Legal

Privacy Policy

Last updated: 10 September 2026

This Privacy Policy explains how McSbuSing (Pty) Ltd ("Informativ", "we", "us"), as responsible party, collects and processes personal information on the Informativ platform, in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Information We Collect

We collect the following categories of personal information:

  • Account and identity details — name, surname, known-as name, username, email address, date of birth, gender, and where required for verification, identity document type and number.
  • Contact details — email, phone number(s), WhatsApp number, social media handles, and an optional physical address (used, among other things, to show you item providers near you).
  • Saved delivery addresses — optional addresses you save to your profile (label, street address, city, province, postal code, country, and a contact phone number) to reuse at merchandise checkout, to prefill a venue address when creating an event, and to book a provider call-out appointment at your address.
  • Partner selling location — if you enable the Partner feature, whether you sell as a mobile seller or from a fixed shop, and if the latter, that shop's physical address (street address, city, province, postal code, country).
  • Business details — company name, registration number, VAT registration status, and VAT number for providers and business leads. Your VAT status at the time of a sale is recorded on the resulting order and invoice.
  • Financial details — banking details you provide for payouts, your platform account balances, and transaction records. Your bank account number, branch code, and SWIFT code are encrypted at rest and only ever decrypted to process or display your own payout details. If an event you paid for is cancelled and you request a refund, we similarly store the banking details you submit for that refund (account holder name, bank, account number, and branch code — encrypted at rest the same way) — these are shared only with the event's organizer, who pays you directly and uploads proof of payment for you to confirm. See "Refunds on Event Cancellation" in our Terms of Service. Card details are captured and processed by our payment gateway; we never see or store your full card number. If you choose to save your card for future payments at checkout, our payment gateway (PayFast) tokenizes it and we store only that token (encrypted at rest) plus the card's brand and last 4 digits for display — never a full card number, expiry, or CVV. You can view and remove saved cards at any time from Dashboard → Profile → Payment Methods. A PDF invoice or receipt is generated for a paid order or booking (your name, contact details, and order/booking details) and emailed to you; you can also download it again later from the order's page on the dashboard.
  • Transaction and listing data — events, tickets, bookings, rentals, equipment listings, vendor stall bookings, policies, reviews and ratings, and related communications. For artist bookings this includes booking requests, quotes (fees, deposit terms, and payment deadlines), acceptance or rejection reasons, agreements, and payment and refund records.
  • Artist profile content — stage name, bio, artist types, profile and background images, portfolio and media links, awards and achievements you choose to add (title, awarding organization, year, and an optional short description), your booking agreement, any SAMRO, CAPASSO, SAMPRA, or RISA reference/membership numbers you choose to add, and collaboration (split sheet) records including revenue split percentages. When you electronically sign a split sheet, we record your account's full name and the IP address you signed from, alongside a timestamp — the same way an artist booking contract's signatures are recorded. If you and your collaborators confirm the completed split sheet was submitted to SAMRO and/or CAPASSO, we record who confirmed it and when.
  • Vendor profile content — your vendor type(s) (Food & Beverage, Merchandise & Crafts, Commercial Exhibitors, or Activity Provider) and, where Food & Beverage applies, your uploaded Certificate of Acceptability document, submitted for our review.
  • Merchandise store content — product listings, variants, prices, stock, images, shipping options (including any Courier Guy/Fastway collection address, Delivery by Distance location and price bands, or PAXI settings you configure), orders, and reviews, for artist and vendor stores alike.
  • Requested order details — if a merchandise seller asks you for a specific detail after purchase (for example a name or a reference photo/file), we store the text or file you submit in response. This is shared only with the seller who requested it and is retained per section 6 below.
  • Seller News & Updates — if you post a News & Update as an artist or vendor, we store the title, body, and optional image, and display it publicly on your profile or store page while published.
  • Page Design — if you customize your public page as an artist or vendor (Dashboard → Page Design), we store your chosen colors and any background/hero images you upload, and display them publicly on your profile or store page.
