PeaceJob Privacy Policy
Version 1.0.0-draft, 21 September 2026. This is a draft that has not yet been reviewed by a South African attorney. It will be replaced by a reviewed version, and you will be asked to accept that version before it applies to you.
This policy explains what personal information PeaceJob collects, why, who sees it, how long it is kept and what your rights are under the Protection of Personal Information Act 4 of 2013 (POPIA).
1. Responsible party
The responsible party for your personal information is Peace Job App (Pty) Ltd.
- Registration number: 2026/455418/07
- Address: Remote, South Africa
- Privacy requests and the Information Officer: support@peacejobapp.co.za
- Telephone: +27 (0)72 223 0599
2. What we collect and why
2.1 Your account
- What: your name, mobile number, email address (if you use one), password, the role you choose (Seeker or Employer), whether you are an individual or a company, and the date and version of the terms you accepted. If you sign in with Google or Apple, we receive your name and email address from them.
- Why: to create your account, sign you in and show you the right parts of the app.
- How it is kept: passwords are stored by our authentication provider as a one-way hash. PeaceJob staff cannot read them.
2.2 Your profile
- What: profile photo, bio, category, services, skills, qualifications and rates. For a company: company name, registration number, industry, overview, office location, and a contact person's name, phone number and email. Portfolio photos you upload.
- Why: so that Employers and Seekers can find and choose each other.
2.3 Verification documents (KYC and KYB)
- What, for an individual: a photo or scan of your identity document (green ID book, Smart ID card, passport, or asylum-seeker or refugee document), proof of residential address with its date, and a selfie.
- What, for a company: CIPC registration documents, the names of the directors, an identity document for each director, proof of business address with its date, and the SARS Tax Compliance Status PIN.
- Why: so that a person at PeaceJob can check who is behind an account, to prevent fraud and identity theft, and to protect the people who pay and are paid through PeaceJob.
- How it is used: the files are stored privately. Only you and authorised PeaceJob reviewers can open them. A reviewer looks at the documents and compares your selfie with your identity document by eye. PeaceJob does not run automated face recognition, does not extract your ID number from the document into a separate record, and does not currently check your documents electronically with Home Affairs, CIPC or SARS. The review result (and, if rejected, the reviewer's note) is recorded on your account.
- Consent: a selfie used to confirm your identity may be biometric information, which POPIA treats as special personal information. We process it only with your consent, which you give by submitting it. You can withdraw that consent by removing the selfie before you submit, or after a rejection, but your account cannot then be verified. Once submitted, documents are locked while they are reviewed.
2.4 Location
- Your approximate location. If you allow it, the app reads your phone's location to set your position. What we store is rounded to about 1 km (two decimal places), with an area name such as "Pimville, Soweto". You can pick an area by hand instead. Why: to show nearby work and nearby talent and the distance between them.
- Gig site location. An Employer enters where the work is. It is stored with the gig and shown to signed-in users. Why: so that Seekers know where the work is.
- Site check-in. During a booking, if you allow background location, your phone watches for your arrival at the site and tells the app when you get there. The app records that the check-in happened. It does not send us a trail of your movements.
You can switch location access off at any time in your phone's settings.
2.5 Gigs, bookings, reviews and disputes
- What: gigs you post, bids, bookings and their steps, ratings and comments you give and receive, and disputes (the reason, and the administrator's decision and note). Photos taken at the start and end of a job stay on the phone that took them. We store only the file's location on that phone, which cannot be opened from anywhere else.
- Why: to run bookings, build trust between users and resolve disputes.
2.6 Messages and notifications
- What: messages you send and receive, when you last read each conversation, and the notifications the app sends you.
- Why: to deliver your conversations and alerts, and so that an administrator can review what was said if a dispute is raised about a booking.
2.7 Payments and your wallet
- What: each payment's amount, status and date, Stripe's reference numbers for it, your wallet balance and your wallet transaction history.
- Why: to credit your wallet, hold and release booking money, produce statements, answer questions about payments and meet financial record-keeping obligations.
