How BidShop currently handles account, commerce, payment and delivery information.
This working Privacy Policy describes how the current BidShop platform handles information needed to create accounts, operate auctions, process orders, verify payments, arrange delivery, provide account history and secure the service.
Depending on how you use BidShop, this may include account identifiers, email address, password hash, profile information, phone number, province, saved delivery addresses, order delivery snapshots, bidding activity, wallet and bid-credit balances, order history, payment references, uploaded proof-of-payment files and shipment/tracking information.
Information is used to authenticate accounts, verify email ownership, operate bidding and commerce workflows, prevent duplicate or unauthorised transactions, process payments, fulfil orders, provide customer history, send transactional communications, investigate errors and protect platform integrity.
BidShop stores password hashes rather than plain-text passwords. Email-verification and password-reset flows use time-limited security tokens, with hashed token values stored by the application where implemented.
Manual EFT proof files are stored outside the public web root and are served only through authenticated application routes with ownership or administrative access checks.
Reusable customer addresses are kept separately from immutable order delivery snapshots. This allows a saved address to be updated without rewriting the historical destination recorded on an earlier order.
BidShop may rely on hosting, email, payment, delivery, analytics or other service providers as the platform moves into production. The final policy will identify relevant categories and formal processing arrangements once the launch stack is finalised.
Transaction, order, bidding, payment and fulfilment records may need to be retained for operational, accounting, fraud-prevention, dispute-resolution or legal purposes. Final retention periods will be documented before commercial launch.
Customers will be able to maintain account and reusable delivery information through the platform where those features are provided. Formal procedures for privacy enquiries, access, correction or deletion requests will be published with the final support and company details.
This is a pre-launch working policy, not the final registered-entity privacy notice. It will be reviewed and updated before commercial launch, including the final responsible-party details and applicable South African privacy requirements.