Privacy Policy
Last updated: 25 June 2025
1. Introduction
Oopsee ("we", "us", "our") operates the online booking platform at oopsee.co (the "Platform"). We are committed to protecting the personal information of all persons who interact with our Platform, whether as business owners ("Vendors") or end-customers making bookings ("Customers").
This Privacy Policy describes how we collect, process, store, share, and safeguard personal information. It is drafted in compliance with:
- The Protection of Personal Information Act 4 of 2013 (POPIA) and the regulations thereunder;
- The Electronic Communications and Transactions Act 25 of 2002 (ECTA);
- The Consumer Protection Act 68 of 2008 (CPA) where applicable;
- The Cybercrimes Act 19 of 2020; and
- Any other applicable South African legislation governing data protection and privacy.
By accessing or using the Platform you confirm that you have read and understood this Privacy Policy and consent to the processing of your personal information as described herein. If you do not agree, please discontinue use of the Platform.
2. Who We Are — Responsible Party
Under POPIA, Oopsee is the Responsible Party in respect of personal information collected through the Platform.
If you have any questions, requests, or complaints regarding the processing of your personal information, please contact us at the email address above. We have designated an Information Officer as required by section 55 of POPIA, who is responsible for ensuring compliance with this policy.
3. Personal Information We Collect
We collect personal information only where it is necessary, relevant, and adequate for the purposes set out in this policy. The categories of personal information we collect include:
3.1 Vendor (Business Owner) Information
- Full name and business name
- Email address and phone number
- Business address and company registration details (where provided)
- Profile and branding information (logo, brand colour, slug/subdomain)
- Payment and banking details for receiving payouts
- Authentication credentials (managed securely via Supabase Auth)
3.2 Customer (Booking) Information
- Full name and email address
- Phone number (where required by the Vendor)
- Booking details including service, date, time, and any notes provided
- Payment information (processed by our third-party payment provider — we do not store raw card data)
3.3 Technical and Usage Information
- IP address and browser type
- Device identifiers and operating system
- Pages visited, time spent, and referring URLs
- Cookies and similar tracking technologies (see Section 9)
We do not intentionally collect special personal information as defined in section 26 of POPIA (such as health data, biometric information, or political views) unless expressly disclosed and consented to for a specific purpose.
4. Lawful Grounds for Processing
POPIA requires that the processing of personal information must be justified by a lawful ground. We process your personal information on the following grounds:
- Consent (s11(1)(a)): Where you have given express or implied consent, for example by registering an account or making a booking.
- Contractual necessity (s11(1)(b) read with s11(3)): Processing that is necessary to perform or enter into a contract with you, such as providing the booking service.
- Legitimate interests (s11(1)(f)): Where processing is necessary for our legitimate interests — for example, security monitoring, fraud prevention, and product improvement — balanced against your right to privacy.
- Legal obligation (s11(1)(c)): Where we are required to process personal information to comply with a legal obligation, such as tax record-keeping under the Income Tax Act 58 of 1962.
5. Purposes of Processing
We collect and process personal information for the following specific, explicitly defined, and lawful purposes:
- To create and manage Vendor accounts on the Platform
- To enable Customers to discover, book, and pay for services
- To send booking confirmations, reminders, and transactional notifications
- To process payments and manage financial records
- To provide customer support and respond to enquiries
- To improve the Platform, diagnose technical issues, and conduct analytics
- To comply with legal and regulatory obligations
- To detect and prevent fraud, abuse, and security incidents
- To send marketing communications where you have opted in (you may opt out at any time)
We will not process your personal information for any purpose incompatible with the purposes listed above without first obtaining your consent or establishing a new lawful ground.
6. Sharing of Personal Information
We do not sell personal information. We share personal information only in the following circumstances:
6.1 With Vendors
When a Customer makes a booking, the Vendor for whom the booking is made receives the Customer's booking details (name, contact details, and appointment information). Vendors are bound by their own privacy obligations to Customers.
6.2 With Operators and Service Providers
We engage trusted third-party service providers ("Operators" as defined in POPIA) who process personal information on our behalf and under our instruction, including:
- Supabase Inc. — database, authentication, and storage infrastructure
- Vercel Inc. — web hosting and deployment infrastructure
- Payment processors (Payfast / Paystack) — secure payment processing
- Email service providers — transactional and notification emails
All Operators are required to process personal information only on our documented instructions and to maintain appropriate security measures.
