Cookies Policy
Legal & Policy
Cookies Policy
Document: Cookies Policy | Version: 2.0 | Effective date: [INSERT: effective date] | Owner: LIST SECURE (PTY) LTD
Contents
- 1. Introduction
- 2. Definitions
- 3. Read this first — the cookie table must be audited
- 4. What cookies and similar technologies are
- 5. The legal position
- 6. The cookies we use
- 7. How to manage your consent on the Platform
- 8. How to control cookies in your browser
- 9. What happens if you refuse cookies
- 10. Do Not Track and Global Privacy Control
- 11. Cookies and your rights
- 12. Third parties and cross-border transfers
- 13. Changes to this Policy
- 14. Contact us
1. Introduction
1.1 This Cookies Policy explains how LIST SECURE (PTY) LTD ("List Secure", "we", "us", "our") uses cookies and similar technologies on the Platform, why we use them, which of them need your consent, and how you can control them.
1.2 Our details are:
| Legal name | LIST SECURE (PTY) LTD |
| Registration number | [INSERT: company registration number] |
| Registered and physical address | 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa |
| Website | https://listsecure.co.za |
| Support email | support@listsecure.co.za |
| Privacy / Information Officer email | data@listsecure.co.za |
| Information Officer | [INSERT: full name of the Information Officer] |
| Telephone | [CONFIRM: +27 28 123 4567] |
1.3 This Cookies Policy forms part of the Platform Terms. Read it with the Privacy Policy, which explains everything else we do with your Personal Information, and with the Terms & Conditions.
1.4 This Policy takes effect on [INSERT: effective date] and replaces the cookie section that appeared in the Privacy Policy dated 15 December 2025.
2. Definitions
In this Policy:
2.1 "Platform" means the List Secure website at listsecure.co.za, its subdomains, mobile applications and related services.
2.2 "User" means any person who accesses or uses the Platform.
2.3 "Buyer" means a User who purchases or offers to purchase an Item through the Platform.
2.4 "Vendor" means a User approved by List Secure to list Items for sale on the Platform.
2.5 "Item" means any product or goods listed for sale on the Platform.
2.6 "Listing" means a Vendor's offer of an Item, including all text, images and specifications.
2.7 "Order" means a Buyer's accepted offer to purchase an Item.
2.8 "Escrow Provider" means TradeSafe, or such other escrow provider as List Secure may appoint.
2.9 "Payment Provider" means PayFast, or such other payment service provider as we may appoint.
2.10 "Personal Information" has the meaning given to it in POPIA.
2.11 "Content" means any material a User uploads, posts or transmits through the Platform.
2.12 "POPIA" means the Protection of Personal Information Act 4 of 2013 and its Regulations.
2.13 "Consent Banner" means the cookie consent tool that appears when you first visit the Platform, and the preference centre it links to.
3. Read this first — the cookie table must be audited
3.1 [CONFIRM: run a cookie audit/scan of listsecure.co.za and populate the table in clause 6 with the actual cookies set, including any set by Elementor, MultiVendorX and Google Business Profile embeds]
3.2 This is the single most important item in this document. A cookies policy that does not match the cookies the site actually sets is inaccurate, and an inaccurate cookies policy is worse than none — it misleads Users about what is happening on their devices and undermines the validity of the consent we collect.
3.3 Clause 6 is drafted from what we know about the software the Platform runs on. It names cookies only where the name is well established for that software. Everywhere else it uses a placeholder. Those placeholders must be replaced with real cookie names, real durations and the real first- or third-party position, taken from a scan of the live site, before this document is published.
3.4 The scan must be repeated whenever we add or change a plugin, an embed, an analytics tag, a payment or escrow integration, or a marketing tool. [CONFIRM: the frequency of the recurring cookie scan — a quarterly scan is a common practice]
4. What cookies and similar technologies are
4.1 Cookies. A cookie is a small text file that a website asks your browser to store on your device. When you come back, the browser sends the cookie back, so the site can recognise your browser and remember things — that you are logged in, what is in your cart, what language you chose.
