Draft — pending legal review. Not yet a binding policy.
Policies in plain language
Privacy
What we collect, and why
- An anonymous session id.A random cookie value, set by the server, httpOnly (your browser’s JavaScript can never read it), kept for one year. We store a hashed version of it against page-view and click events so we can count things like “how many searches led to a directions click” — never your identity, never anything you typed.
- Interaction events. A record that a search happened, a profile was viewed, directions were opened, or a save/share button was tapped — written by the server, readable only by us (service-role access), never sold or shared.
- Submission contact info, if you give it. When you suggest a venue or submit a correction, the contact field is optional and readable only by our review team.
- A salted, rotating rate-limit hash.Submissions are throttled per IP address using a hash that changes every day and can’t be reversed back to your IP — it exists only to stop spam, and is a completely different identifier space from the session id above.
- Your saved venues.The list itself is stored in your browser’s local storage and is never sent to us. Tapping Save does record an anonymous save event (see the interaction events above), so we can count how often people save a venue — but the list of what you saved stays on your device.
- A short-lived draft cookie.If you’re partway through suggesting a venue or filing a correction, your in-progress answers round-trip through a short-lived, httpOnly cookie so a page refresh doesn’t lose your work. It expires quickly and is never used for tracking.
- Staff email, for sign-in only. Our reviewers sign in via a one-time magic link sent to their email — this is an authentication credential, not a marketing list.
- Venue photos.Taken by us during a visit, stored in a private bucket, and served only through our own proxy. We don’t knowingly photograph identifiable customers without their consent.
What we don’t do
No third-party analytics. No ad trackers. No selling or renting any data we hold — this isn’t a promise made in the abstract, it’s verifiable directly in this project’s own dependencies, which include none of the above.
Retention, correction, and deletion
We intend to keep interaction events for roughly 13 months — long enough to compare a season year-over-year, short enough that stale data doesn’t linger indefinitely. If you’d like to know what we hold about you, have it corrected, or have it deleted, email hello@apha.work and we’ll respond as required under South Africa’s Protection of Personal Information Act (POPIA).
Contact
Questions about this policy: hello@apha.work.