Trading Securely 24 Hours a Day
028 123 4567

Privacy Policy

Legal & Policy

Privacy Policy | LIST SECURE

Privacy Policy

Document: Privacy Policy | Version: 2.0 | Effective date: [INSERT: effective date] | Owner: LIST SECURE (PTY) LTD


Contents


1. Who we are and what this Policy is for

1.1 This Privacy Policy explains how LIST SECURE (PTY) LTD ("List Secure", "we", "us", "our") collects, uses, shares, protects and deletes your Personal Information when you use the Platform.

1.2 Our details are:

Legal nameLIST SECURE (PTY) LTD
Registration number[INSERT: company registration number]
VAT registration number[INSERT: VAT number, or delete this line if not VAT-registered]
Registered and physical address16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa
Postal address[INSERT: postal address if different]
Directors[INSERT: full names of directors]
Websitehttps://listsecure.co.za
Support emailsupport@listsecure.co.za
Privacy / Information Officer emaildata@listsecure.co.za
Legal notices email[INSERT: legal@listsecure.co.za or confirm support@]
Telephone[CONFIRM: +27 28 123 4567 — the number currently on the website appears to be a placeholder]
Hosting provider[INSERT: hosting provider]

1.3 We are the responsible party (in the GDPR, the "controller") for the Personal Information described in this Policy, except where we say otherwise. Clause 4 explains where a Vendor, and not List Secure, is the responsible party.

1.4 This Policy is written in plain language, as section 22 of the Consumer Protection Act 68 of 2008 requires. Where we have had to use a legal term, we explain it.

1.5 This Policy replaces the Privacy Policy dated 15 December 2025 and any earlier privacy notice. It takes effect on [INSERT: effective date].

1.6 What this Policy applies to

1.6.1 This Policy applies to the Platform, to your account, to Orders placed through the Platform, to our verification and dispute processes, to our marketing, and to our dealings with you as a visitor, Buyer, Vendor, applicant or business contact.

1.6.2 This Policy does not apply to:

1.6.2.1 a Vendor's own use of Personal Information it receives about its Buyers (see clause 4);

1.6.2.2 any third-party website, payment page, courier tracking page or social media page that you reach through a link on the Platform — those operators have their own privacy notices, and you should read them; or

1.6.2.3 information that is not Personal Information, or that has been fully de-identified so that it can no longer be linked to you.

1.7 This Policy forms part of the Platform Terms. It must be read with the Terms & Conditions, the Cookies Policy, the Payment Terms, the Shipping Policy, the Returns & Refunds Policy, the Marketplace Rules and the Vendor Agreement.


2. Definitions

In this Policy:

2.1 "Platform" means the List Secure website at listsecure.co.za, its subdomains, mobile applications and related services.

2.2 "User" means any person who accesses or uses the Platform.

2.3 "Buyer" means a User who purchases or offers to purchase an Item through the Platform.

2.4 "Vendor" means a User approved by List Secure to list Items for sale on the Platform.

2.5 "Item" means any product or goods listed for sale on the Platform.

2.6 "Listing" means a Vendor's offer of an Item, including all text, images and specifications.

2.7 "Order" means a Buyer's accepted offer to purchase an Item.

2.8 "Escrow Provider" means TradeSafe, or such other escrow provider as List Secure may appoint.

2.9 "Escrow Account" means the trust/escrow account in which Order funds are held.

2.10 "Payment Provider" means PayFast, or such other payment service provider as we may appoint.

2.11 "Purchase Price" means the price of the Item excluding Delivery Charges.

2.12 "Order Total" means the Purchase Price plus Delivery Charges plus any applicable fees and VAT.

2.13 "Commission" means the fee payable by the Vendor to List Secure on each completed Order.

2.14 "Acceptance Window" means the period after delivery within which a Buyer must confirm acceptance or lodge a dispute, failing which acceptance is deemed.

2.15 "Dispute" means a Buyer/Vendor disagreement lodged through the Platform before the Acceptance Window closes.

2.16 "Business Day" means any day other than a Saturday, Sunday or South African public holiday.

2.17 "Personal Information" has the meaning given to it in POPIA.

2.18 "Content" means any material a User uploads, posts or transmits through the Platform.

2.19 "POPIA" means the Protection of Personal Information Act 4 of 2013 and its Regulations.

2.20 "Regulator" means the Information Regulator (South Africa).

2.21 "Operator" means a person who processes Personal Information for us in terms of a contract or mandate, without coming under our direct authority — in the GDPR, a "processor".

2.22 "Special Personal Information" means the categories listed in section 26 of POPIA, which include biometric information and information about criminal behaviour.


3. The law we apply

3.1 We process Personal Information in accordance with POPIA and the eight conditions for lawful processing in sections 8 to 25 of POPIA: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.

3.2 We also apply:

3.2.1 the Electronic Communications and Transactions Act 25 of 2002 ("ECTA"), including section 43 (supplier information), section 45 (unsolicited commercial communications) and the principles in section 51 for the electronic collection of personal information, which a data controller may voluntarily subscribe to and which we apply as a matter of practice;

3.2.2 the Consumer Protection Act 68 of 2008, including section 16 (cooling-off after direct marketing) and section 22 (plain language);

3.2.3 the Promotion of Access to Information Act 2 of 2000 ("PAIA");

3.2.4 FICA-aligned customer due diligence and record-keeping controls, as described in clause 9 — [CONFIRM with attorney: whether List Secure falls within Schedule 1 of the FIC Act];

3.2.5 the Cybercrimes Act 19 of 2020, including any obligation to report certain offences within 72 hours — [CONFIRM applicability]; and

3.2.6 the General Data Protection Regulation (EU) 2016/679 ("GDPR"), but only where and to the extent that you are in the European Union or European Economic Area and the GDPR applies to our processing. We do not claim that the GDPR applies to all of our processing. Clause 8 sets out the GDPR position alongside the POPIA position for those Users.


4. Our role — we are a marketplace, and Vendors are separate responsible parties

This clause is important. Please read it.

4.1 List Secure is an online marketplace and intermediary. We provide a venue, verification, escrow facilitation and dispute support. We are not the seller, importer, distributor, producer or supplier of any Item, and we are not a party to the contract of sale. The contract of sale is concluded between the Buyer and the Vendor.

4.2 Because of this, Personal Information on the Platform is handled by two different responsible parties:

4.2.1 List Secure is the responsible party for your account, your verification, your use of the Platform, our payment and escrow facilitation, our fraud and risk controls, our dispute handling, and our own marketing.

4.2.2 The Vendor is a separate and independent responsible party for the Personal Information it receives about its Buyers.

4.3 What this means when you buy. When you place an Order, we disclose to the Vendor the information the Vendor needs in order to fulfil that Order. This ordinarily includes your name, delivery address, contact telephone number and email address, the Order details, and any delivery instructions you give. From the moment the Vendor receives that information, the Vendor processes it as an independent responsible party in its own right under POPIA. The Vendor — not List Secure — decides how it stores that information, how long it keeps it (subject to clause 4.5), and how it secures it. The Vendor is accountable to you and to the Regulator for its own processing.

4.4 We are not liable for a Vendor's failure to comply with POPIA in respect of information it holds as a responsible party. If you have a privacy complaint about a Vendor, you may raise it with us and we will assist you to route it (clause 21), but you may also take it up with that Vendor directly and with the Regulator.

