Saffary Digital
Websites Online stores Marketing Automation Client login
Book a call
Home Websites Online stores Marketing Automation Client login Book a call →
Home/Privacy policy

Privacy policy

Last updated 7 October 2026

What we collect, why, who we share it with and how long we keep it, for our website, client portal and the Signal by Saffary platform. Written for people, in line with POPIA.

On this page
  1. Who we are
  2. Our two roles
  3. What we collect
  4. How we use it
  5. Signal by Saffary
  6. Google user data
  7. Meta user data
  8. Who we share it with
  9. Transfers outside South Africa
  10. How long we keep it
  11. Security
  12. Cookies
  13. Your rights
  14. Deleting your data
  15. Changes and contact

1. Who we are

Saffary Digital is the trading name of Pop Squad (Pty) Ltd, a company based in Cape Town, South Africa ("Saffary", "we", "us"). This policy covers:

  • our website, saffary.digital, including the booking form;
  • the Saffary client portal, for clients and their teams;
  • Signal by Saffary ("Signal"): our WooCommerce plugin and the hosted platform that measures a store's orders and sends purchase data to Meta and Google Ads on the store's behalf.

We process personal information in line with the Protection of Personal Information Act 4 of 2013 (POPIA). Questions go to our Information Officer at allen@saffary.digital.

2. Our two roles

Responsible party. For people who visit our website, book a call, become clients or use the client portal, we decide why and how their information is used.

Operator. When an online store uses Signal, the store is the responsible party for its customers' information. We process it only on the store's instructions and under a written operator agreement (POPIA sections 20 and 21). If you bought from a store that uses Signal, the store's own privacy policy applies, and requests about your information should go to the store first. We will help the store answer them.

3. What we collect

Website and booking form

  • What you enter when you book a call: your name, email address, WhatsApp number, business details and the answers you give.
  • Website analytics from Plausible, which counts visits without cookies and without identifying you.

Clients and the client portal

  • Account details for you and your team: name, email address, role and login records.
  • What you and we add while working together: messages, files, tasks, reports and billing details.

Signal, on a store's behalf

  • Order details: order number, products, prices, discounts, shipping, tax, payment method, refunds, billing province and country, and when the order was placed.
  • How the shopper arrived: random first-party visitor and session IDs set by the store, the landing page, the referring site and campaign tags, and ad click IDs (such as Google's gclid and Meta's fbclid).
  • The shopper's consent choices for analytics, ad measurement and personalised ads, as recorded by the store.
  • Contact details, only where the shopper's consent or the store's lawful basis allows advertising use: name, email address, phone number, billing address, IP address, browser details and Meta's browser IDs (fbp and fbc).
  • Store set-up details: the store's address, plugin version, consent settings, product costs, and changes to products, prices and plugins on the store.

Connected ad accounts

When a client connects Google or Meta to Signal, we receive access to the accounts they choose. See sections 6 and 7.

4. How we use it

  • To reply to enquiries, book calls, and provide and bill for our services.
  • To run the client portal and keep it secure.
  • For Signal: to give a store accurate reports on its own sales, margin and marketing channels, and to send its purchases to Meta and Google Ads so its advertising is measured correctly.
  • To meet legal, tax and accounting obligations.

We do not sell personal information. We do not use clients' or shoppers' personal information to train AI models. Where Signal uses AI to explain results, the model receives aggregated figures only, never personal information.

5. How Signal handles shoppers' information

  • Consent first. Each order carries the shopper's consent state. Without ad consent, nothing about the shopper is sent to Meta or Google. Meta receives an order only when the shopper allowed personalised ads. Google receives orders with ad measurement consent, and is told when personalisation was declined.
  • Hashed before it leaves us. Names, email addresses, phone numbers and addresses are normalised and hashed (SHA-256) before they are sent to Meta or Google. Raw contact details are never sent.
  • Deleted after 72 hours. Raw contact details, IP addresses, browser details and Meta browser IDs are deleted 72 hours after the order reaches us. After that we keep only a hashed email address, used to tell new customers from returning ones, and the billing province and country.
  • Store's data, store's control. A store can ask us to export or delete its data at any time.

6. Google user data

When a client connects their Google account to Signal, we ask only for the access the features they use need:

AccessWhat we do with it
Google Ads (adwords)List the client's Ads accounts and conversion actions, read campaign performance, spend and change history for the client's reports, and record the purchase conversions the client asks us to send.
Data Manager (datamanager)Send the store's purchases, with hashed customer details and consent signals, to the client's Google Ads account.
Your email address and basic profileShow which Google account is connected.

