This disclosure explains why eRunna collects background location data, what is collected, how it is used, and how you can manage your permissions. It is published in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) section 18 openness obligation and the prominent-disclosure requirements of the Apple App Store and Google Play Store for applications that access device location while not in use.
This disclosure applies to the eRunna mobile application ("App") available on iOS and Android. Read it alongside our Privacy Policy.
1. Who is responsible for your location data
The responsible party (data controller) for personal information collected by the eRunna App is eRunna (Pty) Ltd (registration number [TBD: company registration number]), a private company incorporated under the laws of the Republic of South Africa.
Registered office: 1 Wedgewood Link Rd, Bryanston, Johannesburg, Gauteng, 2191 (by appointment only).
Information Officer: [TBD: name and contact of registered Information Officer — mandatory under POPIA (duties of the Information Officer; [ATTORNEY-REQUIRED: confirm citation to s55/s56 and the applicable POPIA Regulation number]); must be registered on the Information Regulator's eServices portal before these duties may be exercised].
Contact for privacy matters: info@erunna.app.
2. Why we use background location — the specific purposes
2.1 Runners — "Always Allow" / "Allow all the time"
For users registered as runners, eRunna requests background location at the start of an active delivery so location updates can continue when the App is minimised or the screen is off. The background service stops when the delivery ends or is cancelled and does not restart itself after the App is terminated or the device reboots.
The specific purposes for runner background location are:
- Real-time customer tracking: continuous location updates allow us to display the runner's position on the customer's live-tracking map.
- Delivery continuity: the same live-tracking updates continue while the runner uses another app for navigation, receives a call, or turns off the screen during the active delivery.
2.2 Customers — "While Using" (foreground only)
For customers, the App requests foreground location permission ("While Using the App") for selecting pickup/drop-off points, viewing nearby runners, and route calculation. Customer accounts do not request or use background location.
3. What we collect
- Precise GPS coordinates (latitude, longitude, accuracy radius) derived from GPS, Wi-Fi, and mobile-network signals.
- Timestamps for each location fix.
The job-bound background service does not collect location outside an active delivery and does not build movement profiles for marketing purposes.
4. Legal basis for collection (POPIA)
Under POPIA, personal information may be processed only on a lawful basis. The primary bases for background location processing are:
- Consent (POPIA — consent ground [ATTORNEY-REQUIRED: confirm citation to s11(1)(a)]): you are asked to grant background location permission explicitly through your device's operating-system permission dialogue. You may withdraw consent at any time by changing your device settings (see section 6 below). Withdrawal of consent may limit service functionality as described in section 6.
- Contractual necessity (POPIA — performance-of-a-contract ground [ATTORNEY-REQUIRED: confirm citation to s11(1)(c) AND confirm that this ground is available given the runner's legal status — the characterisation of the runner relationship (independent contractor vs. employee) is unsettled and directly affects which lawful basis applies]): background location supports customer-visible tracking while the runner App is minimised during an active delivery. Without it, the customer sees only the last position reported before the App was backgrounded.
5. How long we keep location data
The backend writes the runner's latest reported coordinates to the runner-presence record. The retention period for that location data remains [TBD: confirm in the Data Retention Policy and align with POPIA s14]. See our Data Retention Policy for the current schedule.
6. Your controls
6.1 In-app controls
- Runners: background location starts only when an active delivery begins and stops automatically when that delivery ends or is cancelled.
- Customers: customer accounts use foreground location only.
6.2 Device settings
- iOS: go to Settings → Privacy & Security → Location Services → eRunna. You may select "Never", "While Using the App", or "Always". Without "Always", runner live-location updates cannot continue while the App is minimised during an active delivery.
- Android: go to Settings → Apps → eRunna → Permissions → Location. You may select "Deny", "Allow only while using the app", or "Allow all the time". The consequences for runners are the same as above.
6.3 Effect of withdrawing permission
You will never be penalised for exercising your right to withdraw location consent. Revoking background permission does not block an active delivery, but live location updates cannot continue while the runner App is minimised and the customer may see the last reported position become stale.
7. Who we share location data with
- Customers: your current reported position is shared with the customer whose active delivery you are serving.
- Service providers (subprocessors): location data is processed on our cloud infrastructure (Google Cloud Platform / Firebase, hosted in [TBD: confirm primary data-residency region for location data post-ADR 0061 africa-south1 migration]). See our Subprocessors list.
- Safety and legal: location logs may be disclosed to law enforcement or the Information Regulator where required by a lawful order, or to prevent imminent harm.
We do not sell location data to third-party advertisers.
8. International transfers
Location data processed by our cloud providers may transit or be stored in data centres outside South Africa. Where this occurs, we apply appropriate safeguards as required by POPIA's rules on transfers of personal information outside the Republic ([ATTORNEY-REQUIRED: confirm citation to s72]), including contractual protections with our subprocessors. See our Privacy Policy section on international transfers for details.
9. Consistency with in-app permission prompts
The permission rationale displayed in the iOS "Allow Location Access" prompt and the Android runtime permission dialogue is intended to match the purposes described in section 2 of this disclosure. Apple and Google both require that the in-app prompt text accurately reflects the specific reasons for the permission request and that a prominent, pre-permission disclosure is available (typically by linking to this page). If you notice a material discrepancy between the in-app prompt text and this disclosure, please contact us at info@erunna.app.
[ATTORNEY-REQUIRED: review the current in-app prompt text — "Allow background location so live tracking continues while you handle this delivery, even if the app is minimised" — against the Apple App Review Guidelines and Google Play Location Permissions policy.]
10. Your POPIA rights
Under POPIA, you have the right to:
- Request access to the location data we hold about you (subject to limitations in the Promotion of Access to Information Act 2 of 2000 (PAIA)).
- Request correction or deletion of inaccurate location records.
- Object to the processing of your location data on legitimate-interests grounds.
- Withdraw consent at any time (see section 6).
- Lodge a complaint with the Information Regulator of South Africa (www.justice.gov.za/inforeg/) if you believe your rights under POPIA have been infringed.
To exercise any of these rights, contact our Information Officer at info@erunna.app. We will respond within [ATTORNEY-REQUIRED: confirm the statutory response period for the relevant request type — the PAIA access-request timeframe and any POPIA-prescribed period must be verified before stating a fixed number of days].
11. Changes to this disclosure
We may update this disclosure when we add new location-dependent features, change our subprocessors, or to reflect changes in law or store policy requirements. We will post updates with a revised "Last updated" date and, where changes are material, provide in-app notice. Continued use of background location features after notice constitutes acceptance of the updated disclosure.
Related policies
- Privacy Policy — full POPIA s18 openness notice covering all personal information collected by eRunna.
- Data Retention Policy — retention schedules for location data and all other personal information categories.
- Subprocessors — third-party providers that process location data on our behalf, including cloud infrastructure and mapping services.
- App Store Privacy (iOS) — Apple privacy nutrition-label data categories, including precise location.
- Google Play Data Safety (Android) — collection, sharing, and security disclosures for Android, including background location.
- Runner Agreement — contractual basis for background location collection from runners.
- Security Incident Response — our procedure if location data is involved in a security breach (POPIA s22 notification obligations).