Back to home
Legal

Privacy Policy

Last updated: 1 June 2026

1. Who we are (Responsible Party)

Trust Passport ("we", "us", "our") is an early-stage research project based in Cape Town, South Africa. For the purposes of POPIA, we are the Responsible Party for any personal information you share with us through this site. Our acting Information Officer can be reached at privacy@trustpassport.co.za.

2. What we collect

We only collect information you choose to give us:

  • Survey responses — what you tell us about how you buy and sell online, the categories you shop in, and your experiences with online safety.
  • Contact details — your email address (and optional name) if you join our waitlist or send us a message.
  • Basic technical data — standard server logs (IP, browser, referrer) used to keep the site secure and to understand broad usage patterns. We do not run third-party advertising trackers.

3. How we use it

  • To learn what real users actually need from a trust product.
  • To contact you about the research, if you opted in.
  • To notify you when Trust Passport is ready for early access, if you joined the waitlist.
  • To keep the site secure and operational.

We do not sell your data. We do not share it with advertisers. We do not pass it to third parties for marketing.

4. Legal basis under POPIA

Section 11 of POPIA requires a lawful basis for processing personal information. We rely on:

  • Your consent — given freely and specifically when you submit a survey, send us an email, or join the waitlist. You can withdraw it at any time.
  • Our legitimate interest in conducting research that informs a future South African trust product, balanced against your rights and reasonable expectations.
  • Compliance with the law where we're required to process or retain information (for example, in response to a lawful request from the Information Regulator).

We commit to the eight conditions for lawful processing in POPIA: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.

5. Special personal information and children

We do not knowingly collect special personal information as defined in section 26 of POPIA (race, health, religion, political views, biometric data, etc.). Please don't share this kind of information in survey responses. Our site is not directed at children under 18, and we don't knowingly process the personal information of children without parental consent.

6. Cross-border transfers

Some of the services we use to run this site (hosting, analytics-light tooling, email) may store data on servers outside South Africa. Where this happens, we only use providers that offer protections substantially similar to POPIA — for example, through standard contractual clauses or providers in jurisdictions with adequate data protection law, as required by section 72 of POPIA.

7. How long we keep it

Research responses are kept for as long as they're useful to our research, and at most until the project either launches publicly or is shut down. Waitlist emails are kept until you ask us to remove them or you unsubscribe. When information is no longer needed for the purpose it was collected, we delete or de-identify it, in line with section 14 of POPIA.

8. Your rights as a data subject

Sections 23–25 of POPIA give you the following rights. You can exercise any of them free of charge, and we aim to respond within 30 days:

  • Confirmation of whether we hold personal information about you.
  • Access to that information and details of who it's been shared with.
  • Correction, deletion, or destruction of inaccurate or excessive information.
  • Objection to processing on reasonable grounds.
  • Withdrawal of consent at any time.
  • Unsubscribing from any direct marketing.
  • Lodging a complaint with the Information Regulator of South Africa if you believe we've mishandled your information.

To exercise any of these rights, email privacy@trustpassport.co.za. You may also use POPIA Form 2 to request access, or POPIA Form 3 to request correction or deletion.

9. Security safeguards

In line with section 19 of POPIA we use reasonable technical and organisational measures to protect your data — including encrypted connections (HTTPS), access controls on our research database, and the principle of least privilege for anyone on the team. If a security compromise affects your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.

10. Information Regulator

If you're not satisfied with how we've handled your personal information, you have the right to complain to the Information Regulator:

11. Changes to this policy

As Trust Passport grows from a research project into a real product, this policy will be updated. We'll post material changes on this page and update the "Last updated" date above.

12. Contact us

Questions, concerns, or data requests: privacy@trustpassport.co.za.