Privacy Policy

Privacy Policy

Introduction

DIY Connect ("we," "us," or "our") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and share your information when you use our multi-vendor e-commerce platform. This policy complies with the Protection of Personal Information Act (POPIA) and other applicable South African privacy laws.

By using DIY Connect, you consent to the collection and use of your information as described in this Privacy Policy.

Information We Collect

Personal Information

We collect the following personal information when you register, place orders, or use our platform:

  • Full name and surname

  • Email address

  • Phone number (mobile and landline)

  • Physical address (residential or business)

  • Delivery address (if different from physical address)

  • Date of birth (for age verification purposes)

  • Government-issued ID number (for high-value transactions or vendor registration)

Account Information

When you create an account:

  • Username and password (encrypted)

  • Account preferences and settings

  • Communication preferences

  • Profile information (optional)

Payment Information

Payment details collected during transactions:

  • Credit/debit card information (processed securely by third-party payment providers, not stored by DIY Connect)

  • Bank account details (for EFT payments and vendor payouts)

  • Billing address

  • Transaction history

Note: Complete credit card numbers are never stored on our servers. We use tokenization through PCI-compliant payment gateways.

Order and Transaction Information

When you make purchases:

  • Order history and details

  • Products purchased

  • Prices and payment amounts

  • Vendor information

  • Delivery tracking information

  • Returns and refunds history

Vendor Information

Additional information collected from vendors:

  • Business registration details

  • Tax registration numbers

  • Business bank account information

  • Product listings and inventory

  • Sales and financial records

  • Performance metrics

  • Communication with customers

Technical and Usage Information

Automatically collected when you use the platform:

  • IP address

  • Browser type and version

  • Device type and operating system

  • Pages visited and time spent on pages

  • Clickstream data

  • Referring website

  • Geographic location (approximate, based on IP address)

  • Cookies and similar tracking technologies

Communications

Information from your interactions with us:

  • Customer support inquiries and correspondence

  • Feedback and reviews

  • Survey responses

  • Messages sent through the platform messaging system

How We Use Your Information

We use your information for the following purposes:

Order Processing and Fulfillment

  • Processing and completing your orders

  • Communicating order status and delivery updates

  • Coordinating with vendors and courier services

  • Managing payments and refunds

  • Handling returns and exchanges

Account Management

  • Creating and managing your user account

  • Authenticating your identity

  • Personalizing your experience on the platform

  • Remembering your preferences and settings

Customer Service

  • Responding to inquiries and support requests

  • Resolving complaints and disputes

  • Providing technical assistance

  • Processing warranty claims

Platform Improvement

  • Analyzing usage patterns and trends

  • Improving platform functionality and user experience

  • Developing new features and services

  • Conducting research and analytics

  • Testing and troubleshooting

Marketing and Communications

With your consent:

  • Sending promotional emails and newsletters

  • Notifying you of special offers, sales, and new products

  • Providing personalized product recommendations

  • Conducting surveys and requesting feedback

You can opt out of marketing communications at any time using the unsubscribe link in emails or through your account settings.

Security and Fraud Prevention

  • Detecting and preventing fraudulent transactions

  • Protecting against unauthorized access

  • Enforcing our terms of service

  • Complying with legal obligations

  • Resolving disputes

Legal Compliance

  • Complying with applicable laws and regulations

  • Responding to legal requests and court orders

  • Protecting our legal rights and interests

  • Enforcing our policies

Information Sharing

We share your information only in the following circumstances:

With Vendors

When you place an order, we share necessary information with the vendor:

  • Your name

  • Delivery address

  • Contact phone number

  • Email address (for order updates)

  • Order details

Vendors may only use this information for order fulfillment and are prohibited from using it for marketing or other purposes without your consent.

With Service Providers

We work with third-party service providers who assist with:

  • Payment processing (payment gateways)

  • Delivery and logistics (courier companies)

  • Email services

  • Cloud hosting and data storage

  • Analytics and reporting

  • Customer support tools

  • Marketing platforms

These providers have access only to information necessary to perform their services and are contractually obligated to protect your data.

With Courier Services

We share necessary delivery information:

  • Recipient name

  • Delivery address

  • Contact number

  • Package details

For Legal Reasons

We may disclose information when required:

  • To comply with legal obligations or court orders

  • To protect our rights, property, or safety

  • To protect the rights, property, or safety of our users or the public

  • In connection with legal proceedings

  • To prevent fraud or criminal activity

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and provide options regarding your information.

With Your Consent

We may share information for other purposes with your explicit consent.

