Privacy Policy
Sheahaircare ("Sheahaircare", "we", "us") respects your privacy and is committed to protecting your personal information in line with the Protection of Personal Information Act, 2013 (POPIA). This policy explains what personal information we collect, why, how we protect it, and the rights you have.
For the purposes of POPIA, the responsible party is FL4LL (Pty) Ltd (Registration No. 2023/810686/07), operator of the Sheahaircare platform, of 279 Wessels, Georgie, Pretoria, Gauteng, 0083, contactable at support@sheahaircare.com.
1. Scope
This policy applies to everyone who uses Sheahaircare — customers who discover and book stylists, and stylists who list their services — through our website and app at sheahaircare.com.
2. Information we collect
From customers
- Name, email address and phone number
- Booking details (services requested, dates, the stylist booked)
- Payment confirmation data processed through our payment partner, Paystack — we do not store your full card details
- Reviews and ratings you submit
- Messages you send to stylists or to our support team
From stylists
- Account and profile details (business name, name, contact details, bio, location, services, pricing and photos)
- Bank account details, used to create your Paystack subaccount so that you can receive payouts
- Verification information you choose to provide as part of our stylist trust programme (see section 6)
- Subscription and billing records
Collected automatically
- Device and usage data, and your approximate location — only with your consent — to show nearby stylists
- Cookies and similar technologies for essential functionality and, where you consent, analytics
3. Why we use your information
- To create and manage your account
- To enable bookings and process payments through Paystack
- To operate our stylist trust and verification programme and keep the marketplace safe
- To provide support and resolve disputes
- To send service-related messages (booking confirmations, reminders, review requests)
- To improve and secure the platform
- To comply with our legal obligations
4. Lawful basis for processing
We process personal information where it is necessary to perform our contract with you, where you have given consent, where it is necessary to comply with the law, or where we have a legitimate interest that is not overridden by your rights (POPIA section 11).
5. Who we share information with (operators)
We use trusted service providers ("operators" under POPIA) who process personal information on our behalf, only on our instructions, and under written agreements. We share only the information each operator needs for its purpose. They include:
- Paystack — payment processing, payouts and subscription billing
- Smile Identity — stylist identity verification (planned, not yet active; see section 6)
- Cloudinary — image hosting for profile and gallery photos
- Resend — transactional email (booking confirmations, reminders, receipts)
- Twilio — SMS one-time passcodes and notifications
- PostHog — product analytics, where you consent
- Sentry — error and performance monitoring, to keep the platform reliable
- Vercel — application hosting, and basic traffic and performance analytics
- MongoDB Atlas — database hosting
- Inngest — background processing (for example reminders and scheduled tasks)
- Google — "Sign in with Google" for stylists who choose it, maps and address lookup, and product import from Google Sheets
- AI providers — to power in-app assistant and content features, prompts are routed through the Vercel AI Gateway to Anthropic, Google (Gemini) and Groq
We do not sell your personal information.
6. Stylist verification and KYC
To keep customers safe, we are building a stylist trust programme. Today it draws on genuine customer reviews from completed, paid bookings and, where available, confirmation of the stylist's bank-account name through Paystack.
We may introduce identity verification through a verification partner (Smile Identity) at a later stage. It is not active today, and no identity documents, selfies or biometric data are collected from any stylist on the platform at this time. If and when we enable it, it will be optional and opt-in, and we will ask for your explicit consent before any check runs. The planned design, which will be expanded in this notice before launch, is:
- a South African ID number, validated against the Department of Home Affairs; or
- for foreign nationals, a passport together with a valid South African permit or visa;
- and, where used, a one-time selfie matched against the document photo by the verification partner (a biometric check) to confirm the person presenting the document is its genuine holder.
Under that design we would apply the principle of minimality and store only the result — for example a confirmed name, a pass or fail outcome, the document type, and the last four digits of the ID or document number — not copies of identity documents, the selfie, or any biometric template. If you withdrew consent we would delete the related result unless the law required us to keep it. Verification information would be accessible only to authorised staff and never shown publicly. Until then, the trust programme relies only on the signals described in the first paragraph of this section.
7. Cross-border transfers
Several of the operators listed in section 5 process information outside South Africa (for example in the United States or the European Union). Where this happens, we take steps to ensure the information enjoys protection that is substantially similar to that required by POPIA (section 72), through contractual safeguards with those operators.
8. How long we keep information
We keep personal information only for as long as necessary for the purposes described above, or as required by law (POPIA section 14). As a general guide:
- Account and profile information — for as long as your account is active, then deleted or de-identified within about six months of closure, unless we must keep it longer.
- Booking, payment and invoicing records — about five years, to meet South African tax and company record-keeping obligations.
- Verification (KYC) results — kept to a minimum and deleted when no longer needed, or when you withdraw consent, unless the law requires otherwise.
- Support and dispute records — about three years after the matter is resolved.
- Analytics and usage data — kept for a limited period and, where possible, in aggregated or de-identified form.
When information is no longer needed, we delete or de-identify it securely. If you withdraw consent to a verification check, we delete the related verification result unless we are required to retain it. These periods are guidelines and may be refined as our obligations are confirmed.
9. How we protect information
We take appropriate, reasonable technical and organisational measures to secure personal information against loss, unauthorised access and misuse (POPIA section 19), including access controls, encryption in transit, and restricted access to sensitive data.
If a security compromise occurs and there are reasonable grounds to believe your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected users as soon as reasonably possible after we have established what happened, in line with POPIA section 22.
10. Your rights
Subject to POPIA, you have the right to ask what personal information we hold about you and to access it; to ask us to correct or delete information that is inaccurate, irrelevant, excessive or out of date; to object to processing in certain circumstances; to withdraw consent where we rely on it; and to lodge a complaint with the Information Regulator. To exercise any of these rights, contact support@sheahaircare.com.
11. Information Officer and the Regulator
Our Information Officer, Maditsi Mogano, can be reached at support@sheahaircare.com.
You may also contact the Information Regulator (South Africa) at inforegulator.org.za.
12. Cookies and analytics
We use essential cookies to run the site and, where you consent, analytics cookies to understand and improve how the platform is used. You can control cookies through your browser settings.
13. Children
Sheahaircare is not intended for use by children under 18 without the involvement of a parent or guardian. We do not knowingly collect information from children except as permitted by law.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "Last updated" date shown above.
15. Contact us
Questions about this policy or your personal information: support@sheahaircare.com.