3. Why we process it, and our lawful basis
We process your information only where POPIA allows it, namely to:
- take, fulfil and deliver your orders and quotes, and administer returns, warranties and refunds — necessary to perform our contract with you;
- issue tax invoices and keep accounting and tax records — to comply with a legal obligation (including the Value-Added Tax Act and the Companies Act);
- provide support, prevent fraud, secure our systems, and measure how the store is used with a first-party random session token that does not identify you and builds no profile — our legitimate interests, balanced against your rights;
- send you service messages about your orders — necessary for the contract; and
- send you marketing, or set non-essential third-party analytics or advertising cookies — only with your consent, which you may withdraw at any time.
4. Who we share your information with
We share personal information only as needed to run the store, with:
- payment gateways to process and reconcile payments;
- couriers and collection partners to deliver your order (name, delivery address and contact number);
- our IT, database, email and analytics service providers acting as operators on our written instruction;
- certified installers in our network — only where you request installation, and limited to what they need to perform the job; and
- professional advisers, or authorities, where the law requires it.
We do not sell your personal information.
5. Cross-border transfers (POPIA section 72)
Some of our service providers store or process information on servers outside South Africa. In particular:
- Supabase — Application database, authentication and file storage.
- Stripe — Card payments (subscriptions and future US orders).
- PayFast (Network9 / Payfast by Network) — South African payment gateway.
- Resend — Transactional and lifecycle email delivery.
Where information is transferred outside the Republic, we do so on a basis permitted by section 72 of POPIA — typically because the recipient is bound by laws or binding agreements that provide an adequate level of protection comparable to POPIA, or because the transfer is necessary to perform our contract with you.
6. How long we keep your information
We keep personal information only as long as necessary for the purpose it was collected, unless the law requires longer. Tax and accounting records (including invoices) are retained for at least five years as required by South African tax law. Order, warranty and dispute records are kept for as long as needed to support consumer-law obligations. When information is no longer needed, we delete or de-identify it.
7. How we protect your information
We take reasonable technical and organisational measures to secure personal information, including encryption in transit, access controls, and using reputable processors. No system is perfectly secure, but we work to protect your information against loss, unauthorised access and misuse.
8. Your rights as a data subject
Under POPIA you have the right to:
- be told what personal information we hold about you and to receive a copy of it;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive or out of date;
- object, on reasonable grounds, to processing based on our legitimate interests;
- withdraw a consent you previously gave (this does not affect processing already carried out);
- not be subject to a decision based solely on automated processing that significantly affects you; and
- complain to the Information Regulator (see below).
To exercise any of these, email our Information Officer at info@todae.net. We may need to verify your identity first. Formal access requests are handled under our PAIA manual.
9. Direct marketing
We only send electronic marketing where you have opted in, or as otherwise permitted by law to our existing customers about similar products. Every marketing message includes an unsubscribe link, and you can opt out at any time by using that link or emailing info@todae.net. Newsletter sign-ups use double opt-in — we only add you once you confirm.
10. Cookies & analytics
We use cookies and similar technologies that are strictly necessary to run the site (for example, to keep you signed in and to remember your cart). To understand how the store is used so we can improve it, we record basic, first-party usage events against a random session token that does not identify you and is not used to build a profile of you — we rely on our legitimate interests for this limited, privacy-preserving measurement, and you may object at any time. Any non-essential third-party analytics or advertising cookies are set only with your consent, which you can manage through the consent banner or your browser settings.
11. Children
The store is intended for business and adult consumers. We do not knowingly collect the personal information of children without the consent of a competent person. If you believe we have, please contact our Information Officer and we will delete it.
12. Security compromises
If a security compromise affects your personal information, we will notify the Information Regulator and you as soon as reasonably possible after becoming aware of it, as required by section 22 of POPIA, and tell you what happened and what you can do to protect yourself.
13. Complaints
Please raise any concern with our Information Officer first so we can put it right. You also have the right to complain to the supervisory authority:
Information Regulator (South Africa)
Website: https://inforegulator.org.za
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
If you are in the United States, please also see our US privacy notice, which sits alongside this policy.
We may update this policy from time to time. The “last updated” date above shows when it last changed; material changes will be highlighted on this page.