4.1.1 A first-party cookie is set by the site you are visiting — here, listsecure.co.za.
4.1.2 A third-party cookie is set by a different organisation whose content or service is loaded into the page — for example an analytics provider or an embedded map.
4.1.3 A session cookie is deleted when you close your browser.
4.1.4 A persistent cookie stays on your device until it expires or you delete it.
4.2 Pixels, web beacons and tags. A tiny, usually invisible image or piece of code loaded into a page or an email. It tells the sender that the page or email was opened, and can read or set cookies.
4.3 Local storage and session storage. Storage inside your browser that a website can write to. It works like a cookie but is not sent with every request and can hold more data. We use it for things like keeping your cart and interface preferences.
4.4 Software development kits (SDKs). Code built into a mobile application that can store identifiers on the device and report usage back. [CONFIRM: whether a List Secure mobile application exists or is planned, and which SDKs it embeds — if there is no application, delete this clause]
4.5 Server logs. Our servers automatically record technical information about each request: IP address, date and time, the page requested, the referring page, browser and operating system, and the response. Server logs are not cookies and are not set on your device, but they do involve Personal Information, so we describe them in the Privacy Policy and account for them here.
4.6 Device and browser fingerprinting signals. Some fraud-prevention and security tools combine technical attributes of a browser or device to recognise it without storing anything. Where we or a security provider do this, we treat it in the same way as a cookie and, unless it is strictly necessary for security, we ask for consent. [CONFIRM: whether any fingerprinting-based fraud or bot-detection tool is in use, and which]
4.7 In this Policy, "cookies" means all of the technologies in clauses 4.1 to 4.4 unless we say otherwise.
5. The legal position
5.1 POPIA
5.1.1 A cookie identifier, an IP address, a device identifier and a record of what you looked at can, alone or together with other information, identify you. When that is so, the information is Personal Information and POPIA applies to it.
5.1.2 We therefore process cookie data in line with the conditions for lawful processing in sections 8 to 25 of POPIA, and in particular:
5.1.2.1 section 10 — we collect only what is adequate, relevant and not excessive;
5.1.2.2 section 11 — we rely on a justification for every category, as clause 5.5 sets out;
5.1.2.3 section 13 — we collect for a specific, explicitly defined and lawful purpose;
5.1.2.4 section 18 — we tell you, through this Policy and the Consent Banner, what we collect and why; and
5.1.2.5 section 19 — we secure what we collect.
5.2 ECTA
5.2.1 Section 51 of the Electronic Communications and Transactions Act 25 of 2002 sets out principles for the electronic collection of personal information. A data controller may voluntarily subscribe to those principles under section 50(2). We apply them as a matter of practice.
5.2.2 In line with those principles, we:
5.2.2.1 collect information only with your express written permission, unless it is collected under a law or in the performance of a lawful contract to which you are a party;
5.2.2.2 use it only for the lawful purpose for which it was collected, and disclose that purpose;
5.2.2.3 keep a record of the information and of the purpose for which it was collected;
5.2.2.4 do not disclose it to a third party unless required or permitted by law or by the terms of a lawful contract;
5.2.2.5 keep a record of any third party who has accessed the information and of the date of access;
5.2.2.6 delete or destroy the information when it has become obsolete; and
5.2.2.7 do not use it to create a profile of you for the purpose of trading in that profile.
5.2.3 Section 43 of ECTA also requires us to disclose supplier information on the Platform. That information is in the Terms & Conditions and in clause 1.2 above.
5.3 Visitors in the EU or EEA
5.3.1 If you visit the Platform from the European Union or the European Economic Area, Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC), as given effect in your country's law, applies. It requires your prior, informed consent before anything is stored on, or read from, your device — except where the storage or access is strictly necessary to provide a service you have expressly requested.
