Privacy Policy

What NeedEverything does with personal information — the sellers who run shops here, and the shoppers who buy from them. Written under POPIA, South Africa's Protection of Personal Information Act.

Last updated · Version 2026-09-17

The short version

  • Two different roles. For a seller’s own account we decide what happens to the information. For a shopper’s information we act on the seller’s instruction and nothing else.
  • We never store a card number, a CVV or a bank account number. Our payment provider holds the card; we hold an encrypted token and the last four digits.
  • We do not sell personal information, we run no advertising trackers, and we never build a profile of a shopper across different shops.
  • Other companies see some of it to make the product work: Cloudflare, Paystack, Resend, and Google if you use Google sign-in.
  • POPIA gives you the right to see what we hold, to have it corrected, and to complain to the Information Regulator. Section 8 says how.

This box is a plain-language summary. The sections below are the agreement.

1. Two sets of people, two different roles

POPIA gives the two roles names, and the difference decides everything else in this policy.

Responsible party
Whoever decides why and how personal information is processed. They answer for it.
Operator
Whoever processes it for a responsible party, on their instruction, and does nothing else with it.

For sellers, we are the responsible party. Your account, your shop’s details and your billing are ours to decide about, and section 2 lists what we hold.

For shoppers, the seller is the responsible party and we are their operator. When somebody buys from a shop on NeedEverything, they are dealing with that shop. The shop decides what to ask for and what to do with it. We hold it on the shop’s behalf, in the shop’s own data, and we do not use it for our own purposes: we do not market to shoppers, we do not sell shopper information, and we never join one shop’s customers to another’s. The same person shopping at two shops here is two separate records that cannot see each other.

If you are a shopper with a privacy question, ask the shop you bought from first — they are the ones who decide. Reply in the chat you bought through, or email the shop’s contact address. If they need us to do something to answer you, they can ask us and we will.

2. What we collect from sellers

Your account

Your name, your email address and your password. The password is stored as a one-way hash and is never kept in a form anybody can read, including us. We also keep whether your email has been verified and when you last signed in.

Your sign-ins

Each session stores a hashed session token, the IP address the sign-in came from, the browser’s user-agent string, and a short label used for the “new sign-in” notice. That label is not a fingerprint: it is a one-way hash of a secret, your own user id, a browser family, an operating-system family and a coarse network band — never your actual address. Because your user id is mixed in, the same laptop signing into two accounts produces two unrelated labels, so the table cannot be used to link accounts to each other.

Your shop

The shop’s name, contact email, address, business details, branding, and your VAT declaration — whether you are registered, and the VAT number you typed, which we check only for shape and never against SARS.

Your billing

Your plan, your subscription status and dates, every invoice, and the commission ledger showing which of your orders each line came from. For the card you pay us with we keep the brand, the last four digits, the expiry month and year, the issuing bank, and an encrypted reusable token from our payment provider. We never store the card number, the CVV or a bank account number, and the token is never decrypted for anybody outside our servers — including our own administrators.

Your gateway keys

The credentials for the payment gateway you connected, encrypted before they are stored and decrypted only on our servers when we need to talk to your gateway for you. They are never sent to a browser.

What your team did

An audit log of actions taken in your shop — who did what, to what, and from which IP address. It is how a shop owner can see what a staff member changed, and how we investigate a dispute about an account.

We also keep any support conversation you start with us, and the emails we sent you (the address, the subject and the content).

3. What we hold about shoppers, on the seller’s behalf

Everything in this section belongs to the shop it was collected in. We hold it as that shop’s operator.

The customer record

Email address, phone number, first and last name where given, an optional customer password (stored hashed), whether they agreed to marketing, their spend and order counts, and when they were last active. Delivery addresses they saved.

The conversation

Messages between the shopper and the shop, and any photos or files attached to them. That is the shop; it is the whole product.

Orders and payments

What was ordered, what it cost, delivery details, the payment’s status at the gateway and its reference, refunds, disputes, and which digital files were downloaded and how often. Card details are not among them — a shopper’s card goes to the seller’s own gateway and never reaches us.

The shop session

A hashed session token in a cookie, valid for 180 days, so a returning shopper picks up their conversation and cart. Recorded against it, once, when the session is first seen at a shop:

  • The page of the shop they landed on, with the query string stripped.
  • The host of the site that referred them — the host only, never the full URL.
  • The utm source, medium and campaign, if the link carried them.
  • A device bucket: mobile, tablet, desktop or bot. The raw user-agent string is deliberately not kept, because four values answer the question a shop is actually asking and a full user agent is a fingerprinting surface.

Recorded once, on first arrival, and never overwritten — so a shopper who comes from a campaign and returns directly tomorrow is not re-counted.

Shop analytics

We record events so a shop can see what is happening in it: a store visit, a conversation started, a customer message, a staff reply, a listing viewed or discussed, an add to cart, a checkout started, an order placed, an order paid, an offer sent or accepted, a project completed, and a catalogue search (with the search term, so a shop can see what people ask for that it does not sell). Each event may carry the shop, the conversation, the customer, the session, the listing, the order and a value.

There is nothing else. No advertising cookies, no third-party analytics script, no pixel, no cross-site tracking, and no profile of a shopper that spans more than one shop.

4. Why we are allowed to (the lawful basis)

POPIA requires a ground for every use. Ours are:

  • Performance of a contract. Running your shop, taking and delivering orders, working out and collecting our bill, sending the emails a sale needs.
  • A legal obligation. Tax invoices and the records South African tax law requires us and you to keep.
  • Our legitimate interests, and yours. Keeping accounts secure, spotting fraud and abuse, enforcing rate and upload limits, investigating a dispute, and understanding whether the product works. We keep this to the least information that answers the question — which is why a device bucket exists instead of a stored user agent.
  • Consent. Marketing to a shopper who ticked the box, and signing in with Google if you choose that instead of a password. You can withdraw consent at any time; it does not undo what was lawful before you did.

