Privacy Policy

Profit Pigeon (Pty) Ltd
Effective date: 31 August 2026
Last updated: 31 August 2026


1. Overview#

Profit Pigeon is a profit analytics application for Shopify merchants. It reads order data from a merchant's Shopify store and advertising data from advertising accounts the merchant connects, combines that data with cost information the merchant enters, and presents profit reporting back to the merchant.

This Privacy Policy explains what personal information Profit Pigeon processes, why, where it is stored, how long it is kept, and what rights individuals have in relation to it.

Two points are set out early because they determine how the rest of this policy applies.

Profit Pigeon does not receive the names, email addresses, telephone numbers or postal addresses of a merchant's customers. The application requests only Shopify Protected Customer Data Level 1 access. It reads order values, refunds, line items, costs and a pseudonymous customer identifier. It does not request or receive customer contact details, and those details are not visible anywhere in the application.

Profit Pigeon does not sell or share personal information. It is not disclosed to any third party for that third party's own purposes, it is not used for cross-context behavioural advertising, and it is not used to train or fine-tune any artificial intelligence or machine learning system.


2. Who Profit Pigeon is#

Legal entityProfit Pigeon (Pty) Ltd
Registration number2026/196128/07
Registered officeUnit 201 Masons Press, Woodlands Road, Woodstock, Cape Town, Western Cape, 7925, South Africa
Postal addressAs above
Privacy contactdeveloper@profitpigeon.com
Support contactdeveloper@profitpigeon.com
Telephone+27 73 818 4983
Information OfficerTheo van Wyk

References to "Profit Pigeon", "the Company", "we" or "us" are references to Profit Pigeon (Pty) Ltd. References to "the Merchant" are references to the Shopify merchant who has installed the application.

2.1 Representatives in the European Union and United Kingdom#

Profit Pigeon has no establishment in the European Union or the United Kingdom.

The application is offered to Shopify merchants, which are businesses, rather than to individuals in the Union or the United Kingdom. Profit Pigeon does not direct marketing at those regions, does not price in euro or pounds sterling, and does not target individuals located there.

On that basis no representative has been appointed under Article 27 of the GDPR or Article 27 of the UK GDPR. This position is kept under review. A representative will be appointed, and named in this section, before Profit Pigeon markets to the European Union or the United Kingdom, or otherwise begins to offer services to or monitor the behaviour of individuals located there.

The absence of a representative does not affect the protections in this policy. Where the GDPR or UK GDPR applies to a merchant's data, the safeguards in section 10 and the processing terms in the annex to the Terms of Service apply in full.


3. The two roles Profit Pigeon holds#

Data protection law distinguishes between a party that decides why and how personal information is processed, and a party that processes personal information only on another party's instructions. Profit Pigeon holds both roles, for different categories of information. The distinction matters because different obligations and different rights attach to each.

InformationProfit Pigeon's role
Store data read from the Merchant's Shopify and advertising accountsOperator (POPIA), processor (GDPR and UK GDPR), service provider (CCPA)
Cost information entered into the application by the MerchantOperator, processor, service provider
Merchant account, billing, support and marketing informationResponsible party (POPIA), controller (GDPR and UK GDPR), business (CCPA)
Information collected through the Profit Pigeon websiteResponsible party, controller, business

Where Profit Pigeon acts as an operator, the Merchant decides the purposes of processing and Profit Pigeon acts only on the Merchant's documented instructions, recorded in the Data Processing Terms annexed to the Terms of Service at profitpigeon.com/terms. In that role Profit Pigeon has no independent right to use the information, and requests from a merchant's customers are directed to the Merchant.

Where Profit Pigeon acts as a responsible party, it decides the purposes of processing and this policy is the notice required by section 18 of POPIA and Article 13 of the GDPR.

Australian law does not distinguish between these roles in the same way. Where the Australian Privacy Act applies, Profit Pigeon is an overseas recipient and is contractually bound not to act inconsistently with the Australian Privacy Principles. Section 18 of this policy sets out how that works.


4. Information processed as an operator#

This is information belonging to the Merchant's business. It is read from systems the Merchant connects, or entered by the Merchant.

4.1 Shopify order data#

Read through the Shopify Admin API after the Merchant authorises the connection:

Profit Pigeon does not read, request, receive or store customer names, email addresses, telephone numbers or postal addresses. It does not subscribe to the Shopify customer creation or customer update webhooks.

