10% Off

Subscribe to our newsletter for 10% off your first purchase

Privacy Policy

Privacy Policy for Candles&Things

Last Updated: 14 June 2025

Your privacy is of utmost importance to us at Candles&Things. This Privacy Policy outlines how we collect, use, protect, and handle your personal information in compliance with the South African Protection of Personal Information Act (POPIA).

By using our website and purchasing our products, you consent to the data practices described in this policy.

1. Who We Are

We are Candles&Things, a South African-based creator of handcrafted luxury gifts. Our official details are:

Website Address: https://candlesandthings.co.za
Physical Address: Plattekloof, Cape Town, South Africa
Email Address: candlesandthings2022@gmail.com
Contact Number: (+27) 72 736 2221
For any privacy-specific concerns, you can contact our designated Information Officer at candlesandthings2022@gmail.com.

2. The Personal Information We Collect

We collect information to provide you with the best possible service and to process your orders efficiently. We collect information in the following ways:

Information You Provide to Us:

When Placing an Order: We collect your name, surname, email address, delivery address, and telephone number to process and deliver your order.
When Creating an Account: If you register on our site, we store the personal information you provide in your user profile.
When Leaving Comments: We collect the data shown in the comments form, your IP address, and browser user agent string to help with spam detection. An anonymised string (hash) created from your email address may be sent to the Gravatar service to see if you are using it.
When Contacting Us: If you contact us via our contact form, we will collect your first name, last name, email address, and the message you provide.
Information We Collect Automatically:

Cookies: Our website uses cookies to enhance your experience. These are small text files stored on your device. We use them to remember your preferences, keep items in your shopping cart, and for analytical purposes. For more details, see our “Cookies” section below.
Analytics: We may use analytics tools to collect non-personally identifiable information about your visit, such as the pages you viewed and the time you spent on our website. This helps us improve our website and services.
3. How We Use Your Information

We use the information we collect for specific, explicit, and lawful purposes related to our business functions:

To Process Your Orders: To manage your payments, arrange for shipping, and provide you with invoices and order confirmations.
To Communicate With You: To respond to your enquiries, send you information about your order, and provide customer support.
For Marketing Purposes: With your explicit consent (opt-in), we may send you emails about our new products, special offers, and other news. You can withdraw your consent and unsubscribe at any time by clicking the “unsubscribe” link in our emails.
To Improve Our Website and Services: To understand how our customers use our site and to improve its functionality and user experience.
For Legal and Security Purposes: To prevent fraud, detect spam, and comply with our legal obligations in South Africa.
4. Cookies

If you leave a comment on our site, you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

When you log in, we will set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

You have the right to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. Please note that this may prevent you from taking full advantage of the website.

5. Who We Share Your Data With

We do not sell your personal information. We will only share your data with trusted third-party service providers when it is necessary to run our business and provide you with our services. These include:

Payment Gateways: To process your payments securely, your payment information is passed directly to our trusted payment providers (e.g., PayFast, Yoco). We do not store your full credit or debit card details on our servers.
Courier and Delivery Services: We share your name, delivery address, and contact number with our courier partners to deliver your orders.
Spam Detection Services: Visitor comments may be checked through an automated spam detection service.
Legal Obligations: We may disclose your information if required to do so by law or in response to valid requests by public authorities.
We have agreements in place to ensure that all our third-party partners treat your data with the same level of protection as we do and in accordance with POPIA.

6. Data Retention

We will not retain your personal information for longer than is necessary for the purpose for which it was collected.

Order Information: We are required by law to retain transactional information for a minimum of 5 years for tax and accounting purposes.
Comments: If you leave a comment, the comment and its metadata are retained indefinitely so we can recognise and approve any follow-up comments automatically.
User Accounts: We store the personal information for registered users in their user profile. Users can see, edit, or delete their personal information at any time (except they cannot change their username).
7. Security of Your Information

We take our responsibility to protect your information seriously. We have implemented appropriate and reasonable technical and organisational security measures to protect your personal data from loss, misuse, unauthorised access, disclosure, alteration, and destruction.

In the unlikely event of a data breach, we will notify the Information Regulator and affected individuals as soon as reasonably possible.

8. Your Rights Over Your Data

Under the Protection of Personal Information Act, you have the following rights regarding your personal data:

The Right to Access: You can request a copy of the personal information we hold about you.
The Right to Rectification: You can request that we correct any information you believe is inaccurate or incomplete.
The Right to Erasure: You can request that we erase your personal data, under certain conditions.
The Right to Object to Processing: You have the right to object to us processing your personal information for direct marketing or on other legitimate grounds.
The Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Regulator of South Africa if you believe we are not processing your data lawfully.
To exercise any of these rights, please contact our Information Officer at candlesandthings2022@gmail.com. We will require proof of identity before we can process your request.

The Information Regulator (South Africa):

Website: https://www.justice.gov.za/inforeg/
Email: inforeg@justice.gov.za
9. Embedded Content from Other Websites

Articles on this site may include embedded content (e.g., videos, images, articles). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, and monitor your interaction with that embedded content.

10. Changes to This Privacy Policy

We may update this policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We encourage you to review this page periodically for the latest information on our privacy practices.

Shopping Cart
Scroll to Top