This policy explains how Privately Property (Pty) Ltd (“Privately”, “we”, “us”) collects, uses, shares and protects your personal information when you use our website and services. We comply with the South African Protection of Personal Information Act, 2013 (Act 4 of 2013) (“POPIA”).
Who we are
Privately is a private property marketplace that lets buyers and sellers in South Africa transact directly, without estate-agent commission. The legal entity behind the service is:
- Privately Property (Pty) Ltd
- 6 Rainbow Drive, Midfield Estate, South Africa
- Privacy queries: info@privatelyproperty.com
Information Officer
As required by POPIA section 56, we have appointed an Information Officer who is accountable for our compliance with POPIA.
- Name: Chandre Niemand
- Email: info@privatelyproperty.com
- Postal address: 6 Rainbow Drive, Midfield Estate, South Africa
You may contact the Information Officer for any privacy-related request, including data access, correction, deletion, or to lodge a complaint before approaching the Information Regulator.
What we collect
We only collect information that is necessary to provide the Privately service. Categories include:
- Identifiers and contact details: full name, email address, phone number, and (where applicable for FICA) South African ID number.
- Property data: listings you create, viewings booked, offers/bids submitted or received, disclosure form answers, and property photographs.
- Verification data: documents you upload to verify your buying capacity (for example bond pre-qualification letters or proof of funds).
- Communication data: messages you send through our on-platform chat to other users.
- Behavioural data: pages visited, searches performed, properties favourited and saved searches — collected only with your analytics-cookie consent.
- Payment data: the platform-access fee is processed by PayFast. We never see or store your card details — we only receive a payment confirmation and reference.
- Technical data: IP address, browser type, and device information collected for security, fraud prevention and to deliver the service reliably.
Why we collect it
- To create and maintain your account.
- To allow you to list, browse, favourite and enquire about properties.
- To book and confirm property viewings between buyers and sellers.
- To facilitate offers and the negotiation between parties.
- To deliver transactional emails about your activity on the platform.
- To verify buyer financial capacity where you choose to participate.
- To prevent fraud, abuse and security incidents.
- To improve the product, measure performance and fix bugs.
- To comply with our legal obligations (FICA, tax, court orders).
- To send you marketing communications — only if you opt in.
Legal basis for processing (POPIA section 11)
We rely on one of the following lawful bases for each processing activity:
- Contractual necessity — we cannot deliver the service without processing the data (for example, we cannot show your listing to buyers without storing it).
- Legal obligation — FICA, the Income Tax Act, court orders and other applicable laws may require us to retain or disclose certain information.
- Legitimate interest — for security, fraud prevention and reasonable improvement of the platform, balanced against your privacy.
- Consent — for marketing emails, optional analytics and any non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Who we share it with
We do not sell personal information. We share data only with operators (POPIA-speak for “processors”) that help us run the service. Each operator is bound by a written agreement that limits use to our instructions.
- Supabase — database, authentication and file storage. Hosted in the EU.
- Vercel — application hosting and serverless functions. EU/US regions.
- Resend — transactional and notification email delivery.
- PayFast — processing of the once-off platform-access payment. Card details are handled directly by PayFast.
- Google Maps & Google Fonts — map tiles, places autocomplete and font delivery. Subject to Google’s own privacy terms.
- Lightstone — property valuation data, where you use a valuation feature for a specific property.
- PostHog — product analytics, EU servers, enabled only with your analytics-cookie consent.
- Sentry — error and performance monitoring, enabled only with your analytics-cookie consent.
- Attorneys you choose — once you accept an offer and select a conveyancing attorney, we share the deal details with that firm so they can complete the transfer.
- Bond originators (optional) — only if you request a bond pre-qualification or originator referral.
International transfers
Some of our operators store data outside South Africa (primarily in the EU and the United States). Where this happens, we rely on POPIA section 72 — specifically the operator’s adherence to binding corporate rules or Standard Contractual Clauses, or your explicit consent. You can request a list of current sub-processors and their locations from the Information Officer.
How long we keep it
- Active account data — while your account is active, plus 30 days after deletion (the POPIA-aligned grace period during which you can change your mind).
- Bid, offer and transaction records — seven (7) years, as required by FICA and SARS record-keeping rules.
- Verification documents — five (5) years post-transaction, in line with FICA.
- Marketing consent records — until you withdraw, plus three (3) years as proof of the consent decision.
- Server and application logs — up to 90 days for security and debugging.
After the retention period we delete or de-identify the data. Certain records (such as anonymised market statistics) may be retained indefinitely once de-identified.
Your POPIA rights
You have the right to:
- Access — request a copy of the personal information we hold about you (POPIA s23). You can export your data yourself in your privacy settings.
- Correct — ask us to correct information that is inaccurate, irrelevant, outdated or misleading. You can edit most fields directly on your profile.
- Delete — request that we delete your account and personal information (POPIA s24). Some data must be retained longer under FICA — see “How long we keep it”.
- Object — object to processing based on legitimate interest or for direct-marketing purposes.
- Withdraw consent — at any time, with no effect on prior lawful processing.
- Lodge a complaint — with the Information Regulator (details below).
To exercise any of these rights, use Privacy & data in your dashboard or email info@privatelyproperty.com. We will respond within a reasonable time, normally within 30 days.
Cookies
We use cookies and similar storage to keep you signed in, remember your preferences and — with your consent — understand how the product is used. Categories:
- Essential — required for the site to work (authentication, security, load balancing). Cannot be disabled.
- Analytics — help us understand which pages and features are useful (PostHog, Sentry). Off by default.
- Marketing — used to measure campaign effectiveness. Off by default.
You can change your choices at any time using the link in our footer.
Security
- All traffic is encrypted in transit using TLS.
- Data is protected by row-level security policies in our database so that one user’s data is never visible to another.
- Passwords are stored as salted hashes by our authentication provider — we never see them.
- Verification documents are stored in a private bucket that requires authentication and a signed URL.
- Access to production data is limited to the Information Officer and essential engineering staff and is logged.
We will notify you and the Information Regulator without undue delay (and where feasible within 72 hours of becoming aware) if a security compromise affects your personal information, as required by POPIA section 22.
Children
Privately is not intended for users under 18. We do not knowingly collect personal information from minors. If you become aware that a minor has provided information to us, please contact the Information Officer and we will delete it.
Changes to this policy
We may update this policy from time to time. If we make a material change we will email account holders and post a notice on the site at least 14 days before the change takes effect. The current version and effective date are shown at the top of this page. Each consent decision you give is recorded against the policy version in effect at the time.
Contact us
For any privacy question, request or complaint, contact the Information Officer:
- Chandre Niemand
- info@privatelyproperty.com
- 6 Rainbow Drive, Midfield Estate, South Africa
Information Regulator
You have the right to lodge a complaint with the South African Information Regulator:
- The Information Regulator (South Africa)
- JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- General: inforeg@justice.gov.za
- POPIA complaints: POPIAComplaints@inforegulator.org.za
- +27 (0)10 023 5200
- https://inforegulator.org.za/
