DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication.
This document is a working draft prepared for review by a qualified South African attorney before it is published or relied upon.
All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.
Several items require attorney completion and are marked [ATTORNEY-REQUIRED].
Missing or unconfirmed operational details are marked [TBD].
This page provides the Google Play Data Safety disclosure for the eRunna Android application. It describes what personal information the app collects, why, how it is used, whether it is shared, and the security practices we apply. This disclosure is consistent with eRunna's full Privacy Policy and the App Store Privacy Summary. Where this summary and the full Privacy Policy conflict, the Privacy Policy governs.
eRunna is an on-demand errand, delivery, and marketplace platform connecting customers, runners [ATTORNEY-REQUIRED: confirm the correct legal characterisation of runners' engagement status under South African labour and employment law before describing them as independent contractors or independent service providers], merchants, and partners across South Africa.
1. Data collected and linked to you
The following data types are collected and are linked to your identity:
1.1 Personal info
- Name — collected at account creation; used for service delivery, account management, and support.
- Email address — collected at account creation; used for authentication, account management, support, and (where consented) direct marketing.
- Phone number — collected at account creation; used for authentication, service delivery, and support.
- Profile photo — optional; used to personalise your profile.
1.2 Identity and financial info (runners and merchants)
- South African identity number (SA ID) — collected during runner KYC onboarding for identity verification, fraud prevention, and regulatory compliance. This is sensitive personal information under POPIA s26. [ATTORNEY-REQUIRED: confirm Google Play Data Safety category mapping for SA ID numbers.]
- Biometric / KYC selfie image — a facial image or liveness video captured during runner KYC for identity-matching purposes; constitutes biometric information under POPIA s1 and special personal information under POPIA s26; collected with explicit, separate consent. [ATTORNEY-REQUIRED: confirm whether s57 prior authorisation from the Information Regulator is required before this processing goes live.]
- Payment tokens and authorisation codes — Paystack-issued tokens representing your payment method; we do not store full card numbers, CVVs, or PINs.
- Banking details (runners and merchants) — bank account number and branch code for payout processing.
1.3 Location
- Precise location (foreground) — all users; used for errand matching, routing, ETA calculation, pickup / drop-off pinning, and nearby-runner display.
- Precise location (background — runners) — runners only; used to provide customer-visible live tracking during an active delivery even when the app is minimised or the screen is off. We request the "Allow all the time" Android permission for this purpose. See the Background Location Disclosure for the full explanation.
1.4 Photos and videos
- User-supplied images — optional profile photos, KYC identity-document images and selfie/liveness captures, item/reference photos, chat image attachments, runner pickup/drop-off/receipt proof, and expense receipt images. Used only for the feature where the user supplies them.
1.5 App activity
- In-app interactions — screens visited, features used, search terms, errand and order history; used for service delivery, analytics, and product improvement.
- Support and chat messages — in-app chat transcripts and support communications; used for dispute resolution and customer support.
- Ratings and reviews — feedback you submit; used to maintain platform quality.
1.6 Device or other identifiers
- Device ID (Android ID) — used for account security, fraud prevention, and device binding.
- Firebase UID and session tokens — used for authentication and session management.
- Installation ID — used for device binding and realtime connection management.
1.7 App diagnostics and performance
- Crash logs — captured automatically by Google Firebase Crashlytics to detect and fix app stability issues.
- Performance data — response times, error rates, and app version; used for monitoring and improvement.
- OS version and device model — used to ensure compatibility and diagnose platform-specific issues.
2. Data collected but not linked to you
- Aggregated analytics — where technically feasible, analytics are aggregated or de-identified before use in product research and reporting, so that the data is not attributable to any individual.
3. Data sharing
We share personal information only in the following circumstances:
-
Service providers (operators under POPIA s20/s21): we share data with the following categories of subprocessors who process data on our behalf under written agreements:
- Cloud infrastructure and database: Google Cloud Platform and Firebase.
