Privacy policy

Last updated: March 30, 2025

This Privacy Policy describes how Sunny St. Clair (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from sunnystclair.com (the "Site") or otherwise communicate with us regarding the Site (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Services.

Compliance with the Protection of Personal Information Act (POPI Act)

We are committed to protecting your privacy and ensuring that your personal information is processed in accordance with the South African Protection of Personal Information Act, 4 of 2013 ("POPI Act"). This Privacy Policy outlines how we comply with the principles of the POPI Act in collecting, using, and safeguarding your personal information.  

 

Changes to This Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons, including changes to the POPI Act. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.

How We Collect and Use Your Personal Information

To provide the Services, we collect personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.

In addition to the specific uses set out below, and in accordance with the POPI Act, we may use information we collect about you to communicate with you, provide or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

What Personal Information We Collect

The types of personal information we obtain about you depend on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.

Information We Collect Directly from You

Information that you directly submit to us through our Services may include:

  • Contact details including your name, address, phone number, and email.
  • Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
  • Account information including your username, password, security questions and other information used for account security purposes.
  • Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.

Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.

Information We Collect about Your Usage

We may also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.

Information We Obtain from Third Parties

Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

  • Companies who support our Site and Services, such as Shopify.
  • Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.

When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

Any information we obtain from third parties will be treated in accordance with this Privacy Policy and the POPI Act. Also see the section below, Third Party Websites and Links.

How We Use Your Personal Information

Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account.

Marketing and Advertising. We may use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites. We will only send you direct marketing communications in accordance with the POPI Act, and you will have the right to opt-out of receiving such communications at any time.

Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.

Communicating with You and Service Improvement. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you, and is done in accordance with the POPI Act.

Cookies

Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for contract fulfillment purposes, legitimate purposes and other reasons subject to this Privacy Policy and in accordance with the POPI Act. Such circumstances may include:

  • With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping). We will enter into agreements with these parties to ensure they also comply with the POPI Act.
  • With business and marketing partners to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices and in compliance with applicable laws.
  • When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
  • With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
  • In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

We disclose the following categories of personal information and sensitive personal information about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":

Category Categories of Recipients
Identifiers such as basic contact details and certain order and account information Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)
Commercial information such as order information, shopping information and customer support information Business and marketing partners
Internet or other similar network activity, such as Usage Data Affiliates

Geolocation data such as locations determined by an IP address or other technical measures 

We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you.  

 

Third Party Websites and Links

Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.

Children's Data

The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.

As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.

Security and Retention of Your Information

We take reasonable technical and organizational measures to secure your personal information and protect it from loss, misuse, unauthorized access, disclosure, alteration, and destruction. However, please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.  

How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies, and in accordance with the requirements of the POPI Act.

Your Rights

Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. These rights may also be subject to limitations under the POPI Act.

  • Right to Access: You have the right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
  • Right to Rectification: You have the right to request that we correct inaccurate or incomplete personal information we hold about you.
  • Right to Erasure: You may have the right to request that we delete personal information we maintain about you, subject to certain exceptions under the POPI Act.
  • Right to Restriction of Processing: You may have the right to request that we restrict the processing of your personal information in certain circumstances.  
  • Right to Data Portability: You may have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format and to request that we transmit this data to another controller, where technically feasible.  
    Right to Object: You have the right to object, on reasonable grounds, to the processing of your personal information.
  • Right to Withdraw Consent: Where we rely on consent to process your personal information, you have the right to withdraw this consent at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Regulator (South Africa) if you believe that we have contravened the POPI Act.   

You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. We will respond to your request in a timely manner as required under applicable law, including the POPI Act.

Complaints

If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with the Information Regulator (South Africa).  

 

International Users

Please note that we may transfer, store and process your personal information outside the country you live in. Your personal information is also processed by staff and third party service providers and partners in these countries. If we transfer your personal information across borders, we will take steps to ensure that your personal information is adequately protected as required by the POPI Act and other applicable laws.

Contact

Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call or email us at sunnystclairco@gmail.com.

Important Considerations:

  • Information Regulator (South Africa): Be sure to include information about the Information Regulator and how individuals can contact them. I've added the right to lodge a complaint with them.
  • Lawfulness, Minimality, and Further Processing Limitation: The POPI Act emphasizes lawfulness, minimality (collecting only what's necessary), and limitations on further processing. Ensure your descriptions of data use align with these principles.
  • Conditions for Lawful Processing: The POPI Act sets out conditions for the lawful processing of personal information (e.g., consent, contractual necessity, legal obligation, legitimate interest). Make sure your "How We Use Your Personal Information" section reflects these conditions accurately.
  • Security Safeguards: The POPI Act requires you to implement reasonable security measures. While the policy mentions security, ensure your actual practices are robust.
  • Data Subject Participation: The POPI Act gives data subjects specific rights. The revised policy includes these rights, but you must have processes in place to facilitate them.
  • Cross-Border Transfers: If you transfer data outside South Africa, the POPI Act has requirements for that. The policy mentions this, but ensure you comply with the specifics of the Act.
  • PAIA Manual: In South Africa, you might also need a Promotion of Access to Information Act (PAIA) manual, which is separate from the privacy policy.

Disclaimer: I am an AI and cannot provide legal advice. It is essential to consult with a qualified legal professional in South Africa to ensure your privacy policy and data processing practices fully comply with the POPI Act and all other applicable laws.