5.3.2 Where the General Data Protection Regulation (EU) 2016/679 applies to you, consent must meet the Article 4(11) and Article 7 standard: freely given, specific, informed, unambiguous, given by a clear affirmative act, and as easy to withdraw as it was to give.
5.4 The rule we apply everywhere
5.4.1 Strictly necessary cookies do not require your consent. Without them the Platform cannot deliver the service you have asked for — you could not log in, hold a cart, check out, or be protected against certain attacks. We set them as soon as you arrive, and we tell you about them in clause 6.
5.4.2 Every other cookie is set only after you have given consent through the Consent Banner. Until you make a choice, non-essential cookies are not set. We do not treat scrolling, continued browsing or closing the banner as consent. We do not use pre-ticked boxes. Refusing is as easy as accepting.
5.4.3 We apply this rule to all visitors, wherever you are. It is the standard the ePrivacy rules require in the EU and EEA, and it is the standard POPIA's consent requirement points to for non-essential processing. Applying one standard is simpler and safer than applying two.
5.5 Which justification applies to which category
| Category | POPIA s11 justification | GDPR / ePrivacy position (EU/EEA visitors) |
|---|---|---|
| Strictly Necessary | s11(1)(b) — necessary to perform the contract with you; s11(1)(f) — our legitimate interest in a working, secure site | ePrivacy Art 5(3) strictly necessary exemption; Art 6(1)(b) / 6(1)(f) GDPR |
| Security & Fraud Prevention | s11(1)(f) — legitimate interests of List Secure and of other Users; s11(1)(d) — protection of your own legitimate interest; s11(1)(c) where a law requires it | Art 6(1)(f); ePrivacy exemption where the cookie is strictly necessary for security of the requested service, otherwise consent |
| Performance / Analytics | s11(1)(a) — consent | Consent under ePrivacy Art 5(3); Art 6(1)(a) |
| Functional | s11(1)(a) — consent, except where the feature is one you have expressly requested | Consent under ePrivacy Art 5(3); Art 6(1)(a) |
| Targeting / Advertising | s11(1)(a) — consent | Consent under ePrivacy Art 5(3); Art 6(1)(a) |
6. The cookies we use
6.1 The table below is organised by category. It is subject to the audit required by clause 3. Where a cookie name, duration or party is not yet confirmed, the entry is marked for insertion. We have not invented cookie names or durations.
6.2 "Consent required?" means: do we set this cookie only after you have consented through the Consent Banner?
6.3 Strictly Necessary
Purpose. To let you log in and stay logged in, to keep your shopping cart and session, to route your request to the right server, to remember your cookie choices, to protect forms against cross-site request forgery, and to complete checkout, payment and escrow. Without these the Platform does not work.
| Cookie / technology | Set by | Purpose | First or third party | Duration | Consent required? |
|---|---|---|---|---|---|
| wordpress_[hash] | WordPress (Automattic) | Authenticates a logged-in User during the session | First party | [INSERT: duration — confirm by cookie scan] | No |
| wordpress_logged_in_[hash] | WordPress (Automattic) | Indicates that a User is logged in, and who they are | First party | [INSERT: duration — confirm by cookie scan] | No |
| wordpress_sec_[hash] | WordPress (Automattic) | Secures access to the administration and account areas | First party | [INSERT: duration — confirm by cookie scan] | No |
| wp-settings-[user id] and wp-settings-time-[user id] | WordPress (Automattic) | Remembers interface preferences in the account area | First party | [INSERT: duration — confirm by cookie scan] | No |
| wp_woocommerce_session_[hash] | WooCommerce | Links your browser to your cart and session data on our server | First party | [INSERT: duration — confirm by cookie scan] | No |
| woocommerce_cart_hash | WooCommerce | Tells the site when the cart contents have changed | First party | [INSERT: duration — confirm by cookie scan] | No |
