Privacy Policy
Last updated: April 22, 2026
PannaAfric is committed to protecting your personal information. This policy explains what data we collect, how we use it, and your rights — including your rights under the GDPR (for EU/UK customers) and applicable data protection laws.
1. Who We Are
PannaAfric operates the online store at pannaafric.com. Our contact email for data matters is pannaafric@gmail.com.
2. What Data We Collect
When you shop with us or sign up for our newsletter, we may collect:
- Order information: your name, email address, shipping address, and order details
- Payment information: handled entirely by Stripe — we never see or store your full card number
- Email address: if you subscribe to our newsletter (opt-in only)
- Usage data: pages visited, time on site, referral source — collected via Google Analytics (anonymised)
- Device and browser information: collected automatically by standard web server logs
3. How We Use Your Data
- To fulfil your order — we pass your name and shipping address to our fulfilment partner CJ Dropshipping to arrange delivery
- To send order confirmations and shipping updates — via our email provider Brevo
- To send marketing emails — only if you opted in; you can unsubscribe at any time
- To improve our store — anonymised analytics help us understand what content and products serve our community best
4. Third Parties We Share Data With
We only share data with service providers necessary to run our store:
- Stripe — payment processing. Stripe is PCI-DSS compliant. View their privacy policy at stripe.com/privacy
- CJ Dropshipping — product fulfilment. Your name and address are shared to ship your order
- Brevo (formerly Sendinblue) — transactional and marketing emails
- Google Analytics — anonymised website traffic analytics
We do not sell your personal data to any third party. Ever.
5. Data Retention
We retain order records for 3 years for accounting and legal compliance. Email subscribers are retained until they unsubscribe. You can request deletion of your data at any time by emailing us.
6. Your Rights (GDPR / UK GDPR)
If you are located in the European Union or United Kingdom, you have the following rights:
- Right to access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to object — object to marketing emails at any time
- Right to portability — receive your data in a portable format
To exercise any of these rights, email us at pannaafric@gmail.com. We will respond within 30 days.
7. Cookies
We use essential cookies for checkout functionality (Stripe) and optional analytics cookies (Google Analytics). You can disable cookies in your browser settings, though this may affect checkout functionality.
8. Data Security
Our site uses HTTPS/SSL encryption. Payment processing is handled by Stripe's secure, PCI-compliant servers. We do not store payment card data on our servers.
9. Children's Privacy
Our store is not directed to children under 16. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes. Continued use of our store after changes constitutes acceptance.
11. Contact Us
For any privacy questions or data requests: pannaafric@gmail.com