Privacy & consent

Collect less. Protect it. Ask permission.

The Hub follows privacy-minimising principles appropriate to South African users and aims to handle personal information consistently with POPIA.

Community firstClear information. Human review.

POPIA-minded

Privacy principles—not a promise to collect everything.

  • Minimum necessary information
  • Clear purpose and consent
  • No sale of member lists
  • Private by default
01

Responsible party

Emille Van der Merwe, sole proprietor trading as Hub4Communities, is the responsible party and head of this private body. The operating locality is Montagu, Langeberg, Western Cape, South Africa. The electronic address for privacy notices, requests and complaints is hubforcommunities@gmail.com.

02

What we collect

The form collects the details needed to review and respond: name, private phone or email, town, dates, source, submitted content, consent choices—including the two optional AI choices where offered—and a pseudonymous anti-abuse fingerprint. A List & Sell submission also collects a fixed ZAR price, category, condition, safe public meetup area, lawful-owner or authorised-seller declaration, required adult confirmation, private moderation email and seller phone or WhatsApp number. That seller number is published only with explicit consent; the email stays private. A seller may optionally add up to three item photos and must separately confirm authority to use them. Each photo is kept private, decoded and re-encoded as a smaller WebP image to remove embedded metadata; the original upload is discarded. A moderator decides each processed image separately, and only an approved image attached to a current approved listing can be served publicly.

03

Quick Update access

A nominated contact for a current job, business, event, notice or service starts from one exact approved listing and enters the nominated private email. The response never confirms whether a match exists. If it matches, a six-digit code is emailed without the listing title, public contact details or a management URL. The code expires after 30 minutes, works once and locks after five wrong attempts. Correct same-origin confirmation creates a strictly necessary, HttpOnly, Secure, SameSite=Strict session cookie for 20 minutes. The Quick Update session stays limited to that one item, cannot publish directly and cannot change its own management identity. Unexpired one-time links issued before Quick Update remain usable only through the legacy confirmation page; no new legacy links are issued. Mailbox control verifies access to the nominated email, not legal ownership. Each proposed change is revision-bound and checked under the Hub’s operating rules. Verified practical updates and removals may be applied automatically when enabled; changed editorial copy requires bilingual review. For new events, notices and services, optional explicit consent nominates the supplied email as the private listing management identity. Emails supplied previously only for receipts are not converted into management permission.

04

Private Hub accounts

An adult may create a free private Hub account before making a submission or claiming a listing. Registration stores a keyed one-way email identity fingerprint, private display name and main town, account and verification status, policy and login timestamps, the organisation name and type, private membership metadata, and identifiers for listings later linked through authorised mailbox confirmation. It stores no password, does not retain the account email as readable profile data and creates no public user or organisation profile. Email confirmation proves access to that mailbox; it does not prove legal ownership, authority to bind an organisation, endorsement by the Hub or verification of every organisational claim. Registration and later sign-in use a generic response, a one-time secure email link and a six-digit backup code that expire after 10 minutes. A strictly necessary HttpOnly, Secure, SameSite=Strict cookie gives access only to active memberships and linked items, has a seven-day inactivity limit and a 30-day absolute limit. Choosing a linked item creates a separate 20-minute, listing-scoped Quick Update session whose delegated authority ends immediately on sign-out, suspension, membership revocation or listing unlinking. An account cannot publish, approve, rank, charge, transfer a listing or bypass the Hub’s operating checks. Accountless first submissions remain available.