| woocommerce_items_in_cart | WooCommerce | Tells the site whether the cart has anything in it | First party | [INSERT: duration — confirm by cookie scan] | No |
| [INSERT: MultiVendorX cookie names — confirm by cookie scan] | MultiVendorX | Vendor store selection, multi-vendor cart splitting, Vendor dashboard state | First party | [INSERT: duration — confirm by cookie scan] | No, where strictly necessary — [CONFIRM: whether any MultiVendorX cookie is analytics or preference related, in which case it moves to a consent category] |
| [INSERT: PayFast transaction/session cookie names — confirm by cookie scan and with PayFast] | PayFast | Carries the payment session between the Platform and the payment page, and prevents duplicate or replayed payments | Third party | [INSERT: duration — confirm with PayFast] | No — necessary to complete a payment you have requested |
| [INSERT: TradeSafe transaction/session cookie names — confirm by cookie scan and with TradeSafe] | TradeSafe | Carries the escrow transaction session and links the Order to the Escrow Account | Third party | [INSERT: duration — confirm with TradeSafe] | No — necessary to complete an escrow transaction you have requested |
| [INSERT: consent tool cookie name — confirm by cookie scan] | [INSERT: name of the cookie consent tool or plugin in use] | Records your cookie choices so we do not ask again on every page | First party | [INSERT: duration — a period of 6 to 12 months is common practice; confirm] | No — we must store your choice in order to honour it |
| Local storage and session storage keys | List Secure | Cart contents, interface state, draft Listing data, form recovery | First party | Until cleared by you or by the browser | No, where strictly necessary — [CONFIRM: the full list of storage keys, by cookie scan] |
6.4 Security and Fraud Prevention
Purpose. To protect the Platform, your account and other Users against unauthorised access, credential stuffing, bots, scraping, denial-of-service attacks, payment fraud and account takeover. This supports the fraud and risk controls described in the Privacy Policy.
| Cookie / technology | Set by | Purpose | First or third party | Duration | Consent required? |
|---|---|---|---|---|---|
| __cf_bm | Cloudflare | Distinguishes human visitors from bots, to protect the site | Third party | [INSERT: duration — confirm by cookie scan] | No, where used only for bot management — [CONFIRM: whether Cloudflare or another WAF/CDN is in front of the Platform; if not, delete this row] |
| cf_clearance | Cloudflare | Records that a challenge has been passed, so you are not challenged repeatedly | Third party | [INSERT: duration — confirm by cookie scan] | No — [CONFIRM: as above] |
| [INSERT: security plugin cookie names — confirm by cookie scan] | [INSERT: name of the WordPress security or firewall plugin in use, if any] | Login protection, brute-force detection, IP reputation | First party | [INSERT: duration — confirm by cookie scan] | No |
| Anti-CSRF tokens and nonces | List Secure / WordPress | Prevents a third-party site from submitting a form or action as you | First party | Session | No |
| Fraud and risk signals collected in-session | List Secure | Device and behaviour signals used in the risk scoring described in the Privacy Policy | First party | [INSERT: retention period for in-session risk signals] | No, where strictly necessary for security — [CONFIRM: whether any third-party fraud or fingerprinting service is used; if it is, consent is likely to be required and it must be listed here] |
6.5 Performance and Analytics
Purpose. To understand how the Platform is used — which pages and Listings are visited, how people move through search and checkout, where errors and drop-offs occur — so that we can fix problems and improve the service. We use this at an aggregated level. We do not use analytics to make decisions about you as an individual.