  • Fan Letters — if you write a private letter to an artist (or an artist replies), we store the message content, both participants' identities, timestamps, and its status (Draft, Sent, Opened, or Rejected). A draft is stored as soon as you start saving one, but is never visible to the artist or delivered in any way until you choose to send it. A fan letter is never shown publicly and is never visible to anyone other than the two participants — not even a delegated team member managing the artist's account. If an artist blocks a sender, we record that block to prevent further letters from them.
  • Team/staff invitations — if an account holder invites you as staff to help manage their events, venues, equipment, bookings, or fleet, we store the email address (and optional name) they invited, and which permissions were granted, until the invite is accepted, declined, or revoked. Once you accept, you can see and manage the parts of that account you were granted access to, within the scope of those permissions.
  • Verification documents — for example proof of venue ownership, or a fleet vehicle's license disc and proof of ownership.
  • QR table orders — when you order via a venue's table QR code, no account or login is required. We store the order itself (items, quantities, and price at the time of order), an optional name and order notes if you choose to provide them, and whether you self-certified being of legal drinking age for an alcoholic item. These orders are not paid through the platform — you settle up with the venue directly — so no payment data is collected for them.
  • Images — profile pictures, background images, event posters, and equipment photos.
  • Rental delivery/collection evidence — if you rent equipment through the platform, photos and voice-note recordings you or the lessor submit when confirming a delivery/collection or reporting equipment damage, kept against that booking as a record of what was reported.
  • Fleet and delivery data — if you run a fleet, your business name, vehicles (type, make, model, plate number, load capacity, license-disc expiry), cancellation policy settings (refundable flag, waiting period hours, cancellation fee percentage, policy text), and submitted verification documents. For each delivery request: pickup and dropoff addresses (plus any extra stops), item description and weight, extra-hands and coming-along flags, timing, fee, verification status, the assigned vehicle and driver, trip mileage and fuel readings, and fuel purchase amounts with receipt photos — kept against that delivery as its record. If you drive for a fleet, your driver license number, license document photo, and license expiry date — kept against your account and used for renewal reminders.
  • Points/standing records — for each role you hold, a points balance and a history of the events that changed it (for example a cancellation, a no-show, a late response, equipment damage, or a review outcome), plus whether a role is currently suspended. See "Points & Account Standing" in our Terms of Service.
  • Technical data — login records, session cookies, and basic usage information needed to run and secure the platform.
  • Push notification token — if you use our mobile app, or enable browser notifications on the website, we store a Firebase Cloud Messaging token for your device once you sign in, so we can send you push notifications (for example ticket, booking, and event updates). The token is removed when you sign out (mobile app) or turn notifications off (browser), and is only ever paired with whichever account is signed in on that device.
  • Device and approximate location — each time you sign in, we identify the browser or app used (a "device"). The first time a genuinely new device signs in, we resolve its approximate location from its IP address via a third-party geolocation lookup, and store the device, location, and sign-in time so we can alert you (by notification and email) to a sign-in you don't recognise. We do not re-look-up location on later sign-ins from an already-known device.
  • Precise device location (mobile app, opt-in only) — if you turn on "Automatic Arrival Check-In" in the mobile app (More → Automatic Arrival Check-In), we use your device's GPS location, while the app is open or recently in the background, to tell whether you've arrived at or left a service booking you've confirmed with a provider that day, so you can be checked in and out automatically instead of the provider having to guess or you having to open the app and tap a button. This is off by default, only ever looks at your own confirmed bookings for the current day, and location tracking stops immediately if you turn the setting back off. We do not store a history of your movements — only whether you've arrived at or left each specific booking's location.
  • Precise device location (mobile app, weather chip) — the Home dashboard's weather chip asks for a single, one-off GPS location reading (not a continuous or background one) so the forecast reflects where you actually are; that coordinate is sent to Open-Meteo to look up current conditions and used on-device to work out a nearby town/city name, then discarded — we don't store it, and if location access isn't available or is denied, the app falls back to the coarser IP-based location described below instead.
  • Bot-protection signals — when you log in, register, reset your password, or submit the demo-request form, Google reCAPTCHA analyses your device and interaction behaviour to produce a bot/human risk score. We only receive that score (and whether it passed our threshold), not your browsing history. See "Google reCAPTCHA" under section 3.

