1. Responsible party and scope
CGH VENTURES (PTY) LTD, registration number 2026/489747/07 (“CGH Ventures”, “Privy Rewards”, “we”, “us” or “our”), is the responsible party for personal information processed for the Privy Rewards Platform.
- Privacy email: legal@privyrewards.co.za
- Support email: support@privyrewards.co.za
Company-information and formal privacy enquiries may be sent to the privacy email above. We will provide additional information where applicable law requires it.
This Policy applies to customers, prospective customers, Partner applicants, Partner representatives and staff, website visitors, and people who contact us. It should be read with the applicable Customer Terms or Partner Terms.
2. Information we collect and where it comes from
We collect information directly from you, automatically from your device and use of the Platform, from a Partner when its authorised staff record a redemption, from payment and identity providers, and from another lawful source described below.
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Full name, email address, Partner contact name, phone number and business contact details. | You; an authorised Partner representative. |
| Account and authentication | Password hash, email-verification state, role, linked Apple or Google identifier and verified email, login nonce, one-time-code records and account status. | You; Apple or Google; our security systems. |
| Device and session | Device name and key, platform, app version, session identifier, trusted-device state, push token, IP address, user agent and relevant timestamps. | Your device and Platform use. |
| Membership and payment | Plan, status, paid-through date, renewal or scheduled plan change, payment-provider customer or transaction reference, amount, currency, verification result and billing-support history. | You; our systems; our payment provider. We do not store your full card number or card security code. |
| QR and redemption | Short-lived QR token, customer, Partner and staff identifiers, offer, time, status, bill total, discount, final amount and limited verification or dispute metadata. | Our systems; the Partner and its authorised staff. |
| Partner and venue | Business and trading names, category, venue tags, contact details, city, area, address, website or social link, proposed reward, application notes, venue details, offers, images and staff accounts. | Partner applicants and authorised Partner users; public business sources if lawful. |
| Communications | Support requests, privacy requests, complaints, feedback and related attachments or correspondence. | You, a Partner or another person involved in the request. |
| Security and audit | Security events, administrative actions, access and change logs, suspected misuse, investigation notes and related IP or device information. | Your use; Partner use; our systems and service providers. |
| Approximate/precise location | Your current device location when you choose the “Near me” feature. | Your device, with operating-system permission. |
Please do not send us special personal information or other sensitive information unless we specifically request it and explain why it is necessary.
3. Mandatory and voluntary information
Information marked as required during account creation, verification, checkout, QR redemption or a Partner application is necessary to perform that action, secure the Platform, enter into or perform the relevant agreement, or comply with law. If you do not provide it, we may be unable to create or verify the account, process the application or payment, activate a membership, validate a reward or answer the request.
Optional profile, Partner, location, marketing and feedback information is voluntary. Refusing optional information may limit the relevant optional feature—for example, “Near me” sorting—but will not by itself prevent unrelated use.
4. Purposes and lawful justification
Depending on the context, POPIA allows processing with consent, to conclude or perform a contract, to comply with law, to protect a legitimate interest, or to pursue our or a third party’s legitimate interests where the processing is reasonable and proportionate.
| Purpose | Information involved | Typical justification |
|---|---|---|
| Create, verify and manage accounts, sessions and trusted devices. | Identity, contact, authentication, device and session information. | Contract; requested pre-contract steps; security and other legitimate interests. |
| Process and verify subscriptions, renewals, cancellations, plan changes and refunds. | Identity, membership, payment references and support records. | Contract; legal obligations; legitimate accounting and fraud-prevention interests. |
| Create and validate QR access and redemptions. | Account, membership, Partner, staff, offer, QR and redemption information. | Contract; legitimate interests of you, the Partner and Privy Rewards in accurate redemption. |
| Review Partner applications and operate Partner listings and offers. | Partner, venue, content, contact, staff and application information. | Requested pre-contract steps; Partner agreement; legitimate business interests. |
| Send service messages and provide support. | Contact, account, transaction, device and communication information. | Contract; legal duties; legitimate support and security interests. |
| Send permitted marketing and optional push notifications. | Contact details, push token, consent and opt-out status. | Consent or another basis expressly allowed for a customer’s own similar services, with a free opt-out. |
| Secure the Platform and investigate errors, misuse, disputes or incidents. | Account, device, session, IP, transaction, redemption, audit and communication information. | Legal obligations; legitimate interests in security, evidence and protecting affected people. |
| Meet tax, accounting, corporate, consumer, privacy and lawful enforcement duties. | Relevant account, payment, redemption, Partner, audit and correspondence records. | Legal obligation; establishment, exercise or defence of legal claims. |
| Measure and improve reliability and plan or offer performance. | Operational, offer and aggregated or de-identified usage information where practical. | Legitimate product and business interests, balanced against privacy rights. |
We will not use personal information for a materially incompatible purpose without a further lawful basis and any notice or consent required by law.
