01 / Purpose
Your information
Privacy notice
What personal information we collect, why we use it, who receives it, how long it is kept and the choices available to you.
02 / Sharing
We do not sell personal information
Only the providers and authorities needed for the stated purpose receive it.03 / Control
You can exercise your POPIA rights
Ask for access or correction, object where permitted, or withdraw optional consent.On this page
1. Responsible party
[Complete before publication: legal company name], registration number [Complete before publication: company registration number], is the responsible party for the personal information described in this notice.
Business address: [Complete before publication: business physical address]
Information Officer: [Complete before publication: Information Officer name]
Privacy contact: [Complete before publication: customer-service email address]; [Complete before publication: customer-service telephone number]
This notice applies to our website, customer accounts, checkout, orders, delivery, returns, support, reviews and marketing. It should be read with the short notices shown when information is collected.
2. Information we collect
Depending on how you use the store, we collect:
- identity and contact details, including name, email address and telephone number;
- account credentials, passkeys, session and consent records;
- billing and delivery addresses and recipient details;
- basket, order, payment-status, tax-invoice, delivery, return, refund and warranty records;
- messages, support history, complaints, reviews and photographs you choose to send;
- after verified sign-in, a bounded shopping-preference profile such as recent product interest,
a budget, material choice or size constraint, together with products bought through that account;
- fraud and security information, including the IP address and browser details associated with checkout or sign-in; and
- basic technical records needed to keep the service secure and working.
We receive information directly from you, from your use of the website, and from service providers involved in payment, fraud prevention and delivery. We do not receive or store your complete payment-card or bank-login details from the hosted payment page.
3. Why we use it
We process personal information to:
- provide the website and account you request;
- quote delivery, take and fulfil an order, send transactional messages, deliver the chair and handle returns or support;
- verify payment and prevent, investigate or defend fraud and disputed transactions;
- issue tax records and meet accounting, consumer-protection, product-safety and other legal duties;
- keep the service, customers and our business secure;
- understand aggregate product interest and improve the store; and
- make the signed-in catalogue more relevant without changing prices or hiding products; and
- send direct marketing only where permitted and according to your recorded preference.
Our grounds are performance of the contract with you, compliance with law, protection of legitimate interests that do not override your rights, and consent where consent is required. We do not ask you to consent to processing that is necessary to fulfil your order.
4. Information you must provide
Information marked required at checkout is needed to verify, fulfil and deliver the order or create a legally valid record. If you do not provide it, we may be unable to accept or deliver the order. Account creation, marketing consent, a public review and optional damage-analysis consent are voluntary.
Account-level shopping personalization starts automatically after verified sign-in and can be turned off in Your data. Turning it off does not affect the account, an order or marketing preference.
5. Who receives information
We share only what is reasonably needed with:
- payment and fraud-prevention providers;
- couriers and delivery or returns partners;
- website, cloud-hosting, storage, security and email providers;
- professional advisers, insurers and auditors; and
- regulators, law-enforcement bodies or other recipients where lawfully required.
These parties may act as operators under our instructions or as independent responsible parties for their own regulated services. We do not sell personal information.
6. International transfers and image analysis
Some cloud, email, security or support providers may process information outside South Africa. We use recipients subject to a law, agreement, binding corporate rules or other protection that provides an adequate level of protection as required by POPIA section 72, or another lawful transfer ground.
If we offer automated analysis of a damage photograph using a provider outside South Africa, we send the image only after separately recording your explicit consent. The result assists support staff and does not decide your CPA remedy. You may refuse or withdraw that consent for future analysis without losing your return or warranty rights.
7. Cookies and similar storage
We use first-party storage that is necessary for the store to work, including a basket identifier kept for up to 30 days, authentication and security sessions, temporary checkout and return state, a short-lived payment-handoff record, and a short-lived receipt reference. Blocking necessary storage can prevent the basket, sign-in or checkout from working.
We may count a product view in aggregate. That counter does not retain a visitor identifier, cookie, IP address, referrer or browser user-agent with the view.