4.5 Vendors are contractually bound. Under clause 18 of the Vendor Agreement, every Vendor must:

4.5.1 use Buyer Personal Information only to fulfil, deliver, invoice, support and, where applicable, return or refund the Order, and to meet its own legal obligations;

4.5.2 not use Buyer Personal Information for its own direct marketing, for building its own marketing lists, or for any purpose outside the Order, unless the Buyer has separately and lawfully consented to that Vendor;

4.5.3 not sell, rent or otherwise make Buyer Personal Information available to any other person, except to a courier or other Operator it needs in order to fulfil the Order;

4.5.4 apply appropriate, reasonable technical and organisational security measures as section 19 of POPIA requires;

4.5.5 notify us without delay, and in any event within [INSERT: security compromise notification period — number of hours], if it becomes aware of or suspects a security compromise affecting Buyer Personal Information, so that we can meet our own obligations under section 22 of POPIA;

4.5.6 delete or return Buyer Personal Information when it no longer has a lawful basis to keep it; and

4.5.7 comply with POPIA generally, and with the Second-Hand Goods Act 6 of 2009 where it trades second-hand goods as a business, including the five-year register that Act requires.

4.6 We may suspend or terminate a Vendor's account for a material breach of clause 4.5.

4.7 Vendors: your own Personal Information. If you are a Vendor, we are the responsible party for the information we collect about you as a Vendor — your identity and verification records, your bank and payout details, your Listings, your sales history, your Commission and tax records, and your conduct on the Platform.


5. Information Officer and the Information Regulator

5.1 Our Information Officer, appointed and acting in terms of section 55 of POPIA, is [INSERT: full name of the Information Officer].

5.2 The Information Officer may be contacted at:

5.2.1 email: data@listsecure.co.za;

5.2.2 post: 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa, marked for the attention of the Information Officer; and

5.2.3 telephone: [CONFIRM: +27 28 123 4567 — the number currently on the website appears to be a placeholder].

5.3 Our Information Officer is registered with the Information Regulator in terms of section 55 of POPIA and the Regulator's registration process — [CONFIRM registration]. Registration reference: [INSERT: Information Regulator registration reference number and date].

5.4 The Information Officer is responsible for:

5.4.1 encouraging and monitoring our compliance with POPIA;

5.4.2 dealing with requests made to us under POPIA and PAIA;

5.4.3 working with the Regulator on investigations;

5.4.4 maintaining our personal information impact assessment, our processing register and our PAIA manual; and

5.4.5 approving any notification of a security compromise under section 22 of POPIA.

5.5 We may appoint one or more Deputy Information Officers. Their details, when appointed, appear in our PAIA manual — [INSERT: names of Deputy Information Officers, if appointed].


6. The Personal Information we collect

6.1 We collect only the Personal Information that is adequate, relevant and not excessive for the purposes set out in clause 8, as section 10 of POPIA requires.

6.2 The categories we collect are set out below. Not every category applies to every User. A visitor who only browses gives us far less than a Vendor who is verified and paid out.

6.3 Identity and KYC information

6.3.1 Full names, including any previous or alternative names you give us.

6.3.2 South African identity number, or passport number and nationality where you are not a South African citizen.

6.3.3 Date of birth.

6.3.4 Images of your identity document, passport, driving licence or other identifying document that you upload or that are captured during verification.

6.3.5 A selfie image, and the "liveness" data captured during the selfie check — this includes biometric information, because it is used to confirm that the face presented is a live person and that it matches the face on the identity document.

6.3.6 The results of database checks carried out through our verification provider, including confirmation of whether an identity number is valid, deceased-status indicators where returned, and identity-verification match outcomes.

6.3.7 For business Vendors: company or close corporation registration number, trading name, VAT number, registered address, and the identity and verification details of directors, members, and beneficial owners where we are required to collect them.

6.3.8 Where a Vendor trades second-hand goods as a business: its Second-Hand Goods Act dealer registration details and, where applicable, register entries such as serial numbers, IMEI numbers, and vehicle identification and engine numbers.

6.4 Contact information

Postal, physical, delivery, collection and return addresses; email addresses; mobile and landline telephone numbers; and your preferred contact channel.

6.5 Financial and transaction information

6.5.1 Bank account name, number, branch and account type for Vendor payouts and for Buyer refunds.

6.5.2 Order records: Items purchased or sold, Purchase Price, Delivery Charges, Order Total, Commission, VAT, dates, escrow release and refund records, and chargeback or reversal records.

6.5.3 Payment metadata received from the Payment Provider and the Escrow Provider — for example the payment reference, the payment method type, the outcome, the last four digits of a card, and the bank's response code.

6.5.4 We do not collect or store your full card number, card expiry date or card security code (CVV). Card details are entered directly with the Payment Provider on its own PCI-DSS compliant systems. We never see them.

6.6 Account and credential information

Username, display name, hashed password, password reset tokens, two-factor authentication settings and codes, security questions where used, account status, and your account preferences and settings. We store passwords in hashed form and cannot read them.

6.7 Listing and Content information

Listing text, titles, descriptions, specifications, condition disclosures, prices, photographs and videos of Items, store or shopfront descriptions, profile photographs, reviews, ratings, and any other Content you upload. Photographs may contain Personal Information — for example, a face, a number plate, an address on a package or metadata embedded in the image file.

6.8 Communications

6.8.1 In-platform messages between Buyers and Vendors, and between you and us.

6.8.2 Emails, support tickets, contact-form submissions, and WhatsApp or SMS messages you send to our published support channels.

6.8.3 Records and, where you are told at the start of the call, recordings of telephone calls with our support team — [CONFIRM: whether support calls are recorded, and if so the retention period and the wording of the pre-call notification].

6.8.4 Reviews and public interactions on our Google Business Profile.

6.9 Device and technical information

IP address; browser type and version; operating system and device type; device and browser identifiers; screen resolution and language settings; referring and exit pages; time zone; server log data; error and crash reports; and cookie and similar identifiers as described in the Cookies Policy.

6.10 Location information

Approximate location derived from your IP address, and the delivery, collection and return addresses you supply. We do not collect continuous or precise GPS location from your device — [CONFIRM: whether any mobile application collects precise device location; if it does, this clause must be rewritten and consent obtained].

6.11 Behavioural and usage information

Pages and Listings viewed, searches run, filters applied, items added to cart or wishlist, session duration and frequency, click paths, cart abandonment, email open and click events where our email platform records them, and the outcome of any A/B or usability test you are included in.

6.12 Verification outcomes and risk information

6.12.1 Verification status (for example: verified, pending, referred to human review, declined) and the reason codes attached to it.

6.12.2 Fraud, trust and risk scores generated by our systems about an account, a Listing, a device or a transaction.

6.12.3 Records of manual review decisions, moderator notes, enforcement actions, warnings, suspensions and terminations, and the reasons for them.

6.12.4 Information about suspected fraudulent, unlawful or prohibited activity, including suspected counterfeit or stolen goods, and any report we make to or receive from law enforcement or an industry body. This may include information about criminal behaviour, which is Special Personal Information (see clause 7).

6.13 Dispute information

Dispute descriptions; photographs and videos of Items, packaging and damage; courier waybills, tracking records and proof-of-delivery signatures; inspection and repair reports; correspondence between the parties; and the determination we issue.

6.14 Personal Information about other people that you give us

6.14.1 You may give us Personal Information about someone else — most often an alternate delivery recipient, a person at a security gate or reception, an emergency or alternative contact, a beneficial owner of a business Vendor, or a person appearing in evidence you upload for a Dispute.

6.14.2 If you do this, you warrant that you are entitled to give us that information, that you have informed that person of the matters in section 18 of POPIA — who we are, what we will do with the information, and that they may object — and that, where the law requires their consent, you have obtained it.

6.14.3 You indemnify us against any claim, fine or loss arising from a breach of the warranty in clause 6.14.2, subject to clause 6.14.4.

6.14.4 That indemnity does not apply to loss caused by our own gross negligence or intentional misconduct, and nothing in this Policy limits any liability that may not lawfully be limited.

6.14.5 Please do not upload other people's Personal Information into a Listing, a message or Dispute evidence unless it is necessary. Blur faces, number plates and address labels where you can.

