Privacy information
Privacy Policy
This Privacy Policy explains how Omnaza describes the handling of information related to the Omnaza app, customer support, orders, delivery, and account requests.
Last updated: July 21, 2026
This Privacy Policy explains how GOLDEN BRIGHT TECHNOLOGY LIMITED, incorporated in Hong Kong and trading as OMNAZA ("OMNAZA", "we", "us" or "our"), collects, uses, shares and protects personal information when you use the OMNAZA mobile application, www.omnaza.com, customer-support channels, and related services (together, the "Services"). OMNAZA is the responsible party or data user that determines why and how personal information is processed, unless a separate notice says otherwise.
OMNAZA is an online store offering fashion, accessories and lifestyle products for delivery within South Africa. This Policy is intended for users in South Africa and is written with the Protection of Personal Information Act, 2013 ("POPIA") in mind. The Hong Kong Personal Data (Privacy) Ordinance may also apply to processing connected with our Hong Kong operations.
1. Information We Collect
We collect only the personal information that we need to provide, operate, protect and improve the App and our services.
Information you provide to us
- Account information, such as your name, email address, phone number, login details and account preferences.
- Order and delivery information, such as shipping and billing addresses, recipient details, order details, delivery instructions, returns and refunds.
- South African ID number or passport number where required for customs clearance. We use it only for customs clearance and related legal, fraud-prevention, or logistics requirements, not for marketing or general profiling.
- Payment status, transaction reference, billing details and fraud-prevention signals. We do not store your full payment card number.
- Customer-support messages, enquiries, complaints, photos and other information you send to us.
- Your marketing and communication preferences.
Information collected automatically
- Device and App information, including device model, operating system, App version and language settings.
- Usage information, including pages viewed, products browsed, searches, cart and checkout activity.
- Approximate location based on IP address or delivery region. We do not collect precise GPS location.
- Diagnostic, security and performance information, including crash logs, error reports, authentication events and fraud-prevention signals.
- Resettable advertising identifiers only where a relevant feature is enabled, law permits it, and any required permission or consent has been obtained.
We do not collect your IMEI, IMSI, MAC address, list of installed apps or precise GPS location.
Cookies and similar technologies
Our website and App may use cookies, local storage, SDKs, pixels, or similar technologies for authentication, security, preferences, essential functionality, diagnostics, analytics, and—only where enabled and lawfully permitted—advertising measurement. Where consent is required, non-essential technologies will not be activated until the relevant choice is made.
Information from third parties
We may receive information from payment processors; logistics and customs providers; analytics, security, hosting and technical providers; and marketing or advertising partners where permitted.
2. How We Use Your Information
- Create, manage and secure your account.
- Process, fulfil, deliver, return, refund and support orders.
- Process payments, refunds, disputes and fraud-prevention checks.
- Use ID or passport information only where needed for customs clearance.
- Send order, delivery, refund, security and other service messages.
- Respond to support enquiries and resolve complaints.
- Operate, maintain, troubleshoot, protect and improve the App.
- Understand product and App usage and send marketing where permitted by law and your choices.
- Detect fraud, abuse, security incidents or unlawful activity and comply with legal obligations.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects unless the required notice, safeguards and rights are provided. Fraud or security signals may flag a transaction for human review.
3. Legal Basis For Processing
Where POPIA applies, we process personal information only where there is a lawful basis, including consent; conclusion or performance of a contract; compliance with a legal obligation; protection of your legitimate interests; or our or a third party's legitimate interests where permitted by law and not outweighed by your privacy rights.
4. How We Share Your Information
We do not sell, rent or trade your personal information to third parties for their own marketing purposes.
Where necessary, we may share personal information with payment processors; logistics, delivery and customs providers; hosting, cloud, security, analytics and technical providers; communications and support providers; permitted marketing partners; professional advisers and insurers; public authorities and courts; and a genuine business transferee. Service providers may use the information only to provide their services or meet legal obligations, subject to appropriate confidentiality and security protections.
5. Third-Party Services And SDKs
- Stripe or another payment processor: payment processing, refunds, disputes, fraud prevention and payment security.