Google Analytics is optional and remains off unless you choose “Allow analytics” in our cookie controls. If you allow it, Google Analytics uses first-party identifiers such as _ga to distinguish browsers and measures page paths, general device and browser characteristics, broad location, referral source, and store actions such as viewing or adding a product, beginning checkout, submitting a contact request, and a confirmed purchase. We configure it without advertising storage, Google Signals or ad-personalisation signals, and we do not send your name, email address, telephone number, delivery address, order-message text or other direct contact details to Google Analytics.
Google may process this analytics information outside South Africa. The transfer protections in section 6 apply. You can refuse analytics without losing any store function, or withdraw your choice at any time through “Cookie preferences” in the site footer. Withdrawal stops future analytics collection in that browser and removes the analytics cookies available to us there. It does not make previously aggregated reports identifiable or remove records Google has already processed under our instructions.
We do not use third-party advertising cookies unless this notice and the consent controls are changed first.
While you are anonymous, a short-lived preference summary remains in first-party browser storage and is not attached to a person. After verified sign-in, we automatically merge only the bounded preferences described above into that account so they can work across devices. We do not upload a raw page-by-page clickstream, typed search history or device identifier. You can turn this off in Your data; doing so deletes the saved preference profile and stops future synchronization. This choice is separate from direct-marketing permission.
8. Direct marketing
We send promotional email only where applicable law permits it and our records show the required permission or existing-customer basis. You can unsubscribe in any marketing email or change your preference in your account. Service messages about an order, return, security issue or legal notice are not marketing.
We retain a minimal suppression record after opt-out so we can honour it. We also apply the national opt-out registry and direct-marketer requirements when they are legally in force and applicable. We will not ask you to pay to opt out.
9. How long we keep information
We keep information only for a defined purpose or legal duty:
- inactive basket identity is removed after about 30 days;
- temporary checkout, return and payment-handoff records expire after their short operational windows;
- order, payment and tax records are generally kept for at least five years after the relevant tax return is submitted, and longer where a return was not submitted or an audit, dispute, investigation or other law requires it;
- support, return, warranty, fraud and dispute evidence is kept while the matter and relevant legal claim periods remain active;
- account data is kept while the account is active and then deleted or de-identified unless another lawful reason applies;
- inferred shopping preferences expire within 180 days at the latest, and the saved preference profile is deleted when personalized shopping is turned off or the account is erased;
- rejected or unpublished review submissions are deleted under our review-retention rules, while a published review may remain in de-identified form; and
- a minimal marketing-suppression record may be kept indefinitely to prevent future contact.
Backups are protected and overwritten on a routine cycle. Information isolated in a backup is not returned to ordinary use after deletion.
10. Security and incidents
We use reasonable, appropriate technical and organisational safeguards based on the nature of the information and foreseeable risks. No online system can promise absolute security.
If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected people as soon as reasonably possible, subject to lawful notification delays and POPIA section 22.
11. Your rights
Subject to POPIA and other applicable law, you may:
- ask whether we hold personal information about you and request access to it;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, outdated, incomplete, misleading, unlawfully obtained, or no longer authorised to be kept;
- object to processing on a legally recognised ground;
- withdraw consent for future processing where consent is the ground;
- opt out of direct marketing; and
- turn account-level shopping personalization off without losing account or ordering features; and
- complain to the Information Regulator.
Account tools provide a copy and erase much of your account data immediately. We will explain any information we must retain by law or for a permitted purpose. We may need to verify identity before giving access or making a high-risk change.
12. Automated decisions
We do not use solely automated processing to make a decision that produces legal or similarly significant effects for you. Automated risk signals and optional image analysis are reviewed by a person where they affect customer support or an order.
13. Children
The store is intended for adults able to enter a contract. We do not knowingly seek children's personal information. A parent or competent person may contact us if a child supplied information without proper authorisation.
14. Complaints and contact
Contact the Information Officer at [Complete before publication: customer-service email address], [Complete before publication: customer-service telephone number], or [Complete before publication: business physical address]. We will respond within the periods required by law.
You may also complain to the Information Regulator of South Africa using the current details at inforegulator.org.za.
15. Changes
The version and effective date appear at the top of this notice. We will give appropriate notice of a material change and request new consent where the change requires it.

