Legal
Privacy policy.
What we collect, why we collect it, who else sees it, and what you can make us do about it. Written under the Protection of Personal Information Act 4 of 2013.
Last updated 8 September 2026
Who is responsible
Navéh Olive is the responsible party for the personal information described here.
What we collect
- When you create an account: your name, email address and a password. The password is stored only as a bcrypt hash, so nobody here can read it, including us.
- When you order: your delivery address, your phone number and what you bought. We need all three to get a parcel to you.
- When you pay: nothing. Your card details go straight to our payment provider and never touch our servers. We are told only whether the payment succeeded, and a reference.
- When you subscribe: your email address, and your name if you gave one.
- When you write a review: your name and what you wrote, both of which are public once approved.
- Automatically: the technical basics any web server records, including your IP address, so we can rate limit abuse and keep the site up.
Why we are allowed to hold it
Most of it because we cannot perform the contract without it. You cannot be sent a parcel without an address, and you cannot sign back in without an account record.
The newsletter is different: that one runs on your consent, you gave it deliberately, and you can withdraw it at any time using the unsubscribe link in the footer of every email we send.
A small amount, such as the records behind rate limiting and fraud prevention, we keep because we have a legitimate interest in the store not being abused.
Who else sees it
We use three outside services, and each gets only what it needs to do its job:
- Paystack processes payments. Your card details go to them, not to us.
- Mailgun sends transactional email, meaning order confirmations, password resets and address verifications.
- Mailchimp holds the newsletter list, and only if you subscribed to it.
Our courier gets your name, address and phone number, for the obvious reason. Beyond that we do not sell, rent or trade your personal information to anybody, for any amount of money.
Some of these providers process data outside South Africa. POPIA permits that where the receiving party is bound by comparable protection, and their standard terms bind them to it.
Cookies
We set two, and neither of them is for advertising. naveh_token is what keeps you signed in, and naveh_csrf is a security token that stops another site from acting as you.
There is no advertising or tracking network on this site. If you block the two cookies above you can still browse and read, but you will not be able to sign in, because signing in is what they do.
How long we keep it
Order records are kept for as long as tax and consumer protection law requires us to keep them, which is a matter of years rather than months, and is not something we can shorten on request.
When you delete your account we anonymise it rather than erase the row. Your name, email address and other identifying details are stripped, and what remains is an order history with no person attached to it. We are straightforward about this because the alternative, deleting the record outright, would destroy the order and payment records we are obliged to keep.
What you can ask us to do
POPIA gives you real powers here, and we will act on them:
- Ask what we hold about you, and get a copy of it.
- Have anything wrong corrected. Most of it you can edit yourself on your account page.
- Have your account anonymised, as described above.
- Object to us processing your information on the grounds of legitimate interest.
- Withdraw your consent to marketing at any moment, without it affecting anything else.
Ask through our contact page. We answer within a reasonable time, and we do not charge for it.
How we protect it
Traffic runs over HTTPS. Passwords are hashed with bcrypt, never stored in a form anybody could read. Sessions are held in a cookie that JavaScript cannot reach, and a password change invalidates every existing session immediately. Sign-in attempts are rate limited per address so a guessing attack runs out of road.
No system is perfect, and we would rather say that than pretend otherwise. If a breach ever affects your information, POPIA requires us to notify both you and the Information Regulator, and we will.
If we let you down
Tell us first, and give us a chance to fix it. If we do not, you can complain to the Information Regulator of South Africa, which is the body that supervises POPIA, at inforegulator.org.za.
Still need a hand? Get in touch and a real person will answer.