Signal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • we use Google user data only to provide and improve the Signal features the client can see;
  • we do not use it for advertising, sell it, or use it to train general AI models;
  • we transfer it to others only to provide those features, to comply with the law, or as part of a merger or sale with the same protections;
  • our people do not read it unless the client asks us to (for example, for support), it is needed for security or the law, or it has been aggregated and anonymised.

Access tokens are encrypted at rest. A client can disconnect Google in Signal's settings or at myaccount.google.com/permissions at any time.

7. Meta user data

When a client connects Meta to Signal with Facebook Login for Business, they choose the business portfolio, ad account and dataset (pixel) Signal may use. We use that access to send the store's purchases to the chosen dataset through Meta's Conversions API, and to read ad performance for the client's reports. We do not post on the client's behalf or change their campaigns. Access tokens are encrypted at rest, and the client can remove Signal's access in Meta Business Settings under Integrations at any time. Section 14 explains how to have your data deleted.

8. Who we share it with

We share personal information only with service providers who process it for us under contract, and only as needed:

  • Vercel hosts our website, portal and Signal (functions run in Cape Town where available).
  • Neon hosts Signal's database (London, United Kingdom), and managed database providers host the portal's data.
  • Resend sends our emails.
  • Plausible provides cookieless website analytics.
  • Meta and Google receive a store's purchase data as described in sections 5 to 7, on the store's instructions.
  • Anthropic provides AI features in Signal, and receives aggregated figures only.

We may also disclose information where the law requires it, or to a buyer of our business, who must protect it as this policy does.

9. Transfers outside South Africa

Some of our providers store or process information outside South Africa, including in the United Kingdom, the European Union and the United States. We use only providers bound by agreements that give protection substantially similar to POPIA, as section 72 of POPIA requires. Where a store's purchases are sent to Meta or Google, that transfer is made on the store's instructions.

10. How long we keep it

  • Booking enquiries that do not become clients: up to 12 months.
  • Client and billing records: for as long as we work together, then as long as tax and company law requires (usually five years).
  • Signal raw contact details: 72 hours. Other Signal order data: for as long as the store uses Signal, then deleted within 30 days of the store asking or leaving, unless the law requires us to keep it.
  • Google and Meta access tokens: until the client disconnects or leaves.

11. Security

We protect information with encryption in transit and at rest, encrypted secrets, access limited to the people who need it, separation of each store's data in the database, and logging. If a breach affects your personal information, we will tell you and the Information Regulator as POPIA requires, and stores will be told about anything affecting their customers.

12. Cookies

Our website analytics use no cookies. The client portal uses essential cookies to keep you signed in. The Signal plugin sets first-party cookies on a store's own website (a random visitor ID, a session ID, and how the shopper arrived, kept for up to 90 days) so the store can measure its orders. Each store explains these in its own privacy policy and consent banner, and we give stores suggested wording.

13. Your rights

Under POPIA you may ask us whether we hold your personal information and for a copy of it, ask us to correct or delete it, object to how we use it, and object to direct marketing at any time. Email allen@saffary.digital. We will reply within 30 days and may need to confirm your identity. If you are not happy with our answer, you can complain to the Information Regulator (South Africa) at inforegulator.org.za.

14. Deleting your data

Stores and clients: to delete your Signal data, including anything received from Meta or Google, email allen@saffary.digital from your account's email address with the subject "Delete my data", or disconnect your accounts in Signal's settings. We delete access tokens at once and the rest of your data within 30 days, and confirm by email. You can also remove Signal's access yourself in Meta Business Settings or in your Google account permissions.

Shoppers: contact the store you bought from, or email us with the store's name and the email address you used. We will delete what we hold about you for that store, and tell the store.

15. Changes and contact

We will update this policy when our services or the law change, and show the date at the top. If a change materially affects how we use your information, we will tell clients by email before it takes effect.

Pop Squad (Pty) Ltd, trading as Saffary Digital, Cape Town, South Africa. Information Officer: Allen Henn, allen@saffary.digital.

Saffary Digital AI growth agency · Based in Cape Town, serving all of South Africa · © 2026
Websites Online stores Marketing Automation Client login Privacy Terms