6.15 Information we receive from others

6.15.1 From our verification provider: identity verification outcomes and match results.

6.15.2 From the Payment Provider and the Escrow Provider: payment, settlement, refund, chargeback and escrow release records.

6.15.3 From couriers: collection, tracking, delivery and failed-delivery records, and proof of delivery.

6.15.4 From other Users: reviews, ratings, reports and Dispute evidence about you.

6.15.5 From publicly available sources and, where lawful, from fraud-prevention and sanctions or politically-exposed-person screening sources.

6.15.6 From Google Analytics and Google Business Profile, in the form of aggregated statistics and public reviews and interactions.

6.16 Information we do not want

We do not ask for, and you should not send us, information about your health, religious or philosophical beliefs, political persuasion, trade union membership, race or ethnic origin, or sex life. If you send it to us anyway, we will delete it unless we are legally required to keep it.


7. Special Personal Information, biometrics, unique identifiers and prior authorisation

7.1 Section 26 of POPIA prohibits the processing of Special Personal Information unless section 27 or a specific authorisation applies. Two categories are relevant to us:

7.1.1 Biometric information — the selfie image and the liveness and face-match data processed during identity verification; and

7.1.2 Information about criminal behaviour, or about unlawful or objectionable conduct — records we create or receive about suspected fraud, counterfeiting, the sale of stolen or prohibited goods, and similar conduct on the Platform.

7.2 Your identity number. A South African identity number is a unique identifier as POPIA uses that term. We process it to confirm who you are, to prevent duplicate and fraudulent accounts, to meet FICA-aligned due diligence obligations, and to support the investigation of fraud. Section 57(1)(a) of POPIA requires prior authorisation from the Regulator where a responsible party processes a unique identifier for a purpose other than the one for which it was specifically intended at collection, with the aim of linking that information with information processed by other responsible parties.

7.3 The grounds we rely on. We rely on:

7.3.1 for biometric information: your express consent, given at the point of verification, under section 27(1)(a) of POPIA; and, in the alternative, section 27(1)(b), because the processing is necessary for the establishment, exercise or defence of a right or obligation in law — including our obligation to run a marketplace that is not used as a vehicle for identity fraud;

7.3.2 for information about criminal behaviour and unlawful or objectionable conduct: section 27(1)(b) of POPIA, and section 33 of POPIA, which authorises the processing of information concerning a data subject's criminal behaviour by a body charged by law with applying criminal law, or by a responsible party that obtained the information in accordance with the law, together with our legitimate interest and the legitimate interests of other Users in preventing crime on the Platform.

7.4 Consent is real consent. If you do not want your biometric information processed, you may decline the AI verification step. If you decline, we cannot verify you through that route, and we may not be able to approve you as a Vendor or to allow certain transactions. Where an alternative manual verification route exists, we will tell you what it is — [CONFIRM: whether a non-biometric manual verification route is offered, and on what terms].

7.5 [CONFIRM: whether prior authorisation from the Information Regulator is required for the biometric/unique identifier processing and criminal-behaviour screening carried out through Verify ID and the fraud-detection systems]

7.6 The question in clause 7.5 must be answered by our attorney before publication. Section 57 of POPIA requires prior authorisation before processing begins, and section 58 requires the responsible party to notify the Regulator and to suspend the relevant processing until the Regulator has completed its assessment. Three limbs of section 57 need to be considered:

7.6.1 section 57(1)(a) — processing of unique identifiers for a purpose other than the one intended at collection, with the aim of linking the information with information processed by other responsible parties;

7.6.2 section 57(1)(b) — processing information on criminal behaviour, or on unlawful or objectionable conduct, on behalf of third parties; and

7.6.3 section 57(1)(d) — the transfer of Special Personal Information, or the Personal Information of children, to a third party in a foreign country that does not provide an adequate level of protection. This limb matters because some of our Operators process outside South Africa (clause 12).

7.7 Until that question is resolved, the biometric and criminal-behaviour processing described in this clause 7 must be treated as subject to confirmation, and any processing that in fact requires prior authorisation must be suspended until authorisation is obtained.


8. Why we process your Personal Information, and our lawful justification

8.1 Section 11 of POPIA allows processing only where at least one justification applies. The table below maps each of our purposes to the justification we rely on, and, for Users in the EU or EEA to whom the GDPR applies, to the equivalent lawful basis in Article 6 of the GDPR.

8.2 Where we rely on our legitimate interests, we have weighed those interests against your rights and freedoms and have concluded that the processing is proportionate. You may ask us for a summary of that assessment by writing to data@listsecure.co.za, and you may object under clause 16.

#PurposeMain categories usedPOPIA s11 justificationGDPR equivalent (EU/EEA data subjects only)
1Creating and administering your account; authenticating you; keeping you logged inAccount and credentials; contact; devices11(1)(b) — necessary to conclude or perform the contract with youArt 6(1)(b) — contract
2Verifying your identity, including AI identity and document checks and the liveness selfieIdentity and KYC; biometric; devices11(1)(a) — consent, read with s27(1)(a) for biometric information; s11(1)(b); s11(1)(d) — protection of a legitimate interest of the data subjectArt 6(1)(a) consent, read with Art 9(2)(a) for biometric data; Art 6(1)(b)
3Verifying and moderating Listings, including AI review of Listing content and imagesListing Content; identity; risks11(1)(f) — legitimate interests of List Secure, of Buyers and of rights holders; s11(1)(c) where the law requires removalArt 6(1)(f) — legitimate interests; Art 6(1)(c)
4Publishing Listings and operating the marketplaceListing Content; Vendor identity display names11(1)(b)Art 6(1)(b)
5Processing Orders, taking payment and holding funds in escrowFinancial and transaction; contact; Orders11(1)(b)Art 6(1)(b)
6Arranging delivery, tracking and returnsContact; location and addresses; Orders11(1)(b)Art 6(1)(b)
7Handling Disputes and issuing determinationsDispute; Order; communicationss11(1)(b); s11(1)(d); s11(1)(f)Art 6(1)(b); Art 6(1)(f)
8Paying Vendors, calculating Commission, and reconciling accountsFinancial; identity; Orders11(1)(b); s11(1)(c)Art 6(1)(b); Art 6(1)(c)
9Fraud detection and prevention; risk scoring of accounts, Listings, devices and transactions; investigating suspected unlawful conductRisk and verification outcomes; device; behavioural; criminal-behaviour informations11(1)(f) — legitimate interests; s11(1)(d) — protection of a legitimate interest of the data subject; s11(1)(c) where reporting is required, read with s27(1)(b) and s33 for criminal-behaviour informationArt 6(1)(f); Art 6(1)(c); Art 9(2)(f)/(g) where applicable
10Customer support and communication with youCommunications; account; Orders11(1)(b); s11(1)(f)Art 6(1)(b); Art 6(1)(f)
11Transactional and service messages (Order confirmations, dispatch, escrow release, security alerts, policy changes)Contact; Orders11(1)(b); s11(1)(c)Art 6(1)(b); Art 6(1)(c)
12Direct marketing to existing customers about our own similar products or servicesContact; Order historys11(1)(f), read with s69(3) of POPIA — the soft opt-in; see clause 17Art 6(1)(f), read with the ePrivacy soft opt-in
13Direct marketing to people who are not our customersContacts11(1)(a) — consent, obtained in Form 3 under s69(2)Art 6(1)(a) — consent
14Analytics, measurement and improving the PlatformBehavioural; device; cookiess11(1)(a) — consent for non-essential cookies (see the Cookies Policy); s11(1)(f) for aggregated and de-identified analysisArt 6(1)(a) for cookies; Art 6(1)(f)
15Security of the Platform, logging, access control, and preventing unlawful access under the Cybercrimes ActDevice; account; server logss11(1)(f); s11(1)(c)Art 6(1)(f); Art 6(1)(c)
16Meeting legal, tax, accounting and record-keeping obligations, including FICA-aligned records and VAT recordsIdentity; financial; Orders11(1)(c) — obligation imposed by lawArt 6(1)(c)
17Responding to lawful requests from law enforcement, regulators, SARS or a courtAny relevant categorys11(1)(c); s11(1)(e) where it supports a public body's public law dutyArt 6(1)(c); Art 6(1)(e)
18Establishing, exercising or defending legal claims, including debt collectionAny relevant categorys11(1)(f); s11(1)(c)Art 6(1)(f); Art 6(1)(c)
19Corporate transactions — a merger, sale or restructureAccount; Order; Vendor recordss11(1)(f)Art 6(1)(f)
20Research, statistics and reporting using de-identified or aggregated dataDe-identified datas11(1)(f); s6 of POPIA where the data is de-identified and cannot be re-identifiedArt 6(1)(f); Art 89 safeguards

8.3 Further processing. If we want to use your Personal Information for a purpose that is not in the table and is not compatible with the purpose for which it was collected, we will tell you and, where the law requires it, obtain your consent, as sections 15 and 18 of POPIA require.

