Plain English Summary: This policy explains what personal information we collect, how we use it, who we share it with, your rights under South Africa's POPIA, and how to contact us.
1. Who We Are & Scope
1.1 FineApple Pixels (Pty) Ltd ("FineApp", "we", "us") operates FineApp, a freelance platform for creative services in South Africa.
1.2 This Policy applies when you browse, create an account, post a listing, book/pay for services, contact support, or otherwise use the Platform.
2. Information We Collect
2.1 Account & Profile – name, surname, display name, email, mobile number, country, profile photo, biography, portfolio/links, specialties, pricing.
2.2 Identity & Verification (if enabled) – ID number, government ID copy, date of birth, business registration details, address, liveness/face‑match signals.
2.3 Transaction Data – bookings, messages, briefs, deliverables, invoices/receipts, payouts, VAT numbers, refund/chargeback records.
2.4 Payment Data – tokenised card or bank details handled by our payment provider; FineApp does not store full card PANs. Where applicable, bank account numbers are collected solely for payouts.
2.5 Technical Data – device identifiers, IP address, log data, cookie IDs, analytics events.
2.6 Support & Safety – communications with support, reports/flags, trust‑and‑safety signals.
2.7 Marketing Preferences – opt‑ins for emails, notifications, and cookie categories.
3. How We Use Personal Information (Purposes & Legal Bases)
We process personal information for:
- Account creation & service delivery (contract necessity).
- Payments, commission, and payouts (contract necessity; legal obligations).
- Identity verification, trust & safety, and fraud prevention (legitimate interests; legal obligations).
- Customer support & dispute assistance (contract necessity; legitimate interests).
- Improving and securing the Platform (legitimate interests).
- Marketing & communications with your consent and/or legitimate interests (opt‑out available for direct marketing).
- Legal compliance (e.g., responding to lawful requests; tax/financial record‑keeping).
4. POPIA Principles We Follow
- Lawfulness, fairness, transparency – we explain our processing and your rights.
- Purpose limitation & minimality – we collect only what is relevant for stated purposes.
- Accuracy – we aim to keep data up to date; you can update your profile.
- Security safeguards – we implement measures appropriate to risk.
- Data subject participation – you can access, correct, or delete personal information (see Section 8).
5. Sharing Your Information
We share personal information with:
- PayFast (payments) to process transactions and payouts.
- Auth0 (authentication) to provide secure login and identity services.
- Cloudinary (media hosting) to host and deliver images and other media you upload.
- Service providers (hosting, analytics, communications, KYC/AML, customer support) under contracts with confidentiality and security obligations.
- Other Users as necessary to complete bookings (e.g., project details) inside Platform messaging.
- Authorities or advisors where required by law or to protect our rights, Users, or the public.
- Business transfers in the context of a merger, acquisition, or restructuring, with appropriate safeguards.
We do not sell personal information.
6. Data Retention
We retain personal information only as long as necessary for the purposes above—typically:
- Account & transaction records: 5–7 years (financial/record‑keeping laws).
- Verification and trust‑and‑safety records: as needed for fraud prevention and legal defence.
- Marketing preferences: until you opt out or your account is deleted.
We securely delete or anonymise data when no longer required.
7. Security
We implement technical and organisational safeguards appropriate to the risks of our processing (e.g., access controls, logging, least‑privilege, backups). No system is 100% secure; you must also protect your credentials and devices.
8. Your Rights (POPIA)
Subject to legal limits, you may:
- Access your personal information.
- Correct inaccurate or incomplete data.
- Delete personal information (where allowed).
- Object to certain processing, including direct marketing (opt‑out anytime).
- Withdraw consent where processing is based on consent.
- Complain to the Information Regulator (South Africa) if you believe we have infringed your rights.
Requests can be made via support@fineapp.co.za. We will verify your identity and respond within statutory timeframes.
9. Cookies & Similar Technologies
We use cookies for essential functionality, analytics, and (if you consent) marketing. You can manage preferences in our cookie banner/settings and through your browser.
10. Third‑Party Links
The Platform may link to third‑party sites/services. Their privacy practices are their own; review their policies.
11. Changes to This Policy
We may update this Policy periodically. Material changes will be announced on‑platform or via email. Continued use after the effective date signifies acceptance.
12. Contact Us & Information Officer
Information Officer:
Email: support@fineapp.co.za
13. Records, Requests & PAIA Manual
Where required, FineApp will publish/maintain a PAIA Manual (Promotion of Access to Information Act) explaining how to request records in our possession and applicable fees.
End of Policy