4.2 Advertising platform data#

Read through the official APIs of Meta Ads, Google Ads and TikTok Ads, in each case only after the Merchant authorises the connection through that platform's own authorisation flow:

Profit Pigeon does not read audience lists, customer match lists or any other personal information from these platforms. The connection is read-only. Profit Pigeon does not send merchant order data, customer data or cost data to Meta, Google or TikTok.

4.3 Cost information entered by the Merchant#

The application allows the Merchant to configure cost lines including agency fees, platform and software subscriptions, shipping and fulfilment costs, salaries, rent, insurance and other operating costs, together with monthly targets, notes and annotations.

Merchants must not enter personal information into these fields. Cost lines are intended for amounts and descriptions, not for names or details of individuals. A salary line should record an amount, not an employee. The Terms of Service prohibit entering personal information into free-text fields, and prohibit routing special personal information, health information, criminal record information or the personal information of children through the application.


5. Information processed as a responsible party#

5.1 Merchant account information#

5.2 Billing information#

Subscription fees are charged through Shopify Billing and appear on the Merchant's Shopify invoice. Profit Pigeon does not receive, process or store card numbers or bank account details. What is received from Shopify is the subscription plan, charge amount, charge date and charge status.

5.3 Support information#

Where a Merchant contacts support, Profit Pigeon receives the contents of the message, any attachments, and the contact details used to send it.

5.4 Website information#

Where an individual visits the Profit Pigeon website, information is collected as described in section 21.


6. Why information is processed, and on what basis#

6.1 As an operator#

Store data and cost information are processed for one purpose: to provide the profit analytics service to the Merchant. This includes reading the data, storing it, computing metrics from it, and displaying the result to the Merchant and to users the Merchant has authorised.

Profit Pigeon is additionally instructed by the Merchant to aggregate and irreversibly anonymise that data to produce statistical information that cannot be attributed to the Merchant, to any store or to any individual. Once anonymised, that information is no longer personal information.

The legal basis for this processing is determined by the Merchant, who is the responsible party or controller for that information. Profit Pigeon processes it only on the Merchant's documented instructions.

6.2 As a responsible party#

PurposeBasis under POPIABasis under GDPR and UK GDPR
Creating and administering the Merchant's account, and providing the serviceNecessary to perform a contract (s11(1)(b))Contract, Article 6(1)(b)
Charging subscription fees through Shopify BillingNecessary to perform a contract (s11(1)(b))Contract, Article 6(1)(b)
Responding to support requestsNecessary to perform a contract, and legitimate interests (s11(1)(f))Contract and legitimate interests, Article 6(1)(b) and (f)
Securing the service, detecting and preventing fraud and abuse, and maintaining audit logsLegitimate interests (s11(1)(f))Legitimate interests, Article 6(1)(f)
Diagnosing faults and improving the applicationLegitimate interests (s11(1)(f))Legitimate interests, Article 6(1)(f)
Sending service messages about outages, changes and billingNecessary to perform a contract (s11(1)(b))Contract, Article 6(1)(b)
Sending marketing messagesConsent (s11(1)(a) and s69)Consent, Article 6(1)(a)
Retaining financial recordsCompliance with a legal obligation (s11(1)(c))Legal obligation, Article 6(1)(c)

Where legitimate interests are relied on, the interest is in operating a secure and functioning service, and in understanding how the application is used so that faults can be found and fixed. That interest has been weighed against the rights of the individuals concerned. The information involved is business contact information and technical log data, the processing is what a person would reasonably expect from a business application they have installed, and an objection may be raised at any time under sections 14 and 15 of this policy.

Providing account information is a contractual requirement. The application cannot be provided without it.


7. Sources of information#

Personal information reaches Profit Pigeon from four sources:

  1. Directly from the Merchant, when an account is created, cost information is entered, or support is contacted.
  2. From Shopify, through the Shopify Admin API and webhooks, after the Merchant authorises the application.
  3. From Meta, Google and TikTok, through each platform's advertising API, after the Merchant authorises the connection.
  4. Automatically, from the Merchant's device when the application or website is used.

8. Disclosure of information#

Profit Pigeon does not sell personal information, does not share it for cross-context behavioural advertising, and does not disclose it to any third party for that third party's own purposes.

Information is disclosed only in the following circumstances.

To sub-processors, as set out in section 9.

To Shopify, where Shopify sends a customer data request, customer redaction or shop redaction notification, as described in section 13.

