Field24 is committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what we collect, why we collect it, how we use it, and your rights as a data subject.
1. Who We Are
Field24 (Pty) Ltd ("Field24", "we", "us", "our") operates an AI-powered field service marketplace connecting buyers with verified field service technicians across South Africa. We act as the Responsible Party under POPIA for the personal information we process on our platform.
Our registered address is in South Africa. For privacy enquiries, contact: privacy@field24.co.za
2. Information We Collect
2.1 Account & Identity Information
- Full name and email address
- Phone / cell number (including WhatsApp)
- Password (stored as a one-way cryptographic hash — never in plain text)
- Account role (buyer, technician, enterprise)
- POPIA consent timestamp
2.2 Professional & Business Information (Technicians)
- Business or trading name
- Service categories and skills
- Years of experience and certifications
- Province, city and service areas
- Uploaded credentials and compliance documents (encrypted in transit and at rest)
2.3 Job & Transaction Information
- Job descriptions, locations, status and history
- Bid and counter-bid amounts
- Payment records including amounts, gateway references (Ozow / PayFast) and escrow release dates
- Invoices and receipts
2.4 Location Information (GPS)
When you use our mobile or web app to track or claim a job, we may collect your GPS coordinates. Location data is used solely for job dispatch, route optimisation and real-time tracking visible to the relevant buyer. We do not sell or share GPS data with third parties for advertising.
2.5 Technical & Usage Data
- IP address, browser type, device information
- Pages visited, features used, time on platform
- Error logs and crash reports
- AI interaction logs (prompts and responses for support tickets)
2.6 Payment Information
Payment card details are never stored on Field24 servers. All payment processing is handled by our PCI-DSS compliant gateway partners (Ozow and PayFast). We store only transaction references, amounts and statuses.
3. How We Use Your Information
- Platform operation: Creating and managing your account, matching jobs to technicians, processing escrow payments and releasing funds.
- Communication: Sending job alerts, status updates, invoices and platform notifications via email or SMS.
- Safety & verification: Verifying technician credentials and qualifications before activation.
- Customer support: Responding to tickets, resolving disputes, and improving AI-assisted support responses.
- Platform improvement: Analysing usage patterns (in aggregate) to improve features and reliability.
- Legal compliance: Fulfilling our obligations under POPIA, tax laws and financial regulations.
4. Third Parties We Share Data With
We do not sell your personal information. We share data only with trusted service providers who process it on our behalf under strict data processing agreements:
- Sentry (error monitoring) — receives anonymised error reports and stack traces. No personal data in error payloads unless explicitly included.
- PostHog (product analytics) — receives pseudonymised usage events. We configure PostHog to mask personally identifiable fields.
- Ozow / PayFast (payment processing) — receives payment initiation data required to process transactions. Subject to their own PCI-DSS and privacy obligations.
- Cloud infrastructure providers — our hosting, database and storage services are operated within South Africa or the EU with equivalent data protection standards.
We may also disclose your information where required by law, court order or a competent authority.
5. Data Retention
- Active accounts: Data is retained for as long as you maintain an active account.
- Completed jobs & payments: Retained for 5 years for tax and financial compliance purposes.
- Deleted accounts: Your profile is anonymised within 30 days of an erasure request. Anonymised records may be retained in aggregated form for fraud prevention and compliance.
- Error logs: Retained for 90 days.
- AI support logs: Retained for 12 months then purged.
6. Your Rights Under POPIA
As a data subject under POPIA, you have the following rights:
- Right of access: Request a copy of all personal information we hold about you.
- Right to erasure: Request deletion (anonymisation) of your account and personal data.
- Right to portability: Request your data in a structured, machine-readable format (JSON).
- Right to correction: Update your account details at any time via your profile settings.
- Right to object: Object to processing for direct marketing at any time.
- Right to complain: Lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.
Exercising Your Rights via the API
Authenticated users may programmatically exercise data rights:
- Export data:
GET /api/v1/auth/me/export — returns your complete data record as JSON.
- Delete account:
DELETE /api/v1/auth/me — anonymises your account immediately.
7. Security
We implement industry-standard security measures including TLS encryption in transit, bcrypt password hashing, HttpOnly/Secure/SameSite cookies, parameterised database queries, and regular security reviews. Despite these measures, no system is completely immune from attack. We will notify affected users and the Information Regulator in the event of a material data breach.
8. Cookies
We use a single HttpOnly authentication cookie to maintain your session. We do not use third-party advertising cookies. Analytics events are sent server-side to PostHog without placing tracking cookies.
9. Children's Privacy
Field24 is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a minor has registered, please contact us immediately at privacy@field24.co.za.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to registered users via email at least 14 days before taking effect. Continued use of the platform after that date constitutes acceptance.
11. Contact Us