Privacy policy
Version 1.0 · in force from 20 August 2026
This policy is written to be read, not to be survived. It says what VarsityAlly Market collects, why, who else sees it, how long we keep it, and how you get it back or get rid of it.
The short version
- We collect what a marketplace needs to work: who you are, what you ordered, and — only if you allow it — where you are while you are browsing.
- We never see your full card number. Card payments happen on our payment provider’s own checkout page.
- We do not sell your personal information, and there are no advertising or tracking SDKs in the app or on this site.
- You can download everything we hold, correct it, or delete your account yourself, from Account Centre.
- Financial records outlive a deleted account by seven years because South African law requires it — but they stop being connected to you.
Who we are
VarsityAlly Market is a marketplace connecting student and campus-area sellers with the people buying from them. This policy explains what we do with personal information when you use the website or the mobile app, whether you are buying, selling, or just browsing.
It covers everyone: shoppers, sellers, and the staff members a seller adds to their store team. Where something applies only to sellers, it says so.
What we collect, and why
We ask for information at the point we need it, not up front. Optional fields stay optional, and leaving one blank costs you nothing except the feature that depends on it.
| Information | What that means | Why we need it |
|---|---|---|
| Account and identity | Your name, email address and mobile number. Your password is stored only as a salted hash — we cannot read it. Date of birth, gender and student number if you choose to add them. If you sign in with Google, the account identifier Google returns. | To create and secure your account, sign you in, confirm a contact address is really yours, and reach you about your orders. |
| Location | Your device’s approximate or precise coordinates while you are using the app or site, and the campus you pick. | To rank stores and products by how near they are and to show honest pickup distances. Sharing coordinates is optional; the campus you select is saved to your profile. |
| Orders and collection | What you ordered, from whom, the amounts, the status history, collection codes and QR codes, plus any cancellation or problem you report. | To place and fulfil the order, let the seller prepare it, prove collection, and settle disputes fairly. |
| Payments | The method, amount, status and the reference our payment provider returns. Card details are typed on the provider’s own checkout and never reach our systems. | To take payment, refund it when that is due, and reconcile what each seller is owed. |
| Seller verification and payouts (sellers only) | Identity documents, proof of address, proof of bank account, business registration documents, banking details, and commission and settlement records. | To verify who we are paying, meet our legal and anti-fraud obligations, and pay sellers what they have earned. |
| Device and technical | A push notification token, the app version and build, and a record of each signed-in session including its IP address and a device or browser description. | To deliver notifications you asked for, show you every device signed in to your account, and let you end a session you do not recognise. |
| What you publish | Product photos, store logo and banner, ratings and reviews, and the messages you send support. | To display your listings and reviews, and to answer you. |
| Preferences and consent | Notification and communication choices, saved and wishlisted items, cart contents, and a consent record noting the date, IP address and the version of this policy in force at the time. | To honour your choices, and to be able to show which version of this policy you actually agreed to. |
Location, specifically
Distance is the whole point of a campus marketplace, so location is the permission we are asked about most.
It is optional, and the product is built to work without it. Decline, and you pick a campus instead — you still see everything, ranked by that campus rather than by where you are standing.
We ask for location only while you are using the app. There is no background location permission, so the app cannot follow you around once it is closed. Coordinates rank what you see at the time of the request; we do not build a location history, and coordinates are stored only when you save an address yourself.
You can withdraw the permission at any time in your device settings, and revoking it does not lock you out of anything.
Payments
Card payments are handled by Yoco, a South African payment provider. You are taken to their checkout to enter card details, which means your card number, expiry and CVV never touch our servers or our database.
What we keep is the outcome: the amount, the status, the method, and the reference Yoco gives us, so an order can be matched to a payment and refunded if needed.
For a cash or bank-transfer order we record that the order was placed and how it was to be paid, so the buyer and the seller are looking at the same facts.
Your choices, and what you cannot switch off
We split consent into four purposes, so agreeing to one does not quietly agree to the rest. Each is recorded separately with the date and the policy version, and the record is append-only — we keep the history rather than overwriting it.
| Purpose | What it covers | Can you withdraw it? |
|---|---|---|
| Essential | Running your account, processing orders, taking payment, keeping the platform secure, and meeting our legal obligations. | No — this is what performing our side of the agreement requires. If you no longer want it, the route is to close the account. |
| Marketing | Promotional email and notifications about deals, new sellers and features. | Yes, at any time. |
| Personalisation | Using your campus, location and activity to order what you see. | Yes. You still see everything, just less tailored. |
| Analytics | Understanding which parts of the product get used, so we can improve them. | Yes. |
There is no third-party analytics or advertising SDK in the app or on this site today. Aggregate, non-identifying counts of what shoppers search for may be recorded to help sellers stock the right things — and that is off by default. If either of those changes, this policy changes first.
