Effective Date: 1 January 2026
Last Updated: 1 January 2026
The Krom Cafe (“we”, “our”, or “us”) is committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and other applicable South African legislation. This Privacy Policy explains how we collect, use, store, and protect your personal data.
1. Information We Collect
We may collect the following personal information:
- Contact information: Name, email address, phone number, and physical address when you make a reservation, place an online order, or contact us.
- Payment information: Credit/debit card details and billing information processed securely through PayFast. We do not store your full payment card details on our servers.
- Order information: Details of items ordered, delivery preferences, and order history.
- Event enquiry information: Event type, date, guest count, and special requirements when you enquire about hosting an event.
- Website usage data: IP address, browser type, pages visited, and cookies for website analytics and improvement.
2. How We Use Your Information
We use your personal information for the following purposes:
- Processing and fulfilling your food orders and reservations
- Processing payments securely through PayFast
- Responding to enquiries and providing customer support
- Coordinating event bookings and function arrangements
- Sending order confirmations and updates
- Improving our website, services, and customer experience
- Complying with legal obligations
3. Legal Basis for Processing (POPIA)
Under POPIA, we process your personal information on the following lawful bases:
- Consent: When you voluntarily provide your information through our website, order forms, or contact forms.
- Contractual necessity: To fulfil orders and reservations you have placed.
- Legitimate interest: To improve our services and ensure the security of our website.
- Legal obligation: To comply with tax, accounting, and other regulatory requirements.
4. Third-Party Sharing
We do not sell or rent your personal information. We may share your information with:
- PayFast: Our payment gateway provider, for processing online payments securely.
- Delivery partners: If applicable, to fulfil delivery orders.
- Legal authorities: When required by law or to protect our legal rights.
5. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- SSL/TLS encryption for all data transmitted through our website
- Secure payment processing through PCI-DSS compliant PayFast
- Access controls limiting who can view personal information
- Regular security reviews and updates
6. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Order records are retained for 5 years for tax and accounting purposes. Marketing consent records are retained until you withdraw consent.
7. Your Rights Under POPIA
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Objection: Object to the processing of your personal information for direct marketing.
- Withdrawal of consent: Withdraw your consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at info@thekrom.co.za.
8. Cookies
Our website uses cookies to improve your browsing experience and analyse website traffic. You can manage cookie preferences through your browser settings. Essential cookies required for the website to function (such as shopping cart cookies) cannot be disabled.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Email: info@thekrom.co.za
- Phone: +27 15 962 0000
- Address: The Krom Cafe, Thohoyandou, Limpopo, South Africa
You may also lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.