Legal information
Privacy Policy
This policy explains how OneStop Kitchen, trading as OneStop Kitchen, handles personal information when you browse, create an account, order food, pay, request support or use order tracking.
We aim to process personal information lawfully, reasonably and transparently in accordance with South Africa’s Protection of Personal Information Act, 2013 (“POPIA”).
Version 2026-07 · Last updated 30 July 2026
1. Scope and responsible party
OneStop Kitchen is the responsible party for the personal information described in this policy because we determine why and how it is processed. The policy covers this website, customer accounts, guest checkout, delivery and collection, order tracking, reviews, refunds and customer support.
Payment providers, identity providers and other third parties may separately be responsible for information they collect directly under their own privacy notices.
2. Personal information we collect
- Identity and contact: name, email address, phone number and account identifiers.
- Account and authentication: password credentials in protected form, verification state, sessions, account role and optional profile image.
- Order information: ordered meals, modifiers, customer notes, fulfilment choice, requested time, delivery instructions, status history, issue reports and refunds.
- Address information: delivery/contact address and saved-address preferences.
- Payment and transaction: payment method, amount, status, PayFast transaction reference and payment callback data. We do not receive full card credentials.
- Customer content: product reviews, ratings and support communications.
- Technical and security: IP address, browser/device information, timestamps, request logs, cookie/session identifiers and information needed to detect abuse.
Please do not put health information, identity numbers, payment-card details or other unnecessary sensitive information in meal notes, reviews or support messages.
3. Where information comes from
We collect information directly from you, from the person placing an order for you, from your browser or device, and from your interactions with the website. We also receive limited status or identity information from providers such as PayFast or Google when you choose those services.
4. Why and on what grounds we process information
Depending on the context, processing is necessary to conclude or perform an order or account agreement, comply with law, pursue a legitimate operational or security interest, protect your or another person’s legitimate interests, or act with consent where consent is required.
- Create and secure accounts, authenticate users and recover access.
- Validate carts, process orders, arrange delivery or collection and provide tracking.
- Verify payments, prevent fraud and reconcile financial records.
- Send necessary account, payment, order, cancellation and refund messages.
- Provide support, investigate complaints and resolve order issues.
- Moderate verified-purchase reviews and protect other customers.
- Maintain, troubleshoot and secure the service.
- Meet tax, accounting, consumer-protection, legal and regulatory duties.
- Establish, exercise or defend legal claims.
If required information is not supplied, we may be unable to create the account, process the order, deliver to you or respond to a rights request.
5. Payment information and PayFast
For PayFast orders, you enter payment credentials on PayFast’s service. We send order identifiers and payment amounts needed for the transaction, and receive verification data such as payment status and transaction reference. A verified PayFast callback—not the browser return page—is used to confirm online payment.
For offline methods, we record the selected method and payment/order status. We do not ask you to send full card details or passwords by email, WhatsApp or meal notes.
8. Operators and contractual safeguards
Some suppliers process information for us as operators—for example hosting, database, email and object-storage providers. We select providers appropriate to the service and require protection and confidentiality measures where POPIA requires them. Staff and administrators receive access according to their role and operational need.
9. Processing outside South Africa
Some cloud, email, authentication or payment infrastructure may process or store information outside South Africa. Where personal information is transferred across borders, we use providers, contracts or other safeguards intended to provide an adequate level of protection as required by POPIA.
10. How long we keep information
We retain information only for as long as reasonably needed for the purpose collected, an ongoing customer relationship, security and fraud prevention, legal claims, or tax, accounting and consumer-law obligations. Retention therefore differs by record:
- account and saved-address information is generally kept while the account is active and for a reasonable closure period;
- orders, payments, refunds, acceptance evidence and financial records are retained for applicable statutory and audit periods;
- security logs and guest sessions are retained for shorter operational periods unless an incident requires investigation;
- reviews may remain while published or needed to preserve moderation and purchase-verification records.
When retention is no longer authorised or required, information is deleted, destroyed or de-identified in a manner appropriate to the record and system.
11. Security and personal-information breaches
We use reasonable technical and organisational safeguards appropriate to the information and risks, including access controls, protected authentication, secure connections, restricted administrative routes, payment-provider verification and service logging. No internet system can guarantee absolute security.
If a security compromise affects your personal information, we will investigate, contain it and notify the Information Regulator and affected people where POPIA requires notification. Protect your password and tell us immediately about suspicious account activity.
12. Your rights under POPIA
Subject to lawful limitations and verification of your identity, you may:
- ask whether we hold personal information about you and request access;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing on grounds permitted by POPIA;
- withdraw consent where processing depends on consent, without invalidating earlier lawful processing;
- request restriction or deletion where we are no longer authorised to retain information;
- complain to us or the Information Regulator.
We may retain transaction or legal records despite a deletion request where retention is required or permitted by law. We may ask for information needed to verify identity and protect your account before fulfilling a request.
13. Direct marketing and service messages
Order receipts, payment verification, fulfilment updates, refunds, security notices and responses to support requests are service communications, not promotional marketing, and may be necessary to perform the transaction.
We will send electronic direct marketing only where permitted by POPIA and will provide a practical way to opt out. Opting out of marketing does not stop necessary transactional or security communications.
14. Children’s information
The service is not directed at children who cannot independently consent under applicable law. A parent or guardian should place an order for a child. Do not knowingly submit a child’s unnecessary personal information in notes or reviews. Contact us if you believe a child’s information was supplied without proper authority.
15. Automated decisions
The application automatically validates matters such as cart availability, delivery zones, opening hours, payment state and order ownership. We do not currently make solely automated decisions that produce legal or similarly significant effects about a person. Contact us if you believe an automated rule produced an incorrect result.
16. Third-party links and services
This site may link to PayFast, Google, social platforms or other third parties. Their services are governed by their own privacy notices. Review those notices before providing information directly to them.
17. Changes to this policy
We may update this policy when processing, providers, legal requirements or the service change. The version and date above identify the current notice. Material changes will be communicated through an appropriate channel and apply prospectively unless law requires otherwise.
18. Privacy requests, contact and complaints
Send a privacy request to support@onestopkitchen.co.za, call +27612728258, or use our contact page. Address the request to the Information Officer and describe the information or right involved.
If we cannot resolve your concern, you may lodge a POPIA complaint through the Information Regulator’s complaints service. The Regulator publishes current forms and contact channels on its website.
Read the official Protection of Personal Information Act or consult the POPIA forms for objection, correction and deletion requests.