These cookies are set only after you consent.
| Cookie / technology | Set by | Purpose | First or third party | Duration | Consent required? |
|---|---|---|---|---|---|
| _ga | Google Analytics | Distinguishes one browser from another so that visits can be counted | Third party | 2 years [CONFIRM by cookie scan — Google may change this] | Yes |
| _ga_[INSERT: GA4 measurement/container ID suffix] | Google Analytics (GA4) | Keeps session state for GA4 | Third party | 2 years [CONFIRM by cookie scan] | Yes |
| _gid | Google Analytics | Distinguishes one browser from another; used for short-term reporting | Third party | 24 hours [CONFIRM by cookie scan] | Yes |
| _gat or _gat_gtag_[INSERT: property ID] | Google Analytics | Limits the rate at which requests are sent to Google | Third party | 1 minute [CONFIRM by cookie scan] | Yes |
| [INSERT: any other analytics or heatmap cookie names — confirm by cookie scan] | [INSERT: name of any other analytics, session-recording or heatmap tool in use, if any] | [INSERT: purpose] | [INSERT: first or third party] | [INSERT: duration] | Yes |
Google Analytics settings. [CONFIRM: whether IP anonymisation / IP truncation is enabled, whether Google Signals is enabled, whether data sharing with Google is switched off, and what the data retention setting is — these settings materially affect the POPIA and GDPR analysis and must be recorded here]
6.6 Functional
Purpose. To remember choices you make so that the Platform behaves the way you expect — your saved preferences, recently viewed Items, saved searches, chat and support widgets, and embedded content such as maps and videos.
These cookies are set only after you consent, except where the feature is one you have specifically asked for in that moment.
| Cookie / technology | Set by | Purpose | First or third party | Duration | Consent required? |
|---|---|---|---|---|---|
| [INSERT: preference cookie names — confirm by cookie scan] | List Secure | Remembers display, currency, sort order and similar preferences | First party | [INSERT: duration] | Yes |
| [INSERT: cookie names set by Elementor — confirm by cookie scan] | Elementor | Page-builder features, pop-up and form behaviour, view counts | First party, and third party [CONFIRM] | [INSERT: duration] | Yes, unless the scan shows the cookie is strictly necessary to render a page [CONFIRM] |
| [INSERT: cookie names set by Google Business Profile / Google Maps embeds — confirm by cookie scan] | Renders our business listing, reviews and any embedded map | Third party | [INSERT: duration] | Yes — the embed is blocked until you consent | |
| [INSERT: cookie names set by any embedded video player — confirm by cookie scan] | [INSERT: video platform, if any] | Plays embedded video and remembers playback preferences | Third party | [INSERT: duration] | Yes |
| [INSERT: chat or support widget cookie names — confirm by cookie scan] | [INSERT: name of the chat or helpdesk widget in use, if any] | Keeps a support conversation open across pages | Third party | [INSERT: duration] | Yes |
6.7 Targeting and Advertising
Purpose. To measure the performance of our marketing, to show you our advertisements on other websites, and to avoid showing you the same advertisement repeatedly.
These cookies are set only after you consent.
| Cookie / technology | Set by | Purpose | First or third party | Duration | Consent required? |
|---|---|---|---|---|---|
| [INSERT: advertising and remarketing cookie or pixel names — confirm by cookie scan] | [INSERT: name of each advertising platform in use, for example a Google Ads or Meta pixel — if none is in use, state that plainly and delete this table] | Conversion measurement, audience building, remarketing | Third party | [INSERT: duration] | Yes |
| [INSERT: email marketing tracking pixel — confirm with the email platform] | [INSERT: email/marketing platform] | Records whether a marketing email was opened and which links were clicked | Third party | Not stored on your device; recorded by the sending platform | Yes, and only where you have consented to marketing under the Privacy Policy |
6.7.1 [CONFIRM: whether any advertising, remarketing or social media pixel is currently installed on listsecure.co.za. If none is installed, this clause 6.7 must say so plainly rather than describing advertising cookies that do not exist.]
6.7.2 We do not sell your Personal Information, and we do not allow an advertising partner to use data collected on the Platform to build a profile of you for its own unrelated purposes.
7. How to manage your consent on the Platform
7.1 The Consent Banner. The first time you visit, a banner appears. It lets you:
7.1.1 accept all cookies;
7.1.2 reject all non-essential cookies, in a single click that is as prominent as "accept"; or
7.1.3 open the preference centre and choose category by category.