- What we never receive: your card number, expiry date or CVV. You enter those on Stripe's payment page, and they go to Stripe.
2.8 Availability and devices
- What: whether you have set yourself Online, when you last changed it, your push notification token, your phone's platform (Android or iOS) and its device name.
- Why: to show you in the talent directory while you are Online and to deliver push notifications to your phone.
2.9 Records of administrative changes
- What: when an administrator or one of our systems changes an account record, we keep a record of the change, who made it, when, and the IP address and app or browser details of the request.
- Why: security, accountability for staff actions, and fraud investigation.
2.10 Notification preferences
- What: whether you would like SMS or WhatsApp alerts. Both are off unless you switch them on.
- Note: nothing is sent to these channels yet. We will ask for your consent before any SMS or WhatsApp alerts, job broadcasts or other messages start.
3. Our legal grounds
We process personal information:
- to perform our agreement with you (your account, bookings, payments and messages);
- with your consent (location, notifications, and your selfie and identity documents for verification);
- to meet legal obligations (financial and tax records, and requests from authorities we are legally obliged to answer); and
- for our legitimate interests and those of other users (preventing fraud, keeping the platform safe and resolving disputes).
We do not sell personal information, and we do not use it for advertising. The app contains no advertising or analytics trackers.
4. Who can see your information
4.1 Other PeaceJob users
- The talent directory, while you are Online: name, photo, bio, category, services, skills, qualifications, rates, verification status, approximate location and area name, when you last changed your availability, and portfolio photos. For a company, also the company details and the contact person's name, phone number and email from the company profile.
- Gigs and reviews: visible to all signed-in users.
- The other party to a booking: your name, the gig, your messages and the booking's progress.
Your identity documents, proof of address, selfie, tax PIN, wallet and payments are never shown to other users.
4.2 PeaceJob staff
Authorised administrators can see verification documents to review them, and booking records, messages and payments to resolve disputes and support requests. Administrative changes are recorded (section 2.9).
4.3 Service providers (operators)
These companies process personal information for PeaceJob, only to provide their service to us:
- Supabase: database, sign-in, file storage and server functions. It holds all the information in section 2, including verification documents.
- Stripe: card payments. It receives your payment and card details on its payment page, and the payment amount and reference from us.
- Twilio, through Supabase: sends SMS sign-in codes. It receives your mobile number and the code.
- Expo, with Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS): delivers push notifications. They receive your push token and the notification's title and text.
- Google: Maps (map images, which receive the coordinates of the map area shown) and Google sign-in if you use it.
- Apple: Sign in with Apple if you use it.
4.4 Authorities
We disclose personal information to the police, a regulator or a court when the law requires it, or where needed to report or prevent a crime such as fraud or identity theft.
5. Information sent outside South Africa
Stripe, Twilio, Expo, Google and Apple process information in other countries, including the United States and countries in Europe. Supabase stores PeaceJob's database in a data centre that may be outside South Africa. We use these providers because the app cannot work without them, and we rely on their contractual data-protection commitments to protect your information to a standard comparable to POPIA.
6. How we protect your information
- Every account can read only its own records. Other users see only the directory, gig and review information listed in section 4.1.
- Verification documents are in private storage and can be opened only by you and authorised reviewers.
- Information travels between the app and our servers over encrypted connections.
- Card details never reach PeaceJob.
- Administrator access is limited to named accounts, and changes they make are recorded.
If we have reasonable grounds to believe your personal information has been accessed without authority, we will notify the Information Regulator and you, as POPIA requires.
7. How long we keep information
- While your account is open: we keep your information for as long as it is needed to provide the service.
- Directory listing: you leave the directory as soon as you set yourself Offline or your account is closed.
- After your account is closed: we keep your wallet transactions, payment records, statements and verification records (documents and review results) for 5 years from closure. This is to meet financial record-keeping and tax obligations, to prevent and investigate fraud, and to deal with disputes and legal claims. During that time they are not used for anything else, and they cannot be deleted at your request.
