Privacy Policy
Last updated: March 2026
1. Introduction
Welcome to Keovation Digital Store (https://keovationdigital.store). We are committed to protecting your personal information and your right to privacy in accordance with the Protection of Personal Information Act, 2013 (POPIA) and the Electronic Communications and Transactions Act, 2002 (ECT Act).
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our website, create an account, place orders, or otherwise interact with our services.
By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our website and services.
2. Responsible Party (ECT Act Section 43)
The responsible party for the processing of your personal information is:
- Trading name: Keovation Digital Store
- Operated by: Keovation Solutions
- Registration number: [COMPANY REGISTRATION NUMBER]
- VAT number: [VAT NUMBER]
- Physical address: WeWork, 155 West Street, Sandton, Johannesburg
- Email: support@keovationdigital.store
- Phone: support@keovationdigital.store
- Website: https://keovationdigital.store
3. Information Officer (POPIA Section 55)
In terms of Section 55 of POPIA, we have appointed an Information Officer who is responsible for ensuring compliance with POPIA and for handling all requests related to your personal information:
- Name: Ikaneng
- Email: support@keovationdigital.store
- Phone: support@keovationdigital.store
- Address: WeWork, 155 West Street, Sandton, Johannesburg
4. What Personal Information We Collect
We may collect the following categories of personal information:
4.1 Information You Provide Directly
- Identity information: Full name, email address, phone number
- Delivery information: Physical address, suburb, city, province, postal code
- Account information: Username, password (encrypted), account preferences
- Payment information: We do not store your credit card details directly. Payment is processed securely by PayFast. We may store transaction reference numbers and payment confirmation details.
- Communication records: Emails, support queries, and any other correspondence with us
4.2 Information Collected Automatically
- Device information: Browser type, operating system, screen resolution
- Network information: IP address, internet service provider
- Usage data: Pages visited, time spent on pages, click patterns, search queries
- Cookies and similar technologies: See Section 12 below
5. How We Collect Information
We collect personal information through the following means:
- Directly from you: When you create an account, place an order, subscribe to our newsletter, contact us, or otherwise provide information voluntarily
- Automatically: Through cookies, web analytics, and similar technologies when you browse our website
- From third parties: Payment confirmation from PayFast, delivery status updates from courier partners
6. Purpose of Collection
We collect and process your personal information for the following specific, explicitly defined, and legitimate purposes:
- Order fulfilment: Processing your orders, managing your account, and providing customer support
- Payment processing: Facilitating secure payment through PayFast
- Shipping and delivery: Providing your delivery details to our courier partners (Dawn Wing, Aramex, The Courier Guy, DPD Laser, RAM Hand-to-Hand) to deliver your orders
- Communication: Sending order confirmations, shipping updates, and responding to your enquiries
- Account management: Maintaining your user account and order history
- Website improvement: Analysing usage patterns to improve our website, products, and services
- Legal compliance: Complying with applicable laws, regulations, and legal processes, including tax and accounting obligations
- Fraud prevention: Detecting and preventing fraudulent transactions
7. Legal Basis for Processing
Under POPIA, we process your personal information based on one or more of the following lawful grounds:
- Consent (Section 11(1)(a)): Where you have given us explicit consent to process your information, such as subscribing to our newsletter or opting in to marketing communications
- Contractual necessity (Section 11(1)(b)): Where processing is necessary to fulfil a contract with you, such as processing your order and delivering goods
- Legal obligation (Section 11(1)(c)): Where we are required by law to process your information, such as tax records and financial reporting
- Legitimate interest (Section 11(1)(f)): Where processing is necessary for our legitimate interests, such as improving our services and preventing fraud, provided your rights are not overridden
8. Third Parties We Share With
We may share your personal information with the following categories of third parties, only to the extent necessary to provide our services:
- Payment processor — PayFast (Pty) Ltd: Your payment details are processed securely by PayFast. We share your name, email, and transaction amount. PayFast is a South African company and processes data within South Africa. See PayFast's Privacy Policy.
- Courier companies: We share your name, phone number, and delivery address with our courier partners (Dawn Wing, Aramex, The Courier Guy, DPD Laser, RAM Hand-to-Hand) solely for the purpose of delivering your order.
- Database hosting — SpacetimeDB: Our application data, including your account information, is hosted on SpacetimeDB's infrastructure. See Section 9 regarding cross-border transfers.
