DRAFT for legal review. This page has not yet been approved by the studio owner or checked by a lawyer. Items marked [OWNER TO CONFIRM] are still to be filled in.
Last updated: 11 October 2026
This policy explains what personal information The Purple Pigeon collects, why, who it is shared with, where it is processed, how long it is kept and what your rights are under South Africa's Protection of Personal Information Act, 2013 (POPIA). It is written to be read, not skimmed past.
1. Who is responsible
The responsible party (the organisation that decides why and how your information is used) is The Purple Pigeon (Pty) Ltd, the yoga, pilates and reformer studio ("the studio", "we", "us").
Registered address and company registration number: [OWNER TO CONFIRM: registered address and registration number].
Information Officer: [OWNER TO CONFIRM: name, email address and phone number of the studio's Information Officer, who must also be registered with the Information Regulator].
This policy covers the studio's web app, its website and its mobile apps (they all use the same system). For day-to-day contact details see the Contact studio page.
2. What we collect
We collect only what the system needs to run a studio. Depending on what you do, that is:
- Your account: first and last name, email address, a phone number, a profile photo (optional) and your password. Your password is never stored as you typed it; we keep only a salted, one-way hash of it.
- A note to your instructor (optional): the "Anything we should know?" box on your profile, where you may mention injuries, pregnancy or similar. This is health-related information, which POPIA calls special personal information. We ask for it only so instructors can look after you, it is entirely optional, and only the studio team can see it.
- Bookings: which classes you booked, your spot or bed, waitlist entries, whether you were checked in, attended, cancelled or did not show, and any reason given for a cancellation. If you leave a class review, the rating and comment.
- Credits, packages and wallet: the packages you bought, a ledger of every class credit added or used, and a ledger of every Rand added to or spent from your wallet.
- Payments: amounts, dates and status of payments, PayFast's payment reference, and the last four digits and brand of a card you saved. We never see or store your full card number or CVV. You type those on PayFast's own page; we keep only a token that lets PayFast charge that card when you ask us to.
- Shop: your bag, your orders, and for delivered orders the name, street address, city and postcode you enter.
- Guests (no account): if you book or pay for a class or event without an account we keep your name, email address and phone number and the payment details above. The same goes for event registrations and event enquiries (which may also include a business name and your message).
- Notifications: your in-app notifications and notification preferences, a log of emails we sent you (address, subject, whether it was delivered), and, if you switch on push notifications, your browser's push address and keys.
- Security records: your sign-in sessions (a hashed session identifier, your IP address, your browser and device description, and when you were last active) and an activity log of important actions (who did what, when, and from which IP address). Rate-limit counters used to stop abuse are stored under a one-way hash, so no readable IP address or email address is kept in them.
- Your agreement to the Terms and Indemnity: when you tick the box (at sign-up, at a later sign-in, or when booking as a guest) we keep which version you accepted, when, where (sign-up, sign-in or which booking), and the IP address and browser description it came from, as proof of the agreement.
- Staff and instructors: in addition, their class pay rate, availability and time-off requests, and a hashed team access code.
- Pictures: photos uploaded to the app (for example a profile photo) are stored in our database.
We do not use analytics or advertising trackers, we do not build advertising profiles, and the system does not make automated decisions about you, other than the bot check described under Google reCAPTCHA below.
3. Why we use it
- To create and run your account, take your bookings, manage your credits, wallet and orders, and keep your class safe and organised (performing our agreement with you).
- To take payments and to give refunds.
- To send you messages you need, such as booking confirmations, reminders, waitlist offers and notice that a class was cancelled. Cancellation notices cannot be switched off because they are about a class you are expecting to attend.
- To send studio news and offers. These have their own switches in Notification settings, and you can turn them off at any time. Newsfeed posts are off by default; promotions and announcements are on by default. [OWNER TO CONFIRM: confirm the marketing opt-in/opt-out approach with your lawyer (POPIA section 69)]
- To keep records the law requires, for example for tax and accounting.
- To protect the system and our members: preventing fraud and bot abuse, limiting sign-in attempts, and keeping an activity record.
- Your optional health note is used only with your consent, which you give by choosing to fill it in. You can clear it again on your profile.
We do not sell your personal information.
4. Who handles it for us
The studio's own team can see the information they need for their work. Instructors see who is booked into their classes. Beyond that, we use these service providers (called "operators" in POPIA). They may only use your information to provide their service to us.
- Supabase (database): our database is hosted in the European Union, in Ireland (AWS eu-west-1). Your bookings, payments records and account details live there.
- Vercel (hosting): the app's server functions run in Dublin, Ireland. Vercel also serves static files through a worldwide content network, so your requests may pass through servers in other countries.
- Resend (email): sends our emails, so it sees your email address and the message. [OWNER TO CONFIRM: Resend processing region]
- Sentry (error reports): when something breaks in the app, a report of the error goes to Sentry so we can fix it. It contains the error, the page or screen it happened on (without any search or link details), your browser type and your member number, never your name, email address, IP address, passwords or payment details. Sentry stores these reports in the European Union.