7.2 Changing your mind. You can change or withdraw your consent at any time, and it is as easy to withdraw as it was to give:
7.2.1 use the "Cookie settings" link in the footer of every page — [INSERT: the exact label and location of the persistent cookie settings link]; or
7.2.2 delete our cookies in your browser, which will make the banner appear again on your next visit.
7.3 What withdrawal does. Withdrawing consent stops the further setting and reading of cookies in that category. It does not undo processing that was lawful before you withdrew. Where a third party has already received data under your earlier consent, you may need to use that third party's own controls as well — clause 8.6 gives the Google Analytics route.
7.4 What we record. We keep a record of each consent: the choice made, the categories, the version of the banner and of this Policy, the date and time, and a pseudonymous identifier. We keep it so that we can prove the consent, and so that we can honour it.
7.5 Consent is per browser and per device. If you use a different browser, a different device, or a private browsing window, you will be asked again.
7.6 [CONFIRM: the name of the consent management platform or plugin in use, that it blocks non-essential tags before consent rather than only hiding the banner, that it offers a one-click reject, and that it logs consent] — a banner that does not actually block tags until consent is given does not make the processing lawful.
8. How to control cookies in your browser
8.1 Your browser also lets you block or delete cookies. Browser menus change, so treat the paths below as a guide.
8.2 Google Chrome. Settings > Privacy and security > Third-party cookies (and > Delete browsing data to remove cookies already stored). Chrome also has a per-site control in Settings > Privacy and security > Site settings.
8.3 Apple Safari.
8.3.1 On macOS: Safari > Settings (or Preferences) > Privacy — "Prevent cross-site tracking" and "Manage Website Data".
8.3.2 On iOS and iPadOS: Settings > Apps > Safari > Privacy & Security — "Block All Cookies", and "Clear History and Website Data".
8.4 Mozilla Firefox. Settings > Privacy & Security > Enhanced Tracking Protection, and > Cookies and Site Data to clear or manage stored cookies.
8.5 Microsoft Edge. Settings > Cookies and site permissions > Manage and delete cookies and site data, and Settings > Privacy, search, and services > Tracking prevention.
8.6 Google Analytics opt-out. You can install Google's browser add-on, which stops Google Analytics collecting data about your visit across all websites, at https://tools.google.com/dlpage/gaoptout. The add-on is not available on every browser or mobile platform.
8.7 Mobile devices. On Android and iOS you can reset or limit the advertising identifier in the device's privacy settings.
8.8 A warning about "block all cookies". Setting your browser to block all cookies will block the strictly necessary cookies too. See clause 9.
9. What happens if you refuse cookies
9.1 Refusing non-essential cookies is fine. If you reject analytics, functional and advertising cookies, you can still browse the Platform, view Listings, register, buy and sell. You will lose some conveniences: preferences may not be remembered, embedded maps and videos may not load until you allow them, and our reporting on how the site is used will be less accurate.
9.2 Blocking strictly necessary cookies breaks the Platform. If you block all cookies in your browser, or block first-party cookies for listsecure.co.za, then:
9.2.1 you will not be able to log in, or you will be logged out on every page;
9.2.2 your cart will empty between pages;
9.2.3 checkout will fail — the payment session with the Payment Provider cannot be maintained;
9.2.4 the escrow flow will fail — the transaction session with the Escrow Provider cannot be maintained, which means funds cannot be placed into or released from the Escrow Account through the Platform;
9.2.5 Vendor dashboard functions, including Listing management and Order fulfilment, will not work;
9.2.6 security protections such as anti-forgery tokens will fail, and forms will be rejected; and
9.2.7 the Consent Banner will reappear on every page, because we cannot store your choice.
9.3 We cannot provide the Platform without the strictly necessary cookies. If you are not willing to accept them, please do not transact on the Platform.
