Privacy
LegalEffective Date: 28 June 2026 Version: 1.0
This Privacy Policy is a notice issued by Toker (the sole proprietorship, also trading as "Toker", "we","us", "our") in compliance with section 18 of the Protection of Personal Information Act 4 of 2013 ("POPIA"). It describes the personal information we collect, why we collect it, how long we keep it, who we share it with, and the rights you have.
1. Who we are (the Responsible Party)
- Responsible Party: Toker (Sole Proprietorship)
- Trading name: Toker
- Legal form: Sole proprietorship (Republic of South Africa)
- Registered address: 999A Marlin Street, Garsfontein, Pretoria, Gauteng, 0181, South Africa
- Operational email: support@go-toker.com
- Privacy email: privacy@go-toker.com
- Information Officer: formal Regulation 4 notice pending appointment and registration with the Information Regulator. Until it is published, direct data-subject requests to privacy@go-toker.com.
2. What this policy covers
This policy applies to:
- The Toker website at
https://go-toker.comand any URL under that domain - The Toker Progressive Web App (PWA), including push notifications
- Email, SMS, Web Push and any other channel through which Toker contacts you
- All forms, buttons and interactive elements on the Platform
- All API endpoints under
https://go-toker.com/api/*
It does not cover third-party websites linked from the Platform, or the legal relationship between you and any shop you visit after purchasing a Day Pass — that relationship is between you and the shop, governed by the shop's own policies and by South African law.
3. What we are NOT (scope clarification)
- Not a cannabis retailer, wholesaler, distributor, transporter, cultivator, or producer.
- Not an advertising platform for cannabis. The Platform contains no cannabis marketing material, no product listings, no prices for cannabis, no imagery of cannabis for promotional purposes, and no affiliate links to cannabis retailers.
- Not a data broker. We do not sell, rent, trade, lease or otherwise commercially exploit your personal information to any third party for that third party's own purposes.
- Not a payment or financial services provider. All payment processing is performed by independent, regulated third-party payment processors.
4. The legal basis on which we process
We rely on the following bases under POPIA:
- Consent (s.11) — marketing, optional profile categories, optional location, optional push notifications.
- Performance of a contract (s.11(2)(a)) — account creation, authentication, Day Pass issuance, payment processing.
- Legal obligation (s.11(2)(b)) — tax record-keeping, FICA records, Cybercrimes Act retention window.
- Legitimate interests (s.11(2)(d)) — fraud prevention, platform security, anonymised analytics, AUP enforcement.
5. Categories of personal information we collect
5.1 Information you give us directly
- Account identity: First name, surname, email address, cellphone number, password (hashed with PBKDF2-SHA-256)
- Shop business information (shop owners): Trading name, legal entity name, registration number, owner ID, VAT number
- Shop public listing (shop owners): Address, lat/long, contact details, operating hours, hero image, gallery, logo, description (markdown, max 1 000 chars), amenities
- Profile preferences (clients): Preferred categories, default search radius (1–50 km)
- Ratings (clients): Numeric rating (1–10) per shop. No free-text body is collected or stored.
- Merchandise orders (clients, where applicable): Shipping name, shipping address, contact phone, email, order contents, payment reference. Collected only when you place a merchandise order. See the Delivery Policy §6 and Refund Policy §14.
- Support communications: Email body, attachments, chat transcripts
- Identity verification (shop owners, on request): ID copy, utility bill, CIPC registration certificate
5.2 Information we collect automatically
- Device and connection: IP address, browser type, OS, screen size, referrer URL, timestamp
- Geolocation: Latitude, longitude, accuracy radius (with your permission)
- Usage analytics: Pages viewed, time on page, click events, scroll depth
- Session and authentication: Session token (HMAC-signed cookie), role, last-activity
- Service interaction: Check-ins, Day Pass purchases, level-ups, badges earned, challenge progress
- Push subscription: Endpoint URL, p256dh key, auth secret
- Payment metadata (not card data): the payment processor shown at checkout customer ID, last 4 digits, payment intent ID, transaction status, amount, currency
- Operational logs: Request path, response status, latency, error class (no user-agent per D1 migration 0049)
5.3 Information we receive from third parties
- Payment processor — confirmation of successful payment, amount, currency, fraud signal
- Google Maps Platform — address geocoding result, autocomplete suggestions
- Web Push network — delivery confirmation
We do not receive personal information from social media platforms, advertising networks, or data brokers.