- Website hosting — Vercel: Our website is hosted on Vercel's global infrastructure.
We do not sell, rent, or trade your personal information to any third parties for their own marketing purposes.
9. Cross-Border Data Transfers
Some of the third-party services we use may store or process data outside of South Africa:
- SpacetimeDB: Our database is hosted on SpacetimeDB's cloud infrastructure, which may have servers located outside South Africa
- Vercel: Our website is hosted on Vercel's global edge network, which includes servers outside South Africa
- PayFast: Processes payment data within South Africa
Where your personal information is transferred outside of South Africa, we ensure that adequate safeguards are in place in accordance with Section 72 of POPIA, including that the recipient country has adequate data protection legislation, or that the transfer is necessary for the performance of a contract between you and us (Section 72(1)(a)).
10. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law:
- Account data: Retained for as long as your account is active. You may request deletion of your account at any time.
- Order and transaction records: Retained for a minimum of 5 years as required by the Tax Administration Act and Companies Act
- Communication records: Retained for 3 years from the date of the communication
- Browsing and analytics data: Retained for up to 2 years
- Marketing consent records: Retained for the duration of the consent plus 1 year after withdrawal
When personal information is no longer required, we will securely delete or de-identify it so that it can no longer be associated with you.
11. Your Rights Under POPIA
As a data subject under POPIA, you have the following rights regarding your personal information:
- Right of access (Section 23): You may request confirmation that we hold your personal information, and request a copy of it
- Right to correction (Section 24): You may request that we correct or update inaccurate, incomplete, or misleading personal information
- Right to deletion (Section 24): You may request that we delete your personal information where it is no longer necessary for the purpose for which it was collected
- Right to object (Section 11(3)(a)): You may object to the processing of your personal information on reasonable grounds
- Right to object to direct marketing (Section 69): You may object to receiving direct marketing communications at any time
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal
- Right to complain: You may lodge a complaint with the Information Regulator if you believe your personal information has been processed in violation of POPIA (see Section 17 below)
To exercise any of these rights, please contact our Information Officer at support@keovationdigital.store. We will respond to your request within 30 days as required by POPIA.
12. Cookies
Our website uses cookies and similar technologies to enhance your browsing experience. Cookies are small text files stored on your device when you visit our website.
12.1 Types of Cookies We Use
- Essential cookies: Required for the website to function properly (e.g., maintaining your shopping cart, keeping you logged in). These cannot be disabled.
- Analytics cookies: Help us understand how visitors interact with our website, which pages are most popular, and how to improve the user experience
- Preference cookies: Remember your settings and preferences for future visits
12.2 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. Please note that disabling essential cookies may affect the functionality of our website (e.g., you may not be able to add items to your cart or complete checkout).
13. Security Measures
We take the security of your personal information seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, misuse, or alteration:
- Encryption: All data transmitted between your browser and our website is encrypted using TLS/SSL (HTTPS)
- Secure payments: Payment processing is handled entirely by PayFast, a PCI-DSS compliant payment gateway. We never store your full credit card details.
- Access controls: Access to personal information is restricted to authorised personnel who need it to perform their duties
- Password security: User passwords are stored using industry-standard hashing algorithms and are never stored in plain text
- Regular monitoring: We monitor our systems for potential vulnerabilities and security incidents
While we take all reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. If you become aware of any security breach, please contact us immediately.
14. Direct Marketing
In accordance with Section 69 of POPIA, we will only send you direct marketing communications (such as promotional emails, newsletters, or special offers) if you have given us your explicit, opt-in consent to do so.
You may withdraw your consent and unsubscribe at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Emailing us at support@keovationdigital.store with the subject line "Unsubscribe"
- Updating your communication preferences in your account settings
Please note that even if you unsubscribe from marketing communications, we may still send you transactional emails related to your orders (e.g., order confirmations, shipping updates).
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a prominent notice on our website
- Where appropriate, notify you by email
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
16. Contact Details for Privacy Queries
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal information, please contact us:
- Email: support@keovationdigital.store
- Phone: support@keovationdigital.store
- Post: WeWork, 155 West Street, Sandton, Johannesburg
- Information Officer: Ikaneng
17. Information Regulator
If you are not satisfied with our response to your privacy concern, or if you believe that your personal information has been processed in a manner that violates POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa:
- Email: complaints@inforegulator.org.za
- Phone: +27 10 023 5207
- Website: https://inforegulator.org.za
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001