A transparent look at what data Mall Drop collects, how it flows through our systems, and the measures we take to protect it.
Last Updated: 10 April 2026Mall Drop collects only the data necessary to provide our marketplace services. Here is a complete breakdown by category:
| Data Field | Purpose | Required |
|---|---|---|
| Full name | Account identity, order processing, display to other users | Yes |
| Username | Unique account identifier, display name | Yes |
| Email address | Account login, notifications, password recovery | Yes |
| Phone number | Account recovery, delivery contact | Yes |
| Profile picture | Personalisation, identity in reviews and stores | No |
| User role | Determines app features and access permissions | Yes |
| Data Field | Purpose | Required |
|---|---|---|
| Order details | Items, quantities, prices for purchase processing | Yes (per order) |
| Delivery address | Shipping and delivery logistics | Yes (per order) |
| Payment records | Transaction amounts, status, charge and transaction IDs | Yes (per payment) |
| Refund records | Refund amounts, status, processing | If applicable |
| Payout records | Vendor and courier earnings and disbursements | If applicable |
| Data Field | Purpose | Required |
|---|---|---|
| Delivery coordinates | Pickup and drop-off location for deliveries | Yes (per delivery) |
| Courier live location | Real-time tracking during active deliveries | Yes (couriers) |
| Store location | Display on maps, distance calculation | Yes (vendors) |
| Data Field | Purpose | Required |
|---|---|---|
| Device information | Device type and OS for compatibility and security | Automatic |
| Biometric enrolment status | Secure login via Face ID or fingerprint | No (optional) |
| Authentication tokens | Secure session management (access + refresh tokens) | Automatic |
| Last authentication time | Session expiry enforcement (30-minute timeout) | Automatic |
| Data Field | Purpose | Required |
|---|---|---|
| Product images | Product listings and display | Yes (vendors) |
| Store assets | Store branding and presentation | Yes (vendors) |
| Reviews and ratings | Community feedback for products and stores | No (optional) |
| Support messages | Customer support ticket communication | If applicable |
Understanding the journey of your data from collection to storage:
Step 1 — Collection: Data is collected through the Mall Drop app when you register, make purchases, list products, or use features like delivery tracking.
Step 2 — Transmission: All data is transmitted over encrypted HTTPS/TLS connections between your device and our backend servers hosted on Supabase.
Step 3 — Processing: Data is processed by Supabase server-side functions (Edge Functions) to handle business logic such as order creation, payment initiation, and delivery coordination.
Step 4 — Storage: Structured data is stored in a PostgreSQL database. Media files (images) are stored in dedicated object storage buckets. Authentication tokens are stored in encrypted device storage.
Step 5 — Third-Party Sharing: Specific data is shared with payment (Yoco, Ozow), shipping (ShipLogic, Easyship), and mapping (Google Maps) providers only as required to complete transactions.
product-images — Product photos uploaded by vendors.store-assets — Store logos, banners, and branding images.Note: We do not store banking details, card numbers, or sensitive financial data on your device or in our database. All payment data is handled exclusively by Yoco (card payments) and Ozow (bank transfers and payouts).
We share data with the following third-party services, limited to what is strictly necessary for their function:
| Provider | Data Shared | Purpose |
|---|---|---|
| Yoco | Order amount, order reference, checkout session ID | Primary card payment processing and refunds |
| Ozow | Order amount, order reference, user email | Bank transfer payments, vendor payouts, courier payouts |
| ShipLogic | Pickup address, delivery address, parcel dimensions | Domestic shipping quotes and deliveries |
| Easyship | Pickup address, delivery address, parcel details | International shipping quotes and deliveries |
| Google Maps | Coordinates (latitude, longitude) | Map display, route calculation, delivery tracking |
| Supabase | All application data | Backend infrastructure, database, authentication, storage |
We do not sell your data. Third-party sharing is limited to operational necessities. Each provider is bound by their own privacy policies and data protection obligations.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account profile data | Active account + 30 days after deletion | Account operations and grace period for recovery |
| Order and transaction records | 5 years after transaction | Financial and legal compliance |
| Payment and payout records | 5 years after transaction | Tax and audit requirements |
| Support tickets | 2 years after resolution | Service quality and dispute reference |
| Delivery tracking data | 90 days after delivery | Dispute resolution and service improvement |
| Product images | While product is active + 30 days after deletion | Marketplace operations |
| Reviews and ratings | Indefinite (anonymised after account deletion) | Community value and product quality signals |
| Authentication logs | 12 months | Security monitoring and incident response |
You have control over your personal data. Here's how to exercise your rights:
Access your profile, order history, payment history, and reviews at any time through the App.
Update your name, email, phone, avatar, and address through your profile settings.
Request a full export of your personal data by emailing privacy@bountifulai.co.za.
Request account deletion through the App or by contacting support. Subject to legal retention requirements.
In the event of a data breach, Mall Drop commits to the following response:
For any questions about how we handle your data, or to exercise your data rights:
Data Protection Inquiries: privacy@bountifulai.co.za
General Support: contact@bountifulai.co.za