5. Payments
Payments are currently processed by Paystack. Payment details are entered into the payment provider’s secure flow. The provider may process payment credentials under its own privacy terms and returns transaction identifiers, status, amount and related verification data to us. We do not receive or store full card details.
A payment provider, bank or card network may independently process information as a responsible party for its legal, risk and payment-network obligations.
6. What Partner staff can see
When an authorised Partner staff member verifies a QR or reviews that Partner’s redemption history, the Platform may show:
- your full name and internal customer identifier;
- your eligible plan, membership status and paid-through information;
- the offer, redemption status, date and time;
- the recorded bill total, discount and final amount; and
- the staff member or venue linked to the redemption.
This disclosure is required to validate the benefit, keep accurate transaction records, resolve disputes and prevent misuse. A Partner must not use Platform customer information for unrelated marketing, profiling, customer-list building or disclosure. Partners do not receive passwords, full payment-card details, unrelated redemption histories or general access to the customer database.
A Partner may separately collect information from you when it supplies its own goods or services. That separate collection is governed by the Partner’s own privacy practices.
7. Other recipients and service providers
We disclose only information reasonably necessary for a lawful purpose to:
- authorised CGH Ventures personnel and contractors who need it for their duties;
- Partners and their authorised staff as described above;
- hosting, database, storage, security and deployment providers, currently including Render and Supabase;
- payment services, currently Paystack;
- email services, currently Brevo;
- push-notification infrastructure, currently Firebase Cloud Messaging;
- identity and platform providers you choose to use, such as Apple and Google;
- professional advisers, insurers, auditors or a purchaser/investor under confidentiality and only where reasonably necessary; and
- regulators, courts, law-enforcement bodies or other recipients when required or permitted by law.
Provider names may change as the Platform develops. A replacement must be assessed and contractually required to protect personal information where it acts as our operator. We do not sell or rent personal information or give Partners customer lists.
8. Processing outside South Africa
Some providers and their infrastructure may be located outside South Africa or use distributed global systems. This means personal information may be transferred to or accessed from another country, including where Apple, Google, Firebase, Paystack, Brevo, Render or Supabase provides a relevant service.
We will make a cross-border transfer only where section 72 of POPIA permits it—for example, where the recipient is bound by a law, binding corporate rules or an agreement that provides an adequate level of protection; you consent where valid and appropriate; or the transfer is necessary to perform a contract or requested pre-contract step. Safeguards and remedies may differ between countries.
9. Location, local storage and website technology
The customer app asks for foreground location only when you choose the “Near me” function. In the version reviewed for this Policy, your location is used on the device to sort nearby Partners and is not sent to the Privy Rewards backend. You can deny or withdraw the operating-system permission and browse without distance sorting.
The app uses local device storage for essential preferences and secure account or device functions. The public website version reviewed for this Policy does not use advertising or behavioural-analytics cookies. Hosting and security infrastructure may still process ordinary request data such as IP address, browser type, requested page and time. If we introduce non-essential cookies or tracking, we will update this notice and obtain consent where required.
10. Marketing and notifications
Account verification, security, payment, subscription and support messages are service communications. Optional promotional emails or push notifications are direct marketing.
We will send electronic direct marketing only with consent or where another narrow legal permission applies, and each marketing message will identify the sender and provide a practical, free way to stop it. You may withdraw push permission in the app or device settings and object to email marketing using the message’s unsubscribe method or legal@privyrewards.co.za. We will keep a limited suppression record so we can respect the opt-out.