- Messages: the content of a message is removed 3 years after the booking it belongs to last moved, which is the longest a claim about that work could still be brought. A message that is not about a booking is removed 3 years after it was sent. Who sent it and when is kept, because that is part of the dispute record; what they said is not.
- Records of administrative changes (section 2.9): the change itself, and who made it, are kept. The IP address and app or browser details are removed after 12 months — they are there to investigate something recent, not to build a history of where you were.
- Notifications: deleted after 6 months. They tell you something happened; the gig, booking or message they point at is the record.
- Everything else: deleted or de-identified when it is no longer needed.
We apply these periods in a single pass that we run and check ourselves, rather than on an automatic schedule, so that a change to what we keep is always something a person decided.
8. Your rights
Under POPIA you have the right to:
- ask what information we hold about you and to receive a copy. You can get that copy yourself, at any time: App Settings → Download my data gives you a file containing everything in section 2 that relates to your account. It does not include your verification files themselves — you can open those in the app — or our internal records of administrative changes, because those identify the staff member who made the change; ask us for those and we will provide what we can;
- correct information that is wrong. You can edit your profile in the app. Verification details can be changed until they are submitted, or after a rejection;
- ask us to delete information we no longer need or may no longer keep, subject to section 7;
- object to processing based on our legitimate interests;
- withdraw consent where we rely on it: switch off location or notifications in your phone's settings, set yourself Offline, or change your notification preferences. Withdrawing consent does not undo processing that already happened;
- not receive direct marketing without your consent. PeaceJob does not send any; and
- complain to the Information Regulator (www.inforegulator.org.za) if you believe we have not handled your information lawfully.
To use any of these rights, email support@peacejobapp.co.za from the email address or phone number on your account. We may ask you to confirm your identity first, and we will reply within a reasonable time and in any event within the time POPIA sets.
8.1 Closing your account
You can close your account yourself: App Settings → Close my account. You can also ask us to close it by email.
Closing an account cannot be undone, and it is not the same as deleting everything we hold. When you close it:
- your name, phone number, bio, rates, skills, services, company details and contact person, location and push notifications are erased, and your name is replaced with "Closed account" wherever another user could still see it — on a booking, a bid, a conversation or a review you left;
- your profile photo and portfolio photos are removed from your profile, so nobody can see or reach them. The image files are deleted separately, when the records in section 7 are;
- any gig you posted that nobody has been booked for, and any bid still waiting on a decision, are removed, so nobody is left waiting on you; and
- the records in section 7 — your wallet transactions, payment records, statements, and your verification documents and their review result — are kept for 5 years, without your name attached to your profile any more.
A booking that is still in progress has to be completed, or its dispute resolved, before the account can close: money is held for that job and the other party is relying on it. If money is left in your wallet, email accounts@peacejobapp.co.za — closing the account does not pay it out.
9. Automated decisions
PeaceJob makes no decision about you based solely on automated processing that has legal or similarly significant effects. Verification and dispute decisions are made by a person. Sorting the directory by distance is not a decision about you.
10. Children
PeaceJob is for people aged 18 and over. We do not knowingly collect information from children. If you believe a child has an account, tell us at support@peacejobapp.co.za and we will close it.
11. Features that are not offered yet
Cash vouchers, cardless cash-out, in-app withdrawals, and access to PeaceJob from a basic phone by USSD and SMS are not available yet. They would involve new information (for example voucher references, cash-out details and SMS or USSD session records) and new service providers. Before any of them starts, we will update this policy and ask for your consent where it is needed.
12. Changes to this policy
The version number is shown at the top. When this policy changes in a way that affects you, the app will ask you to accept the new version, and the date and version you accepted are recorded on your account.
13. Contact
Privacy questions and requests: support@peacejobapp.co.za or +27 (0)72 223 0599.
---
© 2026 Peace Job App (Pty) Ltd. Software and Intellectual Property of Mel Tech (Pty) Ltd.