8.4 Withdrawing consent. Where we rely on consent, you may withdraw it at any time by writing to data@listsecure.co.za or by using the relevant setting in your account. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing we carry out on a different justification — for example, records we must keep by law.


9. AI, automated processing and automated decision-making

9.1 We use automated systems, including artificial intelligence and machine learning models, as part of how we run the Platform. We describe them here plainly, because you are entitled to know how decisions about you are reached.

9.2 What our automated systems do

9.2.1 Identity verification. During onboarding, automated systems compare the identity document you upload against the selfie you take, run liveness checks to detect a photograph, mask or replayed video, read the data on the document, and query identity databases through our verification provider. The system produces a match score and a recommended outcome.

9.2.2 Listing verification and moderation. Automated systems analyse Listing text and images to detect prohibited or restricted Items, suspected counterfeit goods, duplicated or stolen images, misleading claims, off-Platform payment solicitation, and Listings that breach the Marketplace Rules.

9.2.3 Fraud and risk scoring. Automated systems score accounts, devices, Listings and transactions for fraud risk, using signals such as device and network characteristics, behaviour patterns, velocity of activity, verification outcomes, payment signals and prior enforcement history.

9.2.4 Operational automation. Automated systems also carry out routine tasks such as sending transactional messages, ranking search results, recommending Items, and flagging Orders for review.

9.3 Human oversight

9.3.1 A decision that has legal consequences for you, or that affects you to a substantial degree, is not made solely by automated means. Those decisions include:

9.3.1.1 declining or reversing your identity verification;

9.3.1.2 rejecting or removing a Listing;

9.3.1.3 restricting, suspending or terminating your account;

9.3.1.4 holding, delaying or reversing a payout or an escrow release; and

9.3.1.5 issuing a Dispute determination.

9.3.2 In each of those cases an automated system may flag, score, prioritise or recommend, but a trained member of our team reviews the matter and takes the decision. Our verification is described throughout our documents as "AI verification with human oversight", and this clause states precisely what that means.

9.3.3 The exception is an urgent, temporary and precautionary measure — for example an automatic hold on a payout, or the temporary hiding of a Listing, where an automated system detects a strong fraud signal and waiting for a human would put another User's money or safety at risk. Where that happens:

9.3.3.1 the measure is temporary;

9.3.3.2 we place the matter in the human review queue as soon as possible, and in any event within [INSERT: number] Business Days; and

9.3.3.3 you may ask for immediate human review under clause 9.4.

9.4 Your rights over automated decisions

9.4.1 Section 71 of POPIA gives you the right not to be subject to a decision that results in legal consequences for you, or that affects you to a substantial degree, if that decision is based solely on the automated processing of Personal Information intended to provide a profile of you.

9.4.2 If you believe a decision about you was made solely by automated means, or if you disagree with a decision that was informed by automated processing, you may:

9.4.2.1 ask for human intervention and a fresh review by a person;

9.4.2.2 make representations about the decision, and give us information you say we did not take into account; and

9.4.2.3 ask us for sufficient information about the underlying logic of the automated processing to understand how the decision was reached.

9.4.3 Send the request to data@listsecure.co.za with the words "Automated decision review" in the subject line, together with your account details and the reference of the decision. We will acknowledge within [INSERT: number] Business Days and give you a reasoned outcome within 30 days.

9.4.4 There are limits on clause 9.4.2.3. We will not disclose information that would reveal a trade secret, that would tell a fraudster how to defeat our controls, or that would compromise another person's Personal Information or an ongoing investigation. We will still tell you the general basis of the decision and the main factors that counted against you.

9.4.5 If you are in the EU or EEA and the GDPR applies to you, Article 22 of the GDPR gives you an equivalent right, and Articles 13(2)(f) and 15(1)(h) require us to give you meaningful information about the logic involved and the significance and envisaged consequences of the processing.

9.5 What our automated systems are not

9.5.1 Verification reduces risk. It does not eliminate it. A verified Vendor is a Vendor whose identity has passed our checks at a point in time. It is not a guarantee, endorsement or warranty by us of that Vendor, that Vendor's Listings, or any Item.

9.5.2 Automated systems make mistakes. They can produce false positives and false negatives. That is exactly why the human review right in clause 9.4 exists, and we encourage you to use it.

9.5.3 We do not use your Personal Information to train general-purpose AI models for third parties. [CONFIRM: whether any Platform data is used to train or fine-tune models, whether models are supplied by a third party, and whether that third party may use Platform data for its own model training — the answer must be reflected here and in the Operator agreements]


10. Who we share your Personal Information with

10.1 We do not sell your Personal Information. We do not rent it, and we do not trade it for value with data brokers or advertisers.

10.2 We share Personal Information only as set out in this clause.

10.3 Vendors

As described in clause 4, when you place an Order we give the Vendor the delivery and contact details it needs to fulfil that Order. The Vendor then processes that information as an independent responsible party, bound by clause 4.5 of this Policy and by clause 18 of the Vendor Agreement.

10.4 Buyers

We give a Buyer the Vendor's trading name, store details, published contact route and any information the Buyer needs in order to exercise its rights against the Vendor — including, where a Dispute or a legal claim requires it, the Vendor's identifying and contact details. Vendors should understand that a marketplace cannot shield a supplier's identity from a consumer who needs it to enforce a right.