11. Retention
We keep a record only while authorised by law and reasonably necessary for its stated purpose. The following are intended standard periods; a shorter or longer period may apply where law, a live dispute, a security incident, a legal hold, a contract or a data-subject request justifies it.
| Record | Intended standard period |
|---|---|
| Active account, authentication, trusted-device and current membership information | While the account is active, then deletion or de-identification ordinarily within 30 days after a verified deletion request, except for records listed below. |
| Expired sessions, one-time challenges, nonces and inactive push tokens | Only for the short operational or security period needed for expiry, investigation and safe cleanup; inactive tokens should be removed or deactivated on a recurring basis. |
| Payment, subscription and financial transaction records | Generally five years after the transaction or longer where tax, accounting, corporate or other law requires. |
| Redemption and associated Partner transaction records | Generally three years after redemption, then deletion or de-identification, unless a longer period is needed for a dispute, financial record or fraud investigation. |
| Security and audit logs | Generally 24 months, or longer where linked to an incident, enforcement matter or legal claim. |
| Support, complaint and privacy-request records | Generally three years after closure, or longer where necessary to prove compliance or resolve a dispute. |
| Unsuccessful Partner applications | Generally 12 months after the decision, unless the applicant asks us to retain it for a future opportunity. |
| Partner agreement, offer and operational records | For the relationship and generally five years afterward, subject to legal and dispute requirements. |
| Backups | Rotate out according to the backup cycle, targeted not to exceed 90 days, unless isolated under a legal or security hold. |
At the end of an authorised period, we will delete, destroy or de-identify the record as soon as reasonably practicable and in a manner intended to prevent reconstruction. Information retained only for proof, a legal hold or another restricted purpose will be protected from unrelated use.
12. Security
We use appropriate, reasonable technical and organisational measures based on the information and risks involved. Current measures include password hashing, email verification, session and device controls, role-based permissions, short-lived QR credentials, transport encryption, provider access controls, audit records, environment-secret separation and operational monitoring.
No connected service can guarantee absolute security. You should use a unique password, protect access to your email and linked login provider, keep your device updated and report suspicious activity promptly. Service providers that process personal information for us must be subject to appropriate confidentiality and security obligations.
13. Security compromises
If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will investigate, contain and document the incident. We will notify the Information Regulator and affected data subjects as soon as reasonably possible where POPIA requires it, subject to any lawful delay directed by law enforcement. A notice will include available information required by law and practical protective steps where relevant.
14. Automated rules and human review
Automated rules validate login challenges, payment status, plan eligibility, QR expiry and redemption conditions. These rules may temporarily decline access or a redemption when a requirement is not met. We do not intend to make a decision based solely on automated profiling that has unlawful legal or substantial effects.
If you believe an automated result is wrong, contact support. We will provide a reasonable opportunity to submit information and will arrange human review where required by law.
15. Questions and privacy requests
You may ask us about your personal information, request access or correction, ask us to delete information we are no longer authorised to keep, object to certain processing, withdraw consent, or stop direct marketing.
Email legal@privyrewards.co.za from the account address where possible and describe what you need. We may request proportionate proof of identity or authority, and we will respond as required by law.
Account deletion instructions are on the Account Deletion Request page. Subscription cancellation and account deletion have different financial and access consequences, which that page explains.
Please contact us first so we have an opportunity to investigate and resolve any privacy concern. You also have the right to lodge a complaint with the Information Regulator (South Africa) at POPIAComplaints@inforegulator.org.za.
16. Intended audience
Customer accounts are intended for people aged 18 or older. We rely on each account holder’s declaration and do not routinely request proof of age. If we learn that an account holder is under 18, we may restrict or close the account and will delete information we are not lawfully authorised or required to retain. Concerns may be sent to legal@privyrewards.co.za.
17. Changes to this Policy
We may update this Policy when processing, providers or law changes. We will publish the effective date. If a change materially affects how we use information already collected, we will provide additional notice and obtain consent where the law requires it.