- PayFast (payments, South Africa): processes card and instant payments and holds saved cards. You are sent to PayFast's own page to pay or to save a card. PayFast has its own privacy policy.
- Google reCAPTCHA v3 (bot protection): used on the sign-up, sign-in, password-reset, event and guest-checkout forms to tell people from automated programs. Google receives information such as your IP address and how your browser behaves, and may refuse a request it believes is a bot. See the Cookie notice.
- Google Fonts and icons (fonts.googleapis.com and fonts.gstatic.com): every page of the app loads its typefaces and icons from Google, so Google receives your IP address and browser details whenever a page loads, whether or not you are signed in.
- Browser push services: if you switch on push notifications, the message travels through the push service run by your browser's maker (for example Google, Apple, Mozilla or Microsoft). When the mobile apps launch, notifications on Android and iPhone will be sent through Firebase Cloud Messaging (Google).
We may also disclose information when the law requires it, to the Information Regulator or a court, or to protect people from harm. Where the studio changes hands, your information may transfer to the new owner under this same policy.
5. Information that leaves South Africa
Several of the providers above process information outside South Africa: the database and server functions are in Ireland (the European Union), Vercel's network and the Google services operate globally, and Resend and Sentry are outside South Africa too. This is a transfer of personal information to another country under section 72 of POPIA.
We rely on those providers being bound by strong data-protection law (for the EU, the GDPR) and by written agreements that protect your information to a level substantially similar to POPIA, and on the transfer being necessary to run your account and bookings. By creating an account you accept this transfer.
[OWNER TO CONFIRM: confirm that data processing agreements are signed or accepted with Supabase, Vercel, Resend, Sentry and PayFast, and that a lawyer is happy with this section 72 wording]
6. How long we keep it
- Sign-in sessions end after 14 days, or after 72 hours without activity, and expired sessions are deleted automatically. Email verification codes expire after 15 minutes.
- Abuse-limit counters are deleted automatically within about an hour of their window ending.
- Unfinished sign-ups (someone who started but never confirmed their email) are temporary records (your name, email and hashed password and code). They are removed when you confirm, after too many wrong codes, when you start the sign-up again, and otherwise automatically about a day after the code expires.
- Financial records (payments, credits, wallet movements, orders, bookings that involved money) are kept for as long as the law requires us to keep accounting and tax records. [OWNER TO CONFIRM: retention period, commonly five to seven years under South African tax and company law]
- Nothing is hard-deleted. The system retires bookings, classes and products rather than erasing them, so that financial history stays consistent.
- Deleting your account: when signed in, go to Profile, then Personal details, then "Delete my account" (you re-enter your password). People without the app can use the delete-account page. Deleting removes your personal details, cancels your future bookings, removes your saved cards (they are also cancelled at PayFast) and your notification devices, and keeps the financial records the law requires in anonymised form, shown as "Deleted member".
- Email and activity logs are kept for [OWNER TO CONFIRM: how long email_log and audit_log records are kept before deletion or anonymisation].
7. How we protect it
- All traffic uses HTTPS, and browsers are told to use only HTTPS after their first visit.
- Passwords are hashed with PBKDF2 (SHA-512, 210,000 rounds) and a per-person salt. Session identifiers are also stored only as hashes.
- Eight wrong passwords in a row lock sign-in for 15 minutes, and sensitive actions are rate-limited.
- The database is reachable only through our own server. Row-level security is switched on for every table, and public access to the database is switched off.
- Team members see only what their role and permissions allow; the team area needs a separate access code and locks itself after a period of inactivity; important actions are written to an activity log.
- Your card number never passes through our servers.
No system is perfectly secure. If a breach puts your information at risk, we will tell you and the Information Regulator as POPIA requires.
8. Your rights
Under POPIA you may ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct or update it (you can edit most of it yourself in My profile);
- delete or destroy it, where we no longer have a lawful reason to keep it (see section 6 about financial records);
- stop using it for a purpose you object to, including marketing, and withdraw any consent you gave.
To delete your account yourself, use "Delete my account" in your profile or the delete-account page. To do any of these, contact the Information Officer (section 1) or the studio through the Contact studio page. We will reply within a reasonable time and may need to confirm your identity first.
If you are unhappy with how we handled your information, you have the right to complain to the Information Regulator (South Africa): website inforegulator.org.za, complaints email POPIAComplaints@inforegulator.org.za, general line 010 023 5200. We would appreciate the chance to put things right first, but you do not have to come to us before complaining.
9. Children
This service is meant for adults. [OWNER TO CONFIRM: minimum age to hold an account, and whether under-18s may join with a parent or guardian]
We do not knowingly collect a child's personal information without the consent of a parent or guardian. If you think a child has given us information without that consent, contact us and we will deal with it.
10. Cookies and changes
See the Cookie notice for the cookie and browser storage we use.
If we change this policy in a way that matters, we will update the date at the top and tell members in the app. The latest version is always at this address.
Other legal pages: Terms of Use · Cancellation and refund policy · Cookie notice. Questions? Contact the studio.