10.5 Our Operators and other recipients

RecipientWhat they do for usCategories of Personal InformationPOPIA justificationDoes data cross SA borders?
WordPress (Automattic)Website platform, Content management system and, where used, hosting-related servicesAccount, Listing Content, communications submitted through the site, server log and device datas11(1)(b); s11(1)(f)[CONFIRM: whether the WordPress installation is hosted in South Africa or abroad — Automattic and its infrastructure providers are ordinarily outside South Africa. Identify the actual hosting location and provider]
ElementorWebsite builder and page-editing software used to build and serve Platform pagesLimited: usage and technical data, and any form data submitted through Elementor formss11(1)(f)Yes — Elementor processes in Israel, the EU and the United States
MultiVendorXMulti-vendor marketplace software that runs Vendor stores, Orders and Vendor dashboardsVendor account and store data, Order data, Buyer delivery and contact data attached to Orders, Commission recordss11(1)(b)Yes — India [CONFIRM: whether MultiVendorX is self-hosted software only, or whether the vendor accesses or supports the installation from India; this determines the s72 analysis]
PayFast (a Network International company)Payment gateway — collecting Buyer payments and processing refundsName, contact details, payment instrument data collected directly by PayFast, transaction amount and reference, outcome codess11(1)(b); s11(1)(c)No, for core processing — PayFast operates in South Africa and is PCI-DSS compliant [CONFIRM: whether any group processing or support occurs outside South Africa following the Network International acquisition]
TradeSafeEscrow and transaction protection — holding Order funds in an escrow trust account and releasing them on the agreed triggerName, contact details, identity details where TradeSafe's own onboarding requires them, bank account details, transaction and release recordss11(1)(b); s11(1)(c)[CONFIRM: TradeSafe's processing and hosting locations] — understood to be South Africa
Verify IDIdentity verification and KYC — ID number validation, document authentication, face match and liveness checksIdentity number, identity document images, selfie and liveness data (biometric information), date of birth, verification outcomess11(1)(a) with s27(1)(a) for biometric information; s11(1)(b); s11(1)(d)[CONFIRM: Verify ID's processing and hosting locations and whether any sub-operator processes outside South Africa] — understood to be South Africa
Google AnalyticsWebsite analytics and measurementIP address (truncated where the setting is enabled), cookie identifiers, pages viewed, events, approximate location, device datas11(1)(a) — consent through the cookie bannerYes — the United States and other countries in which Google operates
Google Business ProfileOur public business listing, reviews and customer interactionsReviewer name and content, interaction data, any information you choose to post publiclys11(1)(f)Yes — the United States and other countries in which Google operates
[INSERT: courier partners]Collection, transport, delivery, tracking and returnsRecipient name, delivery address, contact number, Order reference, delivery instructions, proof of deliverys11(1)(b)[CONFIRM: each courier's processing locations — most South African couriers process locally]
[INSERT: email/marketing platform]Transactional email, SMS and marketing messagesName, email address, mobile number, message and campaign engagement data, Order-triggered fieldss11(1)(b) for transactional; s11(1)(a) or s69(3) for marketing[CONFIRM: the platform's processing location — most major providers process in the United States or the EU]
Professional advisersAttorneys, auditors, accountants, tax advisers and insurersOnly what the specific matter requiress11(1)(c); s11(1)(f)[CONFIRM: whether any adviser is outside South Africa]
Law enforcement, regulators, SARS and courtsInvestigation, reporting and legal complianceOnly what the request or the law requiress11(1)(c); s11(1)(e)Ordinarily no
An acquirer or funderDue diligence for, and implementation of, a merger, acquisition, funding round, restructure or sale of the business or its assetsAccount, Order and Vendor records, ordinarily aggregated or pseudonymised at the due diligence stages11(1)(f)[CONFIRM: at the time of any such transaction]
Our staff and contractorsOperating the Platform, support, moderation, verification review and dispute handlingAs needed for the role, subject to role-based access controls11(1)(b); s11(1)(f)No

10.6 Business transfers

If our business, or a material part of it, is sold, merged or restructured, Personal Information may be transferred to the acquirer as part of the transaction. We will require the acquirer to continue to process it in accordance with a policy no less protective than this one, and we will notify you of any material change in the responsible party.

10.7 Public information

Some information is public by design: your Vendor store name and public store details, your Listings, and any review or public comment you post. Do not put information in those places that you do not want the world to see.

10.8 Aggregated and de-identified information

We may create and share aggregated or de-identified statistics — for example, category sales trends — that cannot reasonably be linked back to you. Section 6 of POPIA does not apply to information that has been de-identified to the extent that it cannot be re-identified. We do not attempt to re-identify de-identified data, and we require our recipients not to.


11. Operator agreements — how we control our suppliers

11.1 Section 20 of POPIA requires an Operator to process Personal Information only with our knowledge or authorisation and to treat it as confidential. Section 21 requires us to conclude a written contract with every Operator and to ensure that the Operator establishes and maintains the security measures required by section 19.

11.2 Before we appoint an Operator we carry out due diligence on its security, its sub-processing, its location and its track record, proportionate to the sensitivity of the data involved.

11.3 Every Operator agreement we conclude requires the Operator to:

11.3.1 process Personal Information only on our documented instructions and only for the purposes we specify;

11.3.2 treat the Personal Information as confidential and impose confidentiality obligations on its own personnel;

11.3.3 establish and maintain appropriate, reasonable technical and organisational measures under section 19 of POPIA;

11.3.4 notify us immediately, and in any event within [INSERT: security compromise notification period — number of hours], where there are reasonable grounds to believe that the Personal Information has been accessed or acquired by an unauthorised person, as section 21(2) of POPIA requires;

11.3.5 not appoint a sub-operator without our prior written authorisation, and to remain liable for its sub-operators;

11.3.6 assist us in responding to data subject requests, to the Regulator and to a security compromise;

11.3.7 not transfer Personal Information out of South Africa except as clause 12 permits;

11.3.8 delete or return the Personal Information at the end of the engagement, except where it must keep it by law; and

11.3.9 submit to audit or to the provision of evidence of compliance, at a frequency proportionate to the risk.

11.4 [CONFIRM: that signed, POPIA-compliant Operator agreements (or acceptable data processing addenda) are in place with each provider named in clause 10.5, and diarise a review of each]

11.5 Where a provider is not, in law, an Operator but is itself a responsible party — for example the Payment Provider and the Escrow Provider acting under their own regulatory obligations, and a Vendor under clause 4 — that provider is accountable in its own right for the processing it controls.


12. Sending Personal Information outside South Africa

12.1 Section 72 of POPIA restricts the transfer of Personal Information to a recipient in a foreign country. We may transfer only where one of the section 72(1) grounds applies.

12.2 Based on clause 10.5, the transfers we currently make or may make are:

RecipientCountry or regionSection 72 ground relied onSafeguards
ElementorIsrael, the EU and the United Statess72(1)(a) — the recipient is subject to a binding agreement that provides an adequate level of protection; and, for Israel and the EU, laws that uphold principles for the reasonable processing of information substantially similar to POPIAData processing addendum with POPIA and GDPR terms; EU Standard Contractual Clauses where the provider offers them; limited technical and form data only
MultiVendorXIndias72(1)(a) — binding agreement; alternatively s72(1)(c) — necessary for the performance of the contract between you and usData processing addendum; restriction of access to support cases; [CONFIRM: whether any Order or Buyer data is in fact accessible from India, or whether the software is self-hosted with no supplier access]
Google Analytics and Google Business ProfileThe United States and other countries in which Google operatess72(1)(b) — your consent to non-essential cookies; s72(1)(a) — binding agreementGoogle's data processing terms and Standard Contractual Clauses; IP truncation where available; retention controls set to the shortest practical period
WordPress (Automattic) and the hosting provider[CONFIRM: hosting location]s72(1)(a); alternatively s72(1)(c)[INSERT: hosting agreement and security terms]
[INSERT: email/marketing platform][CONFIRM: processing location]s72(1)(a); s72(1)(c) for transactional messagesData processing addendum; Standard Contractual Clauses where applicable

12.3 We take reasonable steps to satisfy ourselves that the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, that upholds principles for reasonable processing substantially similar to POPIA's conditions, and that includes provisions substantially similar to section 72 for onward transfers.

12.4 Special category caution. We do not send identity document images, biometric information or the Personal Information of children to a recipient outside South Africa except where clause 7 has been resolved and, if required, prior authorisation has been obtained under section 57(1)(d) of POPIA. [CONFIRM: that no biometric or ID document data leaves South Africa through any Operator, including any sub-operator of the verification provider]

12.5 If you are in the EU or EEA, transfers of your Personal Information to South Africa or elsewhere are made on the basis of the European Commission's Standard Contractual Clauses or another Chapter V transfer mechanism, with a transfer impact assessment where required.

12.6 You may ask us for a copy of the safeguards relied on for a particular transfer by writing to data@listsecure.co.za. We may redact commercially sensitive terms.


13. How we protect your Personal Information

13.1 Section 19 of POPIA requires us to secure the integrity and confidentiality of Personal Information by taking appropriate, reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction, and unlawful access or processing.