2. How We Use It

  • To create and manage your account, roles, and profile.
  • To operate the marketplace: publishing listings, processing ticket sales, bookings, rentals and deliveries, allocating equipment and vehicles, and managing returns, damage, and late-return charges.
  • To process payments, calculate platform commission, manage provider balances, and make and record payouts (including proof of payment).
  • To run the artist booking process: delivering booking requests and quotes between organizers and artists, enforcing response and payment deadlines, processing deposit and balance payments, and processing deposit refunds where the quoted refund terms allow.
  • To add VAT to your prices at checkout and include your VAT number on invoices where you are VAT registered.
  • To verify identity and ownership where the platform requires it (for example venue owners, or a vendor's Certificate of Acceptability).
  • To recognise the devices that sign into your account and alert you by notification and email when we see one we don't recognise, so you can catch a sign-in that wasn't you.
  • If you turn on Automatic Arrival Check-In in the mobile app, to automatically check you in and out of your own confirmed service bookings and notify the provider, without you needing to open the app.
  • To display provider information to customers — for example your username, company name, ratings, and policies on your listings.
  • To show you relevant content, such as item providers near your provided address.
  • To send you service communications: booking confirmations, payment results, meeting invitations, and important account or policy updates.
  • To manage business leads you submit to us or that our team captures when you enquire about our services, including sending relevant updates or promotional messages about our services by email or WhatsApp — you may ask us to stop these at any time (see "Your Rights" below). Draft wording for these messages, and suggested replies for our staff, may be generated by an automated tool (including an AI model) — see "Abacus.ai" under "Who We Share It With" below for how this is processed — but every message is reviewed by a staff member before it is sent; nothing is sent automatically without that review. If our staff upload a photo of a business card, contact form, or event poster to speed up capturing a new lead, that image is processed the same way to read out the contact details on it and to note any event/service equipment (for example chairs, staging, or lighting) actually shown in the image, so the matching service category can be suggested on the lead — and the image itself is discarded immediately after — it is never stored.
  • To help you write listing content — venue, event, product, and equipment descriptions, artist and provider profile bios, policy text, help articles, and similar long-form fields across the dashboard, including internal records such as CRM notes about a lead — an "Improve with AI" option can fix grammar or draft a first version from a short brief you type. This is processed the same way as the lead-messaging tool above (see "Abacus.ai" under "Who We Share It With" below); nothing is saved until you review the result and submit the form yourself.
  • To keep the platform secure, prevent fraud, and comply with legal obligations (including tax and financial record-keeping).
  • To maintain each role's points/standing balance, so that unreliable conduct (cancellations, no-shows, late responses, equipment damage/loss, poor reviews) can be tracked and, where a role's points reach zero, that role temporarily suspended.

We process personal information on the lawful bases of performing our contract with you, compliance with legal obligations, our legitimate interests in running a safe marketplace, and your consent where POPIA requires it.

3. Who We Share It With

  • Other users, as needed for a transaction — for example a renter sees a lessor's public profile and policies; a lessor sees the renter's name, contact details, and delivery address for a booking; a service provider sees your call-out address when you book an appointment at your own location instead of theirs.
  • My QR Code — your name and contact details (email, phone, WhatsApp) are shown to whoever scans your personal QR code (Dashboard/App → My QR Code), used to identify you for a Direct Sale purchase or to receive a transferred event ticket. The code itself carries no data — scanning it looks your details up fresh each time — so you can invalidate it at any point (a "Regenerate QR Code" button on the same screen) if you've shown it to someone by mistake or a screenshot of it has leaked.
  • Abacus.ai — the AI model behind our "Improve with AI" content tool and our marketing team's lead-communication drafting/suggested-reply tool (including business-card photos staff upload to speed up capturing a new lead) runs on Abacus.ai, a third-party AI service. Nothing from either tool is saved, sent to a lead, or published until a staff member (or, for "Improve with AI", you) reviews it; a business-card photo is discarded immediately after processing and is never stored. This use is subject to Abacus.ai's own Privacy Policy and Terms of Service. Our accounting team's ledger-discrepancy review uses a separate AI model that runs on our own infrastructure and is never sent to Abacus.ai or any other third-party AI service.
  • Payment gateways (Yoco, PayFast) — to process card payments and refunds. PayFast is used specifically when you choose to save your card for future payments; it tokenizes your card so we never handle your full card details.
  • Courier Guy — where a seller offers Courier Guy delivery, your delivery address and order details (weight/dimensions of what you bought) are sent to Courier Guy to get a live delivery quote at checkout.
  • Fastway — where a seller offers Fastway delivery, your delivery address (suburb and postal code) and order details (weight/dimensions of what you bought) are sent to Fastway to get a live delivery quote at checkout.
  • Delivery by Distance — where a seller offers this option, your delivery address is sent to Google's Distance Matrix API to calculate the driving distance from the seller's location, used to work out your live delivery price. The same lookup is also used to price a distance-based equipment rental transport fee, where a lessor has set one up.
  • PAXI (Pep stores) — where you choose PAXI delivery, your order weight and, for Store-to-Store collection, your nearest PEP store, receiver name, and contact number are used to arrange your parcel and send a collection PIN.
  • IP geolocation lookup (ipwho.is) — the first time a new device signs into your account, its IP address is sent to this third-party service to resolve an approximate location for the new-device alert described above. No other browsing data is shared with it.
  • Weather and quotes on the mobile app's Home screen (Open-Meteo, ipwho.is, ZenQuotes) — the mobile app's Home dashboard sends your location to Open-Meteo to show current weather: your device's actual GPS coordinates if you grant location access (see "Precise device location (mobile app, weather chip)" above), or, if not, an approximate location resolved from your device's current IP address via ipwho.is instead; separately, it fetches a batch of quotations from ZenQuotes to rotate through on the same screen. These calls happen directly from your device, not through our servers, and no account or profile information is included in them.
  • Google — if you sign in with Google, or where our team schedules meetings with you via Google Calendar/Meet (your email is used to invite you).
  • Google reCAPTCHA — our login, registration, forgot-password, and demo-request forms are protected by Google reCAPTCHA, which processes device and interaction signals to tell human visitors from bots. This use is subject to Google's own Privacy Policy and Terms of Service.
  • WhatsApp (Meta) — where you interact with the platform through WhatsApp, those messages are processed by Meta under their terms.
  • Service providers — hosting and infrastructure providers who process data on our behalf under appropriate safeguards.
  • Authorities — where the law requires it or to protect rights, safety, or property.

