Data Protection
Last updated: 10 July 2026
This page explains, at an operational level, how Fresoh (Pty) Ltd protects the personal information described in our Privacy Policy, in line with the eight conditions for lawful processing set out in the Protection of Personal Information Act 4 of 2013 (POPIA).
1. Accountability
Fresoh (Pty) Ltd is accountable for ensuring the conditions for lawful processing of personal information are met throughout our Platform, and for the actions of any service provider that processes personal information on our behalf. Our Information Officer, [Information Officer name to be inserted], is responsible for POPIA compliance and can be reached at privacy@fresoh.co.za.
2. Processing and purpose limitation
We only collect personal information for the specific, defined purposes described in our Privacy Policy — operating the marketplace, processing payments, verifying Restaurants, and communicating with users — and we do not process it further in a way that is incompatible with those purposes.
3. Access controls
Access to personal information within Fresoh is role-based and limited to what is reasonably necessary:
- Customers can only view their own account, order, and rating information.
- Restaurants can only view order and contact information relevant to Orders placed with them, and manage their own Listings.
- Administrators have broader access strictly for platform operation, support, and compliance purposes, and all administrative access is logged.
4. Technical safeguards
- Passwords are stored using industry-standard one-way hashing and are never stored or transmitted in plain text.
- Traffic between your device and the Platform is encrypted in transit (HTTPS/TLS).
- The mobile app authenticates using signed, expiring access tokens rather than storing credentials on our servers.
- Card and bank details are never handled or stored by Fresoh — all payments are processed directly by PayFast.
- Databases are access-controlled and regularly backed up.
5. Operators and service providers
Where we use third parties to process personal information on our behalf ("operators" under POPIA) — including PayFast for payments, Amazon Web Services for file storage, and our transactional email providers — we only engage providers that maintain security measures consistent with POPIA section 21, and only for the purposes we have instructed.
6. Data minimisation and retention
We collect only the personal information reasonably required to operate the Platform, and retain it only for as long as necessary:
| Data category | Retention approach |
|---|---|
| Active account & profile data | Retained while your account is active. |
| Order & payment records | Retained for a minimum of five years to meet South African tax and financial recordkeeping obligations. |
| Device push tokens | Removed when you delete your account or uninstall the app. |
| Ratings & reviews | May be retained in de-identified form after account deletion to preserve the integrity of a Restaurant's rating history. |
7. Data breach response
If we become aware of a security compromise that has resulted, or may reasonably result, in unauthorised access to or disclosure of personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with POPIA section 22.
8. Your role in protecting your account
You can help keep your information secure by using a strong, unique password, not sharing your login credentials or QR collection codes, and notifying us immediately at privacy@fresoh.co.za if you suspect unauthorised access to your account.
9. Review
We periodically review our data protection practices as the Platform evolves. This page will be updated to reflect any material changes.