Legal

Privacy Policy

Last updated: May 2026

1. Introduction

Logan's Flowers (“we”, “us”, or “our”) is a sole proprietorship operating an online flower delivery service in Johannesburg, South Africa. We are committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and the Electronic Communications and Transactions Act, 2002 (ECT Act).

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what rights you have regarding your data.

2. Responsible Party & Privacy Contact

Responsible party: Logan's Flowers (Sole Proprietor)

Privacy Contact: Bhavna Padayachy

Email: info@logansflowers.co.za

Website: www.logansflowers.co.za

If you have any questions about this policy or wish to exercise your rights under POPIA, please contact us using the details above.

3. What Personal Information We Collect

We collect the following information when you use our website and place orders:

Account information

  • Full name
  • Email address
  • Phone number
  • Password (stored securely, never in plain text)

Delivery information

  • Street address, suburb, city, and postal code

Order information

  • Products ordered and order history
  • Delivery date preferences
  • Special instructions

Payment information

  • Payment method selected (card via Yoco or PayFast)
  • We do NOT store your card number, CVV, or banking details. All payment processing is handled securely by Yoco and PayFast.

Technical information (collected automatically)

  • IP address, browser type, pages visited, device type

Providing your personal information is voluntary. However, certain information (such as your full name, delivery address, phone number, and email) is required to process and deliver your order or create and manage your account. If you do not provide this information, we will be unable to fulfil your order or provide the requested service. When you order as a gift, you confirm you have authority or the recipient's consent to provide their details.

4. How We Use Your Information

PurposeLegal basis (POPIA)
Processing and delivering your orderPerformance of a contract
Sending order confirmations and delivery updatesPerformance of a contract
Creating and managing your accountPerformance of a contract
Responding to enquiries and customer supportLegitimate interest
Improving our website and servicesLegitimate interest
Analysing website usage and measuring advertising effectiveness via Google Analytics and Vercel Web AnalyticsLegitimate interest
Sending marketing communications (with your consent)Consent
Complying with legal obligationsLegal obligation

5. Marketing Communications

We may send you marketing emails about new products, special offers, and promotions. We will only do so with your explicit consent, and you may withdraw your consent at any time by:

Withdrawing consent for marketing will not affect our ability to send you transactional communications (such as order confirmations and delivery updates).

6. Who We Share Your Information With

Third partyPurposeData shared
Delivery partners / couriersProcess and complete deliveryRecipient name, address, phone, instructions
YocoCard payment processingPayment transaction details
PayFastAlternative payment processingPayment transaction details
SupabaseSecure database hostingAccount and order information
VercelWebsite hosting and anonymised usage analyticsTechnical information (IP, browser, page views, referrer, country)
Google Analytics & Google Ads (Google LLC)Website usage analysis, advertising measurement, and conversion trackingAnonymised browsing data, conversion events, and (with your consent) hashed contact details for Enhanced Conversions

We do NOT sell, rent, or trade your personal information to any third party for marketing purposes.

We have entered into written operator agreements (as required by Section 21 of POPIA) with all third parties listed above. These agreements require them to process your personal information only on our instructions, maintain appropriate security measures, and notify us immediately of any security compromises.

International Transfers of Personal Information

Some of our third-party service providers (Supabase, Vercel, and Google Analytics) are located outside South Africa. Your personal information may therefore be transferred to, stored, and processed in countries such as the United States or the European Union.

We ensure these transfers comply with Section 72 of POPIA by:

  • Entering into written operator agreements that require providers to apply protections substantially similar to POPIA
  • Limiting transfers to the minimum information necessary
  • Where available, using regional infrastructure (e.g., Vercel's Cape Town region)

Yoco and PayFast are South African companies, so your payment data stays within South Africa.

7. How We Protect Your Information

  • All data is encrypted in transit using SSL/TLS
  • Payment processing by PCI-DSS compliant providers (Yoco and PayFast)
  • Access restricted to authorised personnel only
  • Database enforces row-level security policies

In the event of a security compromise that may pose a risk to you, we will notify the Information Regulator and affected data subjects as required by Section 22 of POPIA.

8. Cookies, Consent, and Tracking

Cookie consent

When you first visit our website, you will see a cookie consent banner. For visitors in South Africa and most other countries, analytics and advertising cookies are enabled by default. You can opt out at any time by clicking “Only Essential” on the banner or by clearing your browser cookies and revisiting the site.

For visitors in the European Union, European Economic Area, and United Kingdom, analytics and advertising cookies are denied by default and only enabled after you choose to accept them, in accordance with GDPR and ePrivacy requirements.

Essential cookies

Our website uses essential cookies to:

  • Keep you signed in to your account
  • Remember items in your shopping cart
  • Store your cookie consent preference

These cookies are necessary for the website to function and cannot be disabled.

Analytics and advertising cookies

We use Google Analytics 4 (GA4) and Google Ads conversion tracking to understand how visitors use our website and to measure the effectiveness of our advertising campaigns. This includes tracking actions such as product views, items added to cart, checkout initiated, and completed purchases.

We implement Google Consent Mode v2. If you opt out of cookies (or have not yet accepted them in regions where consent is required), Google tags operate in a privacy-safe manner without storing cookies, and advertising data (ad storage, ad user data, ad personalisation) is restricted.

Enhanced Conversions

When you complete a purchase and have accepted cookies, we may send hashed versions of your name, email address, and phone number to Google for Enhanced Conversions. This helps us accurately measure advertising performance. Google receives this data in a hashed (one-way encrypted) format and processes it in accordance with their privacy policy. This data is never sent if you have declined cookies.

You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Vercel Web Analytics: We also use Vercel Web Analytics, a privacy-focused analytics service provided by Vercel Inc. This service collects aggregated, anonymised data about page views, referrers, browser and device types, country-level location, and routes visited. Vercel Web Analytics does not use cookies and does not collect personally identifiable information.

9. Your Rights Under POPIA

  • Right of access — Request a copy of your personal information
  • Right to correction — Request correction of inaccurate information
  • Right to deletion — Request deletion, subject to legal obligations
  • Right to object — Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent — Withdraw consent at any time
  • Right to lodge a complaint — Complain to the Information Regulator

To exercise any of these rights, contact us atinfo@logansflowers.co.za. We will respond within 30 days.

Information Regulator (South Africa)

Email: enquiries@inforegulator.org.za

Website: inforegulator.org.za

10. Data Retention

We retain your personal information for as long as necessary to:

  • Maintain your account and provide our services
  • Comply with legal and tax obligations (typically 5 years per SARS requirements)
  • Resolve disputes and enforce our agreements

When your information is no longer needed, we will securely delete or anonymise it.

11. Children's Privacy

Our website is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of our website after changes constitutes acceptance of the updated policy.

13. Contact Us

Logan's Flowers

Privacy Contact: Bhavna Padayachy

Email: info@logansflowers.co.za

Website: www.logansflowers.co.za