Where required by law, by a court order, a statutory obligation or a lawful request from a competent authority. Any such request is assessed before it is acted on, and the Merchant is notified unless notifying them is prohibited by law.

On a business transfer, where the Company is acquired or merges with another entity, or sells a part of its business. Any recipient remains bound by this policy in respect of information collected before the transfer, and Merchants are notified before their information becomes subject to a different policy.

To professional advisers, being the Company's auditors, accountants and attorneys, each of whom is under a duty of confidentiality.

Profit Pigeon does not use merchant data or store data to create, develop, train, fine-tune or improve any artificial intelligence or machine learning system. This is a commitment made in this policy and a requirement of the Shopify Partner Program Agreement.


9. Sub-processors and other recipients#

A sub-processor is a third party that processes personal information on Profit Pigeon's behalf. Every one is bound by a written contract restricting it to Profit Pigeon's instructions, requiring security measures no less protective than those in the Data Processing Terms, and restricting onward transfer.

9.1 Sub-processors for merchant store data#

These are the only third parties that touch data read from a Merchant's Shopify or advertising accounts, or cost information a Merchant enters.

Sub-processorPurposeLocation of processing
Vercel Inc.Application hosting and computeSouth Africa (AWS af-south-1, Cape Town)
Amazon Web Services EMEA SARLDatabase and encrypted backupsSouth Africa (af-south-1, Cape Town)
Cloudflare, Inc.Domain name resolution, content delivery and network securityGlobal edge network. Cloudflare is incorporated in the United States.

9.2 Sub-processors and recipients for Company-controlled data#

These process merchant account information, support correspondence, marketing contacts or website visitor data. They do not touch merchant store data.

RecipientPurposeLocation
Vercel Inc.Marketing website hostingUnited States
Cloudflare, Inc.Domain name resolution, content delivery and network securityGlobal edge network, United States
Google LLC (Google Workspace)Business email and support correspondenceGlobal. Google LLC is incorporated in the United States.
Meta Platforms, Google, TikTokAdvertising and analytics cookies on the marketing website, where the visitor consents. See section 21.United States and Ireland

GoDaddy is the Company's domain name registrar. It does not process personal information on the Company's behalf and is not a sub-processor.

Note that Meta, Google and TikTok appear in two different capacities. On the marketing website they receive website visitor data through advertising cookies, where the visitor consents. In the application they are a read-only source of the Merchant's own advertising spend data, and receive nothing.

9.3 Not sub-processors#

Shopify, Meta Ads, Google Ads and TikTok Ads are, in the context of the application, sources. Profit Pigeon reads from them on the Merchant's instruction. Each is the Merchant's own provider under the Merchant's own agreement with that provider.

9.4 Changes#

Profit Pigeon gives at least 30 days notice before a new sub-processor begins processing merchant information. Notice is given by email to the Merchant's account address and by updating this section.

A Merchant may object to a new sub-processor on reasonable data protection grounds within 30 days, by writing to developer@profitpigeon.com. Where the objection cannot be accommodated, the Merchant may terminate before the new sub-processor begins processing, and will not be charged for any billing period beginning after termination.


10. Where information is stored#

Merchant store data and cost information is stored at rest in South Africa, in the Amazon Web Services Cape Town region (af-south-1), together with its encrypted backups.

This is a deliberate choice. For South African merchants it means the substance of their business data stays in the Republic.

Two qualifications are made so that the position is not overstated:

Profit Pigeon (Pty) Ltd is a South African company and is the responsible party for the information it controls.

10.1 Transfers into South Africa#

Where a Merchant is located outside South Africa, storing their data in the Cape Town region is a cross-border transfer from that Merchant's perspective.

European Union and United Kingdom. South Africa is not the subject of an adequacy decision by the European Commission, and is not covered by United Kingdom adequacy regulations. Transfers from EU or UK merchants are made under the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, and under the United Kingdom International Data Transfer Addendum. Both are incorporated into the Data Processing Terms annexed to the Terms of Service and take effect when a Merchant accepts those Terms. A copy as completed may be requested from developer@profitpigeon.com at no charge.

South Africa has comprehensive data protection legislation in POPIA, enforced by an independent Information Regulator, which affords protections comparable in substance to those under European law. An assessment of South African law as it affects the transfer, including the Regulation of Interception of Communications and Provision of Communication-Related Information Act, is maintained and is available to Merchants on request.

