VarsityAlly Market

    Privacy policy

    Version 1.0 · in force from 20 August 2026

    This policy is written to be read, not to be survived. It says what VarsityAlly Market collects, why, who else sees it, how long we keep it, and how you get it back or get rid of it.

    The short version

    • We collect what a marketplace needs to work: who you are, what you ordered, and — only if you allow it — where you are while you are browsing.
    • We never see your full card number. Card payments happen on our payment provider’s own checkout page.
    • We do not sell your personal information, and there are no advertising or tracking SDKs in the app or on this site.
    • You can download everything we hold, correct it, or delete your account yourself, from Account Centre.
    • Financial records outlive a deleted account by seven years because South African law requires it — but they stop being connected to you.

    Who we are

    VarsityAlly Market is a marketplace connecting student and campus-area sellers with the people buying from them. This policy explains what we do with personal information when you use the website or the mobile app, whether you are buying, selling, or just browsing.

    It covers everyone: shoppers, sellers, and the staff members a seller adds to their store team. Where something applies only to sellers, it says so.

    What we collect, and why

    We ask for information at the point we need it, not up front. Optional fields stay optional, and leaving one blank costs you nothing except the feature that depends on it.

    InformationWhat that meansWhy we need it
    Account and identityYour name, email address and mobile number. Your password is stored only as a salted hash — we cannot read it. Date of birth, gender and student number if you choose to add them. If you sign in with Google, the account identifier Google returns.To create and secure your account, sign you in, confirm a contact address is really yours, and reach you about your orders.
    LocationYour device’s approximate or precise coordinates while you are using the app or site, and the campus you pick.To rank stores and products by how near they are and to show honest pickup distances. Sharing coordinates is optional; the campus you select is saved to your profile.
    Orders and collectionWhat you ordered, from whom, the amounts, the status history, collection codes and QR codes, plus any cancellation or problem you report.To place and fulfil the order, let the seller prepare it, prove collection, and settle disputes fairly.
    PaymentsThe method, amount, status and the reference our payment provider returns. Card details are typed on the provider’s own checkout and never reach our systems.To take payment, refund it when that is due, and reconcile what each seller is owed.
    Seller verification and payouts (sellers only)Identity documents, proof of address, proof of bank account, business registration documents, banking details, and commission and settlement records.To verify who we are paying, meet our legal and anti-fraud obligations, and pay sellers what they have earned.
    Device and technicalA push notification token, the app version and build, and a record of each signed-in session including its IP address and a device or browser description.To deliver notifications you asked for, show you every device signed in to your account, and let you end a session you do not recognise.
    What you publishProduct photos, store logo and banner, ratings and reviews, and the messages you send support.To display your listings and reviews, and to answer you.
    Preferences and consentNotification and communication choices, saved and wishlisted items, cart contents, and a consent record noting the date, IP address and the version of this policy in force at the time.To honour your choices, and to be able to show which version of this policy you actually agreed to.

    Location, specifically

    Distance is the whole point of a campus marketplace, so location is the permission we are asked about most.

    It is optional, and the product is built to work without it. Decline, and you pick a campus instead — you still see everything, ranked by that campus rather than by where you are standing.

    We ask for location only while you are using the app. There is no background location permission, so the app cannot follow you around once it is closed. Coordinates rank what you see at the time of the request; we do not build a location history, and coordinates are stored only when you save an address yourself.

    You can withdraw the permission at any time in your device settings, and revoking it does not lock you out of anything.

    Payments

    Card payments are handled by Yoco, a South African payment provider. You are taken to their checkout to enter card details, which means your card number, expiry and CVV never touch our servers or our database.

    What we keep is the outcome: the amount, the status, the method, and the reference Yoco gives us, so an order can be matched to a payment and refunded if needed.

    For a cash or bank-transfer order we record that the order was placed and how it was to be paid, so the buyer and the seller are looking at the same facts.

    Your choices, and what you cannot switch off

    We split consent into four purposes, so agreeing to one does not quietly agree to the rest. Each is recorded separately with the date and the policy version, and the record is append-only — we keep the history rather than overwriting it.

    PurposeWhat it coversCan you withdraw it?
    EssentialRunning your account, processing orders, taking payment, keeping the platform secure, and meeting our legal obligations.No — this is what performing our side of the agreement requires. If you no longer want it, the route is to close the account.
    MarketingPromotional email and notifications about deals, new sellers and features.Yes, at any time.
    PersonalisationUsing your campus, location and activity to order what you see.Yes. You still see everything, just less tailored.
    AnalyticsUnderstanding which parts of the product get used, so we can improve them.Yes.

    There is no third-party analytics or advertising SDK in the app or on this site today. Aggregate, non-identifying counts of what shoppers search for may be recorded to help sellers stock the right things — and that is off by default. If either of those changes, this policy changes first.

    Who else sees it

    We do not sell personal information, and we do not share it with advertising networks or data brokers.

