Data Protection

Last updated: 10 July 2026

This page explains, at an operational level, how Fresoh (Pty) Ltd protects the personal information described in our Privacy Policy, in line with the eight conditions for lawful processing set out in the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Accountability

Fresoh (Pty) Ltd is accountable for ensuring the conditions for lawful processing of personal information are met throughout our Platform, and for the actions of any service provider that processes personal information on our behalf. Our Information Officer, [Information Officer name to be inserted], is responsible for POPIA compliance and can be reached at privacy@fresoh.co.za.

2. Processing and purpose limitation

We only collect personal information for the specific, defined purposes described in our Privacy Policy — operating the marketplace, processing payments, verifying Restaurants, and communicating with users — and we do not process it further in a way that is incompatible with those purposes.

3. Access controls

Access to personal information within Fresoh is role-based and limited to what is reasonably necessary:

  • Customers can only view their own account, order, and rating information.
  • Restaurants can only view order and contact information relevant to Orders placed with them, and manage their own Listings.
  • Administrators have broader access strictly for platform operation, support, and compliance purposes, and all administrative access is logged.

4. Technical safeguards

  • Passwords are stored using industry-standard one-way hashing and are never stored or transmitted in plain text.
  • Traffic between your device and the Platform is encrypted in transit (HTTPS/TLS).
  • The mobile app authenticates using signed, expiring access tokens rather than storing credentials on our servers.
  • Card and bank details are never handled or stored by Fresoh — all payments are processed directly by PayFast.
  • Databases are access-controlled and regularly backed up.

5. Operators and service providers

Where we use third parties to process personal information on our behalf ("operators" under POPIA) — including PayFast for payments, Amazon Web Services for file storage, and our transactional email providers — we only engage providers that maintain security measures consistent with POPIA section 21, and only for the purposes we have instructed.

6. Data minimisation and retention

We collect only the personal information reasonably required to operate the Platform, and retain it only for as long as necessary:

Data category Retention approach
Active account & profile data Retained while your account is active.
Order & payment records Retained for a minimum of five years to meet South African tax and financial recordkeeping obligations.
Device push tokens Removed when you delete your account or uninstall the app.
Ratings & reviews May be retained in de-identified form after account deletion to preserve the integrity of a Restaurant's rating history.

7. Data breach response

If we become aware of a security compromise that has resulted, or may reasonably result, in unauthorised access to or disclosure of personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with POPIA section 22.

8. Your role in protecting your account

You can help keep your information secure by using a strong, unique password, not sharing your login credentials or QR collection codes, and notifying us immediately at privacy@fresoh.co.za if you suspect unauthorised access to your account.

9. Review

We periodically review our data protection practices as the Platform evolves. This page will be updated to reflect any material changes.