Legal

Privacy Rules

Version 2026-05-30. This explains how personal information is handled in line with South African privacy requirements.

0. Scope

This policy applies to personal information processed through MongiKazi digital services and related operational support channels.

1. Information we collect

We collect account details, profile information, booking activity, communication metadata, payment-related records, and device/session logs needed to operate the marketplace.

1.1 Special categories and minors

Users must not upload unnecessary special personal information. Accounts are intended for users with legal capacity; guardianship or legal authority may be required in edge cases.

2. How we use information

Data is used for authentication, fraud prevention, safety checks, booking operations, service communications, support, compliance, and platform improvement.

2.1 Automated risk checks

We may use operational rules and fraud indicators to detect abuse patterns and trigger additional verification or account safeguards.

3. Legal basis and consent records

Where required, processing is based on consent, contractual necessity, legal obligations, and legitimate operational interests. Policy acceptance events are recorded for audit and compliance.

3.1 Withdrawal and objections

Where consent is the legal basis, withdrawal can be requested, but withdrawal does not invalidate prior lawful processing and may limit service functionality.

4. Sharing and operators

Data is shared only where needed to provide the service, comply with law, resolve disputes, or work with vetted service providers under confidentiality and security controls.

4.1 Law enforcement and legal process

We may disclose information where required by court order, statute, or lawful regulatory request.

5. Retention and security

Records are retained for operational, legal, anti-fraud, and dispute-resolution needs. We apply reasonable technical and organizational safeguards against unauthorized access and misuse.

5.1 Security incidents

Where required by law, relevant stakeholders may be notified of material security incidents involving personal information.

6. Your rights

You may request access, correction, or deletion where applicable, and may object to certain processing subject to legal limits and ongoing contractual or compliance requirements.

6.1 PAIA/POPIA process

Formal requests may require identity verification and may be processed in accordance with PAIA/POPIA procedures and timelines.

7. Cookies and session data

Session and preference cookies are used for secure login, CSRF protection, and user experience features such as theme preferences.

7.1 Browser controls

You may manage cookies at browser level, but disabling critical cookies can affect login, security, and booking workflows.

8. International processing

If data is processed outside South Africa through infrastructure or operators, safeguards will be applied consistent with legal requirements.

9. Policy updates

This policy may be revised as services and legal obligations evolve. Version updates and effective dates will be published on this page.

8. Contact and complaints

Privacy requests can be submitted through the Contact page. Users may escalate unresolved complaints to the South African Information Regulator.