Australia. Profit Pigeon is an overseas recipient for the purposes of Australian Privacy Principle 8. The Data Processing Terms are the enforceable contract required by APP 8.1. Individuals should be aware that Profit Pigeon is subject to South African law, that a South African authority may in defined circumstances compel disclosure, and that in that event the individual may not have recourse under the Australian Privacy Act.

Transfers out of South Africa. Profit Pigeon is a South African company. Where personal information is transferred out of the Republic to a sub-processor, including to Vercel and Cloudflare, that transfer is made under section 72(1)(a) of POPIA, on the basis of a binding written agreement that upholds principles for reasonable processing substantially similar to POPIA's conditions and that restricts onward transfer. Each of those providers offers a data processing agreement incorporating the European Standard Contractual Clauses, supplemented so that it meets the section 72(1)(a) test.

Section 9 records the country of each sub-processor. Merchants should be aware that information may be processed in, or routed through, the United States and other jurisdictions, and that the law of those jurisdictions may permit access by public authorities in circumstances that differ from South African law.


11. How long information is kept#

InformationRetention period
Store data and cost informationDeleted within 30 days of the application being uninstalled, or of a Merchant's written deletion request. Retained for the first 14 days of that period so the Merchant can export it.
Backups containing store dataPurged within a further 30 days, so no later than 60 days after uninstall
Merchant account informationDeleted within 30 days of uninstall, other than the records below
Accounting recordsSeven years, as required by section 24 of the Companies Act 71 of 2008
Tax recordsFive years, as required by the Tax Administration Act 28 of 2011
Support correspondence24 months from the last message in the thread
Security and audit logs12 months
Marketing contact detailsUntil consent is withdrawn, then suppressed rather than deleted so that the withdrawal is honoured

Shopify sends a shop redaction notification 48 hours after an application is uninstalled. That notification is treated as confirmation of the deletion instruction. Deletion is completed within 30 days of uninstall, being no more than 28 days after that notification.

Information is retained beyond these periods only where a legal obligation requires it, or where it is needed to establish, exercise or defend a legal claim. Where that happens, the information is isolated and used for no other purpose.

Aggregated statistical information that cannot be linked to any Merchant, individual or store is not personal information and may be retained after deletion. It cannot be reversed to identify anyone.


12. Security#

Profit Pigeon maintains technical and organisational measures appropriate to the risk, as required by section 19 of POPIA, Article 32 of the GDPR and Australian Privacy Principle 11.

The measures in place include:

The full schedule of measures is set out in the Data Processing Terms annexed to the Terms of Service.

No system can be guaranteed to be secure. These measures reduce risk and do not eliminate it.

12.1 Security compromises#

Where Profit Pigeon becomes aware of a security compromise affecting a Merchant's information:

Where Profit Pigeon is the responsible party for the affected information, the Information Regulator and the affected individuals are notified directly, as soon as reasonably possible, in accordance with section 22 of POPIA.


13. Shopify privacy requests#

Shopify requires every application distributed through the Shopify App Store to respond to three notifications. Merchants are entitled to know what each one does.

Customer data request. Sent when a merchant's customer asks that merchant for a copy of their data. Profit Pigeon assembles whatever information it holds relating to that customer identifier and provides it to the Merchant. It goes to the Merchant and not to the customer, because the Merchant is the responsible party and is the party who must respond.

Customer redaction. Sent when a merchant's customer asks that merchant to erase their data. Profit Pigeon erases or irreversibly de-identifies the records identified. Because Profit Pigeon holds no customer contact details, this ordinarily means severing the pseudonymous identifier from the order records, which leaves the Merchant's financial totals intact while removing the ability to link any order to a person.

Shop redaction. Sent 48 hours after a merchant uninstalls the application, and treated as confirmation of the deletion instruction. Deletion is completed within 30 days of uninstall, as described in section 11.

Each action is completed within 30 days. The only exception is where information must be retained to comply with a legal obligation, in which case it is isolated, used for no other purpose, and deleted once the obligation ends.


14. Rights#

The rights available depend on where an individual is and which law applies. The following are offered to every individual, regardless of location, in respect of information for which Profit Pigeon is the responsible party.