We make no decision about anybody by automated means alone, and nothing in the product profiles a person to decide something about them.

5. Who else sees it

These are our operators under POPIA. Each one gets the least it needs, each is bound by its own contract with us, and none of them is permitted to use what they see for their own purposes.

  • Cloudflare — hosting, the database and file storage. Everything in this policy lives on Cloudflare’s infrastructure, and requests to a shop pass through their network.
  • Paystack — the payments you make to us for your plan and commission. They receive your billing email address and your card details, which they hold; we get back a token and the non-secret card facts described in section 2.
  • Your own gateway — Paystack, PayFast, Yoco, Ozow or PayPal, whichever you connected. Your shoppers’ payment details go to them, under your agreement with them, and never to us. For that payment they are your operator, not ours.
  • Resend — the company that delivers our transactional email. They receive the recipient’s address and the content of the message. One-time links and secrets are kept out of anything we log about an email.
  • Google — only if a person chooses “Sign in with Google”. We receive Google’s permanent account identifier, the email address and the name on the account. We store no Google tokens at all — not the access token, not the refresh token, not the identity token. We use the sign-in once to learn who you are, then our own session takes over.

We do not sell personal information, we do not share it for advertising, and we do not give it to anybody else except when the law or a court requires it, or to enforce our terms.

Outside South Africa. These providers process information outside the country. POPIA allows that where the recipient is bound by rules giving comparable protection, which is the basis we rely on, through the data-protection terms in each provider’s contract with us.

6. How long we keep it

  • Shop analytics events: 400 days. Older ones are deleted automatically by a scheduled job, not on request.
  • Shop sessions: 180 days. They expire and are then purged.
  • Payment gateway notifications: seven days if the signature did not verify, 180 days if it did.
  • Orders, invoices, tax invoices and the commission ledger: for as long as the shop exists, and afterwards for as long as South African tax law requires us to keep records of what we charged you.
  • Customer records, conversations and uploaded files: for as long as the shop keeps them. A seller can delete a customer or a file at any time. When a shop is deleted, everything belonging to it goes with it.
  • Audit logs and support tickets: while the shop exists, because their whole purpose is answering a question about something that already happened.

7. How we protect it

  • Passwords are hashed. Session tokens, password-reset tokens and download tokens are stored hashed, so a copy of the database is not a set of working keys.
  • Gateway credentials and the billing token are encrypted with AES-256-GCM and decrypted only on our servers, never for a browser and never for an administrator.
  • Secrets are never written to a log, never returned to a client, and never put in a URL.
  • We never store a card number, a CVV or a bank account number anywhere in the system.
  • Each shop’s data is separated from every other shop’s, and a request can only reach a shop after the server has proved the person belongs to it.

No system is perfectly safe. If personal information is accessed by somebody who should not have it, POPIA requires us to notify the Information Regulator and the people affected as soon as reasonably possible, and we will.

8. Your rights under POPIA

POPIA gives you these, and you do not need a reason to use them:

  • To know. Ask whether we hold personal information about you, what it is, and who it has been given to.
  • To have it corrected or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • To object to processing we do on the ground of legitimate interest, on reasonable grounds relating to your situation.
  • To withdraw consent you gave — for marketing, or for Google sign-in — at any time.
  • Not to receive unsolicited electronic marketing, and to be told who sent it if you do.
  • To complain, and to go to court.

How to ask us. Email us from the address on the account and say what you want. We will answer as soon as we reasonably can, and within 30 days. We may need to check it is really you before we hand anything over. If the request is about a shopper’s information, the shop is the responsible party, so we will pass it to them and help them answer.

Complaining to the Information Regulator. If you are not satisfied with how we have handled your information or your request, you can complain to the Information Regulator of South Africa, which is the body POPIA puts in charge of this. They publish their complaint forms and current contact details at inforegulator.org.za, and complaints are made in writing on their own form. You can complain to them without asking us first.

9. Cookies

We set two cookies, both of which the product needs to work at all:

  • A seller session cookie, so you stay signed in to your dashboard.
  • A shop session cookie, so a shopper returning to a shop finds their conversation and their cart where they left them. It lasts 180 days.

There are no advertising cookies, no analytics cookies from anybody else, and nothing that follows a person off this site.

10. Children

NeedEverything is for businesses, and it is not intended for children. We do not knowingly collect the personal information of a child. If you believe a child’s information is in a shop here, tell us and we will get it removed.

11. Contact

Privacy questions about your seller account come to us. Privacy questions about a purchase go to the shop you bought from — see section 1. If you are not sure which, ask us and we will point you at the right one. Our terms are at /terms and our refunds policy at /refunds.

This can change

We can change these documents. Our plan prices and our commission rate are what they are today and we can change them at any time.

When we change anything here, we bump the version at the top of the page, put a notice in your dashboard and email your store’s contact address before the change takes effect. Carrying on using NeedEverything after that date is how you accept the change. If you would rather not, cancel your plan before the date and you will not be charged the new price.

A change never runs backwards. A billing month that has already closed keeps the price and the commission rate that were in force while it was open, because both are written onto the bill when it is worked out and nothing recalculates them afterwards.

Your rights under POPIA — South Africa’s Protection of Personal Information Act — and your right to complain to the Information Regulator are not ours to change, and nothing we publish here narrows them. See the privacy policy for what those rights are and how to use them.