Information leaving South Africa
Our servers and file storage are in the United States, and some providers above process data in the United States or the European Union. Using VarsityAlly Market therefore involves your information being transferred outside South Africa.
Where that happens we rely on the contractual commitments those providers make, and everything moves over encrypted connections. If you would rather your information were not processed abroad, we cannot offer the service on those terms — the honest answer is that the platform cannot run without it.
How long we keep it
Two rules pull against each other here: personal information should not be kept longer than it is needed, and financial records must be kept for seven years. We resolve that by keeping the record and letting go of the person.
| Information | Kept for |
|---|---|
| Name, contact details, profile, addresses, preferences | Until you delete your account |
| Cart, wishlist, search history, notifications, consent records | Until you delete your account |
| Orders, payments, settlements and commission records | Seven years from the transaction, as South African law requires — anonymised when you delete your account |
| Audit and activity logs | Seven years, with you pseudonymised when you delete your account |
| Seller verification documents | Until the account closes, plus the statutory period. The files are then erased; a record that a document existed and was checked remains. |
| Reviews and ratings | Kept, with the author anonymised — a review is about the product, not the person |
| Push tokens and sessions | Until they expire, you sign out, or you remove the device |
Your rights, and where to exercise them
Under POPIA you can ask what we hold, have it corrected, and have it deleted. We would rather you did not have to ask: each of these is a screen you can use yourself, without emailing anyone or waiting on us.
| What you want to do | Where |
|---|---|
| Download everything we hold, as JSON and CSV | /account/data |
| Correct your name, contact details or profile | /account/personal |
| Change your marketing, personalisation and analytics consent | /account/privacy |
| Change which notifications reach you, and how | /account/communication |
| See where you are signed in, and end a session | /account/security |
| Review your account activity history | /account/data |
| Deactivate your account temporarily | /account/data |
| Delete your account permanently | /account/data |
If you cannot sign in — or you would simply rather ask a person — email us and we will handle it. We may need to verify who you are first, because acting on an unverified deletion request would be its own kind of breach.
Deleting your account
Sign in and go to Account Centre → Your data → Delete account. If you cannot sign in, email us from the address on the account and we will verify you another way.
Because deletion is irreversible we ask you to confirm it deliberately: you prove it is you, we email a confirmation, and you type the confirmation phrase. Some things have to be settled first — an order still in flight, or money owed in either direction — and the wizard tells you exactly what is blocking it and what to do, rather than silently queueing a request that will never complete.
You then have thirty days in which signing back in cancels the deletion. Once that passes, the account is anonymised: your name, contact details, addresses, documents, saved items, preferences and device records are erased, and the transaction records that must survive stop pointing at you.
Deactivation is the gentler option in the same place — it hides your account and stops the notifications without destroying anything.
How we protect it
- Everything travels over encrypted connections (HTTPS/TLS). The mobile app can additionally pin our server certificate.
- Passwords are stored as salted hashes, never in a readable form. Changing your password ends every other session.
- Seller verification documents go to private storage that is never publicly reachable, and access to them is logged.
- Sign-in, verification and deletion endpoints are rate limited, and a reused refresh token is treated as a compromised session.
- Staff access follows the permissions a seller sets for their store team, so a cashier does not silently gain a manager’s view.
No system is perfectly secure. If we ever suffer a breach that puts your information at real risk, we will notify you and the Information Regulator as POPIA requires — not quietly absorb it.
Children
VarsityAlly Market is built for university communities and intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will remove it.
Changes to this policy
When this policy changes we publish the new version here with a new version number and date. Where a change is material we will tell you in the app or by email rather than relying on you to re-read the page.
Your consent records are versioned against the policy text in force when you gave them, so it is always possible to establish what you actually agreed to.
Contact us, or complain
For anything in this policy — a question, a correction, a request, or a complaint — email us and a person will answer.
If you are not satisfied with how we have handled it, you are entitled to complain to the Information Regulator (South Africa), the authority that oversees POPIA. Doing so needs no permission from us and does not affect your account.