A E T L I E R

Policy · version 1.0

Privacy Policy

Last updated: April 17, 2026

A E T L I E R (Pty) Ltd ("we", "us") respects your privacy. This policy explains what personal information we collect, why we collect it, and how you can exercise your rights. It is written to align with South Africa's Protection of Personal Information Act (POPIA) and, where you're based in the EEA or UK, the General Data Protection Regulation (GDPR).

1. Responsible party

A E T L I E R (Pty) Ltd, South Africa. Contact: privacy@aetlier.shop.

2. What we collect

  • Account data — name, email, password hash, avatar, role.
  • Designer data — shop profile, bio, social links, portfolio, business documents (for verification).
  • Order data — delivery address, items purchased, amount, payment reference (we never see full card details; those go to Yoco).
  • Behavioural data— which pieces and designers you view, like, follow, and search for. Used only to personalize what we show you. Only collected after you enable the "Personalization" cookie category.
  • Technical data — device type, browser, IP address, referrer. IP addresses are hashed before storage where used for consent audit.

3. Why we process it

  • To provide the service — account, cart, checkout, delivery, customer support. (Contractual necessity.)
  • To keep the service safe — fraud detection, abuse prevention, audit logs. (Legitimate interest.)
  • To comply with law — tax, record keeping. (Legal obligation.)
  • To improve and personalize — analytics and taste-profile ranking. (Consent; you can withdraw any time.)
  • To communicate — transactional emails are required; marketing emails are opt-in and unsubscribable.

4. Who we share it with

  • Supabase (database, auth, storage).
  • Yoco (payments).
  • Vercel (hosting, CDN, logging).
  • Courier partners (to deliver your order).

Personal information may be transferred outside South Africa (e.g. to EU or US data centres run by the processors above). We rely on standard contractual clauses and the processor's own adequacy status.

5. How long we keep it

  • Account data: until you delete your account.
  • Order data: 7 years (tax-law retention) from the order date.
  • Behavioural data (signed-in): until you delete your account or reset your personalization preferences.
  • Behavioural data (anonymous): automatically deleted after 180 days.
  • Consent audit trail: 3 years from the date of the decision.

6. Your rights

Under POPIA and GDPR you may:

  • Request a copy of your personal information.
  • Correct inaccurate information.
  • Request deletion ("right to be forgotten").
  • Restrict or object to processing.
  • Port your data to another service (where technically feasible).
  • Withdraw consent at any time.
  • Lodge a complaint with the Information Regulator (SA) or your local EU/UK data protection authority.

To exercise these rights, email privacy@aetlier.shop. We respond within 30 days.

7. Security

We use TLS for all connections, hash passwords, restrict database access via Row Level Security, and encrypt backups at rest. No system is perfectly secure, but we take reasonable, contemporary measures.

8. Children

A E T L I E R is not intended for users under 18. We do not knowingly collect data from minors.

9. Changes to this policy

We may update this policy. Material changes will be communicated on-site. The version number at the top changes when the policy changes.

10. Related documents

Cookie Policy · Cookie Settings · Terms of Service