13.2 The measures we apply include:

13.2.1 encryption of data in transit using TLS across the Platform, and encryption at rest for [CONFIRM: which data stores are encrypted at rest];

13.2.2 storage of passwords using a salted one-way hash — we cannot read your password;

13.2.3 role-based access control, so that staff see only what their role requires, with access to identity documents and biometric records restricted to [INSERT: which roles may access identity and biometric records];

13.2.4 two-factor authentication for administrative accounts;

13.2.5 audit logging of administrative access to Personal Information, and periodic review of those logs;

13.2.6 network and application protections, including a firewall, rate limiting and bot protection — [CONFIRM: whether Cloudflare or another WAF/CDN is used];

13.2.7 vulnerability management, patching of the WordPress core, themes and plugins, and [CONFIRM: frequency of vulnerability scanning and whether penetration testing is carried out, and how often];

13.2.8 backups, with [INSERT: backup frequency, retention and restore-testing schedule];

13.2.9 confidentiality undertakings and POPIA awareness training for staff and contractors — [CONFIRM: that POPIA training is delivered at induction and refreshed annually];

13.2.10 vetting of staff with access to identity and financial data, to the extent lawful;

13.2.11 segregation of payment card data, which we never hold, and reliance on the Payment Provider's PCI-DSS environment; and

13.2.12 a documented incident response plan, tested at [INSERT: frequency of incident response testing].

13.3 We regularly verify that these safeguards are effectively implemented, as section 19(2)(c) of POPIA requires, and we update them continually in response to new risks and to deficiencies we identify, as section 19(2)(d) requires.

13.4 We cannot promise absolute security. No website, database or transmission over the internet is completely secure. We take the measures described above and we take them seriously, but we do not and cannot guarantee that your Personal Information will never be accessed, disclosed, altered or destroyed unlawfully.

13.5 What you must do. You must:

13.5.1 keep your password confidential, use a password that you do not use anywhere else, and enable two-factor authentication where we offer it;

13.5.2 not share your account with anyone;

13.5.3 keep the device and email account you use with the Platform secure;

13.5.4 be alert to phishing — we will never ask you for your password, your card number, your card security code or a one-time PIN by email, SMS, WhatsApp or telephone;

13.5.5 keep all communication and payment on the Platform, because payments made off-Platform are outside escrow and outside our protections; and

13.5.6 tell us immediately if you think your account has been accessed by someone else.


14. Security compromises

14.1 A "security compromise" means a situation where there are reasonable grounds to believe that Personal Information of a data subject has been accessed or acquired by an unauthorised person.

14.2 What we do

14.2.1 Contain and assess. When we become aware of a possible compromise, we immediately begin containment, preserve evidence, and assess the scope, the categories of Personal Information involved, the number of data subjects affected and the likely consequences.

14.2.2 Notify the Regulator. Where a security compromise has occurred, we notify the Information Regulator as soon as reasonably possible after discovering the compromise, as section 22(1) and (2) of POPIA require. We do not delay notification while an investigation is completed; we supplement our report as facts emerge.

14.2.3 Notify affected data subjects. We also notify each affected data subject as soon as reasonably possible after discovering the compromise, unless the identity of the data subject cannot be established. We may delay a notification only if a public body responsible for the prevention, detection or investigation of offences, or the Regulator, tells us that notification will impede a criminal investigation — and we notify as soon as that no longer applies.

14.2.4 How we notify you. Notification will be in writing and communicated in at least one of the manners permitted by section 22(4) of POPIA:

14.2.4.1 by email to your last known email address;

14.2.4.2 by post to your last known physical or postal address;

14.2.4.3 by placing it prominently on the Platform;

14.2.4.4 by publication in the news media; or

14.2.4.5 in any other manner the Regulator directs.

14.2.5 What the notification will say. As section 22(5) of POPIA requires, the notification will contain enough information to allow you to take protective measures, including:

14.2.5.1 a description of the possible consequences of the compromise;

14.2.5.2 a description of the measures we intend to take, or have taken, to address it;

14.2.5.3 a recommendation about what you can do to mitigate the possible adverse effects; and

14.2.5.4 if we know it, the identity of the unauthorised person who may have accessed or acquired the Personal Information.

14.2.6 Record. We keep a register of all security compromises and near misses, including those that do not meet the notification threshold, together with the assessment that led to that conclusion.

14.2.7 Other reporting. Where the compromise involves an offence under the Cybercrimes Act 19 of 2020, we consider our reporting obligations under that Act, including the 72-hour reporting obligation that applies to certain categories of entity — [CONFIRM applicability]. Where it involves payment data, we report to the Payment Provider and the Escrow Provider in terms of our agreements with them.

14.2.8 EU/EEA. Where the GDPR applies, we notify the competent supervisory authority within 72 hours where Article 33 requires it, and affected data subjects without undue delay where Article 34 requires it.

14.3 What you must do

14.3.1 If you suspect that your account has been accessed without your authority, that your Personal Information has been compromised, or that you have received a phishing message that appears to come from us, you must:

14.3.1.1 change your password immediately and enable two-factor authentication;

14.3.1.2 report it to us at data@listsecure.co.za, marked "Suspected security compromise", giving the date, what you saw, and any message headers, screenshots or references you have;

14.3.1.3 not delete the evidence; and

14.3.1.4 where money is involved, also notify your bank and the Payment Provider without delay.

14.3.2 We will acknowledge a report under clause 14.3.1 within [INSERT: number] Business Days and tell you the outcome of our assessment.

14.3.3 Reporting a suspected compromise to us does not replace any report you may need to make to the South African Police Service or to your bank.


15. How long we keep your Personal Information

15.1 Section 14 of POPIA says we may not keep records of Personal Information for longer than is necessary for the purpose we collected them for, unless a law requires or authorises us to keep them longer, we need them for a lawful purpose related to our functions or activities, a contract requires it, or you have consented.

15.2 The table below sets out our retention approach. Every period marked for insertion must be fixed by the business, with our attorney, before publication.

Data categoryRetention periodBasis for the period
Account records for an active accountFor as long as the account is activeNecessary to perform the contract
Account records after closure[INSERT: retention period after account closure] from closureHandling residual claims, chargebacks and Disputes; then deletion or de-identification
Identity and KYC verification records, including ID number, ID document images and verification outcomes[INSERT: retention period — draft assumes five years from the end of the business relationship or from the date of the transaction]FICA-aligned record keeping; fraud prevention. [CONFIRM with attorney: whether the five-year FIC Act record-keeping period applies to List Secure, and if not, what shorter period should apply — ID and biometric data must not be kept longer than necessary]
Selfie image and biometric liveness data[INSERT: retention period for biometric data — this should be the shortest period that is defensible, and should be shorter than the ID record period unless there is a specific reason][CONFIRM: whether the raw selfie image can be deleted once verification is complete, and only the outcome and a non-reversible template retained]
Transaction, Order, escrow, payment, refund and Commission records[INSERT: retention period — draft assumes five years]FICA-aligned record keeping; and see the accounting and tax rows below
Accounting records and supporting documentsSeven yearsSection 24 of the Companies Act 71 of 2008 and the Companies Regulations [CONFIRM: the exact record classes and periods with our auditor]
Tax records, including VAT recordsFive years from the date of submission of the returnSection 29 of the Tax Administration Act 28 of 2011 [CONFIRM with our tax adviser]
Second-Hand Goods Act register entries kept by a Vendor dealing in second-hand goods as a businessFive yearsSecond-Hand Goods Act 6 of 2009. [CONFIRM: whether List Secure itself holds any register obligation, or whether the obligation rests only on the Vendor as the dealer — the draft assumes the latter]
Dispute records and evidence[INSERT: retention period] from the date of the determinationDefence of claims; prescription periods
Fraud, risk and enforcement records, including records of accounts we have terminated[INSERT: retention period]Preventing a terminated User from simply re-registering; investigating repeat conduct; legitimate interests under s11(1)(f)
In-platform messages between Buyers and Vendors[INSERT: retention period]Dispute evidence and fraud investigation
Support tickets and correspondence[INSERT: retention period]Service history and complaint handling
Marketing contact records and consent recordsUntil you opt out, and then a suppression record kept indefinitelyProof of consent and proof of opt-out; we must keep enough to honour your opt-out
Server logs, security logs and device data[INSERT: retention period — draft assumes 12 months]Security, incident investigation and Cybercrimes Act evidence
Analytics dataAs set in the Google Analytics data retention setting — [INSERT: the retention setting configured, for example 14 months]Consent; the Cookies Policy
Backups[INSERT: backup retention period]Business continuity. Data deleted from live systems persists in backups until the backup cycle expires
Records subject to a litigation hold, a regulatory investigation or a law enforcement requestUntil the matter is finally resolvedLegal obligation and defence of claims

15.3 When a retention period ends, we securely delete the Personal Information or de-identify it so that it can no longer be linked to you. Where deletion is not immediately possible — for example in a backup — we isolate the information and protect it from further processing until deletion is possible.