05

Optional website analytics

Your EN/AF and My Town choices are stored only in this browser’s device storage. My Town contains one of the supported town names, or no choice, and can be changed or cleared on the regional Today page. After JavaScript runs, the Hub client attempts to send an approved page-route signal so the service can be operated and improved. No-JS, blocked, offline and failed requests are omitted, so these 90-day daily totals are incomplete client signals—not server request logs, page loads or people. Each total contains only the local date, approved page path and count—not an IP address, cookie, query string, referrer, device profile or contact detail. A keyed one-way token derived from the request IP address is kept separately, expires at the end of its current hourly or daily rate-limit window, is never joined to the totals, and is used only to limit automated overcounting; scheduled maintenance removes expired tokens. Optional engagement analytics starts only after you choose Allow analytics. The client may then attempt approved item-visibility, share-link, Channel-link, checked-source-link and sale seller-contact click events. A seller-contact event is a click attempt only: it sends the opaque item ID, publication revision, sale kind and selected town, never the phone number, prefilled message or page query. These are incomplete directional events with no dwell-time, unique-person, successful-open, contact, response, sale, post, send, follow or destination-arrival claim. The local analytics choice gates the client, but no per-event consent record is attached for the server to verify. The 90-day aggregate counters contain only an opaque item ID, content type, town context and count and—for share clicks only—the WhatsApp or Facebook method, not an IP address, cookie, title, source address, account or contact detail. Their separate keyed one-way rate token is kept for at most 48 hours and is never joined to those counters. Google Analytics 4 also receives an approved page path, any complete Hub-issued WhatsApp campaign tag, broad technical usage information and limited key actions. External referrers are reduced to the referring site’s origin; an internal Hub referrer may retain only its approved path and complete Hub-issued campaign tag. Other query values and referring paths are removed. Neither system receives form contents, names, phone numbers, email addresses or submission references. Your optional analytics choice is stored on this device and can be changed using Analytics preferences in the footer; withdrawing consent stops further optional analytics and attempts to expire the visible Hub _ga cookies for the current public host. Google may process consented analytics information outside South Africa under its safeguards.

06

Optional Google advertising

Advertising notice effective 17 September 2026. If the operator activates Google AdSense after its site review and a certified consent message is configured, Google may place third-party display ads only on English regional home pages showing current information in the unfiltered view. Afrikaans views, empty or unavailable content, the national homepage, region and town selectors, Privacy, Terms, forms, accounts, management and admin areas, search or other query/hash views, content boards, individual town pages, and item-detail or result pages remain ad-free. Google and participating advertising vendors may use cookies, local storage, web beacons, IP address, browser and device information, the page being viewed, interactions with an ad and information about prior visits to this or other sites to select, limit, measure and report ads, including personalised ads where the visitor has validly consented. Those vendors may process information outside South Africa under their own safeguards. A Google-certified consent platform controls advertising choices separately from the Hub's local analytics preference; allowing analytics does not allow advertising, and refusing analytics does not itself record an advertising choice. An ad is supplied by a third party, is not verified Hub information or an endorsement, and cannot buy acceptance, ranking or editorial preference for a Hub listing.

How Google uses partner-site information ↗ · Google Ads Settings ↗ · Industry opt-out choices ↗ · Google-authorised advertising vendors ↗

07

Legacy QR and short-link totals

The public QR poster page is retired. Six previously issued /go links still redirect to a stable regional or town Hub page only so an old shared or printed copy does not break. On the canonical public site, an accepted GET request may add one to a rate-capped, separate 90-day daily aggregate containing only the local date, approved legacy code and count. It does not store a name, raw IP address, cookie, query string, referrer, device profile, WhatsApp outcome or destination token. These totals are route requests—not unique people, scans or Channel follows. The redirect still works if counting is unavailable.

08

Adults and children

The public form is for submitters aged 18 or older. Children must not submit directly. A List & Sell listing must contain no child’s personal information. For other submissions, identifiable information about a child may be supplied only by the child’s parent or legal guardian with prior, specific consent, and only when necessary. Do not include a child’s home address, identity number, school identifier, health details or other sensitive information. Child photos are never accepted through the public form.

09

Purpose and lawful processing

Information is used to secure and operate the form, moderate and verify a submission, reply, format approved information, route it to the relevant Hub destination, make corrections, and keep limited evidence of consent or serious incidents. If the submission-assistance feature is enabled and both optional AI choices are selected, minimised public-content fields may also be used for bilingual drafting and moderation suggestions and, after a separate administrator request, a restricted search of configured public-authority sources. A separately controlled private operating review may use aggregate, privacy-minimised service signals to help the owner plan improvements; it receives no row-level submission, content, source, account or proposal data. Processing is based on consent where requested and on the Hub’s legitimate operational, moderation and safety interests, subject to POPIA.

10

Voluntary and required fields

Using the form is voluntary. Required fields are marked and at least one private reply method is needed; without them the Hub cannot moderate or respond and will not accept the record. For ordinary publishable submissions, publishing contact details is a separate optional choice that is off by default. A sale listing requires a public seller phone or WhatsApp number and explicit publication consent because buyer contact is the purpose of that listing; the required email remains private. AI-processing choices are optional only where shown. They are not shown for sale listings, which always remain in the manual-review path.