- Firebase, Google services or similar technical services: installation, authentication support, analytics, diagnostics, crash reporting, push notifications and service reliability, depending on enabled features.
- AWS, Cloudflare or similar infrastructure providers: hosting, security, content delivery, network protection and service reliability.
- Logistics, delivery and customs providers: shipping, tracking, customs clearance, delivery exceptions and proof of delivery.
- Email, customer support and communications providers: service messages, support, order updates and permitted marketing.
- Advertising and measurement partners, where enabled: campaign measurement, attribution and permitted interest-based advertising.
We do not allow SDKs or third-party partners to collect IMEI, IMSI, MAC address or your installed app list through the App.
6. Marketing And Advertising Choices
We send marketing only where permitted by law and your choices. Silence, account creation, or acceptance of Terms is not treated as marketing consent where consent is required. You can opt out using an unsubscribe link, instructions in a marketing message, device push settings, or by contacting service@omnaza.com. Service messages may still be sent.
7. International Data Transfers
Because OMNAZA is operated by a Hong Kong company and uses providers in different countries, personal information may be transferred to, accessed from or processed in Hong Kong and elsewhere. For transfers outside South Africa, we use a basis permitted by POPIA section 72 and apply appropriate contractual, access, security and data-minimisation safeguards where required.
8. Data Retention
- Account information is kept while the account is active. We normally complete a verified account-deletion request within 30 days, except for records we must or may lawfully retain.
- When you delete a reusable address, its protected South African ID number is cleared from that address record. A separate protected customs identity snapshot already attached to an order is not changed by later address edits or deletion.
- Order, payment, delivery, return, refund and customs records may be kept for up to 7 years, or longer where required by law or reasonably needed for a claim, audit, dispute or investigation.
- Security and operational logs are normally kept for up to 90 days.
- Analytics, diagnostics and crash data are normally kept for up to 12 months.
- Marketing preferences are kept until updated or withdrawn and for a reasonable period afterwards to honour your choice.
- Backups are normally deleted or overwritten on a rolling basis within 90 days.
When information is no longer needed, we delete it, de-identify it or reasonably restrict access.
9. Security And Security Incidents
We use reasonable technical and organisational safeguards, which may include access controls, encryption or secure transmission, logging, monitoring, provider controls and staff access restrictions. No system is completely secure. If required by law after a security incident, we will notify the Information Regulator and affected users as soon as reasonably possible.
10. Your Rights
Under POPIA, you may have rights to notice, confirmation and access; correction; deletion where retention is no longer authorised; objection to certain processing and direct marketing; withdrawal of consent; complaint to the Information Regulator; and civil proceedings where permitted.
To exercise a right, contact service@omnaza.com. We may verify your identity and normally respond within 30 days after verification. We will explain a lawful refusal or restriction where required.
South Africa Information Regulator: inforegulator.org.za; POPIA complaints: POPIAComplaints@inforegulator.org.za; general enquiries: enquiries@inforegulator.org.za.
11. Children's Privacy
The App is not intended for anyone under 18. You must be at least 18 to create an account or place an order. We do not knowingly collect personal information from children under 18 and will take reasonable steps to delete it if discovered. A parent or guardian may contact service@omnaza.com.
12. Third-Party Links
The App may link to third-party websites, services or payment pages. We are not responsible for their privacy practices, and you should review their policies before providing information.
13. Changes To This Policy
We may update this Privacy Policy from time to time. For material changes, we will take reasonable steps to notify you, including by posting the updated Policy in the App and changing the "Last updated" date.
14. Information Officer and PAIA Access
Our Information Officer is responsible for encouraging compliance, handling data-subject requests, cooperating with the Information Regulator, and overseeing applicable POPIA and PAIA duties. The person performing those duties must be registered with the Information Regulator before assuming them.
Information Officer contact: service@omnaza.com. A PAIA manual or prescribed request form may be requested using the same contact.
15. Contact Us
GOLDEN BRIGHT TECHNOLOGY LIMITED, trading as OMNAZA
Email and Privacy Contact: service@omnaza.com