    Sellers see only what fulfilling an order requires: what was ordered, your name, and the collection details. They do not see your other orders, or anything you bought from someone else.

    We use a small number of service providers to run the platform. They act on our instructions and may use the data only to provide their service to us.

    ProviderWhat they do for usWhere they process it
    YocoCard payments and refundsSouth Africa
    Amazon Web ServicesHosting, database and file storageUnited States
    Google Firebase Cloud MessagingDelivering push notificationsUnited States
    BrevoTransactional email — confirmations, receipts, verification codesEuropean Union
    WinSMSSMS verification codesSouth Africa
    Google Maps PlatformAddress search, geocoding and map display. Requests are proxied through our own server rather than made from your device.United States
    Google Sign-InOptional sign-in with your Google accountUnited States

    We may also disclose information where the law requires it — a lawful request from an authority, or to establish or defend a legal claim. We will not hand over more than the request actually calls for.

    Information leaving South Africa

    Our servers and file storage are in the United States, and some providers above process data in the United States or the European Union. Using VarsityAlly Market therefore involves your information being transferred outside South Africa.

    Where that happens we rely on the contractual commitments those providers make, and everything moves over encrypted connections. If you would rather your information were not processed abroad, we cannot offer the service on those terms — the honest answer is that the platform cannot run without it.

    How long we keep it

    Two rules pull against each other here: personal information should not be kept longer than it is needed, and financial records must be kept for seven years. We resolve that by keeping the record and letting go of the person.

    InformationKept for
    Name, contact details, profile, addresses, preferencesUntil you delete your account
    Cart, wishlist, search history, notifications, consent recordsUntil you delete your account
    Orders, payments, settlements and commission recordsSeven years from the transaction, as South African law requires — anonymised when you delete your account
    Audit and activity logsSeven years, with you pseudonymised when you delete your account
    Seller verification documentsUntil the account closes, plus the statutory period. The files are then erased; a record that a document existed and was checked remains.
    Reviews and ratingsKept, with the author anonymised — a review is about the product, not the person
    Push tokens and sessionsUntil they expire, you sign out, or you remove the device

    Your rights, and where to exercise them

    Under POPIA you can ask what we hold, have it corrected, and have it deleted. We would rather you did not have to ask: each of these is a screen you can use yourself, without emailing anyone or waiting on us.

    What you want to doWhere
    Download everything we hold, as JSON and CSV/account/data
    Correct your name, contact details or profile/account/personal
    Change your marketing, personalisation and analytics consent/account/privacy
    Change which notifications reach you, and how/account/communication
    See where you are signed in, and end a session/account/security
    Review your account activity history/account/data
    Deactivate your account temporarily/account/data
    Delete your account permanently/account/data

    If you cannot sign in — or you would simply rather ask a person — email us and we will handle it. We may need to verify who you are first, because acting on an unverified deletion request would be its own kind of breach.

    Deleting your account

    Sign in and go to Account Centre → Your data → Delete account. If you cannot sign in, email us from the address on the account and we will verify you another way.

    Because deletion is irreversible we ask you to confirm it deliberately: you prove it is you, we email a confirmation, and you type the confirmation phrase. Some things have to be settled first — an order still in flight, or money owed in either direction — and the wizard tells you exactly what is blocking it and what to do, rather than silently queueing a request that will never complete.

    You then have thirty days in which signing back in cancels the deletion. Once that passes, the account is anonymised: your name, contact details, addresses, documents, saved items, preferences and device records are erased, and the transaction records that must survive stop pointing at you.

    Deactivation is the gentler option in the same place — it hides your account and stops the notifications without destroying anything.

    How we protect it

    • Everything travels over encrypted connections (HTTPS/TLS). The mobile app can additionally pin our server certificate.
    • Passwords are stored as salted hashes, never in a readable form. Changing your password ends every other session.
    • Seller verification documents go to private storage that is never publicly reachable, and access to them is logged.
    • Sign-in, verification and deletion endpoints are rate limited, and a reused refresh token is treated as a compromised session.
    • Staff access follows the permissions a seller sets for their store team, so a cashier does not silently gain a manager’s view.

    No system is perfectly secure. If we ever suffer a breach that puts your information at real risk, we will notify you and the Information Regulator as POPIA requires — not quietly absorb it.

    Children

    VarsityAlly Market is built for university communities and intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will remove it.

    Changes to this policy

    When this policy changes we publish the new version here with a new version number and date. Where a change is material we will tell you in the app or by email rather than relying on you to re-read the page.

    Your consent records are versioned against the policy text in force when you gave them, so it is always possible to establish what you actually agreed to.

    Contact us, or complain

    For anything in this policy — a question, a correction, a request, or a complaint — email us and a person will answer.

    If you are not satisfied with how we have handled it, you are entitled to complain to the Information Regulator (South Africa), the authority that oversees POPIA. Doing so needs no permission from us and does not affect your account.