Privacy Policy

How we collect, use, and protect your personal information

Introduction

This Privacy Policy explains how Rondebosch Local (operating across Rondebosch and other regions) collects, uses, discloses, and otherwise processes personal information in connection with our website and services.

We are committed to protecting your privacy and ensuring you have a positive experience on our platform. This policy describes our privacy practices and your rights under the Protection of Personal Information Act (POPIA) and other applicable laws.

We operate as an independent digital directory service. We do not share your information with third parties for their own marketing purposes without your explicit consent.

Information We Collect

Information You Provide Directly

  • Account Registration: When you create an account or list a business, we collect your name, email address, phone number, and business information
  • Contact Forms: When you submit contact forms or inquiries, we collect the information you provide including name, email, message content
  • Payment Information: When you process payments, payment data is handled by secure third-party processors; we do not store credit card information directly
  • Communications: If you contact us via email or support channels, we retain your communications
  • Information Collected Automatically

  • Usage Data: Pages visited, time spent on pages, navigation patterns, and clicks (via our dataLayer tracking)
  • Device Information: Browser type, operating system, device type, screen resolution
  • Network Data: IP address, referring website, access timestamps
  • Performance Monitoring: Vercel Speed Insights collects performance metrics to improve website speed and reliability
  • Cookies and Tracking Technologies

    We use the following types of cookies:

    Essential Cookies (no consent required):

  • Next.js session cookies for maintaining your login state
  • Security tokens to prevent fraud
  • User preference cookies for site functionality
  • Analytics Cookies (see Cookie Policy for control options):

  • Custom dataLayer tracking for page view analytics
  • Vercel Speed Insights performance data
  • Future: Google Analytics (if implemented)
  • How We Use Your Information

    We use the information we collect for the following purposes:

    1. Service Delivery: Providing, maintaining, and improving our directory platform

    2. Communication: Responding to your inquiries, sending service updates, and system notifications

    3. Account Management: Creating and managing your account, processing transactions

    4. Legal Compliance: Fulfilling our legal and regulatory obligations

    5. Security and Fraud Prevention: Detecting and preventing fraudulent activity and abuse

    6. Analytics and Improvement: Understanding user behavior to improve our services

    7. Marketing Communications: Sending promotional content (only with your consent)

    Legal Basis for Processing (POPIA)

    Under POPIA, we process your information based on:

  • Consent: When you have explicitly agreed to processing (e.g., marketing emails)
  • Contractual Necessity: When processing is necessary to provide our services
  • Legal Obligation: When required by law or regulation
  • Legitimate Interests: When we have a legitimate interest that is not overridden by your rights (e.g., analytics to improve services)
  • Third-Party Services

    We use the following third-party service providers who may access your information:

    Hosting and Infrastructure

  • Vercel (USA) - Website hosting and deployment; includes performance monitoring via Speed Insights
  • AWS S3 (South Africa region) - Image and media storage
  • Supabase (PostgreSQL database) - User data and listing information storage
  • Analytics and Performance

  • Vercel Speed Insights - Performance monitoring and analytics
  • Future Services (Placeholders)

  • Google Analytics - May be implemented for advanced analytics
  • Google Maps - May be embedded for location services
  • Google Adsense - May be implemented for advertising
  • Payment Processing

    When payments are processed, payment data is handled by PCI-compliant payment processors (details to be specified when payment methods are activated). We never store full credit card information.

    All third-party service providers are required to process personal information only as per our instructions and to maintain appropriate security measures.

    Data Retention

    We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:

  • Active Account Data: Retained for the duration of your account plus 2 years after account closure
  • Inactive Accounts: Account data may be deleted after 5 years of inactivity, with 90-day notice
  • Transaction Records: Retained for 7 years for tax and legal compliance purposes
  • Contact Form Data: Retained for 1 year unless you request deletion
  • Analytics Data: Aggregated data retained indefinitely; personal identifiers removed after 12 months
  • Your Rights Under POPIA

    You have the following rights regarding your personal information:

    Right of Access

    You may request access to the personal information we hold about you at any time.

    Right to Correction

    You may request that we correct any inaccurate, incomplete, or misleading personal information.

    Right to Deletion

    You may request deletion of your personal information, subject to legal and contractual obligations. We will delete your data within 30 days of a valid request (except where legally required to retain it).

    Right to Object

    You may object to the processing of your personal information for marketing or analytics purposes.

    Right to Data Portability

    You may request a copy of your personal information in a structured, commonly-used format suitable for transfer to another organization.

    Right to Lodge a Complaint

    If you believe we have violated your privacy rights, you may lodge a complaint with the Information Regulator of South Africa:

    Information Regulator of South Africa

    P.O. Box 31533, Braamfontein, 2017

    Email: info@inforegulator.org.za

    Website: www.inforegulator.org.za

    Security Measures

    We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption: All data in transit is encrypted using HTTPS/TLS
  • Access Control: Database access is restricted to authorized personnel
  • Password Security: Account passwords are hashed and salted
  • Regular Audits: We conduct regular security audits and assessments
  • Staff Training: Our team receives data protection training
  • Incident Response: We have procedures to respond to data breaches
  • However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

    International Data Transfers

    Your personal information is primarily stored in South Africa (via AWS S3 South Africa region and local database infrastructure). However, some data is transferred to the USA for:

  • Website hosting (Vercel - USA)
  • Database services (Supabase - varies by deployment)
  • Performance monitoring (Vercel Analytics - USA)
  • These transfers are made with appropriate safeguards, including standard contractual clauses and adequacy assessments. By using our service, you consent to such transfers.

    Children's Privacy

    Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will delete it immediately.

    Contact Us

    If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

    Email: hi@skewtree.com

    Alternative: Submit a request via our contact form at rondeboschlocal.co.za/contact

    We will respond to all privacy requests within 20 business days.

    Updates to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Updating the "Last Updated" date at the top of this policy
  • Sending you an email notification for material changes
  • Your continued use of our services following any updates constitutes your acceptance of the updated Privacy Policy.

    © 2026 Rondebosch Local. All rights reserved.