DRIVERS & DIVOTS

Privacy Policy

Last updated 7 August 2026

This explains what we do with your personal information, why we need it, and what you can make us do about it. It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA).

Who is responsible for your information

Drivers & Divots is responsible for your data.

Any request about your information goes to info@driversanddivots.co.za.

What we collect

To place an order we ask for, and require:

  • Your full name
  • Your email address
  • Your mobile number
  • Your delivery address — street address, city or suburb, province and postal code

You can also leave optional notes on your order. Whatever you type there is stored with the order, so do not put anything in that box you would not want kept.

We also keep what you bought: club names, the options you chose, quantities, the amount charged and the payment status.

If you start checkout and enter your email (even before paying), we may save a draft customer profile — name, contact details, address and bag contents as far as you filled them — so we can complete or follow up on an abandoned order. That profile is stored in our shop database on our server and is only used for order handling and admin.

We never see any of your banking information. You pay by EFT from your own banking app, so no card number, no banking login and no PIN is ever entered on this site, transmitted to us or stored by us. All we record is that a payment arrived against your order reference.

Cookies and similar technology

We use three categories:

  • Essential — required for the shop to work. Your shopping bag is stored in your browser (local storage) until you check out. If you sign in to the admin area, a signed session cookie keeps you logged in. These are not used to advertise to you.
  • Analytics (optional, only with your consent) — first-party events on this website only: page views, product views, searches, add-to-bag and checkout steps; a durable visitor id (dd_vid), a session id (dd_sid), first-touch campaign parameters when present (dd_ft), a coarse referrer, browser user-agent, screen/timezone hints, a your IP address as seen by our server (for security and traffic analysis on our admin tools only), a hashed form of that IP, and country when our host provides it. If you later place an order, that visitor id may be stored on the order so we can see which anonymous journey became a sale. We do not use this to build a profile of other websites you visit.
  • Marketing (optional, only with your consent) — if we have configured an advertising pixel (for example Meta), that script loads only after you allow marketing cookies. When you check out, we may also send limited conversion events (for example InitiateCheckout and Purchase) to the same platform from our server, including a hashed form of your email and phone for matching — only if marketing consent was on at checkout. It helps measure whether ads brought you here. It still does not give us a list of every other site you use.

A banner asks for your choice on the first visit. You can change it at any time via Cookie settings in the site footer. Your choice is stored in a first-party cookie named dd_consent. Turning analytics off clears the visitor, session and campaign cookies.

Clearing your browser cookies and site data erases the bag, consent choice and analytics ids.

What we do not collect

We do not read your full browsing history or other websites' cookies. We do not sell your personal information. We do not run analytics or marketing scripts until you have opted in through the cookie banner (or later via Cookie settings).

Why we need it, and on what basis

We process order information to conclude and perform the sale you asked for — taking payment, ordering and handling your clubs, getting them delivered, and handling returns or warranty claims afterwards. Under POPIA that is processing necessary to carry out a contract with you.

We also keep order and tax records because the Companies Act and the Tax Administration Act require us to.

Analytics and marketing cookies run only with your consent. You can withdraw that consent any time by opening Cookie settings and choosing Essential only (or turning those toggles off). Withdrawal does not affect the lawfulness of processing before you withdrew.

We do not email you marketing unless you separately ask us to.

Who we share it with

We pass on the minimum each party needs to do its job:

  • Our courier and handling agent — receives your name, delivery address and mobile number, because a parcel cannot be processed or delivered without them.
  • Advertising platforms (only if you allowed marketing cookies and we have enabled a pixel / conversion API) — limited event data such as page views, add-to-bag, checkout and purchase, plus hashed contact details for matching where applicable. Their own privacy policies apply to what they do with that signal.

First-party analytics events are stored on our server and are not sold. They do not include your name, email or full address; those stay on the order record. We do not share personal information with anyone else unless a law or a court obliges us to.

Where it goes

Because your clubs are dispatched from outside South Africa, your name and delivery address are shared with the shipping and handling parties involved. POPIA permits this where the transfer is necessary to perform your contract, which is the basis we rely on.

If a marketing pixel is enabled, that provider may process data on servers outside South Africa under their terms. You control whether that script loads via Cookie settings.

How long we keep it

Order records are kept for five years to satisfy tax and company-records obligations and to honour warranty claims. Enquiries that never became orders are deleted once they are dealt with.

Analytics event logs are kept only as long as they remain useful for improving the shop (typically up to 24 months), then deleted or aggregated. Consent and visitor cookies expire after one year unless you clear them earlier; first-touch campaign cookies expire after 90 days.

How it is protected

Orders are stored on the server, not in the browser, and are reachable only through a password-protected admin area. Payment pages and this site are served over HTTPS. We hold no card or banking data at all, which removes the most damaging thing a breach could otherwise expose.

If a breach does affect your information, POPIA requires us to notify both you and the Information Regulator, and we will.

Your rights

You are entitled, at any time, to:

  • Ask what information we hold about you, and get a copy
  • Have anything inaccurate corrected
  • Have information deleted where we no longer have a lawful reason to keep it
  • Object to processing, and withdraw any consent you have given
  • Complain to the Information Regulator

Write to info@driversanddivots.co.za and we will respond. If you are not satisfied, the Information Regulator (South Africa) takes complaints directly — contact details are published on inforegulator.org.za.

This page describes our own terms and summarises the rights South African law already gives you. Where the two differ, the law wins — nothing here removes a right you have under the Consumer Protection Act 68 of 2008, the Electronic Communications and Transactions Act 25 of 2002, or POPIA.