Notice Me
Back to site
LegalPrivacy Policy

Privacy Policy

Effective from April 2026 · POPIA-compliant · Responsible Party: Notice Me

⚠ Operator action required before publishing

Replace all [PLACEHOLDER] values with your actual details. You must register your Information Officer with the Information Regulator at inforegulator.org.za before processing personal information commercially. Have a qualified South African attorney verify POPIA compliance before going live.

Notice Me (Registration No. [REGISTRATION NUMBER]), the operator of Notice Me, is the Responsible Party in respect of your personal information as defined in the Protection of Personal Information Act 4 of 2013 ("POPIA"). This Privacy Policy explains how we collect, use, store and protect your personal information, and describes the rights you have as a data subject.

This Policy applies to all personal information we process in connection with the Notice Me platform, including information provided by Vendors, Centre users, and visitors to our website.

1

Who We Are (Responsible Party)

Company nameNotice Me
Registration number[REGISTRATION NUMBER]
Registered address[REGISTERED ADDRESS]
Information Officer[INFORMATION OFFICER NAME]
Information Officer email[INFORMATION OFFICER EMAIL]
Information Regulator registration[REGISTRATION REFERENCE — obtained from inforegulator.org.za]

Under POPIA, every organisation that processes personal information must designate an Information Officer and register that officer with the Information Regulator of South Africa.

2

Personal Information We Collect

We collect the following categories of personal information:

2.1 Account and Identity Information (Vendors and Centre Users)

·Full name or business name

·Email address

·Password (stored as a one-way cryptographic hash — we cannot recover your plain-text password)

·Account role (vendor or centre user)

·Account creation date and time

2.2 Advertising Content

·Ad title and descriptive text

·Uploaded media files (images, videos, PDF documents)

·Selected Screens, dates and time slots for each Booking

·Ad approval status and any rejection reasons

2.3 Booking and Payment Records

·Booking reference numbers

·Pricing per Booking

·Payment status and payment gateway reference numbers (PayFast)

·Booking creation and expiry dates

2.4 Usage and Performance Data

Ad play counts: we log each time a registered Screen plays an approved Ad, recording the Ad identifier, Screen identifier, and date/time of play. This data is linked to your account for reporting purposes.

2.5 Complaint Records (Centre Users)

·Complaint text submitted by Centre users regarding Ads displayed on their Screens

·Complaint status and resolution outcome

2.6 Technical Data

Session data: We use a digitally signed session token (JWT) stored in a browser cookie to maintain your login session. It contains your account identifier, role and session expiry. It does not contain your password.

IP addresses: Temporarily held in server memory for rate-limiting only. Never written to any database or log file. Discarded automatically within 60 minutes.

What we do NOT collect: No third-party analytics (e.g. Google Analytics), no advertising cookies, no tracking pixels, no biometric data, no health data, no special personal information as defined in section 26 of POPIA.
3

Purposes and Legal Basis for Processing

We process your personal information only for the specific, explicitly defined and legitimate purposes below, in accordance with Chapter 3 of POPIA.

PurposeInformation UsedLegal Basis (POPIA)
Account creation and authenticationName, email, password hashConsent; contract performance
Processing and managing Ad BookingsAd content, Booking details, Screen selectionsContract performance
Payment processingBooking amount, payment gateway referenceContract performance; legal obligation
Delivering Ads to ScreensAd media files, Booking scheduleContract performance
Performance reporting (play counts)Ad play logsContract performance; legitimate interest
Handling Centre complaintsComplaint text, Ad and Centre identifiersLegitimate interest; contract performance
Security and fraud preventionIP addresses (in memory), session tokensLegitimate interest; legal obligation
Legal and compliance obligationsAccount and transaction recordsLegal obligation
Service communications (transactional)Email addressContract performance
Direct marketing (only with consent)Email address, nameConsent — withdrawable at any time
4

How We Use Your Information

We use your personal information only for the purposes listed in clause 3. We do not sell, rent or trade your personal information to any third party. We do not use your personal information for automated decision-making that produces legal or similarly significant effects without your involvement.

5

Sharing of Personal Information

We may share your personal information in the following limited circumstances:

Payment processor

We share Booking and payment information with our payment gateway provider (PayFast) to process transactions. That provider processes information under its own privacy policy and is subject to applicable data protection law.

PiSignage

Ad media files are transmitted to PiSignage digital signage software running on our local network infrastructure to schedule and display Ads on Screens. This transmission occurs within our own controlled infrastructure; PiSignage does not independently receive or store your personal account data.

Centre operators

Centre users can see the title and status of Ads scheduled on their Screens. They do not have access to your account email address, payment details or other personal information.

