Mzansi Court Q — Privacy Policy · v1.0 · 2026-07-21
Legal entity: Mzansi Sport Q (Pty) Ltd, incorporated in the Republic of South Africa (trading as Mzansi Court Q).
Effective date: 21 July 2026 · Version: 1.0
This Privacy Policy explains how we collect, use, protect and share personal information when you use the Mzansi Court Q platform. It is written to comply with the Protection of Personal Information Act, 4 of 2013 (POPIA) and cites the Act's sections directly so you can hold us to the law by number.
If you are a member of a club, academy or coach that uses Mzansi Court Q, your club is the responsible party for your personal information and we act as the operator under POPIA §21. Where this policy talks about "we", "us" or "our", it refers to Mzansi Sport Q (Pty) Ltd acting in that operator role — unless the section explicitly deals with information we hold about you directly (for example, when you contact us on our support channels).
§ 1 — Who we are and how to contact us
- Legal name: Mzansi Sport Q (Pty) Ltd, trading as Mzansi Court Q
- Country: Republic of South Africa
- Website: https://www.mzansicourtq.co.za
- Email: mzanzicourtq@gmail.com
- WhatsApp: +27 66 049 2460
- Information Officer: contactable via the email address above
Our Information Officer under POPIA §55–56 is the point of contact for all privacy questions, requests to access or correct information, complaints, and breach notifications. Written requests are answered within 30 days.
§ 2 — What personal information we collect
We only collect the information we need to run the platform on your club's behalf. The categories below are the complete set — if a screen ever asks for something not listed here, that is a bug worth reporting.
2.1 Account information
- First name, surname
- Email address
- Mobile phone number
- Birthday (day + month; year optional and never shown publicly)
- Gender (used for gender-balanced matchmaking and age-group reporting)
- Membership type at the club
- Login credentials (password stored as a one-way cryptographic hash — never in plain text)
2.2 Profile and usage information
- Court bookings, cancellations and no-shows
- Match results, doubles partnerships, match statistics and player ratings
- Wallet balance, wallet top-ups and wallet spend
- Membership payments and payment history
- Coaching lesson requests, attendance and lesson notes
- Access-control events (which gate or door you unlocked, and when)
2.3 Communications information
- WhatsApp and email opt-in preferences
- Messages you send to club channels or to our support team
- Notification history (which reminders were sent, delivered and read)
2.4 Device and technical information
- Browser type and version, operating system
- IP address at the moment of a request
- Session cookies and local storage tokens needed to keep you logged in
- Server access logs (used to diagnose problems and protect the platform)
2.5 Information about children (under 18)
Children's profiles are created by a parent or guardian, who provides consent on the child's behalf under POPIA §34–35. Children's contact details are stripped from public views by default (see § 11).
§ 3 — Why we collect it (POPIA § 11 grounds)
We rely on one of the following lawful grounds every time we process your personal information (POPIA §11):
- Contract performance — to deliver the platform services your club has asked us to provide (bookings, payments, communications, statistics).
- Legal obligation — record-keeping we must do under POPIA itself (POPIA §14), the Value-Added Tax Act, the Companies Act and the Cybercrimes Act.
- Legitimate interest — safety, fraud prevention, platform security, and the fair operation of shared facilities. Balanced against your rights.
- Your consent — for marketing, non-essential analytics, WhatsApp opt-ins, and any use that goes beyond what your club needs to run day-to-day. You can withdraw consent at any time.
We do not process your information for any purpose that goes beyond running the platform for your club.
§ 4 — Who we share it with
We do not sell your personal information. Ever.
We share it only with the third parties we need to make the platform work, and each of them is bound by a written data-processing agreement:
- Payment processors (Yoco, PayFast) — for card payments, subscription billing and reconciliation. Card details are handled by the processor directly; we never see or store your full card number.
- WhatsApp Business API provider — for the club communications you have opted in to.
- Google Workspace — where your club has enabled it, for authorised contact sync, document generation and calendar events.
- Cloud hosting provider — for running the platform itself (server, database, storage).
A current list of all sub-operators, where they process information, and links to their data-processing agreements is published at /sub-operators.html and updated whenever we add or change one.
We may also disclose personal information where the law requires it — for example under a lawful court order, or when co-operating with the Information Regulator or the South African Police Service.
§ 5 — How long we keep it (retention)
We keep personal information only as long as we need it. Once the purpose is done, we either delete it or de-identify it so it can no longer be linked to you.
| Category | Retention |
|---|---|
| Active member — profile + contact | For as long as the club membership is active |
| Ended member — general profile | 30 days grace, then anonymised (name blurred, contact details stripped) |
| Payment and financial records | 5 years after the last transaction (SARS / VAT Act) |
| Match history and statistics | Duration of membership + 10 years, then de-identified |
| Contact form enquiries | 2 years |
| Access-control logs (gate, door) | 1 year (Cybercrimes Act § 54) |
| WhatsApp message history | 90 days rolling |
| Server access and error logs | 90 days rolling |
| Anonymised aggregate analytics | Indefinite |
"Anonymised" means the record can no longer be linked to you as an individual — names are blurred, contact details stripped, unique identifiers removed. Aggregate anonymised statistics may be kept indefinitely for reporting and trend analysis.
§ 6 — Your POPIA rights
POPIA gives you strong rights over your personal information. All of them are free to exercise (except in the narrow cases where the Act allows a reasonable fee).
- § 23 — Right of access. You may ask what personal information we hold about you and receive a copy in a reasonable format.
- § 24 — Right to correction or deletion. You may ask us to correct information that is inaccurate, misleading or out of date, and to delete information we no longer have a lawful basis to hold.
- § 11(3)(b) — Right to object. You may object, on reasonable grounds, to us processing your personal information.
- § 69 — Right to opt out of direct marketing. You may unsubscribe from marketing messages at any time. Essential service messages (payment receipts, booking confirmations) are not marketing.
- § 71 — Right to object to automated decisions. You may ask a human to review any decision made about you purely by an automated process.
- § 19 (Chapter 10) — Right to complain to the Information Regulator. If we get it wrong, you may lodge a complaint with the Regulator directly.
Requests are answered within 30 days. We will confirm your identity before releasing personal information — this protects you against someone else pretending to be you.
§ 7 — How to exercise your rights
You have three routes, in order of speed:
- In-app privacy toggles. Sign in to your member portal and open your profile. Communication preferences, directory visibility and stat-blur toggles are self-service and take effect immediately.
- Ask your club admin. For membership status, financial history or lesson records, your club committee is the responsible party under POPIA § 21 and holds the day-to-day authority to correct or delete records.
- Contact us directly. Email mzanzicourtq@gmail.com or WhatsApp +27 66 049 2460 for anything the first two routes cannot resolve, including formal POPIA access or deletion requests, and complaints.
If you would rather escalate straight to the Regulator, their contact details are in § 13.
§ 8 — Security measures (POPIA § 19)
We apply the reasonable technical and organisational safeguards POPIA § 19 requires. In practice:
- All traffic between your device and the platform is encrypted with HTTPS (TLS).
- Passwords are hashed with bcrypt before storage. We cannot read them ourselves.
- Sensitive information — including payment credentials — is encrypted at rest.
- Access to production systems is restricted to named staff and gated by multi-factor authentication.
- Role-based access controls stop a club admin from seeing another club's data.
- We keep automated daily backups and test restoration regularly.
- API keys and secrets are rotated on a schedule; they are never committed to source control.
- We follow a documented incident-response plan and notify affected clients within 24 hours of confirming any unauthorised access, then notify the Information Regulator as soon as reasonably possible.
Full details are published on our Security page.
§ 9 — Cookies and local storage
We use cookies and browser local storage in three categories:
- Essential — session tokens, login state, security anti-forgery tokens. Always on. Without them, the platform cannot function.
- Analytics — anonymous usage statistics. Opt-in only — off by default.
- Marketing — retargeting for people who have shown interest in the product. Opt-in only — off by default.
You can change your preferences any time via the cookie banner or by clearing site cookies in your browser. Detailed cookie information is on our Cookie Policy page.
§ 10 — International transfers (POPIA § 72)
Some sub-operators we rely on operate outside South Africa. POPIA § 72 allows this only where the receiving party is bound by binding rules that provide protection substantially similar to POPIA. We rely on written data-processing agreements with each cross-border sub-operator to meet that standard.
Our hosting infrastructure runs on cloud providers subject to the EU General Data Protection Regulation (GDPR) or equivalent frameworks. Where information moves across borders, standard contractual clauses or an equivalent lawful transfer mechanism is in place.
A per-sub-operator list of processing locations is on the Sub-Operators page.
§ 11 — Children (under 18)
Personal information about children is treated as special personal information under POPIA §§ 34–35 and receives extra protection:
- A parent or guardian must consent before a child's profile is created.
- Children's email addresses and phone numbers are stripped from public directory views by default.
- Photographs of children appear in club galleries only when the parent or guardian has explicitly opted in.
- Communications about a child (booking confirmations, coaching notes, invoices) go to the parent or guardian, not the child.
Parents and guardians may exercise every § 6 right on the child's behalf, and may withdraw consent at any time.
§ 12 — Changes to this policy
We may update this Privacy Policy from time to time — for example when a new feature launches, when we add a sub-operator, or when the law changes.
- The version number and effective date at the top of this page show which version is live.
- Material changes are announced at least one calendar month before they take effect, via the member portal and the email address on your account.
- Historical versions are archived and available on request.
Your continued use of the platform after an update takes effect confirms your acknowledgement of the updated policy.
§ 13 — Contact and complaints
Privacy questions, POPIA requests, or breach reports
- Email: mzanzicourtq@gmail.com
- WhatsApp: +27 66 049 2460
We respond to POPIA requests within 30 days.
If you would prefer to escalate directly to the regulator
Information Regulator of South Africa JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Email: enquiries@inforegulator.org.za Complaints: POPIAComplaints@inforegulator.org.za Web: https://inforegulator.org.za
You do not need to go through us first — you may lodge a complaint with the Regulator at any time.
This document is the master Privacy Policy for the Mzansi Court Q platform. Where a club, academy or coach adds its own privacy notice for its members, that document sits alongside this one and does not replace it.