Privacy Policy

Clear information about what we collect and why.

This policy explains how Supermarketing handles personal information when you use our website, submit an enquiry, apply for Creative Desk or work with us as a client, supplier or authorised contact.

Effective date: 16 August 2026 · Last updated: 16 August 2026

Responsible party

Ruby Rose Designs (Pty) Ltd

Trading as Supermarketing

Business address

30 High Street, Durbanville
Cape Town, 7550, South Africa

Information Officer

Raqual van Wyk

info@supermarketing.co.za

1. Our role

We handle information in two different capacities.

Supermarketing is the responsible party when we decide why and how personal information is used, for example when you submit a website enquiry or Creative Desk application.

We may act as an operator when a client instructs us to process information as part of an agreed service. In that situation, the client remains responsible for the purpose of the processing and we follow the client’s lawful, documented instructions and the applicable data-processing agreement.

Website and enquiry information

Names, contact details, business information, enquiry content, website or social-profile links, service interests, location, budget range and preferred timing.

Franchise retail onboarding information

Store and contact details, operating information, social-media page information, invoicing details and the names and contact details of authorised store representatives.

Client-service information

Briefs, source material, approvals, brand assets, campaign information, account access granted through approved roles, customer enquiries and other information needed to deliver an agreed service.

Technical information

Information generated by the website or hosting platform, such as IP address, browser and device information, security logs and basic usage data.

Please do not submit passwords, payment-card details, identity documents, health information or other sensitive personal information through our public forms unless we have specifically requested it through an approved secure process.

2. Why we use information

Only for a clear business or legal purpose.

Depending on the context, processing may be based on consent, steps requested before entering into a contract, performance of a contract, a legal obligation or a legitimate business interest that does not unfairly override your rights.

Respond to enquiries and assess whether our services are a suitable fit.
Prepare proposals, agreements, onboarding and production plans.
Deliver creative, retail-marketing, social-media and related services.
Manage client accounts, approvals, invoicing and business records.
Protect our systems, investigate misuse and maintain service security.
Meet legal, regulatory, audit and contractual obligations.
Send marketing communication only where permitted and provide a way to opt out.

Who may receive information

Authorised Supermarketing personnel, the relevant client where we act as an operator, and approved service providers that support hosting, cloud storage, communication, administration, accounting, security or agreed campaign delivery.

We may also disclose information where required by law, a court, the Information Regulator or another competent authority.

How we protect information

We apply reasonable technical and organisational safeguards appropriate to the information and risk. These include authorised access, confidentiality obligations, controlled account permissions, secure transmission, device and malware protection, backups, incident procedures and review of service providers.

How long we keep it

We retain information only for as long as it is reasonably needed for the purpose collected, an active client relationship, legal or financial recordkeeping, dispute management or an agreed client instruction. Information is then deleted, returned, archived securely or de-identified as appropriate.

3. Client and retail information

Additional controls apply when we process information for a client.

For work performed in the Pick n Pay retail environment, Supermarketing operates under written data-processing obligations aligned to POPIA and the client’s security requirements.

These contractual obligations support authorised processing, confidentiality, access control, incident escalation, sub-processor oversight, transfer controls and the return or deletion of client information. They do not constitute a public certification or endorsement.

Our operator commitments

Process client information only for the agreed service and authorised purpose.
Limit access to people who need it and are subject to confidentiality obligations.
Use approved service providers and apply appropriate contractual safeguards.
Escalate suspected security incidents promptly under the applicable incident process.
Return, delete or securely retain client information in line with the client instruction, contract and law.

4. Transfers, cookies and marketing

Practical limits apply.

Some approved service providers may process information outside South Africa. Where this occurs, we use the safeguards required by POPIA and any client-specific restriction. Client information subject to contractual location controls is not transferred without the required authorisation.

The website may use essential technical cookies needed for security and operation. Optional Meta advertising technology, including browser- and server-side measurement, is activated only after you accept optional tracking. It helps us understand page visits and completed enquiry forms. We do not send names, email addresses, phone numbers, messages or other form content to Meta. Meta may receive event information and technical identifiers such as your IP address, browser user agent and Meta cookie identifiers for measurement and attribution. You can change your choice at any time through “Cookie preferences” in the website footer.

Submitting an enquiry does not automatically subscribe you to general marketing. Electronic direct marketing is sent only where permitted, and each message will provide a practical way to opt out.

5. Your rights

You may ask us to:

Confirm whether we hold personal information about you.
Provide access to the information, subject to lawful limitations.
Correct information that is inaccurate, incomplete or out of date.
Delete or destroy information we are no longer authorised to retain.
Object to certain processing or withdraw consent where consent is the basis.
Stop direct-marketing communication.

We may need reasonable proof of identity before acting on a request. Some information may need to be retained where required by law or a valid contractual obligation.

6. Contact and complaints

Start with our Information Officer.

Please send privacy questions or requests to the Information Officer. Explain what you need and provide enough information for us to identify the relevant record without sending unnecessary confidential information.

If we cannot resolve the matter, you may contact the South African Information Regulator. Visit inforegulator.org.za .

We may update this policy when our services, systems or legal obligations change. The latest version will always appear on this page.