Privacy Policy
Last updated: 2 May 2026
POPI Act Compliance Notice
ShapShop is committed to protecting your personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA) of the Republic of South Africa. This policy explains how we collect, use, store and protect your personal information.
1. Who We Are
ShapShop is operated as a sole proprietorship trading as ShapShop, based in Mossel Bay, Western Cape, South Africa. We are in the process of registering as ShapShop (Pty) Ltd.
Information Officer
ShapShop
Mossel Bay, Western Cape, South Africa
hello@shapshop.online
2. Personal Information We Collect
We collect only what we need to provide the service:
- Account information: email address and password (hashed, never stored in plain text)
- Family profile: family size, weekly grocery budget, dietary preferences, cuisine preferences, disliked ingredients, cooking time preference, plan duration
- Usage data: meal plans generated, grocery comparisons viewed, subscription status
- Payment information: processed entirely by PayFast — we never store your card details
- Technical data: browser type, device type, IP address (collected by our infrastructure providers for security purposes)
We do not collect sensitive personal information such as race, health records, biometric data, or political views.
3. Why We Collect Your Information
Your information is used only for the following purposes:
- To create and manage your ShapShop account
- To generate personalised AI meal plans tailored to your household
- To compare grocery prices across South African retailers on your behalf
- To process subscription payments via PayFast
- To send transactional emails (account confirmation, password reset)
- To improve and maintain the service
We will never use your information for unsolicited marketing without your explicit consent.
4. How Long We Keep Your Information
- Account data: retained for as long as your account is active
- Meal plans: kept for 12 months then automatically deleted
- Payment records: kept for 5 years as required by South African tax law
- Deleted accounts: all personal data is removed within 30 days of account deletion
5. Who We Share Your Information With
We use the following trusted third-party processors. All are bound by their own privacy policies and applicable law:
Supabase
Secure database hosting for your account, profile and meal plan data
Anthropic
AI meal plan generation — your family profile is sent to their servers to generate meal suggestions. No data is retained beyond the API call.
PayFast
Subscription payment processing — we never see or store your card details
Vercel
Website hosting and infrastructure
We do not sell, rent or trade your personal information to any third party.
6. Your Rights Under POPIA
You have the right to:
- Access the personal information we hold about you
- Correct any inaccurate or outdated information
- Delete your account and all associated personal data
- Object to the processing of your personal information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, email us at hello@shapshop.online. We will respond within 30 days.
7. Cookies
ShapShop uses strictly necessary cookies only — these are required for authentication and keeping you logged in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can disable cookies in your browser settings, but the app will not function without them.
8. Security
We take reasonable technical and organisational measures to protect your personal information, including encrypted data transmission (HTTPS), hashed passwords, and row-level security on our database. No system is 100% secure — if you believe your account has been compromised, contact us immediately at hello@shapshop.online.
9. Information Regulator
If you believe we have not handled your personal information lawfully, you may contact:
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
complaints.IR@inforegulator.org.za
www.inforegulator.org.za
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Continued use of ShapShop after changes constitutes acceptance of the updated policy.