Legal requirements

We may disclose personal information where required by law, court order, or lawful request by a South African government authority.

Business transfers

In the event of a merger or acquisition, personal information may be transferred to the acquiring entity, subject to equivalent obligations.

6

International Transfers

We primarily store and process your personal information within the Republic of South Africa. Where personal information is transferred outside the Republic, we will ensure that the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection, in compliance with section 72 of POPIA.

7

Retention of Personal Information

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

CategoryRetention period
Account informationDuration of account plus 3 years after closure (legal claims / audit)
Ad content and Booking recordsDuration of Booking, then 3 years for records purposes
Payment records5 years (Tax Administration Act 28 of 2011)
Ad play logsDuration of account or 3 years after last activity, whichever is later
Complaint records3 years after resolution
IP addresses (rate limiting)Maximum 60 minutes — in server memory only; never persisted
Session tokens8 hours (standard) or 30 days ("Remember me"), then automatically expire

After the applicable retention period, personal information is securely deleted or anonymised.

8

Security Safeguards

We implement appropriate technical and organisational measures to protect your personal information in accordance with section 19 of POPIA. These include:

🔑bcrypt password hashing (cost factor 12) — plain-text passwords are never stored
🔒HTTPS encryption for all data in transit
🍪Digitally signed, HttpOnly session tokens
🛡️Rate limiting on authentication endpoints
🧹Input validation and sanitisation on all form submissions
🔐HTTP security headers (CSP, X-Frame-Options, X-Content-Type-Options)
📁File type and magic-byte verification for all uploaded media
👥Role-based access controls (Vendor / Centre / Admin)
💾SQLite WAL mode with integrity checks
9

Security Compromise Notification

In the event of a security compromise involving your personal information, we will notify the Information Regulator and, where required, notify you as soon as reasonably practicable, in accordance with section 22 of POPIA. Notifications will be sent to your registered email address.
10

Direct Marketing

We will only send you direct marketing communications where you have given us prior consent, in accordance with section 69 of POPIA and section 45 of ECTA.

You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting our Information Officer at [INFORMATION OFFICER EMAIL].

Transactional emails (Booking confirmations, Ad approval notices, password resets) are necessary for the performance of our contract with you and are not direct marketing. You cannot opt out of transactional emails while your account is active.
11

Cookies and Browser Storage

We use a minimal set of browser storage mechanisms:

next-auth.session-tokenStrictly necessary

A digitally signed, HttpOnly cookie containing your encrypted session token. Expires automatically based on session duration chosen at login (8 hours or 30 days). Does not contain personal information in readable form.

next-auth.csrf-tokenStrictly necessary

Used to protect against cross-site request forgery attacks.

We do not use advertising cookies, analytics cookies, tracking pixels or any third-party cookies.

12

Your Rights as a Data Subject

Under Chapter 2 of POPIA you have the following rights:

Right to be informed

Know what personal information we hold and how we use it (addressed by this Policy).

Right of access

Request a copy of the personal information we hold about you.

Right to correction or deletion

Request that inaccurate, irrelevant, excessive or out-of-date information be corrected or deleted.

Right to object

Object to processing on reasonable grounds. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to object to direct marketing

Object at any time to processing for direct marketing purposes.

Right to complain

Lodge a complaint with the Information Regulator of South Africa.

Submit a written request to our Information Officer at [INFORMATION OFFICER EMAIL]. We will respond within 30 days and may verify your identity first.

13

Information Regulator

The Information Regulator is the independent statutory body established by POPIA to monitor and enforce data protection law in South Africa. If you are not satisfied with our response, you may contact:

Website
www.inforegulator.org.za
Email
inforeg@justice.gov.za
Address
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal
P.O. Box 31533, Braamfontein, Johannesburg, 2017
14

Children's Privacy

The Platform is not directed at persons under the age of 18. We do not knowingly collect personal information from minors. If you are aware that a minor has provided us with personal information without parental consent, please contact our Information Officer immediately and we will take steps to delete that information.

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. We will notify you of material changes by email or by prominent notice on the Platform. The updated Policy will take effect 20 business days after notification.

16

Contact Us

For all privacy-related queries, data subject requests or complaints, please contact our Information Officer:

Name
[INFORMATION OFFICER NAME]
Email
[INFORMATION OFFICER EMAIL]
Postal address
[REGISTERED ADDRESS]
Last updated: April 2026Version: 1.0

Legislation referenced: Protection of Personal Information Act 4 of 2013 · Electronic Communications and Transactions Act 25 of 2002 · Tax Administration Act 28 of 2011.