Privacy Policy
This policy explains how Avuno Technologies (Pty) Ltd (“we”, “us”, “myquack”), the operator of myquack (https://myquack.co.za), collects, uses, shares and protects your personal information, and the rights you have under POPIA. We are the “responsible party” for the personal information we process.
Information Officer: Werno Roodt — privacy@myquack.co.za.
1. The personal information we collect
- Account details — your name, email address, phone number (optional) and a securely hashed password.
- Provider listing (providers only) — business name, industry and specialisation, description, town/area, and public contact details you choose to publish.
- Payout details (providers only) — your bank account holder name, account number and bank, used solely to pay out your released escrow funds.
- Verification documents (providers who choose to verify) — an image or PDF of an official document (e.g. CIPC registration, a trade/qualification certificate, or an ID). See “Automated verification” below.
- Booking & transaction data — the bookings you make or receive, amounts, escrow status, payouts, and related records.
- Communications — messages you send us and emails we send you.
- Technical data — limited log data such as IP address and browser type, used for security and to keep the service running.
We do not collect or store your card or banking login details — card payments are handled entirely by our escrow partner, TradeSafe (see below).
2. How and why we use it, and our lawful basis
Under POPIA we process your personal information only where we have a lawful basis to do so:
| Purpose | Lawful basis (POPIA) |
|---|---|
| Create and manage your account; provide the marketplace | Performance of our contract with you |
| Take bookings, have funds held in escrow by TradeSafe and pay providers out | Performance of contract; our legitimate interests |
| Verify a provider’s business documents (optional) | Your consent (you choose to upload) |
| Send you transactional emails (booking, payment, invoice) | Performance of contract |
| Keep the platform secure and prevent fraud | Our legitimate interests; legal obligation |
| Keep tax and financial records | Compliance with a legal obligation |
Providing your information is voluntary, but some of it is necessary to use myquack — for example, we cannot create an account without a name and email, or pay a provider out without their bank details.
3. Who we share it with (operators & other users)
We share personal information only as needed to run the service, with third parties acting as our “operators” under written agreement, and with the other party to a booking:
- Payments & escrow — TradeSafe, our independent licensed escrow provider, which holds booking funds in escrow, pays providers out, and carries out its own identity, KYC and FICA checks. We share the information needed for payments, payouts and those checks, and cooperate with TradeSafe’s lawful data requests.
- Email delivery — our email provider (Google Workspace), to send booking, payment and invoice emails.
- Document verification — Anthropic, to perform the automated check described below.
- Hosting — our cloud hosting provider, where the service and database run.
- Other users — once a booking is paid, the customer and provider are shown the details needed to fulfil it (such as name and contact details).
We do not sell your personal information, and we do not share it for third-party advertising.
Provider no-shows. If a provider confirms a booking, fails to attend, and does not make reasonable contact with the client within a reasonable time, we may — at the affected client’s request — disclose that provider’s identifying and contact details to the client so the client can seek a remedy or take legal action, as set out in clause 7 of our Terms. Providers give this consent in the Terms, and we disclose only what is reasonably necessary for that purpose.
4. Verification documents — how we handle them
If you choose to submit documents, each one you upload is transmitted to our document-analysis provider (Anthropic) and reviewed automatically: an AI model reads the key identifying details from it and assesses whether it appears to be a document of the type claimed. The details are then compared against the other documents you submitted, for consistency. We do not keep a copy of the uploaded document image once the review is complete — the image is not saved to our servers.
This review is automated and limited. We do not send your document to the body that issued it, and we do not check whether a registration, licence or membership is currently valid. It establishes what you submitted — not that a credential is genuine or in force.
We do keep a verification record: the outcome of each check (verified / not verified) and the key identifying details read from your documents — such as your name, business or registration number, the type of document, and the date it was checked. We keep this record to maintain your verified status, to detect and prevent fraud and impersonation, and — where a booking dispute or a provider no-show arises — to help establish who a provider is so that a client can seek a remedy. This record is stored securely with access restricted to those who need it. Verification is optional; you can use myquack without it, though it is required to reach the higher provider tiers.
5. Cross-border transfers
Some of our operators (for example our email and verification providers) process data on servers outside South Africa. Where personal information is transferred across borders, we take reasonable steps — including contractual safeguards — to ensure it receives a level of protection comparable to POPIA, as required by section 72. By using verification and email features you consent to these transfers where consent is the applicable basis.
6. How we protect it
We take appropriate, reasonable technical and organisational measures to safeguard personal information against loss, damage and unauthorised access, as required by section 19 of POPIA. These include:
- All traffic is encrypted in transit (HTTPS/TLS, with HSTS enforced).
- Passwords are stored only as salted one-way hashes — never in plain text — and we never see or store your card or banking-login details.
- Access to personal information is restricted to what is needed to operate the service (least privilege).
- We apply industry-standard security headers, protect forms against cross-site request forgery, and rate-limit sensitive actions such as sign-in.
- We keep our platform, dependencies and servers maintained and patched, and review our safeguards against new risks.
- Where a third party processes personal information for us (an “operator”), we require it, under our agreement, to keep that information secure and confidential and to use it only on our instructions, as contemplated by sections 20–21 of POPIA.
No online service can be guaranteed perfectly secure. If a security compromise affecting your personal information occurs, we will notify you and the Information Regulator as soon as reasonably possible, as required by section 22 of POPIA, and tell you what happened and what you can do to protect yourself.
7. How long we keep it
We keep your personal information for as long as your account is active and as needed to provide the service. When you request erasure we delete or de-identify your personal information, except records we are entitled or required to keep — including financial and tax records (such as invoices and transaction records), which we keep for the period required by the South African Revenue Service and applicable legislation, and a limited set of verification, booking and dispute records, which we may keep for a reasonable period to prevent fraud, resolve disputes, and establish, exercise or defend legal claims (for example, a client’s claim against a provider for a missed booking). We keep no more than we reasonably need for these purposes.
8. Your rights under POPIA
As a data subject you have the right to:
- Be told what personal information we hold about you and request access to it;
- Ask us to correct or update information that is inaccurate or out of date;
- Ask us to delete or destroy your information (subject to records we must keep by law);
- Object to processing, and withdraw consent where processing is based on consent;
- Not be subject to a decision based solely on automated processing that significantly affects you; and
- Complain to the Information Regulator.
You can update your details, change preferences, deactivate your account or request erasure from your Account page, or contact our Information Officer at privacy@myquack.co.za.
9. Direct marketing
We currently send only transactional and service messages relating to your account and bookings. We will not send you electronic marketing without your consent, and every marketing message we ever send will include an easy way to opt out.
10. Cookies
We use a small number of strictly necessary cookies: a session cookie to keep you signed in and a security token to protect forms against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies.
11. Children
myquack is intended for people aged 18 and over. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, take reasonable steps to let you know.
13. Contact & complaints
Questions or requests: privacy@myquack.co.za. If you believe we have not handled your personal information lawfully, you may lodge a complaint with:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: POPIAComplaints@inforegulator.org.za
Enquiries: enquiries@inforegulator.org.za
inforegulator.org.za