Privacy Policy

Last updated: November 2024

Introduction

Welcome to Rhinocery ("we", "us", or "our"). We are committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner. This Privacy Policy explains how we collect, use, disclose, and protect your information when you visit our website https://www.rhinocery.co.za (the "Site") or use our grocery price aggregation and optimization services. This policy applies to all users, including those in South Africa under the Protection of Personal Information Act (POPIA) and those in the European Union under the General Data Protection Regulation (GDPR). Please read this policy carefully to understand our practices regarding your personal data.

By accessing or using our Site, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our Site.

Information We Collect

Personal Information

We may collect the following personal information when you create an account, use our services, or interact with us:

  • Full name
  • Email address
  • Profile picture (optional)
  • Payment information (if applicable)

Search and Optimization Data

To provide our core grocery price aggregation and optimization services, we collect and store:

  • Shopping lists and search queries
  • Product selections and optimization preferences
  • Search history and patterns
  • Product comparison data
  • Store and brand preferences
  • Price sensitivity indicators
  • Shopping frequency patterns

Usage Data

We automatically collect information about your interactions with our Site, including:

  • Browser type and version
  • Operating system
  • IP address
  • Referral source
  • Pages visited and actions taken
  • Time and date of visits
  • Device information

Cookies and Similar Technologies

We use cookies and similar tracking technologies to enhance your experience on our Site. These technologies help us analyze site usage, remember your preferences, and personalize content. You can control the use of cookies at the individual browser level. However, if you choose to disable cookies, some features of our Site may not function properly.

Aggregated Shopping Analytics

To improve our price optimization algorithms and provide better recommendations, we collect and analyze:

  • Purchase patterns and frequency
  • Price sensitivity indicators
  • Brand preferences and substitution patterns
  • Seasonal shopping behaviors
  • Regional price variations and trends
  • Shopping basket composition analytics
  • Product category preferences
  • Price comparison metrics
  • Store selection patterns

How We Use Your Information

We use the collected data for various purposes, including:

  • Providing and maintaining our services
  • Improving and personalizing your experience on our Site
  • Analyzing usage patterns to enhance our services
  • Developing new products, services, features, and functionality
  • Communicating with you, including sending updates, security alerts, and support messages
  • Processing transactions and managing your orders
  • Deriving insights about consumer spending to optimize grocery basket expenditures
  • Complying with legal obligations and protecting our rights

Data Storage and Security

Your data is stored securely on Google Cloud Platform. We implement a variety of security measures to ensure the safety of your personal information, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication protocols
  • Continuous monitoring for unauthorized access and breaches
  • Data anonymization and pseudonymization where applicable

Despite our efforts, no security measures are perfect or impenetrable. We cannot guarantee the absolute security of your data, and you provide it to us at your own risk.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Personal information used to provide services will be retained for the duration of your account.
  • Data used for analytics and improvement purposes may be retained in aggregated form indefinitely.
  • Information required for compliance with legal obligations will be retained as needed.

When your personal information is no longer required, we will securely delete or anonymize it.

Data Sharing and Disclosure

We do not sell, trade, or otherwise transfer your personal information to third parties without your explicit consent, except in the following circumstances:

  • Service Providers: We may share your information with trusted third-party service providers who assist us in operating our Site, conducting our business, or providing services to you, provided they agree to keep your information confidential.
  • Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).
  • Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
  • Aggregated Data: We may share aggregated, anonymized data with partners, advertisers, and other third parties for analytical or marketing purposes.

We ensure that any third parties with whom we share your data adhere to strict privacy and security standards.

Your Rights

Depending on your location, you have certain rights regarding your personal data. Users in South Africa have rights under POPIA, and users in the European Union have rights under GDPR. These rights may include:

  • Right to Access: You have the right to request access to your personal information.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal information.
  • Right to Erasure ("Right to be Forgotten"): You can request the deletion of your personal data, subject to certain conditions.
  • Right to Restrict Processing: You may request the limitation of the processing of your personal data.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
  • Right to Object: You can object to the processing of your personal data for specific purposes, including direct marketing.
  • Right to Withdraw Consent: If you have provided consent for data processing, you can withdraw it at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or place of the alleged infringement if you believe your data has been mishandled.

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable laws.

International Data Transfers

Your information, including personal data, may be transferred to and maintained on servers located outside of your country of residence. These jurisdictions may have different data protection laws than your country. We take appropriate measures to ensure that your data remains protected in accordance with this Privacy Policy, POPIA, GDPR, and applicable laws.

Lawful Basis for Processing

We process your personal data based on the following lawful bases:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose.
  • Contractual Necessity: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
  • Compliance with Legal Obligations: Processing is necessary for us to comply with the law (not including contractual obligations).
  • Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect your personal data which overrides those legitimate interests.

For more detailed information, please refer to the applicable sections of this Privacy Policy.

Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without parental consent, we will take steps to delete that information promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any significant changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top.

Your continued use of our Site after any changes constitutes your acceptance of the updated Privacy Policy.

Third-Party Links

Our Site may contain links to third-party websites that are not operated by us. We are not responsible for the privacy practices or the content of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.

POPIA-Specific Information

As a South African entity operating under the Protection of Personal Information Act (POPIA), we commit to:

  • Accountability: We have appointed an Information Officer responsible for ensuring compliance with POPIA and handling data-related inquiries.
  • Processing Limitation: We only collect and process personal information that is necessary for our stated purposes and with your consent.
  • Purpose Specification: Your personal information is collected for specific, explicitly defined purposes related to our grocery price optimization services.
  • Further Processing Limitation: Any additional processing of your information will be compatible with our original stated purposes.
  • Information Quality: We take reasonable steps to ensure that your personal information is complete, accurate, and updated when necessary.
  • Openness: We maintain transparency about our data collection and processing practices through this privacy policy and direct communication.
  • Security Safeguards: We implement appropriate technical and organizational measures to protect your personal information.
  • Data Subject Participation: You have the right to access, correct, or delete your personal information.

Automated Decision Making and Profiling

Our service utilizes automated processing, including profiling, to provide personalized grocery optimization recommendations. This involves:

  • Analysis of shopping patterns to predict future needs
  • Price optimization algorithms based on historical purchase data
  • Store recommendations based on location and shopping preferences
  • Product substitution suggestions based on price sensitivity
  • Basket optimization based on historical shopping patterns
  • Price trend analysis and predictions

You have the right to:

  • Obtain human intervention in any automated decision-making process
  • Express your point of view regarding automated decisions
  • Contest any automated decisions made about you
  • Opt-out of certain automated decision-making processes while still using our basic services

Data Minimization and Accuracy

In accordance with POPIA principles, we:

  • Collect only the minimum amount of personal information necessary for our services
  • Regularly review and update stored information to ensure accuracy
  • Implement processes to identify and correct inaccurate information
  • Provide mechanisms for users to review and update their information
  • Delete or de-identify information that is no longer necessary
  • Maintain data quality control procedures
  • Implement data retention schedules
  • Conduct regular data accuracy audits

Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

We will address your inquiries and requests in accordance with applicable laws, including POPIA and GDPR.