11

WhatsApp Channel and private messages

Following the regional WhatsApp Channel is voluntary and subject to WhatsApp’s own privacy settings. The Hub does not scrape follower numbers or copy private contact details. A private message, photo or personal detail will not be republished on the website, Channel or another platform without separate written permission from the person authorised to give it.

12

Optional AI drafting and restricted public-evidence search

List & Sell submissions are manual-review only: the sale form does not offer AI choices and sale rows are not eligible for AI drafting or public-web evidence checking. For other eligible submission types, AI assistance may be used only if the feature is enabled and the submitter selects both optional choices: consent to AI processing and confirmation that the public-content fields contain no child’s personal information. The Hub may then send only minimised public-content fields—submission type, town, title, description, relevant dates, venue, price, business category, opening hours and redacted job-application instructions—to the OpenAI API. Whether a safe application link was supplied may be sent as yes/no, but the link itself is excluded. Bilingual drafting does not browse. A separate evidence button may search only the configured public-authority domains, using at most three search calls, to check populated date, expiry, venue and price claims; it does not check the whole submission. The submitter’s private name and contact details, submission reference, anti-abuse fingerprint, consent record, submitted source name and submitted source URL are excluded. The tool cannot log in, submit forms, contact anyone, moderate or publish. Citations are checked and an administrator remains responsible for every decision. “Not found” does not mean the claim is false. OpenAI states that API data is not used to train its models unless the account opts in. By default, API abuse-monitoring logs may retain submitted API content for up to 30 days, and OpenAI may process it outside South Africa under applicable safeguards. The Hub does not represent this processing as Zero Data Retention. If the feature is unavailable or either optional choice is not selected, that submission’s content stays entirely in the manual review path and is never sent row by row to the private operating review described below.

13

Private aggregate operating review

If the owner separately enables the private operating-review feature, an authenticated owner may start a manual review; a separate flag may later permit at most one scheduled attempt per Johannesburg day. The OpenAI API then receives a read-only, privacy-minimised aggregate snapshot: the active region and date, fixed Hub policy facts, consent-bounded counts of pending publishable submissions, aggregate content and expiry counts, aggregate source-coverage states, contributor-account counts, directional engagement and page-route totals, distribution-decision counts, private proposal-decision counts, and explicit unknowns such as revenue or owner time. It receives no row-level submission, content, source, account or proposal record; no name, contact detail, account identity, submission reference, item or source identifier, title, description, source name, item-level date, URL, decision note or other free text. The request uses store:false, has no tools and cannot browse. The model returns only bounded classifications, action and success enums, and exact aggregate evidence references; trusted server code creates the displayed wording. Results remain private proposals. Accepting one means planning only and cannot publish, send, moderate, deploy, spend or change an account, secret, region or permission. OpenAI states that API data is not used to train its models unless the account opts in; default abuse-monitoring logs may retain API content for up to 30 days and processing may occur outside South Africa under applicable safeguards. The Hub does not represent this as Zero Data Retention.

14

Recipients and hosting

Accepted records are stored in the Hub’s access-controlled website hosting database. Private submissions and moderation records are visible only in the signed-in operator queue; an authenticated account can see only its own active organisations and linked listings. OpenAI Sites and Cloudflare provide website hosting and security. The OpenAI API receives either the minimised submission fields described above when both optional submission-AI choices are selected and an administrator separately requests assistance, or the separate aggregate-only operating snapshot described above when the owner has enabled and started that private review. Google provides the Hub mailbox and, only with the visitor’s separate choice, GA4 processing. When transactional alerts, Quick Update codes or account emails are activated, Resend receives the necessary recipient, sender and reply addresses plus a minimal plain-text operational message. An account email contains a one-time confirmation or sign-in URL, a six-digit backup code and expiry, but no listing title or public contact details. Submission alerts contain the reference, type, town, received time, review target and, for the administrator alert, a protected queue link; they omit the submitted title, description, phone number, source and price. No marketing is sent. Open and click tracking must remain disabled on the sending domain. Resend states that sent-email data is retained for 30 days. Meta/Facebook or WhatsApp receives information only when a user opens or uses the selected service or when separately approved content is posted there. These providers may process information outside South Africa where lawful safeguards apply. Nothing is published automatically, and private contact details are not published without separate consent.

