Legal

Privacy policy

This Privacy Policy explains how Empowr (Pty) Ltd, operator of FIX IT, processes personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA).

1. Information we collect

Account data: name, contact details, role (Customer, Provider, Administrator) and authentication data. Service data: service addresses, property information, Job history, uploaded evidence photos, in-app chat messages, ratings and reviews. Provider verification data: ID, trade qualifications, insurance, Police Clearance Certificate and COIDA Letter of Good Standing where applicable, and payout bank details. Payment data: tokenised card references and transaction metadata processed via Paystack; full card numbers are never stored on FIX IT systems. Device and usage data: IP, device identifiers, diagnostics, and interaction logs used for security and product improvement.

2. Why we process it (POPIA lawful basis)

To operate the platform and perform our contract with you (bookings, Job Cards, Quotes, trip tracking, Completion Reports, payments, receipts, ratings); to comply with legal obligations (tax, anti-fraud, POPIA); for legitimate interests (security, fraud prevention, service improvement); and, where required, on the basis of your consent (for example marketing communications and non-essential cookies).

3. Who can see what

Customers never see Provider ID or bank documents. Providers only see the Customer information needed for an active Job (name, address, contact details and Job details). Administrators access data based on strict role permissions; access is logged.

4. Operators and third parties

We use a small number of vetted operators to deliver the service: our cloud hosting, database, file storage and authentication provider; Paystack (card payments and payouts); Expo / Google Firebase Cloud Messaging (delivery of push notifications to your device); Sentry (crash and performance diagnostics, with personally identifying data disabled); an email delivery provider for account and Job emails; OpenStreetMap-based routing (coordinates only, sent to calculate a driving route — no name, address text or account identifier is sent with them); and, for the Felix assistant, an AI gateway that processes the text of your question. Website analytics use Google Analytics 4 on the website only — the mobile app contains no analytics or advertising SDK. Operators are bound by written agreements requiring appropriate security and POPIA compliance. We do not sell personal information.

5. Cross-border transfers

Where personal information is processed outside South Africa (typically hosting or notification delivery), we ensure adequate protection through the operator's contractual commitments and, where required, POPIA-compliant transfer mechanisms.

6. Security

The platform is designed around privacy-by-design and defence-in-depth: role-based access controls, row-level security in the database, encryption of sensitive documents at rest, encryption in transit, audit logging and administrative access reviews. No system is completely secure; report incidents to security@empowr.co.za.

7. Retention

We retain personal information for as long as necessary to deliver the service and to comply with legal obligations (including tax and audit retention requirements). Job Card and payment records are retained for the periods required by South African law.

Some information is kept only briefly: a push notification token is deleted when you disable notifications, sign out or delete your account; the coordinates used to draw a route are used to calculate that route and are not stored as a location history; crash diagnostics are retained by our diagnostics operator on a rolling short-term basis. When you delete your account, personal information is erased or irreversibly anonymised as described in section 12.

8. Your rights

Under POPIA you have the right to access, correct or delete your personal information, to object to processing, to withdraw consent, and to complain to the Information Regulator. Many of these rights can be exercised through account settings; other requests can be sent to privacy@empowr.co.za.

9. AI and automated decisioning

The scope and safeguards for Felix and any other AI features are set out in the AI Transparency Statement. Where automated processing materially affects you, you have the right to human review under POPIA §71.

10. Cookies

See the Cookie Policy for details of cookies and similar technologies used on the site.

11. Our mobile application

This policy also covers the FIX IT mobile app (co.za.empowr.fixit.customer). FIX IT is a single app containing two workspaces: a Customer workspace and a Provider workspace. Which workspace you see depends on the role held by your account. If your account holds both roles you can switch between them without signing out; the workspace you are in determines which features, and therefore which device permissions, can be used.

Location. FIX IT requests precise location only while the app is open, and only inside the Provider workspace, at the moment a Provider opens the route to a Job they have accepted. It is used to draw that route. Background location is not collected — the app cannot collect it, because the background-location permissions are blocked in the app itself. A Customer-only account is never asked for location, and the arrival progress a Customer sees is rendered from the arrival time the Provider declared and from server-side Job milestones, never from the Customer's device. If location is declined, the route map is unavailable and every other Job action still works.

Camera and photo library. Requested only inside the Provider workspace, at the moment you choose to add a photograph — before/after evidence attached to a Job, or a profile picture. Photographs you attach form part of the Job record and are visible to the Customer of that Job and to authorised administrators. A Customer-only account is never prompted for camera access.

Availability and presence. If you work as a Provider, we store the availability you set (on duty, off duty, working hours and exceptions) so that Jobs are only offered to you when you are available. This is a status you set yourself; it is not derived from tracking your device.

Ratings, reviews and reports. A rating or review you leave is stored against the completed Job and shown with your first name. If you report a safety concern, a review or another user, we store the report, its content and the outcome so we can investigate and keep an auditable record.

Biometrics. Fingerprint or face unlock is optional and is performed entirely by your device's secure hardware. Empowr never receives, transmits or stores biometric templates. Your session is held in the device's encrypted secure store and cleared on sign-out.

Notifications. If you enable notifications we store a push token so Job updates can reach your device. It is not shared for advertising.

Diagnostics. Crash and performance data are processed by Sentry with personally identifying data disabled and screen recording switched off. Payments are processed by Paystack; the apps never store card numbers. Website analytics use Google Analytics 4. The apps contain no advertising SDK and we do not sell personal information.

The apps are intended for users aged 18 and over and are not directed at children.

12. Deleting your account and data

You can delete your account from inside either mobile app under Account → Delete my account, or without installing anything by using our Account & data deletion page. Personal information is erased or irreversibly anonymised; financial and Job records that South African tax and audit law requires us to keep are retained under an anonymous reference that can no longer be linked back to you.

13. Contact and complaints

Information Officer: privacy@empowr.co.za. You may also complain to the Information Regulator (South Africa) at inforeg.org.za.

Last updated: placeholder. Final version pending legal review by EMPOWR (Pty) Ltd.