Saadjie Privacy Notice — version v1
Effective from: 2026-05-25
This Privacy Notice tells you what personal information Saadjie collects about you, why we collect it, how long we keep it, and what rights you have over it. Reading this notice is part of agreeing to our Terms & Conditions: by ticking "I agree" at sign-up you confirm that you have read this notice and understand what we do with your data.
This notice is a plain-language summary of our POPIA (Protection of Personal Information Act, 2013 — South Africa) obligations. The full POPIA Notice is published separately at /legal/popia and lists each obligation against the section of the Act that creates it.
1. Who is the responsible party
Saadjie is the responsible party (the term POPIA uses for what GDPR calls the "data controller") for the personal information described in this notice. Our payment partner Eclipse (operated by EFT Corp (Pty) Ltd) is a separate responsible party for the card-payment data it captures on its own hosted checkout page.
You can reach the Saadjie privacy team at privacy@saadjie.com.
2. What we collect and why
We collect three categories of personal information from a Parent:
- Account data — your name, email address, and the bcrypt-hashed
form of your password. We use this to authenticate you, to email you receipts and notifications, and to honour your right of access.
- Child page data — the first name (or display name) of each child
you add, their age or date of birth, an optional welcome message, and the photos you upload (one primary avatar plus up to ten carousel photos). We use this to render the public contribution page and the thank-you / milestone surfaces.
- Contributor data — the name (or "Anonymous" choice), email address,
optional message, and contribution amount supplied by each Contributor who supports one of your children. We use this to render the public feed, to email a receipt to the Contributor and a notification to you, and (if you opt in per-milestone) to fan out milestone updates to past Contributors.
We also collect the following operational metadata:
- Acceptance audit trail — every time you (or a Contributor) accept
our Terms & Conditions, we store the version you accepted, the timestamp, your IP address, and your browser's User-Agent string. This is the legal evidence of your consent.
- Visitor analytics — we count how many people visit each page each
day using a one-way SHA-256 hash of (your IP address, your browser User-Agent, the day's date, and a daily-rotated salt). We cannot recover any of those inputs from the hash. The hash itself is deleted after 90 days. We do not use Google Analytics, Facebook Pixel, Segment, or any other third-party tracker.
- Onboarding progress — if you start the parent onboarding wizard
and pause partway, we remember where you left off so you can resume on your next visit.
3. What we do NOT collect
- We do not collect your card number. The card details you enter at
the contribution checkout are captured by Eclipse (EFT Corp) on their hosted page; we only ever see the masked metadata (BIN, last 4 digits, authorisation reference, settlement reference).
- We do not sell your information to any third party.
- We do not run any third-party analytics or advertising trackers.
- We do not require you to install a mobile app or accept any cookie
beyond the strictly necessary session cookie that keeps you signed in to the dashboard.
4. How long we keep it
- Active account data — for as long as your account exists.
- Closed-account data — within 30 days of you closing your account
(or asking us to delete it), every personal-data column in the database is scrubbed: child names become "[deleted]", contributor names are blanked, contributor emails are nulled, thank-you and milestone text is removed, carousel photos are deleted from disk.
- Audit-trail records — limited financial-audit metadata (amount,
status, timestamp, payment-processor reference) survives the scrub. POPIA's right of erasure has a carve-out for legal-retention obligations; tax and chargeback investigation windows are the reason. The retained columns carry no personal identifiers.
- Visitor analytics hashes — 90 days, then deleted.
5. Your rights under POPIA
You can at any time:
- Ask us to show you the personal information we hold about you
(POPIA s.23 — right of access). The self-serve export under your dashboard packages every row tied to your account into a single ZIP file.
- Ask us to correct information that is wrong (POPIA s.24(1)(a)).
- Ask us to delete your information (POPIA s.24(1)(b) — right of
erasure). The right of erasure is subject to the legal-retention carve-out described in section 4 above.
- Object to any processing you did not consent to (POPIA s.11(3)) and
withdraw a consent you previously gave (POPIA s.11(2)(b)).
- Complain to the Information Regulator
(inforegulator.org.za) if you believe we have mishandled your information.
To exercise any of these rights, email privacy@saadjie.com and we will respond within the timelines POPIA sets (currently 30 calendar days for an access or erasure request).
6. How we protect your information
- Every page is served over HTTPS with a TLS certificate issued by
Let's Encrypt and renewed automatically before it expires.
- Passwords are hashed with bcrypt at cost factor 14; the plain-text
password is never written to disk or any log.
- Photos are re-encoded to WebP on upload and stripped of EXIF
metadata (including any GPS coordinates a camera may have embedded).
- The database, the application server, and the photo store are
hosted on AWS infrastructure inside the eu-west-1 region.
7. Changes to this notice
We may update this notice from time to time. When we do, we will publish a new version under a higher version number and ask you to re-accept it the next time you sign in. The current version is v1, effective from the date at the top of this page.
8. Contact
Questions about this Privacy Notice, or any of the rights described above, should go to privacy@saadjie.com.