Privacy Policy

Last updated: 2026-08-15

DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication.
This document is a working draft prepared for review by a qualified South African attorney before it is published or relied upon. All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication. Several items require attorney completion and are marked [ATTORNEY-REQUIRED]. Missing or unconfirmed operational details are marked [TBD].

This Privacy Policy ("Policy") is the POPIA section 18 information notice for eRunna (Pty) Ltd ("eRunna", "we", "us", "our"). It applies to every person who interacts with our mobile applications, websites, runner and merchant onboarding portals, and any in-person data-collection activities such as mall activations (collectively, the "Services").

eRunna is an on-demand errand, delivery, and marketplace platform connecting customers, runners [ATTORNEY-REQUIRED: confirm the correct legal characterisation of runners' engagement status (e.g. independent contractor vs employee) under the Labour Relations Act, the Basic Conditions of Employment Act, and applicable case law before describing runners as "independent service providers" anywhere in the Services], merchants, and partners across South Africa. We operate from Johannesburg, Gauteng.

1. Responsible party (POPIA s18(1)(a))

2. Information Officer (POPIA s18(1)(a); s55/s56 + Reg.4)

eRunna has designated an Information Officer as required by POPIA s55/s56 and the Information Regulator Regulations. The Information Officer is responsible for ensuring eRunna's compliance with POPIA, handling data-subject requests, and liaising with the Information Regulator of South Africa.

For all data-subject requests (access, correction, deletion, objection), complaints, or privacy concerns, contact the Information Officer at the address above. You may also lodge a complaint directly with the Information Regulator of South Africa: www.inforegulator.org.za  |  inforeg@justice.gov.za.

3. Categories of personal information collected (POPIA s18(1)(b))

We collect the following categories of personal information, depending on your role and your use of the Services:

3.1 General personal information (all users)

3.2 High-sensitivity information collected at KYC (runners / merchants)

During runner onboarding and identity verification (KYC), we collect high-sensitivity categories of personal information. Only biometric data is special personal information under POPIA section 26 (processed on a section 27 basis). The SA ID number and banking details are not section 26 special personal information — they are ordinary personal information of a high sensitivity, processed on a section 11 basis and secured under section 19. [ATTORNEY-REQUIRED: confirm the categorisation of the SA ID number and banking details, and the lawful basis for each.]

[ATTORNEY-REQUIRED: confirm the complete lawful basis for each special-PII category under s27(1)(a)–(h); confirm the KYC biometric-consent form wording meets the "explicit, specific, voluntary, informed, separate from blanket T&Cs" standard; confirm SA ID minimisation and retention limits.]

3.3 Collection points

4. Purposes of processing (POPIA s18(1)(c))

5. Lawful bases for processing (POPIA conditions — s11; s26/s27)

For special personal information (SA ID number, biometric selfie, banking data — see s3.2), the primary basis is your explicit and specific consent under s27(1)(a), obtained separately from the general Terms of Service at the point of KYC capture, with the right to withdraw as described in section 10.

6. Recipients and sharing of personal information (POPIA s18(1)(d))

7. Cross-border transfers (POPIA s72)

POPIA s72 restricts the transfer of personal information outside South Africa unless certain conditions are met, including that the recipient country or organisation provides an adequate level of protection substantially equivalent to POPIA, or that data subjects have consented to the transfer.

Where transfers occur to countries that have not been assessed as providing adequate protection, we rely on contractual safeguards (standard data-protection clauses or equivalent), and we will disclose the specific safeguard applicable to each transfer in the Subprocessors list.

[ATTORNEY-REQUIRED: attorney to review each cross-border transfer against s72(1)(a)–(e) and confirm adequate safeguards; obtain/review POPIA-compliant DPAs with GCP and Paystack before launch.]

8. Direct marketing (POPIA s69)

We may send you direct marketing communications (email, SMS, push notification, or in-app message) about our Services, offers, and updates in the following circumstances:

Opt-out / withdrawal: you may withdraw marketing consent or object to direct marketing at any time by clicking the "unsubscribe" link in any marketing email, replying "STOP" to any SMS, adjusting notification settings in the app, or contacting us at [TBD: Information Officer contact]. Withdrawal does not affect the lawfulness of processing before withdrawal. We maintain a suppression list and will honour opt-outs within a reasonable period.

8.1 "Join the waitlist" web form

If you submit your contact details via the "Join the waitlist" form on our website:

8.2 In-person mall activations and events

Where we collect personal information in person (for example at a shopping-centre activation):

9. Age policy — 18+ only (POPIA s34/s35)

The Services are intended for persons aged 18 years and older. We do not knowingly collect personal information from children under the age of 18.

POPIA s34 and s35 impose heightened obligations when processing the personal information of children, including a general prohibition on processing children's personal information without prior authorisation from the Information Regulator (s35(1)) unless a specific exception applies. We take this seriously given our marketing reach on platforms such as TikTok.

If you are under 18, you may not use the Services. If we become aware that we have collected personal information from a person under 18, we will delete it promptly. If you believe we have inadvertently collected such information, please notify us at [TBD: Information Officer contact].

[ATTORNEY-REQUIRED: attorney to confirm the applicable children's data protections under s34/s35 in the context of eRunna's TikTok reach and the waitlist web form, and whether any s57 prior-authorisation exposure exists for marketing to potentially under-18 audiences.]

10. Your rights as a data subject (POPIA s5; s18(1)(e)–(h))

Subject to POPIA and applicable law, you have the following rights in respect of your personal information:

To exercise any of these rights, submit a written request to the Information Officer at [TBD: Information Officer contact]. We will acknowledge promptly and respond within the period required by POPIA and its Regulations [ATTORNEY-REQUIRED: confirm citation — confirm the acknowledgement and full-response timelines (and any permissible extension) prescribed by POPIA / the Information Regulator Regulations before stating fixed day-counts]. We may require proof of identity before processing a request.

11. Retention (POPIA s14; s18(1)(d))

We retain personal information for no longer than is necessary to fulfil the purpose for which it was collected, or as required by law. Key retention periods include:

For full details, see the Data Retention Policy.

12. Security (POPIA s19)

We implement appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, disclosure, and processing, including:

No method of transmission or storage is 100% secure. In the event of a security compromise that affects your personal information, we will notify the Information Regulator and affected data subjects as required by POPIA s22. Our internal breach-response procedure is maintained separately.

13. Automated decision-making (POPIA s71)

Our runner-matching and dispatch algorithms make automated decisions that may affect which runners are offered errands and at what priority. You have the right under POPIA s71 to request human review of any automated decision that has a significant effect on you. Contact us at [TBD: Information Officer contact] to exercise this right.

14. PAIA manual

eRunna is required to compile and publish a manual in terms of the Promotion of Access to Information Act 2 of 2000 (PAIA) s51. The exemption for small private bodies has lapsed [ATTORNEY-REQUIRED: confirm citation — verify the exact expiry date of the small-private-body PAIA-manual exemption and that no current exemption applies to eRunna] — on current understanding no exemption applies. [TBD: the PAIA manual will be published at this location before launch. Until it is available, submit information-access requests to the Information Officer at [TBD: Information Officer contact].]

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. Where changes are material, we will post an updated "Last updated" date and, where feasible, provide notice via email or in-app notification. Continued use of the Services after the effective date constitutes acceptance of the updated Policy, to the extent permitted by law. For material changes affecting your rights, we will seek fresh consent where required by POPIA.

16. Related policies