RightWhat it means
AccessTo be told whether information about the individual is held, and to receive a copy
CorrectionTo have inaccurate or incomplete information corrected or completed
DeletionTo have information deleted where it is no longer needed, where consent is withdrawn, or where it has been processed unlawfully
ObjectionTo object to processing based on legitimate interests, and to object to direct marketing at any time
RestrictionTo have processing paused while a dispute about accuracy or lawfulness is resolved
PortabilityTo receive information in a structured, commonly used, machine-readable format, and to have it transmitted to another provider where technically feasible
Withdrawal of consentTo withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
ComplaintTo lodge a complaint with a supervisory authority, as set out in section 22

Requests from a merchant's customers. Where an individual is a customer of a merchant that uses Profit Pigeon, their request should be directed to that merchant. The merchant is the responsible party for that information and decides how it is used. Profit Pigeon will assist the merchant in responding. Any request received directly from a merchant's customer is forwarded to the relevant merchant, and the individual is told that this has been done.


15. How to exercise a right#

Requests should be sent to developer@profitpigeon.com.

Appeals. Where a request is refused, the individual may appeal by replying to the refusal and marking it as an appeal. Appeals are reviewed by a person who was not involved in the original decision and are answered in writing, with reasons, within 45 days, or within any shorter period the individual's own law requires. Where an appeal is refused, the individual is given the details of the relevant regulator, and where the individual is in the United States, a means of submitting a complaint to their State Attorney General.


16. Direct marketing#

Marketing messages are sent only with consent, and only to business contacts. Every marketing message contains an unsubscribe mechanism, and consent may be withdrawn at any time by using it or by writing to developer@profitpigeon.com.

An opt-out is not treated as consent. Withdrawing consent does not affect service messages about outages, changes to the service or billing, which are necessary to provide the service.


17. Individuals in the United States#

Profit Pigeon does not meet the thresholds to be a "business" under the California Consumer Privacy Act. In respect of merchant store data it acts as a service provider. In respect of merchant account information it applies the disclosures below as a matter of policy.

Categories of personal information. In the preceding 12 months Profit Pigeon has collected identifiers (name, business email address, shop domain, internet protocol address), commercial information (subscription plan and charge history), internet activity information (application usage and log data), and, in its service provider capacity, commercial information belonging to merchants together with pseudonymous identifiers. Sources are in section 7, purposes in section 6, and retention periods in section 11.

Sensitive personal information. None is collected. No sensitive personal information is used or disclosed for any purpose that would give rise to a right to limit its use.

Sale and sharing. Profit Pigeon does not sell and does not share personal information as those terms are defined in the California Consumer Privacy Act, and has not done so in the preceding 12 months. No "Do Not Sell or Share My Personal Information" link is provided because there is nothing to opt out of. Personal information is not sold under the law of any other state.

Minors. Profit Pigeon has no actual knowledge that it sells or shares the personal information of consumers under 16 years of age. It does not sell or share personal information at all.

Training of large language models. Profit Pigeon does not collect, use or sell personal information for the purpose of training large language models or any other artificial intelligence system. This statement is made for the purposes of Connecticut law.

Named third parties. Profit Pigeon does not sell personal information to any third party. This statement is made for the purposes of Rhode Island law.

Opt-out preference signals. Because no sale or sharing takes place, there is nothing for a Global Privacy Control signal to opt out of. Any such signal received is nonetheless honoured.

Disclosures for a business purpose. In the preceding 12 months the categories above have been disclosed to the sub-processors listed in section 9, for the business purposes described in section 6.

Service provider commitments. In respect of merchant store data, Profit Pigeon does not retain, use or disclose it for any purpose other than performing the services specified in the Data Processing Terms, does not retain, use or disclose it outside the direct business relationship, does not combine it with information received from any other source, and does not sell or share it. Merchants have the right to take reasonable steps to confirm this, as set out in the audit provisions of the Data Processing Terms.

Rights. Residents of California and of every other state with comprehensive privacy legislation may exercise the rights in section 14, including the right to appeal in section 15. Requests from a merchant's customers are directed to that merchant.


18. Individuals in Australia#

Profit Pigeon is located in South Africa and is an overseas recipient for the purposes of the Privacy Act 1988 (Cth). It is contractually bound, under the Data Processing Terms, not to act in a way that would breach the Australian Privacy Principles.

Kinds of information and how it is held. Set out in sections 4 and 5, with the purposes in section 6. Information is held in electronic form in the Amazon Web Services Cape Town region in South Africa, and is protected as described in section 12.

Overseas recipients and their countries. Profit Pigeon is established in South Africa. Information is held at the location stated in section 10. The countries in which recipients are located are listed in section 9, and include the United States. Reasonable steps are taken to ensure that overseas recipients do not breach the Australian Privacy Principles, by binding each of them in writing.