15.4 If you ask us to delete your Personal Information, we will do so unless we have a lawful ground to keep it. If we keep some of it, we will tell you which categories we have kept and why.


16. Your rights, and how to exercise them

16.1 Section 5 of POPIA gives you the following rights. You may:

16.1.1 be notified that we are collecting your Personal Information, and be notified where it has been accessed or acquired by an unauthorised person (sections 18 and 22);

16.1.2 ask us to confirm, free of charge, whether we hold Personal Information about you, and to be given a record or description of it, together with the identity of anyone who has had access to it (section 23);

16.1.3 ask us to correct or delete Personal Information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully (section 24);

16.1.4 ask us to destroy or delete a record of Personal Information that we are no longer authorised to keep (section 24);

16.1.5 object, on reasonable grounds, to the processing of your Personal Information (section 11(3));

16.1.6 object at any time, and without giving reasons, to the processing of your Personal Information for direct marketing by unsolicited electronic communication (sections 11(3) and 69);

16.1.7 not have your Personal Information processed for direct marketing by unsolicited electronic communication unless clause 17 permits it;

16.1.8 not be subject to a decision based solely on automated processing that has legal consequences for you or affects you to a substantial degree (section 71 — see clause 9);

16.1.9 submit a complaint to the Regulator about an alleged interference with the protection of your Personal Information (sections 74 and 99); and

16.1.10 institute civil proceedings for a breach of your rights under POPIA (section 99).

16.2 If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection under Articles 15 to 21, and the right to lodge a complaint with your local supervisory authority.

16.3 The prescribed forms

16.3.1 Form 1 — objection to the processing of Personal Information, under Regulation 2 of the POPIA Regulations, 2018.

16.3.2 Form 2 — request for the correction or deletion of Personal Information, or for the destruction or deletion of a record, under Regulation 3.

16.3.3 Form 3 — consent to the processing of Personal Information for the purpose of direct marketing, under Regulation 6 (see clause 17).

16.3.4 Form 5 — complaint to the Information Regulator, under Regulation 11 (see clause 21).

16.3.5 We publish Forms 1, 2 and 3 on the Platform at [INSERT: link to the page hosting Forms 1, 2 and 3]. You may also download them from the Regulator's website. If you would rather not use a form, you may simply write to us and tell us what you want — we will not refuse a request because it is not on a form.

16.4 How to make a request

16.4.1 Send your request to data@listsecure.co.za, or by post to the Information Officer at 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa.

16.4.2 In line with the POPIA Regulations as amended in April 2025, we also accept objections and correction or deletion requests through the following accessible channels:

16.4.2.1 email: data@listsecure.co.za;

16.4.2.2 SMS or WhatsApp: [INSERT: the WhatsApp/SMS number to be published for privacy requests];

16.4.2.3 the request form in your account settings at [INSERT: link to the in-account privacy request form]; and

16.4.2.4 telephone, where you are unable to use a written channel: [CONFIRM: +27 28 123 4567 — the number currently on the website appears to be a placeholder].

16.4.3 Tell us:

16.4.3.1 what you want us to do;

16.4.3.2 which Personal Information the request relates to, if you can identify it; and

16.4.3.3 the email address or account you use with us, so that we can find your records.

16.5 Cost

16.5.1 A request to confirm whether we hold Personal Information about you is free.

16.5.2 An objection under Form 1, and a request for correction or deletion under Form 2, are free of charge, in line with the POPIA Regulations as amended in April 2025.

16.5.3 We may charge the prescribed fee for providing a copy of the actual record of your Personal Information under section 23(1)(b) of POPIA and the PAIA fee schedule. If a fee applies, we will tell you what it is and give you the chance to withdraw or narrow your request before we do the work.

16.6 Verifying who you are

16.6.1 Before we act on a request, we must be satisfied that you are the data subject, or a person authorised to act for the data subject. This protects you.

16.6.2 We may ask you to confirm the request from the email address registered on your account, to answer questions only the account holder could answer, or to provide proof of identity. Where you act for someone else, we will ask for a power of attorney, a parental or guardian confirmation, or a letter of authority.

16.6.3 We ask only for what is necessary to verify you. We do not use identity information supplied for verification for any other purpose, and we delete it once the request is closed unless we must keep a record that the request was properly verified.

16.7 Our response

16.7.1 We will acknowledge your request within [INSERT: number] Business Days.

16.7.2 We will respond substantively within 30 days of receiving a request that we can act on. Where a request is complex or where we need more information from you, we may extend that period once, by a further 30 days, and we will tell you before the first period ends why we need the extra time.

16.7.3 We will notify you in writing of the action taken on your request, as the POPIA Regulations as amended in April 2025 require. If we refuse a request, in whole or in part, we will tell you the reason and tell you that you may complain to the Regulator.

16.7.4 If we correct or delete Personal Information, and it is reasonable to do so, we will notify each person to whom we disclosed that information of the correction or deletion, as section 24(3) of POPIA requires.

16.7.5 Where you dispute the accuracy of Personal Information and we are not able to agree on a correction, you may ask us to attach to the record, in a manner that means it will always be read with the information, an indication that a correction was requested but not made, as section 24(2)(d) of POPIA allows.

16.8 When we may refuse

We may refuse a request where POPIA or PAIA permits or requires refusal — for example where the information is subject to legal professional privilege, where disclosure would reveal another person's Personal Information, where it would prejudice the prevention or investigation of an offence, or where we are required by law to keep the record. We will always explain our reason.


17. Direct marketing

17.1 "Direct marketing" means approaching you, in person or by mail or electronic communication, to promote or offer goods or services, or to ask for a donation.

17.2 If you are not our customer

17.2.1 Section 69(1) of POPIA prohibits direct marketing by unsolicited electronic communication unless you have given consent, or you are our customer as clause 17.3 describes.

17.2.2 If you have not bought from us, we may approach you only once to ask for your consent, and we must do so in the prescribed manner and form — Form 3 under Regulation 6 of the POPIA Regulations, 2018. If you do not respond, or you say no, we may not approach you again.

17.2.3 We will not send you marketing on that basis unless and until you have given consent in Form 3 or an equivalent, properly recorded, express opt-in.

17.3 If you are our customer — the section 69(3) soft opt-in

17.3.1 Section 69(3) of POPIA allows us to send you direct marketing by electronic communication without separate consent if all of the following are true:

17.3.1.1 we obtained your contact details in the context of the sale of an Item or service to you;

17.3.1.2 we are marketing our own similar products or services;

17.3.1.3 you were given a reasonable opportunity to object, free of charge and without unnecessary formality, when we collected your details; and

17.3.1.4 you are given that same opportunity to object in every message we send you.