We do not sell your personal information.

4. What Is Public

Your public profile as a provider (username, profile image, company name where applicable, listings, ratings, and published policies) is visible to anyone browsing the platform. If you make your artist profile public, your stage name, bio, artist types, photos, portfolio links, awards and achievements, completed-show count, and upcoming performances at published events are also publicly visible; you can switch the profile back to private at any time. Your legal name, contact details, addresses, identity numbers, VAT number (other than on invoices issued for your sales), SAMRO/ CAPASSO/SAMPRA/RISA reference numbers, and banking details are not shown publicly — your rights organisation reference numbers are only ever shown to your collaborators, on the split sheets you appear on.

A vendor's merchandise store has no equivalent private/public toggle — once you have published products, your store (name, products, and reviews) is visible to anyone browsing the platform. Your Certificate of Acceptability document, contact details, and banking details are never shown publicly.

When you leave a review after a completed purchase or booking, your display name and any comment you write are shown publicly on that listing or provider's page alongside your star rating — this applies even if your own profile is otherwise private.

Your points/standing balance and history, for every role, are private — visible only to you from Dashboard → Profile → Standing. They are never shown on your public profile or listings.

The Partner role has no public profile or storefront — your selling location, banking details, and sales history are never shown publicly.

A fleet provider's business name, address (if given), and number of verified vehicles are visible to anyone browsing delivery providers. Individual vehicle details (plate numbers, documents), trip readings, and fuel receipts are never shown publicly.

5. Security

We take reasonable, appropriate technical and organisational measures to protect personal information, including encrypted storage of sensitive tokens, hashed passwords, access controls on administrative functions, and encrypted connections (HTTPS). No system is perfectly secure; if a breach affecting your information occurs, we will notify you and the Information Regulator as POPIA requires.

If you enable optional two-factor authentication, your authenticator secret and one-time recovery codes are stored encrypted and are never shown again after setup (recovery codes are shown once, at the time they're generated). Root, Sire, Manager, and Admin accounts are required to have two-factor authentication enabled to access administrative functions.

6. Retention

We keep personal information for as long as your account is active and thereafter only as long as needed for the purposes above — in particular financial and transaction records, which we retain for the periods required by South African tax and company law. Deleted records are first deactivated (soft-deleted) before being purged in the ordinary course.

Payment amounts, gateway references, and transaction statuses are additionally kept in an internal, append-only accounting ledger used to verify that every payment, refund, and payout was processed and recorded correctly. Unlike other records, ledger entries are never edited or deleted, even if the underlying order is — this is what makes the ledger useful as an audit trail. It holds no more personal information than the transaction record it mirrors.

Discrepancies in that ledger (for example, a payment that doesn't match what a payment gateway reports) may be reviewed by an automated process, including an AI model, that summarises what it finds for our staff to act on. That process runs on our own infrastructure — your information is never sent to a third-party AI service for this purpose — and it can never itself change an order, an account, or a payment; only a person can act on what it flags.

7. Your Rights

Under POPIA you may:

  • ask what personal information we hold about you and request access to it;
  • ask us to correct or complete inaccurate information (most details you can edit yourself under Profile → Contacts);
  • ask us to delete information we are not required to keep;
  • object to processing based on our legitimate interests, including opting out of promotional emails or WhatsApp messages by telling us at the contact details below;
  • withdraw consent where processing is based on consent;
  • complain to the Information Regulator (South Africa) — inforegulator.org.za.

8. Cookies

We use cookies that are necessary for the platform to work — session cookies that keep you signed in, security (CSRF) cookies, and Google reCAPTCHA cookies that protect our login, registration, password-reset, and demo-request forms from automated abuse — and Google Analytics cookies to understand how the platform is used. We do not use third-party advertising or retargeting cookies, and we do not sell data collected through cookies. See our Cookie Policy for details.

9. Children

The platform is not directed at children, and transacting requires you to be at least 18. We do not knowingly process children's personal information without a competent person's consent.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on the platform and the "Last updated" date above will change.

Contact & Information Officer

To exercise your rights or ask questions about this policy, contact the Information Officer at McSbuSing (Pty) Ltd: privacy@informativ.co.za.