Privacy
Privacy Policy
This Policy explains how Chibara processes personal information when people use Connect accounts, profiles, NFC products, subscriptions, bookings and payment tools.
1. Scope and responsibility
Chibara operates Connect and is responsible for personal information processed to provide the platform, manage accounts, sell Connect products and subscriptions, secure the service, provide support, and meet legal obligations. This Policy applies to Connect’s public website, account area, digital profiles and associated services.
A profile owner or organisation may be separately responsible for information they collect through their profile, booking form or connected payment service. For example, a customer’s service requirements are shared with the profile owner so they can deliver the booking. Chibara and the profile owner do not automatically become jointly responsible for every separate use of that information.
2. Information we process
Account and identity information
- Name, email address, authentication identifiers, account role and security records.
- Information returned by a selected social sign-in provider, such as provider account ID, name, email address and profile image, within the permissions you approve.
- Organisation membership, administrator role and account-support correspondence.
Profile and card information
- Professional and personal details you choose to add, such as role, company, biography, contact details, links, media and downloadable contact information.
- Profile visibility, publishing state, slug, QR destination, NFC card identifier, activation, assignment and status.
- Profile opens, NFC taps, QR visits and contact-download events, including time, referral source, general device information, IP address and coarse location when supplied by infrastructure.
Transactions, bookings and support
- Card order, delivery, invoice, subscription, plan, billing and payment-status information.
- Booking customer name, email, mobile number, chosen service and time, notes, cancellation or rescheduling activity, and payment status.
- Payment references, provider account status and transaction metadata. Connect does not store raw payment-card numbers, expiry dates or CVV codes; those are entered on the hosted payment provider.
- Messages, complaints, evidence and technical diagnostics you send to support.
3. Where information comes from
We receive information directly from account holders, profile visitors, booking customers and purchasers; from an organisation that provisions or administers a profile; from NFC and QR interactions; and from service providers involved in authentication, hosting, email, payment, delivery or fraud prevention.
Please do not submit another person’s personal information unless you are authorised to do so and have given them any notice required by law.
4. Why we process information
We process information when it is necessary to perform a contract or take requested steps, comply with law, pursue a legitimate operational or security purpose that does not unjustifiably override a person’s rights, protect a legitimate interest, or rely on consent where consent is the appropriate basis. You may withdraw consent for future processing when processing depends on consent; earlier lawful processing remains valid.
- Create accounts, authenticate users and protect sessions.
- Create, publish and share profiles through links, QR codes and NFC products.
- Provision cards, process orders, deliver products and provide support.
- Manage plan entitlements, subscription billing and transaction records.
- Record and communicate bookings, initiate hosted payments and provide booking-management links.
- Detect misuse, prevent fraud, diagnose faults, maintain audit records and improve reliability.
- Send operational messages and, where permitted, requested product communications.
- Meet accounting, consumer-protection, legal and regulatory duties and establish or defend legal claims.
5. Profile visibility and sharing choices
A published public profile can be opened by anyone with its address and may be copied, shared or indexed by search services. An unlisted profile is intended to stay out of Connect discovery and may carry search-indexing instructions, but anyone with the link can open it and third-party indexing cannot be guaranteed. A private secure-link profile is accessible to a person who has the secure link; that link must be treated as confidential.
Changing visibility limits future access through Connect but cannot retrieve information already saved, downloaded, indexed, screenshotted or shared by another person. Only publish information you are comfortable sharing with the intended audience.
Organisation administrators may view and manage organisation-owned profile fields and card assignments as allowed by their role. Profile visitors see only the fields rendered on the profile they open.
6. Who receives information
We share information only where reasonably needed for the stated purposes. Recipient categories may include hosting and database providers, authentication providers, email services, payment providers, couriers and fulfilment partners, security and support vendors, professional advisers, authorised organisation administrators, and the profile owner fulfilling a booking or receiving a payment.
A booking customer’s contact details, booking choice and note are made available to the relevant profile owner. Payment providers receive the information required to create and verify checkout. Couriers receive delivery details required to fulfil an order. We do not sell personal information.
We may disclose information where required by law, a lawful court or regulator request, to protect rights or safety, or as part of a genuine business restructuring subject to appropriate safeguards.
7. Service providers and cross-border processing
Some providers may process information in South Africa or other countries. Where personal information is transferred across borders, we take reasonable steps to use providers and arrangements that offer an appropriate level of protection, contractual safeguards, binding rules, consent where suitable, or another lawful basis recognised by applicable data-protection law.
Provider locations and subprocessors can change as infrastructure evolves. You may contact us for further information about the safeguards relevant to your information.
8. Retention
We keep personal information only for as long as reasonably needed for the purpose collected, an active account or transaction, security and dispute handling, legal duties, or the establishment and defence of claims. Retention periods vary by record type.
Active profile information is generally kept while the profile remains active. Closed-account information is deleted or de-identified after operational and backup periods unless a legal, fraud, payment, tax or dispute reason requires longer retention. Transaction and accounting records may be retained for statutory periods. Backups are protected and expire on scheduled cycles.
A profile owner may retain booking or customer information independently for their service, accounting or legal obligations. Requests about that separate copy should be directed to the profile owner.
9. Security
We use reasonable technical and organisational safeguards appropriate to the information and risk. These include access controls, protected credentials, limited administrator permissions, server-side payment verification, encrypted transport, logging and incident response. Sensitive profile-owner payment credentials are designed to be encrypted at rest; raw card details remain with the hosted payment provider.
No internet service can guarantee absolute security. Account holders should use a unique password, protect secure profile and booking-management links, review administrator access and report suspected compromise promptly.
10. Your choices and rights
Subject to the Protection of Personal Information Act, 2013 and other applicable law, you may ask whether we hold personal information about you, request access, ask us to correct or update inaccurate information, request deletion or destruction where lawful, object to certain processing, or ask about a decision or use that affects you. A lawful retention duty or another permitted ground may prevent immediate deletion.
You can update many profile fields and visibility settings in Connect. You may disconnect an optional social provider if another valid sign-in method remains available. Browser settings can control cookies as described in the Cookie Policy.
We may need to verify identity and authority before acting on a request. We will explain if a request is refused or limited. You may complain to us through the Complaints Procedure and may also approach South Africa’s Information Regulator where applicable.
11. Policy changes
We may update this Policy when the product, providers or legal requirements change. The current effective date and version appear above. For material changes, we will use a reasonable notice method before the change takes effect where practicable.