Privacy notice
Your information should stay yours.
This is the working privacy notice for Common Ground. It must receive qualified South African POPIA review before public launch.
Who is responsible
Common Ground is operated by Sanet Britz in South Africa. For privacy requests or questions, email sanetbritz01@gmail.com. The final pre-launch notice must state the responsible organisation’s full legal and contact details.
Information we use
We use your email address, chosen display name, profile details, account settings, safety reports, moderation decisions, payment status, and messages with your matches. During onboarding we record adult confirmation, self-attested spectrum eligibility, and agreement acceptance. Your birth date is used for the adult eligibility check and is not displayed publicly.
Why we use it
We use this information to operate the service, process membership access, enable matching and messaging, conduct human safety review, investigate reports, prevent misuse, comply with legal obligations, and respond to your requests. We do not sell personal information.
Who can see it
Approved members can see only the profile information you choose to make visible. Messages are limited to the two members in a match. Sanet and authorised safety reviewers may access relevant information where needed for safety, moderation, support, payment administration, or legal obligations. Payment processing is handled by PayFast; Common Ground does not store full card details.
Optional verification selfies and pausing
If you choose optional photo verification, your selfie is seen only by safety moderators, used only to confirm you match your profile photo, and deleted after the decision. Verification is never required to join or take part. You can also pause your account at any time in Settings: pausing hides your profile from discovery and stops new interest, while your matches and messages are kept unchanged.
Retention and deletion
You can request deletion from account settings or by email. We immediately hide a deletion-requested profile and restrict member access while the request is handled. We aim to complete requests within 30 days unless lawful recordkeeping, safety investigations, fraud prevention, or another legal duty requires limited retention. The final notice must confirm the exact retention schedule and any processors or international data transfers.
Your POPIA choices
You may ask to access, correct, or delete your personal information, object to certain processing where applicable, or lodge a complaint with the Information Regulator. Send the request from the email connected to your account and include enough detail to verify it. We may ask for information necessary to protect your account before acting.
Security and limits
We use access controls and private file access to reduce unnecessary exposure. No online service can guarantee absolute security. Keep your sign-in code private, avoid sharing financial information, and report anything concerning through the in-app safety tools.