Back to legal hub

POPIA Compliance Notice

Last updated: 6 June 2026 · Applies to Fletcha Eats, operating in South Africa.

This notice explains how Fletcha Eats complies with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) — POPIA — and the rights you have as a data subject in South Africa. It works together with our Privacy Policy.

1. Who is the responsible party?

Fletcha Eats is the "responsible party" for personal information you submit through the app. You can contact our Information Officer at fletchalink.admin@gmail.com.

2. Your privacy rights

  • Right to be informed — what we collect and why (see Privacy Policy).
  • Right of access — request a copy of the personal information we hold about you.
  • Right to correction — ask us to fix anything that is wrong, outdated or incomplete.
  • Right to deletion — ask us to delete your personal information, subject to legal retention rules.
  • Right to object — object to processing that is not strictly necessary.
  • Right to withdraw consent — for processing that is based on your consent (e.g. push notifications, marketing).
  • Right to lodge a complaint — with the Information Regulator (South Africa) at inforegulator.org.za.

3. How we process information lawfully

We process personal information only when one of these legal grounds applies:

  • You have given consent (e.g. enabling location, opting into notifications).
  • Processing is necessary to perform a contract with you (e.g. delivering an order, paying a driver).
  • Processing complies with a legal obligation (e.g. tax records).
  • Processing protects a legitimate interest (e.g. preventing fraud, securing the platform), balanced against your rights.

4. How we protect information

  • Encryption in transit (TLS) for all app traffic.
  • Row-level security on every database table — users only see their own data unless explicitly allowed.
  • Passwords are hashed; verification documents and proofs live in access-controlled storage.
  • Administrator access is logged.
  • Regular reviews of security policies and an internal incident-response process.

5. Sharing of information

  • We share data with order participants (customer ↔ driver ↔ business) only as needed to complete the delivery.
  • We may share data with service providers (hosting, push-notification provider, payment processors) under strict confidentiality.
  • We may share data with law enforcement when legally required.
  • We do not sell personal information.

6. Categories of personal information we process

  • Identity & contact — full name, phone number, email, profile picture.
  • Location — delivery addresses and (during an active delivery) live GPS coordinates.
  • Transactional — order history, payment references, receipts, delivery codes.
  • Driver & business onboarding — vehicle details, ID / licence documents, bank details for payouts.
  • Device & usage — device identifiers, browser type, push-notification tokens, app diagnostics.

7. How long we keep information (retention)

  • Account & order records: kept while your account is active, then archived for up to 5 years to comply with tax and financial-record rules.
  • Live GPS points: retained for 90 days for dispute resolution, then aggregated or deleted.
  • Chat and support messages: 24 months, then deleted unless part of an open dispute.
  • Driver / business verification documents: kept for the life of the account plus 3 years after deletion.
  • Push-notification device tokens: removed automatically when they become invalid or when you sign out.

8. Cross-border transfers

Our hosting and push-notification providers may store data on servers outside South Africa. Where this happens we ensure equivalent protections to those required by POPIA through contractual safeguards with each processor.

9. Children

Fletcha Eats is not intended for children under 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will delete it.

10. Automated decision-making

We use automated systems to match orders with drivers, calculate delivery fees, and detect fraud (e.g. suspicious cancellation patterns). You have the right to request human review of any decision that significantly affects you — email us with the subject POPIA — automated decision review.

11. Security incidents

If a security compromise occurs that is likely to affect your personal information, we will notify the Information Regulator and affected users as soon as reasonably possible, in line with section 22 of POPIA.

12. PAIA — access to information

Requests for records under the Promotion of Access to Information Act, 2000 (PAIA) can be sent to the same Information Officer address below. We publish a PAIA manual on request.

13. Submitting access, correction or deletion requests

  1. Email fletchalink.admin@gmail.com from the email on your account.
  2. Subject: POPIA request — Access or POPIA request — Correction or POPIA request — Deletion.
  3. Describe what you want and attach proof of identity.
  4. We respond within 30 days. There is no charge for reasonable requests.

14. Information Officer

Information Officer, Fletcha Eats — fletchalink.admin@gmail.com. Complaints: Information Regulator (South Africa), inforegulator.org.za.

Last reviewed: July 2026.


Questions? Contact us via the in-app Support page or email fletchalink.admin@gmail.com.