1. Who is the responsible party?
Maavin (“we”, “us”) is the responsible party for personal information processed through the Platform, except where we process information solely on instructions of another party in a defined operator role.
Privacy enquiries and POPIA requests: privacy@maavin.co.za
If we appoint an Information Officer under POPIA, we will publish their details here.
2. Scope
This Policy applies to visitors, customers, service providers, and administrators using Maavin websites, apps, emails, and related services in South Africa. It covers data we process in connection with accounts, job posts, quotes, messaging, ID verification, reviews, and support.
3. What personal information we collect
3.1 Information you provide
- Account: name, email address, password (stored hashed), avatar, preferred role (Customer / service provider), and whether you are currently using Maavin (shown as Online while you are here, and Away when you are not).
- Service provider profile: trade categories, suburbs/regions served, bio, rates guidance, portfolio images, availability, certification claims.
- Identity verification: copies or photos of identity documents (e.g. South African ID or passport), verification status, and admin review notes.
- Jobs and quotes: job titles, descriptions, suburbs, budgets, quote amounts, timelines, and related text.
- Messages: content of in-app messages between customers and service providers about a job.
- Reviews: ratings and written feedback.
- Support: emails or reports you send us.
3.2 Information from social sign-in
If you sign in with Google, we receive basic profile details (such as name, email, and profile image) from that provider according to your Google permissions.
3.3 Information collected automatically
- Device and browser type, IP address, approximate location derived from IP, pages viewed, referring URLs, and timestamps.
- Session cookies and similar technologies (see our Cookie Policy).
- Security logs related to login attempts and OTP issuance.
3.4 Sensitive / special personal information
Identity documents may contain special personal information or highly sensitive identifiers. We process ID uploads only for verification, fraud prevention, and platform trust, and we restrict access to authorised reviewers. Do not upload unnecessary medical or biometric data.
4. Why we process personal information (purposes & lawful bases)
Under POPIA we process information where we have a lawful justification, including consent, contract performance, legitimate interests (balanced against your rights), legal obligation, or protecting legitimate interests of a data subject. In practice we process data to:
- Create and secure your account (including email OTP / 2FA).
- Operate marketplace features: profiles, job posts, quotes, messaging, reviews.
- Verify service provider identity and display verification status.
- Match local demand with local skill in the Western Cape.
- Prevent fraud, spam, abuse, and security incidents.
- Provide customer support and investigate reports.
- Improve product performance and reliability.
- Send transactional emails (verification codes, security notices). Marketing emails, if introduced, will be opt-in or otherwise POPIA-compliant.
- Comply with law, court orders, or regulator requests.
- Establish, exercise, or defend legal claims.
5. How we share information
We do not sell your personal information. We may share it with:
- Other users: as needed for the marketplace — e.g. your public service provider profile, job details you post, quotes you send, messages in a job thread, and reviews. We aim to keep phone numbers private in-product where the design allows.
- Service providers (operators): hosting, email delivery, storage, analytics, and security vendors who process data on our instructions under confidentiality obligations.
- Admin reviewers: for ID verification decisions.
- Authorities: when required by law or to protect rights, safety, or property.
- Business transfers: if we restructure, merge, or sell assets, information may transfer subject to continued protection commitments.
When escrow or payment providers are added, we will update this Policy and disclose what payment data those providers receive.
6. Cross-border transfers
We prefer to host primary application data in South Africa where practical. Some vendors (for example email or OAuth providers) may process data in other countries. Where we transfer personal information outside South Africa, we take steps consistent with POPIA Chapter 9 (adequate protection, agreements, or other lawful transfer mechanisms).
7. Retention
We keep personal information only as long as needed for the purposes above, including:
- Active account data while your account remains open.
- Messages, jobs, and quotes for operational history and dispute context.
- ID documents and verification records for as long as needed for trust & safety, then securely deleted or anonymised when no longer required.
- Security and audit logs for a limited period.
- Longer retention where required by law or for legal claims.
You may request deletion of your account; see Section 9. Some residual records may remain where we must retain them (e.g. fraud prevention or legal obligation).
8. Security
We implement reasonable technical and organisational measures appropriate to the risk, including hashed passwords, OTP login flows, access controls for admin tools, HTTPS in transit, and restricted access to ID document storage. No online system is perfectly secure; please use a strong unique password and protect your email inbox.
If a security compromise is likely to affect your rights, we will notify you and the Information Regulator as required by POPIA.
9. Your rights under POPIA
Subject to POPIA limitations, you may request to:
- Access the personal information we hold about you.
- Correct or update inaccurate information.
- Object to certain processing, or withdraw consent where processing is consent-based.
- Request deletion or restriction where appropriate.
- Lodge a complaint with the Information Regulator (South Africa).
To exercise rights, email privacy@maavin.co.za from your registered email and describe your request. We may need to verify your identity before responding. We aim to respond within a reasonable period (typically within 30 days).
Information Regulator: inforegulator.org.za
10. Children
Maavin is not directed at persons under 18. We do not knowingly collect personal information from children. If you believe a minor has created an account, contact us and we will take appropriate steps.
11. Automated decision-making
We may use automated rules for spam detection, rate limiting, or ranking of listings. Identity verification currently involves human review. If we introduce significant solely automated decisions with legal or similarly significant effects, we will describe them here and provide avenues for human review where required.
12. Cookies and similar technologies
We use cookies and similar technologies for sessions, security, and (if enabled) analytics. Details are in our Cookie Policy.
13. Changes to this Policy
We may update this Policy when our practices or the law change. The “Last updated” date will change, and material updates may be communicated by email or notice on the Platform.