17.3.2 We rely on this soft opt-in for messages such as new categories on the Platform, seller tips, and offers on similar Items. We do not rely on it to market a third party's products, and we do not pass your details to a third party for that third party's marketing.

17.4 Every marketing message

17.4.1 Every marketing message we send will:

17.4.1.1 identify List Secure as the sender, and give our contact details;

17.4.1.2 tell you, on request, the identifying particulars of the source from which we obtained your contact details, as section 45(1)(b) of ECTA requires; and

17.4.1.3 contain a clear, free and simple way to opt out — an unsubscribe link in an email, a reply keyword such as STOP in an SMS or WhatsApp message, and the marketing preference settings in your account.

17.4.2 Section 45 of ECTA also makes it an offence to send further unsolicited commercial communications to a person after that person has opted out. We honour opt-outs promptly, and in any event within [INSERT: number] Business Days.

17.5 An opt-out mechanism is not consent

17.5.1 The presence of an unsubscribe link, a "reply STOP" instruction, or any other opt-out mechanism is not consent to direct marketing. Silence is not consent. A pre-ticked box is not consent. This is confirmed by the POPIA Regulations as amended in April 2025.

17.5.2 Consent under POPIA must be a voluntary, specific and informed expression of will. We record when, how and for what you gave consent, and we can produce that record.

17.6 Transactional messages are not marketing

Messages we must send you to run the service — Order confirmations, dispatch and delivery notifications, escrow and payment notices, Dispute updates, security alerts, invoices, and notices of changes to the Platform Terms — are not direct marketing. You cannot opt out of them while you hold an account, because we need them to perform our contract with you.

17.7 Cooling-off after direct marketing

If you conclude a transaction as a result of direct marketing, section 16 of the Consumer Protection Act gives you five Business Days to cancel without reason or penalty. That right is separate from, and in addition to, the seven-day cooling-off right for electronic transactions in section 44 of ECTA. The Returns & Refunds Policy explains both.

17.8 Changing your preferences

Use the marketing preferences in your account, the unsubscribe link in any message, or write to data@listsecure.co.za. We do not charge for this and we do not ask you to give a reason.


18. Children's Personal Information

18.1 The Platform is not for children. You must be at least 18 years old to register as a User, to place an Order or to list an Item.

18.2 Section 34 of POPIA prohibits the processing of the Personal Information of a child — a person under 18 who is not legally competent to take the action in question — unless one of the grounds in section 35 applies, such as the prior consent of a competent person, or where the processing is necessary for the establishment, exercise or defence of a right or obligation in law.

18.3 We do not knowingly collect Personal Information from a child, and we do not knowingly allow a child to register.

18.4 If we learn that a child has registered or has given us Personal Information, we will:

18.4.1 suspend the account immediately;

18.4.2 stop all processing except what is needed to close the account, to complete or reverse any transaction already in progress, and to meet a legal obligation;

18.4.3 delete the child's Personal Information within [INSERT: number] Business Days, unless we are required by law to keep a record, in which case we restrict it and keep only what the law requires;

18.4.4 cancel or reverse any open Order, and return any funds held in escrow in accordance with the Payment Terms; and

18.4.5 record the incident and, where a competent person contacts us, confirm to them in writing what we have done.

18.5 If you are a parent or guardian and you believe a child has given us Personal Information, contact data@listsecure.co.za and we will act under clause 18.4.

18.6 A separate point for Vendors: section 21 of the Second-Hand Goods Act 6 of 2009 prohibits a dealer from acquiring second-hand goods from a person under 18. Vendors dealing in second-hand goods as a business must have controls to prevent this.

18.7 A photograph or Content that a User uploads may contain a child's image — for example a child's clothing item modelled by a child. Do not upload images of identifiable children. We may remove Listings that do.


19. Cookies and similar technologies

19.1 We use cookies, pixels, local storage and similar technologies on the Platform.

19.2 This Policy does not repeat the detail. The Cookies Policy explains what we use, why, whether consent is required, how long each category lasts, and how you can manage or refuse them. Read it at [INSERT: link to Cookies Policy].

19.3 In short: strictly necessary cookies are set without consent because the Platform cannot work without them; all other cookies are set only after you have given consent through the consent banner, and you may change or withdraw that consent at any time.


20. Access to information — PAIA

20.1 The Promotion of Access to Information Act 2 of 2000 gives you a right of access to records held by us, subject to the grounds of refusal that Act sets out.

20.2 We maintain a PAIA manual that explains what records we hold, how to request them, the fees that apply, and how to appeal a refusal.

20.3 Our PAIA manual is available:

20.3.1 on the Platform at [INSERT: link to PAIA manual];

20.3.2 on request, free of charge, by emailing data@listsecure.co.za; and

20.3.3 for inspection at 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa, during business hours.

20.4 Requests under PAIA must be made to the Information Officer on Form 2 of the PAIA Regulations, and are dealt with in terms of PAIA and not in terms of clause 16 of this Policy. A request for your own Personal Information is easier: use clause 16.

20.5 Section 25 of POPIA governs the manner of access: a request for access to a record of your Personal Information made under section 23 of POPIA must be made and dealt with in the manner set out in section 18 of PAIA (requests to a public body) or section 53 of PAIA (requests to a private body), as the case may be.


21. Complaints

21.1 Complain to us first

21.1.1 If you are unhappy with how we have handled your Personal Information, please tell us. Write to the Information Officer at data@listsecure.co.za, with "Privacy complaint" in the subject line.

21.1.2 Tell us what happened, when, what you want us to do, and how we can contact you.

21.1.3 We will acknowledge within [INSERT: number] Business Days and respond in writing within 30 days. We will tell you what we found, what we have done, and what you can do if you are not satisfied.

21.2 Complain to the Information Regulator

21.2.1 You may complain to the Information Regulator at any time, whether or not you have complained to us first. You do not need our permission and you do not need a lawyer.

21.2.2 A complaint is submitted on Form 5 under Regulation 11 of the POPIA Regulations, 2018, in terms of sections 74 and 99 of POPIA.

21.2.3 The Regulator's contact details are:

Physical addressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal addressPO Box 31533, Braamfontein, Johannesburg, 2017
Telephone010 023 5200
General enquiriesenquiries@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za
OnlineComplaints may also be lodged on the Regulator's online complaints portal, using Form 5

21.2.4 [CONFIRM: verify the Regulator's current address and complaint channel at inforegulator.org.za before publication]

21.2.5 You may also institute civil proceedings for damages in a court having jurisdiction, under section 99 of POPIA, whether or not there is intent or negligence on our part.

21.2.6 If you are in the EU or EEA, you may complain to the supervisory authority in the country where you live, where you work, or where the alleged infringement took place.

21.3 Complaints about a Vendor

If your complaint is about how a Vendor has used your Personal Information, tell us and we will route it to the Vendor and follow up under the Vendor Agreement. You may also complain to that Vendor directly and to the Regulator. Because the Vendor is an independent responsible party for that processing (clause 4), the Regulator's remedies apply to the Vendor in its own right.


22. Changes to this Policy

22.1 We may change this Policy from time to time — for example when the law changes, when we add a feature, or when we appoint a new Operator.

22.2 The current version is always on the Platform, with its version number and effective date at the top.

22.3 Where a change is material — for example a new purpose, a new category of recipient, a new transborder flow, or a change to the legal basis for processing — we will give you reasonable prior notice by email or by a prominent notice on the Platform before it takes effect, and, where the law requires consent for the new processing, we will ask for it.

22.4 We keep previous versions and will provide one on request to data@listsecure.co.za.


23. Contact Us

23.1 For privacy matters, the Information Officer: data@listsecure.co.za.

23.2 For everything else: support@listsecure.co.za.

23.3 By post: The Information Officer, LIST SECURE (PTY) LTD, 16 Pelican Way, Zeekoevlei, Western Cape, 7942, South Africa.


×

Login

Register

A link to set a new password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.