Individuals should be aware that an overseas recipient may in defined circumstances be required to disclose information under the law of the country in which it operates, and that in that event the individual may not have recourse under the Privacy Act.

Access, correction and complaints. As set out in sections 14, 15 and 22.

Automated decision-making. Profit Pigeon does not use any computer program to make, or to do anything substantially related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests. Should that change, this policy will state the kinds of personal information used, the kinds of decisions made solely by such a program, and the kinds of decisions for which such a program does something substantially related to making the decision, before the change takes effect.

Notifiable data breaches. Where an eligible data breach occurs and the Privacy Act applies, an assessment is carried out expeditiously and in any event within 30 days, and the Office of the Australian Information Commissioner and the affected individuals are notified as soon as practicable. Where the information is also held by a merchant, the merchant ordinarily notifies, as the party with the direct relationship with the affected individuals, and Profit Pigeon provides the information necessary for them to do so.


19. Individuals in the European Union and the United Kingdom#

Profit Pigeon does not market to the European Union or the United Kingdom and does not target individuals located there. Where the GDPR or UK GDPR nonetheless applies:


20. Children#

Profit Pigeon is a business application for Shopify merchants and the people they authorise. It is not directed to children, and personal information is not knowingly collected directly from anyone under the age of 18, or under 13 for the purposes of the United States Children's Online Privacy Protection Act.

Where Profit Pigeon becomes aware that it has collected personal information directly from a child under 13 without verifiable parental consent, that information is deleted promptly. This may be reported to developer@profitpigeon.com.

Where a merchant's order data relates to a minor, Profit Pigeon processes it only as an operator on the merchant's documented instructions. The merchant is the responsible party and is responsible for any consent, notice or age verification obligation. Merchants are prohibited by the Terms of Service from routing the personal information of children through the application.


21. Cookies and website tracking#

In the application. Only strictly necessary cookies are used. These maintain the session, keep the user signed in and protect against cross-site request forgery. They cannot be disabled without the application ceasing to function, and no consent is required for them.

On the website. The marketing website at profitpigeon.com uses strictly necessary cookies, and, where the visitor consents, analytics and advertising cookies set by Meta, Google and TikTok. These measure the performance of advertising campaigns. Where a visitor consents, those providers receive information about the visit and may process it for their own purposes under their own policies.

Consent is requested before any non-essential cookie is set. Refusing is as easy as accepting, and refusing does not restrict access to the website. Consent may be changed at any time through the preference control on the website. Closing or navigating away from a consent banner is not treated as consent.


22. Complaints#

A complaint may be raised directly with Profit Pigeon at developer@profitpigeon.com. Complaints are acknowledged within 7 days and answered within 30 days. Raising it directly is usually the fastest route to a resolution and is not a precondition to approaching a regulator.

An individual also has the right to complain to a regulator.

South Africa
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
complaints.IR@inforegulator.org.za
inforegulator.org.za

Australia
Office of the Australian Information Commissioner
oaic.gov.au

United Kingdom
Information Commissioner's Office
ico.org.uk

European Union
The data protection supervisory authority of the individual's country of residence, place of work, or the place where the alleged infringement occurred.

United States
The Attorney General of the individual's state, and in California, the California Privacy Protection Agency.


23. Changes to this policy#

This policy may be amended. The current version is always published at profitpigeon.com/privacy and the effective date appears at the top.

An amendment is material where it reduces the protections in this policy, changes the purposes for which personal information is processed, adds a category of recipient, or changes where information is stored. Any amendment a Merchant reasonably identifies as material is treated as material.

Where a change is material, Merchants are notified by email and in the application at least 30 days before it takes effect. A Merchant who does not accept a material change may uninstall the application, and their data is deleted in accordance with section 11.

Previous versions are retained and may be requested from developer@profitpigeon.com.


24. Contact#

Privacy queries and requestsdeveloper@profitpigeon.com
Information OfficerTheo van Wyk, developer@profitpigeon.com
Supportdeveloper@profitpigeon.com
PostProfit Pigeon (Pty) Ltd, Unit 201 Masons Press, Woodlands Road, Woodstock, Cape Town, Western Cape, 7925, South Africa
Telephone+27 73 818 4983

The Company's manual prepared under section 51 of the Promotion of Access to Information Act is published at profitpigeon.com/paia.