Privacy Rules
Version 2026-05-30. This explains how personal information is handled in line with South African privacy requirements.
0. Scope
This policy applies to personal information processed through MongiKazi digital services and related operational support channels.
1. Information we collect
We collect account details, profile information, booking activity, communication metadata, payment-related records, and device/session logs needed to operate the marketplace.
1.1 Special categories and minors
Users must not upload unnecessary special personal information. Accounts are intended for users with legal capacity; guardianship or legal authority may be required in edge cases.
2. How we use information
Data is used for authentication, fraud prevention, safety checks, booking operations, service communications, support, compliance, and platform improvement.
2.1 Automated risk checks
We may use operational rules and fraud indicators to detect abuse patterns and trigger additional verification or account safeguards.
3. Legal basis and consent records
Where required, processing is based on consent, contractual necessity, legal obligations, and legitimate operational interests. Policy acceptance events are recorded for audit and compliance.
3.1 Withdrawal and objections
Where consent is the legal basis, withdrawal can be requested, but withdrawal does not invalidate prior lawful processing and may limit service functionality.
4. Sharing and operators
Data is shared only where needed to provide the service, comply with law, resolve disputes, or work with vetted service providers under confidentiality and security controls.
4.1 Law enforcement and legal process
We may disclose information where required by court order, statute, or lawful regulatory request.
5. Retention and security
Records are retained for operational, legal, anti-fraud, and dispute-resolution needs. We apply reasonable technical and organizational safeguards against unauthorized access and misuse.
5.1 Security incidents
Where required by law, relevant stakeholders may be notified of material security incidents involving personal information.
6. Your rights
You may request access, correction, or deletion where applicable, and may object to certain processing subject to legal limits and ongoing contractual or compliance requirements.
6.1 PAIA/POPIA process
Formal requests may require identity verification and may be processed in accordance with PAIA/POPIA procedures and timelines.
7. Cookies and session data
Session and preference cookies are used for secure login, CSRF protection, and user experience features such as theme preferences.
7.1 Browser controls
You may manage cookies at browser level, but disabling critical cookies can affect login, security, and booking workflows.
8. International processing
If data is processed outside South Africa through infrastructure or operators, safeguards will be applied consistent with legal requirements.
9. Policy updates
This policy may be revised as services and legal obligations evolve. Version updates and effective dates will be published on this page.
8. Contact and complaints
Privacy requests can be submitted through the Contact page. Users may escalate unresolved complaints to the South African Information Regulator.