Last updated: 10 August 2026
Card payments and PCI DSS
Card details are entered inside our payment provider's hosted checkout and never touch our servers or database. This keeps our card-data environment within the smallest PCI DSS scope (SAQ-A). We store only a payment reference, the amount, the currency and the payment status.
Application security
The site is served over HTTPS. Administrative actions are authorised on the server against a role stored in the database, never in the browser. Database access is protected by row-level security so customers cannot read other customers' records. Secrets and API keys are held in the server environment and are never shipped to the browser.
Data protection and GDPR
We collect the minimum personal data needed to take payment and fulfil an order, keep it only as long as the law requires, and act on data subject requests within one month. Our processors are bound by contract and, where data leaves the UK/EU, by appropriate transfer safeguards. See the privacy policy at /privacy for the full detail.
Access control and retention
Staff and owner accounts are individual, role-limited and removed when access ends. Order records are retained for tax purposes; supporting operational data is removed once it is no longer needed.
Reporting a vulnerability
If you believe you have found a security issue, email teedeuxafricansupermarket@gmail.com with the subject "Security" and enough detail to reproduce it. Please do not access other people's data or degrade the service while testing. We will acknowledge your report and keep you updated while we fix it.
Questions about this policy? Email teedeuxafricansupermarket@gmail.com. This document is provided for information only and is not legal advice.