9.4 Refusing non-essential cookies has no effect on your rights, your prices, the service you receive, or how a Dispute is decided. We do not penalise you for saying no.
10. Do Not Track and Global Privacy Control
10.1 Do Not Track (DNT). Some browsers can send a "Do Not Track" signal. There is no agreed standard for what a website must do with it, and it is now deprecated in most browsers. We do not currently change our behaviour in response to a DNT signal, and we say so plainly rather than claiming a compliance we do not deliver. Use the Consent Banner instead — it works.
10.2 Global Privacy Control (GPC). GPC is a signal that a browser or extension can send to tell a website that you are exercising your privacy rights, including an objection to the sale or sharing of your personal information.
10.2.1 We do not sell or share your Personal Information for cross-context behavioural advertising, so the core of the GPC signal is already satisfied.
10.2.2 [CONFIRM: whether the consent management platform in use detects a GPC signal and automatically applies a "reject non-essential" preference. If it does, say so here. If it does not, this clause must say so honestly, and the business should consider enabling it.]
10.3 Section 11(3) objection. Separately from any browser signal, you may object at any time to our processing of your Personal Information on the grounds in section 11(3) of POPIA, using Form 1 of the POPIA Regulations. The Privacy Policy explains how.
11. Cookies and your rights
11.1 Cookie data that identifies you is Personal Information. All of the rights in the Privacy Policy apply to it — the right to be told what we hold, to ask for a copy, to ask for correction or deletion, to object, and to complain.
11.2 To exercise a right, write to the Information Officer at data@listsecure.co.za. Objections and correction or deletion requests are free of charge, and we accept them by email, SMS or WhatsApp as well as in writing. We respond within 30 days.
11.3 You may complain to the Information Regulator at any time:
| Physical address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal address | PO Box 31533, Braamfontein, Johannesburg, 2017 |
| Telephone | 010 023 5200 |
| General enquiries | enquiries@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Online | Complaints may also be lodged on the Regulator's online complaints portal, using Form 5 |
11.4 [CONFIRM: verify the Regulator's current address and complaint channel at inforegulator.org.za before publication]
12. Third parties and cross-border transfers
12.1 Some of the cookies described in clause 6 are set by third parties, and some of those third parties process data outside South Africa.
12.2 The Privacy Policy sets out the full position on transborder flows under section 72 of POPIA and the safeguards we rely on. In summary, and as it relates to cookies:
12.2.1 Google Analytics and Google Business Profile process in the United States and in other countries in which Google operates. We rely on your consent to the relevant cookie category and on Google's data processing terms and Standard Contractual Clauses.
12.2.2 Elementor processes in Israel, the European Union and the United States.
12.2.3 MultiVendorX is associated with processing in India. [CONFIRM: whether MultiVendorX is self-hosted software only, or whether the vendor accesses or supports the installation from India]
12.2.4 PayFast and TradeSafe are understood to process in South Africa. [CONFIRM: their processing and hosting locations]
12.2.5 [CONFIRM: whether Cloudflare or another WAF/CDN is in front of the Platform; if it is, its processing is global and must be reflected here]
12.3 We do not control the cookies that a third party sets through its own service, beyond deciding whether to load that service at all and blocking it until you consent. Read that third party's own cookie notice for the detail.
13. Changes to this Policy
13.1 We will update this Policy when we add, remove or change a cookie, a plugin, an embed or a tracking tool, when the audit in clause 3 is completed or repeated, or when the law changes.
13.2 The current version, with its version number and effective date, is always on the Platform.
13.3 Where a change means we want to set a new category of non-essential cookie, or use an existing one for a new purpose, we will ask for your consent again through the Consent Banner before we do it.
13.4 We keep previous versions and will provide one on request.
14. Contact Us
14.1 About cookies and privacy, the Information Officer: data@listsecure.co.za.
14.2 About anything else: support@listsecure.co.za.
14.3 By post: The Information Officer, LIST SECURE (PTY) LTD, 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa.