Privacy policy

How we look after your details

This covers our website, enquiries and client work. Last updated: 29 September 2026.

The short version

  • We collect only what we need to reply to you, do your work and get paid.
  • We never sell or rent your information.
  • We use a few trusted online services to run the business, and some store data outside South Africa.
  • You can ask to see, correct or delete your information at any time.

1. Who we are

Nearby Social, run by Hugo Swanepoel (a sole proprietor trading as Nearby Social), is the “responsible party” under the Protection of Personal Information Act (POPIA) for the personal information described here. Our Information Officer is Hugo Swanepoel, registered with the Information Regulator.

Email: nearby.social.primary@gmail.com
WhatsApp: +27 78 040 6698
Address: 37 Marignane Avenue, Bonaero Park, Kempton Park, Gauteng, South Africa

2. What we collect

If you contact us

Through the website form, email, WhatsApp or social media messages: your name, business name, email address, phone or WhatsApp number (if you give it) and your message.

If you become a client

  • Contact and billing details: names, email, phone, business name and address, and invoice and payment records. Card payments are processed by Payfast; we never see or store your card details.
  • Business information for your content: services, prices, brand details, logos, photos and videos, and notes from our chats.
  • Access to your pages and Google Business Profile, through role-based team access, never your passwords.
  • Your customers’ information that appears in material you share with us or in comments and messages on your pages (for example a customer in a photo, or a review). For this, you’re the responsible party and we act as your “operator”: we only use it on your instructions, to do your work.

If we came across your business online (before we’ve spoken)

We look for local businesses we might be able to help, using information businesses have made public themselves: listings on Google Maps (through Google’s Places service), your own website and your public social media pages. We note your business name, category, public phone number, email address and web or social links, your public rating and number of reviews, and short notes about your public pages. We don’t buy or rent contact lists.

We use this to decide whether we could genuinely help and, at most, to send you one message asking whether you’d like to hear from us. If you say no, or don’t reply, we won’t send you marketing messages, and we keep only a short “please don’t contact” note so we never contact you by mistake. Everything else is deleted within 6 months if we don’t end up working together. Ask us any time where we found your details and we’ll tell you.

When you visit this website

We don’t use analytics or advertising cookies. Like any website, our hosting provider (Cloudflare) records technical details such as your IP address and browser type to keep the site running and secure. The site loads its fonts from Google Fonts, so your browser connects to Google.

We don’t intentionally collect special personal information (like health information, religion or ID numbers) or information about children. Please don’t send us any, especially patients’ health information.

Giving us your details is voluntary. Without them we can’t reply to you, do your work or invoice you. The Tax Administration Act requires us to keep invoice and payment records.

3. Why we use it

  • To reply to your enquiry and send what you asked for, like your free post ideas.
  • To plan, create, get approval for and publish your content, and to build and host your website.
  • To invoice you, take payment and keep tax and accounting records.
  • To keep our systems secure.
  • To tell you about our services, but only if you’ve said yes to that, or you’re a client and it’s about similar services. Before we’ve spoken, we may send you one message asking whether you’d like to hear from us; if you say no or don’t reply, that’s the end of it. Every marketing message says who it’s from and how to opt out, and we stop as soon as you ask.

We rely on your consent, what’s needed to carry out our agreement with you, complying with the law (such as tax records), and our legitimate interest in running and growing the business, for example noting publicly listed business details to see whether we could help (POPIA section 11).

4. Who else handles it

We use these services to run the business. They process information on our behalf and apply their own security and data-protection standards:

ServiceWhat forWhere data may be stored
CloudflareWebsite hosting and securityWorldwide, including the USA
FormspreeWebsite contact formUSA
Google (Gmail, Drive, Google Fonts, Google Maps)Email, shared files, website fonts, finding local businesses on Google MapsWorldwide, including the USA
Meta (WhatsApp, Facebook, Instagram)Messages and publishing your postsWorldwide, including the USA
Payfast by NetworkInvoices and paymentsSee Payfast’s privacy policy
Anthropic (Claude)AI assistant for drafting ideas, captions, graphics and researchUSA

We don’t put your customers’ personal information into AI tools. We never sell or rent your information.

5. Sending information outside South Africa

Some of these services store data outside South Africa. Under POPIA section 72, we only send information abroad where the service is bound by data-protection laws, binding company rules or an agreement that gives adequate protection (we check that each service publishes data-protection terms like these), or where the transfer is needed to reply to you or to carry out our agreement with you. We don’t ask you to sign away anything for this.

6. How long we keep it

  • Business details we noted before we’d spoken: deleted within 6 months if we don’t work together, except a short “please don’t contact” note.
  • Enquiries that don’t lead to work: deleted within 12 months.
  • Client information: kept while we work together, then deleted or returned within 12 months after we stop, except records the law says we must keep. Tax records (invoices and payments) are kept for 5 years, as SARS requires.
  • Your content files and page access: handed back or deleted when we stop working together.

7. Keeping it safe

Access is limited to the owner. Our accounts use strong passwords and two-step verification, and we use role-based access to client pages instead of shared passwords. If we ever learn that personal information has been accessed without permission, we’ll tell you and the Information Regulator, as POPIA requires.

8. Your rights

You can:

  • ask whether we hold information about you, and for a copy of it;
  • ask where we got it;
  • ask us to correct or delete it;
  • object to us using it, including for marketing, at any time;
  • withdraw consent you’ve given (this doesn’t affect what we did before);
  • complain to the Information Regulator.

Just ask by email (nearby.social.primary@gmail.com), WhatsApp or any other way that suits you. No special form is needed. We’ll reply within 30 days, and it’s free.

Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za · 010 023 5200
inforegulator.org.za

9. Clients and visitors in the EU or UK

If you’re in the European Union or the United Kingdom, the GDPR or UK GDPR may also apply when we work with you. We handle your information as described above, and you have similar rights: access, correction, deletion, objection, restriction and data portability. You can also complain to the data protection authority where you live.

10. Changes

We’ll update this policy when our services or tools change; the date at the top shows the latest version. If a change significantly affects how we use your information, we’ll tell clients directly.