- Payments: Paystack (South Africa) — payment processing, tokenisation, and payout services.
- Identity verification / KYC: [TBD: name of KYC provider]
- Messaging and notifications: [TBD: email and SMS provider(s)]
- Crash reporting and monitoring: Google Firebase Crashlytics.
- In-context service fulfilment: limited personal information (first name, pickup / drop-off area, order status) is shared between customers, runners, and merchants strictly to fulfil a specific errand or order.
- Legal and safety disclosures: where required by law, court order, or to protect the safety or rights of eRunna, our users, or the public — including suspicious-transaction reporting obligations under FICA where applicable.
- We do not sell personal information to third parties for their own marketing or advertising purposes.
- Tracking: we do not use data to track you across apps and websites owned by other companies for advertising purposes.
4. Purposes of collection and use
- Service delivery: matching customers with runners; routing, tracking, and delivery ETA; order fulfilment; marketplace listings; notifications.
- Account management: creating and maintaining your account; authentication and session security.
- Payments: processing payment authorisations, handling refunds and cancellations, routing payouts to runners and merchants.
- Identity verification and fraud prevention: runner KYC (SA ID and biometric match), fraud detection, abuse investigation, and platform-integrity monitoring.
- Safety: incident investigation, runner and customer safety features, emergency-contact use.
- Customer support: responding to support requests, resolving disputes, in-app messaging.
- Analytics and service improvement: aggregated or de-identified performance monitoring, product improvement, and research.
- Legal and regulatory compliance: tax obligations, FICA / AML-CFT customer due diligence and record-keeping, court orders, and enforcement of our Terms of Service. [ATTORNEY-REQUIRED: confirm whether eRunna falls within an accountable-institution category under FICA Schedule 1 in respect of any payment or marketplace activities, and the resulting CDD / suspicious-transaction reporting obligations.]
- Direct marketing: where you have given consent under POPIA s69, or where the existing-customer exemption applies. You may withdraw marketing consent at any time — see the Privacy Policy section 8.
5. Background location
The eRunna app requests the "Allow all the time" background location permission on Android for runner accounts. This permission is used to:
- Provide customer-visible live runner tracking even when the app is minimised or the screen is off.
Background location starts only after a runner enters an active errand or delivery and stops when it ends or is cancelled. Revoking background location permission prevents live location updates while the runner app is minimised; the active delivery itself remains available. Customer accounts use foreground location only.
Full details: Background Location Disclosure.
6. Security practices
- All data is encrypted in transit using TLS.
- Data at rest is encrypted where supported by the underlying infrastructure (Google Cloud Platform / Firebase).
- Role-based access controls and least-privilege access are applied to internal systems and data stores.
- We do not store full card numbers, CVVs, or PINs — payment data is tokenised by Paystack.
- All subprocessors are bound by written data-processing agreements requiring equivalent security standards.
7. Data deletion
You may request deletion of your personal information by submitting a written request to [TBD: Information Officer email address, e.g. privacy@erunna.app] or by contacting us at info@erunna.app. We will acknowledge within 3 business days and complete the deletion or provide a reasoned response within 30 days (extendable in complex cases, with notice to you).
Certain data must be retained to meet legal obligations — for example, FICA imposes record-keeping obligations for financial transaction records [ATTORNEY-REQUIRED: confirm the applicable minimum retention period and the governing FICA provision]. Where a legal-retention obligation applies, we will inform you and retain only the minimum data required. See the Data Retention Policy for specific retention periods.
8. Related policies
- Privacy Policy — the full POPIA section 18 information notice governing all personal information processing.
- App Store Privacy Summary — the Apple App Store privacy nutrition labels (same data-type list and purposes).
- Background Location Disclosure — prominent disclosure for background location processing.
- Data Retention Policy — specific retention periods for each data category.
- Subprocessors list — current list of operators and cross-border transfer safeguards.
- Terms of Service
- Refunds & Payments Policy