Privacy Policy
Last updated: 22 June 2026
Shap ZA respects your privacy. This policy explains how we collect, use, disclose,
and safeguard your personal information in compliance with the
Protection of Personal Information Act (POPIA), 4 of 2013,
the General Data Protection Regulation (GDPR) for EU users, and
international data protection standards.
1. Information We Collect
We collect the following categories of personal information:
1.1 Information You Provide
- Account Data: name, email address, phone number, and password.
- Profile Data: profile photo, home address, emergency contacts, and
payment details.
- KidSafe Data: child's name, date of birth, school, medical notes,
allergies,
PIN code (hashed), and parental consents.
- SeniorAssist Data: senior's name, date of birth, medical
conditions, medications,
doctor details, mobility aids, and emergency contacts.
- Bid Data: proposed fare amounts, pickup/drop-off locations, and
notes.
1.2 Information Collected Automatically
- Location Data: GPS coordinates during active trips for real-time
tracking
and route optimisation. Location is not collected when the app is in the background.
- Device Data: IP address, browser type, device model, operating
system, and app version.
- Usage Data: pages viewed, features used, trip history, and
interaction patterns.
- Cookies: please see our Cookie Policy.
1.3 Information from Third Parties
- NCPR: criminal background check results for KidSafe driver vetting.
- Payment Processors: transaction confirmations and fraud screening
results.
- OSRM / Nominatim: route distance and geocoding data (no personal
information shared).
2. Lawful Basis for Processing (POPIA & GDPR)
We process personal information on the following lawful bases:
- Consent — for GPS tracking, PIN verification, medical data sharing,
and marketing communications.
Explicit consent is obtained via our enrolment forms with timestamped records.
- Contractual Necessity — to fulfil ride requests, process bids, and
complete payments.
- Legal Obligation — to comply with NLTA record-keeping, NCPR vetting
requirements,
and POPIA retention periods.
- Legitimate Interest — for fraud prevention, platform security, and
service improvement.
3. How We Use Your Information
- Facilitate ride requests, bids, and trip completion.
- Verify Driver NCPR clearance and PDP validity.
- Provide real-time GPS tracking to parents, enrollers, and emergency contacts.
- Send safety alerts, trip confirmations, and delay notifications.
- Improve platform safety through AI anomaly and audio detection.
- Send newsletter and discount deals (with opt-in consent; you may unsubscribe at any
time).
4. Data Sharing & Disclosure
We share personal information only as necessary:
- With Drivers: passenger name, pickup location, drop-off location,
and (for KidSafe)
child's name and PIN verification status. Medical information is shared on a
need-to-know basis only.
- With Emergency Contacts: real-time trip tracking link and incident
notifications.
- With Regulatory Authorities: when required by POPIA, NLTA, or SAPS
under a valid legal request.
- With Service Providers: payment processors, cloud infrastructure
(AWS), and map services
(OpenStreetMap). All providers are POPIA-compliant and bound by Data Processing
Agreements.
We do not sell, rent, or trade personal information to third parties
for marketing purposes.
5. Data Retention
- Account data: retained for the duration of account activity plus 3
years.
- Trip data: retained for 5 years (NLTA requirement).
- KidSafe and SeniorAssist data: retained for active enrolment plus
30 days after
enrolment ends, then securely deleted.
- Medical information: deleted 30 days after enrolment ends.
- Location data: anonymised after 90 days.
- Communications consents: retained as proof of consent for 3 years
after withdrawal.
6. Your Rights (POPIA & GDPR)
You have the following rights regarding your personal information:
- Right to Access: request a copy of the personal information we hold
about you.
- Right to Rectification: request correction of inaccurate or
incomplete data.
- Right to Deletion: request deletion of your data, subject to legal
retention requirements.
- Right to Restrict Processing: request limitation on how we use your
data.
- Right to Data Portability: receive your data in a structured,
machine-readable format.
- Right to Object: object to processing based on legitimate interest
or direct marketing.
- Right to Withdraw Consent: withdraw consent at any time without
affecting the lawfulness
of processing before withdrawal.
To exercise any of these rights, contact our Information Officer at
support@shapza.co.za.
We will respond within 30 days as required by POPIA.
7. Data Security
We implement appropriate technical and organisational measures to protect personal
information,
including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- PIN codes stored as cryptographic hashes (bcrypt).
- Role-based access controls for all staff and Drivers.
- Regular security audits and penetration testing.
- Annual POPIA compliance assessments by an external Data Protection Officer (DPO).
8. International Data Transfers
Your data is primarily stored in South Africa (AWS Africa - Cape Town).
Where data is transferred outside South Africa (e.g., for payment processing),
we ensure adequate safeguards through Standard Contractual Clauses (SCCs) or
equivalent mechanisms as required by POPIA Section 72 and GDPR Articles 44–49.
9. Complaints
If you believe we have violated your privacy rights, you have the right to lodge a
complaint with:
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via
email and on the Platform 14 days before taking effect.
11. Contact
Information Officer:
support@shapza.co.za
+27 12 345
6789
This Privacy Policy is compliant with POPIA (South Africa), GDPR (EU),
and the UN Convention on the Rights of the Child (data privacy provisions).