Information We Do Not Share

We do not:

  • Sell your personal information to third parties

  • Share your information for third-party marketing without your consent

  • Provide customer contact details to vendors for unsolicited marketing

  • Share sensitive payment information (handled by secure payment processors only)

Cookies and Tracking Technologies

What Are Cookies

Cookies are small text files stored on your device that help us provide and improve our services.

Types of Cookies We Use

Essential Cookies: Required for the platform to function properly (account authentication, shopping cart, security)

Performance Cookies: Help us understand how you use the platform to improve functionality

Functionality Cookies: Remember your preferences and settings

Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness (with your consent)

Managing Cookies

You can control cookies through your browser settings:

  • Block all cookies

  • Accept only specific cookies

  • Delete existing cookies

  • Receive notifications when cookies are set

Note: Blocking essential cookies may prevent certain platform features from working properly.

Data Security

We implement robust security measures to protect your information:

Technical Safeguards

  • SSL/TLS encryption for data transmission

  • Encrypted storage of sensitive information

  • Secure authentication systems

  • Regular security audits and testing

  • Firewalls and intrusion detection systems

  • Secure payment processing through PCI-compliant providers

Administrative Safeguards

  • Access controls limiting employee access to personal information

  • Staff training on data protection and privacy

  • Background checks for employees handling sensitive data

  • Incident response procedures

Physical Safeguards

  • Secure data centers with restricted access

  • Environmental controls protecting server infrastructure

  • Backup systems for data recovery

While we take extensive measures to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to maintain the highest security standards.

Data Retention

We retain your information for as long as necessary to:

  • Fulfill the purposes described in this policy

  • Comply with legal obligations (e.g., tax and accounting records)

  • Resolve disputes and enforce agreements

Specific retention periods:

  • Account information: Retained while account is active, plus 7 years after closure (for legal compliance)

  • Transaction records: 7 years (for tax and accounting purposes)

  • Marketing data: Until you unsubscribe or request deletion

  • Technical logs: 12-24 months

  • Cookies: Varies by type (see cookie settings)

After the retention period, we securely delete or anonymize your information.

Your Rights

Under POPIA and applicable privacy laws, you have the following rights:

Right to Access

You can request a copy of the personal information we hold about you.

Right to Correction

You can request correction of inaccurate or incomplete information.

Right to Deletion

You can request deletion of your information, subject to legal retention requirements.

Right to Object

You can object to processing of your information for marketing purposes.

Right to Restrict Processing

You can request restriction of how we process your information.

Right to Data Portability

You can request your information in a portable format to transfer to another service.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time.

Exercising Your Rights

To exercise these rights:

  • Log in to your account and update information directly

  • Contact our Data Protection Officer via email

  • Submit a formal request through our privacy request form

We will respond to requests within 30 days. Identity verification may be required for security purposes.

Children's Privacy

DIY Connect is not intended for children under 18 years of age. We do not knowingly collect personal information from minors. If you believe a child has provided information to us, please contact us immediately, and we will delete such information.

Third-Party Links

Our platform may contain links to third-party websites, plugins, or applications. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.

International Data Transfers

Your information is primarily stored and processed in South Africa. If we transfer data internationally, we ensure adequate safeguards are in place to protect your information in accordance with POPIA requirements.

Marketing Communications

Email Marketing

With your consent, we send:

  • Promotional offers and discounts

  • New product announcements

  • Personalized recommendations

  • Platform updates and newsletters

Opting Out

You can opt out at any time by:

  • Clicking "unsubscribe" in any marketing email

  • Updating preferences in your account settings

  • Contacting customer support

Opting out does not affect transactional emails (order confirmations, shipping updates, etc.) necessary for service delivery.

Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in:

  • Our practices

  • Legal requirements

  • Platform features

  • Technology

When we make material changes:

  • The updated policy will be posted on the platform

  • We will update the "Last Updated" date

  • We may notify you via email or platform notification

  • Continued use after changes constitutes acceptance

We encourage you to review this policy regularly to stay informed about how we protect your information.

Contact Us

For privacy-related questions, concerns, or requests:

General Inquiries

Use the "Contact Us" form on our platform or email our customer support team.

POPIA Complaints

If you believe we have not handled your information appropriately, you may lodge a complaint with:

Information Regulator (South Africa)

Website: www.justice.gov.za/inforeg/

Email: inforeg@justice.gov.za

We are committed to resolving any privacy concerns and will work with you to address issues promptly and fairly.


Last Updated: 1 December 2025

This Privacy Policy is effective as of the date listed above.