6.3 Legal Disclosure
We may disclose personal information where required by law, a court order, or a competent authority, including in response to a request from the South African Police Service, the Information Regulator, or another regulatory body with jurisdiction.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a substantial portion of our assets, personal information may be transferred as part of that transaction. We will notify affected data subjects in such circumstances.
7. Trans-Border Information Flows
Some of our Operators are located outside South Africa. In accordance with section 72 of POPIA, we only transfer personal information to foreign recipients where:
- The recipient country's laws afford an adequate level of protection substantially similar to POPIA; or
- The data subject has consented to the transfer; or
- The transfer is necessary for the performance of a contract between the data subject and us; or
- We have entered into a binding agreement with the recipient that imposes POPIA-equivalent obligations on them.
8. Retention of Personal Information
We retain personal information for no longer than is necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law. Our general retention periods are:
- Active account data: retained for the duration of the account relationship.
- Booking records: retained for five (5) years after the booking date to satisfy potential commercial and tax obligations.
- Payment records: retained for five (5) years as required by South African tax legislation.
- Marketing preferences and communications: retained until you opt out or withdraw consent.
- Server and security logs: retained for up to twelve (12) months.
When personal information is no longer required, it is securely deleted or anonymised so that it can no longer be associated with an identifiable person.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Platform and improve your experience. Cookies are small text files stored on your device.
Types of cookies we use:
- Strictly necessary cookies: Required for authentication and security (e.g. session tokens). These cannot be disabled.
- Functional cookies: Remember your preferences such as language and display settings.
- Analytics cookies: Help us understand how the Platform is used so we can improve it. We use anonymised or aggregated data where possible.
You may control cookies through your browser settings. Disabling strictly necessary cookies may affect your ability to use the Platform.
10. Security
We implement appropriate technical and organisational measures to protect personal information against loss, unlawful access, destruction, misuse, modification, or disclosure, in accordance with section 19 of POPIA. These measures include:
- Encryption in transit (TLS/HTTPS) and at rest
- Row-level security (RLS) enforced at the database layer so Vendors can only access their own data
- Access controls and authentication requirements for all internal systems
- Regular security assessments and vulnerability monitoring
No method of electronic transmission or storage is 100% secure. In the event of a security compromise that affects your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA within the prescribed timeframes.
11. Your Rights as a Data Subject
Under POPIA and applicable South African law, you have the following rights in respect of your personal information:
- Right to access (s23): You may request confirmation of whether we hold your personal information and obtain a copy of it.
- Right to correction or deletion (s24): You may request that we correct inaccurate, incomplete, misleading, or outdated personal information, or delete personal information that we are no longer authorised to retain.
- Right to object (s11(3)(b)): You may object to the processing of your personal information on reasonable grounds. We will consider your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with the Information Regulator of South Africa if you believe we have processed your personal information unlawfully.
Website: inforegulator.org.za
Email: inforeg@justice.gov.za
Tel: +27 (0)12 406 4818
To exercise any of your rights, please contact our Information Officer at privacy@oopsee.co. We will respond within the timeframes prescribed by POPIA (generally within 30 days, extendable by a further 30 days with notice).
12. Children's Privacy
The Platform is not directed at persons under the age of 18 ("children"). We do not knowingly collect personal information from children without the consent of a competent person (parent or guardian) as required by section 35 of POPIA. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete such information.
13. Marketing Communications
We will only send you direct marketing communications (email, SMS, or push notifications) where you have opted in, or where permitted under POPIA and the CPA in respect of our own similar products or services.
You may opt out of marketing communications at any time by:
- Clicking the "Unsubscribe" link in any marketing email; or
- Emailing us at privacy@oopsee.co
Opting out of marketing will not affect transactional or service-related communications (such as booking confirmations) which are necessary for the performance of our contract with you.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Platform. When we make material changes, we will notify you by email (if you have an account) or by displaying a prominent notice on the Platform. The updated policy will be effective from the date indicated at the top of this page.
We encourage you to review this policy periodically. Continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy.
15. Governing Law
This Privacy Policy is governed by the laws of the Republic of South Africa. Any disputes arising in connection with this policy shall be subject to the jurisdiction of the South African courts.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal information, please contact our Information Officer:
We are committed to resolving privacy concerns promptly and fairly. If you are not satisfied with our response, you are entitled to refer the matter to the Information Regulator as set out in Section 11 above.