Privacy Policy
At Bakely, we believe your data is yours. We only collect what we need, use it only to run your bakery tool, and never sell it to anyone. This policy explains exactly what we collect, why, and what you can do about it — written in plain English, because if you can't understand it, it doesn't protect you.
1. Who we are
We're a small team based in Johannesburg, South Africa.
Bakely is a bakery management tool built in Johannesburg, South Africa. We are subject to the Protection of Personal Information Act, 2013 (POPIA). Our designated Information Officer handles all privacy queries and is registered with the Information Regulator of South Africa. Contact: hello@bakely.co.za.
2. What personal information we collect
Only what we need to run your account and keep it safe.
| What we collect | Why | When |
|---|---|---|
| First name | To personalise your experience and emails | When you sign up or join the waitlist |
| Email address | To send you access, reminders, and updates | When you sign up or join the waitlist |
| Business name | To personalise your dashboard | When you complete your profile |
| Customer contact details (your customers' names, emails, phone numbers) | To manage orders and send reminders on your behalf | When you add customers to orders |
| IP address | For security — to detect suspicious login activity | Automatically on every login |
| Device and browser information | For security and to improve mobile performance | Automatically on every login |
| Your business data (orders, recipes, stock) | To provide the Bakely service | When you use the dashboard |
| Optional waitlist responses | To understand what bakers need most | Only if you choose to answer |
3. What we do NOT collect
No payment cards, no ID numbers, no ad profiles, no AI training.
We do not collect:
- Payment card details or banking information (Bakely does not process online payments in the current version)
- South African ID numbers, passport numbers, or any government-issued identifier
- Biometric information of any kind
- Location data beyond your IP address
- Any information to build advertising or marketing profiles
- Your data is never used to train AI models
4. How we use your information
To run your bakery tool, keep your account safe, and improve Bakely.
- To provide the Bakely service — manage your orders, recipes, stock, reminders, quotations, and invoices
- To send order reminder emails — you control the timing and can turn them off at any time
- To send account emails — password resets, verification, security alerts, and important updates
- To protect your account — we monitor and log logins, failed attempts, and suspicious patterns
- To improve Bakely — using aggregated, fully anonymised usage patterns only. No individual baker is identifiable from this data.
- We will never sell, rent, or trade your personal information to any third party
6. How we protect your data
Encryption, hashed passwords, and security monitoring on every account.
- All data is transmitted over HTTPS (encrypted in transit)
- Passwords are hashed — we cannot see your password
- Email addresses in our security logs are hashed (SHA-256) — never stored in plain text
- Access to your data is restricted to you and, where necessary for support, authorised Bakely staff — all such access is logged
- We monitor all login events, failed attempts, and suspicious activity patterns
- If we detect unauthorised access to your account, we will notify you immediately
7. Security logging
We log logins and security events to protect your account — here's exactly what and why.
To protect your account and comply with POPIA's security safeguard requirements (Section 19), Bakely logs the following events:
- Successful logins: timestamp, IP address, device/browser type
- Failed login attempts: timestamp, IP address, reason, attempt count
- Account lockouts: timestamp, IP address
- Password resets and changes: timestamp, IP address
- Logins from new or unrecognised devices: timestamp and previous known IP
- Suspicious patterns: multiple failed attempts from the same IP address
What we do not log: passwords, order content, recipe details, customer names, or any personal content from your baking business. We log security events only — not your business activity.
Standard security logs are retained for 2 years. Critical events (account deletion, email changes) are retained permanently for POPIA compliance.
8. Your customers' data
When you store your customers' details in Bakely, you are responsible for their data under POPIA — not us.
When you use Bakely to store your customers' personal information (names, emails, phone numbers), you are the responsible party under POPIA. Bakely is an operator — it processes this data only on your behalf and on your instruction.
This means you are responsible for ensuring your customers know their contact details are stored in a bakery management system and used to manage their orders and send them reminders. Bakely will never contact your customers for any purpose other than the reminders you configure.
A simple way to tell your customers: "I use Bakely, a South African bakery management app, to keep track of your orders and send you reminders. Your name and contact details are stored securely and only used to manage your orders with me."
9. Data retention
We keep your data as long as you need it, then delete it properly.
| Data type | How long we keep it |
|---|---|
| Your account data (profile, orders, recipes, stock) | While your account is active + 30 days after deletion |
| Your customers' contact details | Same as above — deleted with your account |
| Security logs (standard) | 2 years |
| Critical security logs (account deletion, email changes) | Permanently — POPIA compliance requirement |
| Waitlist data | Until Bakely launches, then you are given the option to delete it |
After the retention period, your data is permanently and irreversibly deleted or anonymised.
10. Your rights under POPIA
You can access, correct, or delete your data — just email us.
As a South African data subject, you have the right to:
- Access — request a copy of all personal information Bakely holds about you
- Correction — ask us to correct inaccurate information
- Deletion — ask us to delete your personal information (subject to legal retention requirements)
- Objection — object to how we process your information
- Data portability — receive your data in a machine-readable format (JSON or CSV)
To exercise any of these rights: email hello@bakely.co.za. We will respond within 30 days. We may ask you to verify your identity before processing your request.
If you are unhappy with our response, you have the right to lodge a complaint with the Information Regulator of South Africa:
Website: www.justice.gov.za/inforeg · Email: inforeg@justice.gov.za · Phone: +27 (0)12 406 4818
11. Cookies
Only login cookies. No tracking. No ads. No third-party analytics.
Bakely uses only the cookies essential to keep you logged in. We do not use advertising or tracking cookies, Google Analytics, or any analytics service that identifies individual users. No cross-site tracking of any kind.
12. Children
Bakely is for adults only — under 18s may not register.
Bakely is not intended for use by persons under the age of 18. If you believe a minor has registered, please contact hello@bakely.co.za and we will delete the account promptly.
13. Breach notification
If there's ever a data breach, we will notify you and the Information Regulator as soon as possible.
In the event of a data breach — unauthorised access to your personal information — Bakely will:
- Notify the Information Regulator as soon as reasonably possible (target: within 72 hours)
- Notify all affected bakers by email, explaining what happened, what data was involved, and what steps we have taken
- Provide guidance on what you should do (e.g. change your password)
We maintain a breach response procedure and incident records in compliance with Section 22 of POPIA.
14. Changes to this policy
We will email you 14 days before anything material changes.
If we make material changes to this policy, we will update the "Last updated" date at the top of this page and notify all registered bakers by email at least 14 days before changes take effect. Continued use of Bakely after that date means you accept the updated policy.
15. Contact us
Real humans, real answers.
Email: hello@bakely.co.za
Information Officer: Registered with the Information Regulator of South Africa
Address: Johannesburg, Gauteng, South Africa