Vintage808 · Legal

Privacy Policy

Last updated: April 2025 · Compliant with POPIA (Act 4 of 2013)

Contents
  1. Who we are
  2. What information we collect
  3. How we use your information
  4. Who we share your information with
  5. How we store and protect your data
  6. How long we keep your data
  7. Your rights under POPIA
  8. Cookies
  9. Children's privacy
  10. Changes to this policy
  11. Contact & complaints
01

Who We Are

Vintage808 operates the website vintage808.co.za. We are the responsible party (as defined in POPIA) for personal information collected through this website.

02

What Information We Collect

We collect information you provide directly when you:

  • Create an account (name, email address, password)
  • Place an order (name, email, phone number, delivery address)
  • Contact us via the contact form (name, email, message)

We also collect information automatically when you use our website:

  • IP address and approximate location
  • Browser type and device information
  • Pages visited and time spent on the site
  • Referring URL

We do not store your payment card details. All payments are processed securely by PayFast. We only receive a transaction reference number confirming payment.

03

How We Use Your Information

We use your information for the following purposes:

  • Order fulfilment — processing your order, arranging delivery, and sending order status updates
  • Account management — creating and managing your Vintage808 account
  • Customer support — responding to your queries and resolving complaints
  • Transactional emails — order confirmations, shipping notifications, password reset codes
  • Legal compliance — meeting our obligations under South African law
  • Fraud prevention — detecting and preventing fraudulent transactions

We do not sell your personal information to third parties. We do not send marketing emails without your consent.

04

Who We Share Your Information With

We share your information only where necessary to operate our business:

  • PayFast — to process your payment. Your name and email are shared with PayFast as required by their platform. See PayFast's Privacy Policy.
  • Courier partners (The Courier Guy, Pargo, etc.) — your name, address, and phone number are shared with our courier to deliver your order.
  • Resend — our transactional email provider. Your email address is used to send you order and account emails.
  • MongoDB Atlas — our database provider, where your account and order data is securely stored.
  • Vercel — our hosting provider.

All third-party providers are required to process your data securely and only for the purposes we specify.

We may disclose your information if required to do so by law, or in response to a valid legal request from a public authority.

05

How We Store and Protect Your Data

Your data is stored on MongoDB Atlas servers. Access is restricted to authorised personnel only and protected by strong authentication.

Passwords are hashed using bcrypt and are never stored in plain text. Payment details are never stored on our servers.

While we take all reasonable precautions, no system is 100% secure. If you suspect unauthorised access to your account, contact us immediately at customersupport@vintage808info.com.

06

How Long We Keep Your Data

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including:

  • Account data — kept for as long as your account is active. You may request deletion at any time.
  • Order records — kept for 5 years to meet South African tax and accounting requirements.
  • Contact form submissions — kept for 12 months.

When data is no longer required, we securely delete it.

07

Your Rights Under POPIA

Under the Protection of Personal Information Act 4 of 2013 (POPIA), you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request that we correct inaccurate or incomplete information
  • Deletion — request that we delete your personal information (subject to legal retention obligations)
  • Objection — object to the processing of your personal information
  • Complaint — lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, email us at customersupport@vintage808info.com with the subject line "POPIA Data Request". We will respond within 30 days.

To lodge a complaint with the Information Regulator: inforeg@justice.gov.za · www.justice.gov.za/inforeg

08

Cookies

We use browser localStorage to store your login session token and cart data locally on your device. This data does not leave your device unless you make a request to our servers.

We do not currently use third-party advertising or tracking cookies. If this changes, this policy will be updated.

09

Children's Privacy

Our website is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

10

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. For significant changes, we will notify you by email or by placing a notice on our website.

Continued use of our website after changes are posted constitutes your acceptance of the updated policy.

Questions about your privacy?

Contact our information officer at customersupport@vintage808info.com.

To lodge a complaint with South Africa's Information Regulator:
inforeg@justice.gov.za · www.justice.gov.za/inforeg