15

Sale listing lifecycle

An approved sale listing publishes the seller-supplied title, description, category, condition, fixed price, town, safe meetup area and consented seller phone or WhatsApp number for no more than 14 days. Up to three processed item photos may appear only after each photo is separately approved and the listing is explicitly published; changing a final photo decision or alt text requires a corrected source and a new moderated publication path. The private moderation email is not published. A listing may be removed sooner when sold, withdrawn, reported, unsafe or inaccurate. Sellers use the correction/report route to mark an item sold or request an update; this does not create an owner account or automatic change.

16

Retention

Unpublished form records are retained for up to 90 days and then removed by automated maintenance. Optional List & Sell photos that are abandoned or remain private expire within 30 days. An approved photo can be publicly available only while its linked listing is current, for no more than the listing’s 14-day public lifetime. Rejected, withdrawn, sold, archived or expired photos are scheduled for deletion immediately and targeted for removal within 24 hours. If object deletion temporarily fails, the Hub retains only a minimal deletion-pending tombstone, random storage key and the photo-consent version and time, detached from the seller record, and retries maintenance; the original upload was never retained. To prevent simultaneous duplicate cases, a submitted-content hash and the pseudonymous fingerprint are paired with one temporary reference owner for a 15-minute duplicate window; maintenance removes expired reservation rows. Minimal local email-outbox status metadata is retained for no more than 30 days and is removed sooner when its linked submission is deleted; submission-email retries use a one-way SHA-256 fingerprint of the exact outbound message, while Quick Update and account-email retries use keyed one-way fingerprints that cannot be tested offline against the six-digit code. No message copy is stored locally, and Resend states that sent-email data is retained for 30 days. For an approved managed job or business item, a one-way normalized-email fingerprint—not the email address—is retained with that item so later requests can be matched. A management access row temporarily holds the supplied recipient email for delivery, redacts it when access is consumed, expires or locks after five wrong code attempts, and is removed within 24 hours. An account-access row holds the recipient only while delivery is pending or retrying; the address is redacted as soon as the provider accepts the message, delivery reaches a terminal state, access is consumed or the code locks. A pending, unverified account and its temporary registration profile are removed after 24 hours. Once a session is created, its remaining access record is removed no later than 24 hours after the 30-day absolute session expiry. A verified account retains its keyed identity fingerprint, private display name and main town, status and verification timestamps, organisation membership and linked-item identifiers while active. Closing an account schedules its private account, membership and listing-link metadata for removal after 365 days once shorter-lived delegated-session and moderated-change evidence has ended; closing access does not remove public content. A private operator audit records the acting administrator, affected account, organisation or listing identifiers, status change and minimum operational reason for no more than 365 days. Neither a reusable bearer link nor a reusable plaintext code is stored. A moderated change request contains only the proposed public fields, integrity fingerprint, target revision and decision metadata and is removed within 90 days. A validated AI drafting suggestion remains private and expires no later than its linked submission. A saved public-evidence result remains private for no more than 24 hours or until the linked submission expires, whichever comes first. Private operating-review snapshots, validated outputs, run metadata, proposals and append-only decision events are retained locally for no more than 365 days; open proposals expire after 30 days, and expired records are not displayed or reused while scheduled deletion is pending. Legacy private image links stop working after 30 days and expired legacy objects are removed by maintenance. Approved public content may remain while accurate and useful. A complaint, security incident, legal duty, legal hold or necessary consent record may justify limited longer retention.

17

Your rights and choices

Email hubforcommunities@gmail.com to ask whether the Hub holds your information, request access or correction, object to processing, withdraw consent, close a private Hub account, or request deletion where applicable. Include the submission reference if available. Reply STOP to opt out of future direct marketing on that method.

18

Complaints

Raise a privacy concern with the Hub first at hubforcommunities@gmail.com. You may also lodge a POPIA complaint with South Africa’s Information Regulator using its official complaint process or at POPIAComplaints@inforegulator.org.za.

Choose an active region

Start with the founding Langeberg region.

National framework · Local regional hubs2 active regions
Built for South Africa · Choose your local region