6. How we use your personal information
- Create and authenticate your account
- Show you a map of nearby shops (if you grant geolocation)
- Show you shop listings, hours, contact details
- Issue a Day Pass after successful payment
- Operate the gamification engine (XP, levels, badges, challenges)
- Send push reminders if you have enabled them (Day Pass about to expire / check-in streak at risk)
- Send optional marketing communications (with consent — opt out any time)
- Collect Day Pass payments from users (Toker retains the pass revenue to operate the Platform; shops are not paid a share)
- Process merchandise orders: confirm payment, share the shipping name and address with the third-party courier that fulfils the order, and notify you of dispatch and delivery
- Prevent fraud, abuse, and platform security incidents
- Comply with a lawful request from a South African court, regulator, or law enforcement agency
- Aggregate, anonymised analytics about the Platform
7. How we share your personal information
We do not sell your personal information. We share only in limited circumstances:
7.2 With shop owners
When you purchase a Day Pass or check in, the shop owner sees:
- An opaque account identifier for you — not your name, and not any other profile information. Where you leave a rating, it is shown to the shop as "Client" followed by a short code.
- The Day Pass code, its status, and its validity window, together with the purchase, use and check-in timestamps
- If a Day Pass was gifted to you by another client, the email address the gift was sent to
- The star rating you have left for that shop — a score only; Toker holds no written review text
Beyond a gifted pass's recipient email as above, the shop owner does not see your email address, cellphone number, payment card details, or precise home location. This matches what the shop owner is told in the Shop Owner Agreement §10.3.
7.3 With our operators (data processors)
We use these third parties, each bound by a written operator agreement imposing POPIA-equivalent safeguards (POPIA s.21):
- Cloudflare Inc. — hosting, D1, KV, R2, Web Push (US + global edge; Cloudflare's DPA with EU SCCs)
- The payment processor shown at checkout — payment processing (see the checkout page for the processor currently in use)
- Google LLC (Maps Platform) — geocoding, map tiles (US + global edge)
- Resend / Postmark / SendGrid — transactional email (US)
- Our AI service provider (MiniMax) — composes replies for Toker's WhatsApp assistant from the text of your conversation with us; processed on our instruction, not used to train its models (see section 14A)
- Third-party courier and dropship / dropservice partners — merchandise fulfilment (SA + cross-border as applicable). Receives only the shipping name, address, contact phone, and order contents needed to deliver your order; no payment details, account email, or other profile data
A complete, up-to-date list is maintained in our Operator Register, available on request to privacy@go-toker.com.
7.4 With regulators, courts and law enforcement
We disclose to a South African regulator, court, or law enforcement agency when required by a valid court order, subpoena, search warrant, or written request from a regulator with jurisdiction (Information Regulator, SAPS, SARS, FIC, NPA, etc.), or when necessary to protect the rights, property or safety of Toker, our users, or the public, in accordance with the Cybercrimes Act 19 of 2020 and the Criminal Procedure Act 51 of 1977.
7.5 Corporate transactions
If Toker is acquired, merges, or sells all or substantially all of its assets, your personal information may be transferred to the acquirer. We will give you at least 30 calendar days' notice by email before the transfer.
7.6 We do NOT share with
- Advertising networks or marketing data brokers
- Cannabis retailers or cannabis marketing platforms
- Political parties or campaigns
- Anyone else, except as set out above
8. Cross-border transfers (POPIA s.72)
Our cross-border transfers are:
- Cloudflare Inc. (US, with global edge) — s.72(1)(a) — Cloudflare participates in the EU-US Data Privacy Framework
- Google LLC (US) — s.72(1)(a)
- Resend / Postmark / SendGrid (US) — s.72(1)(a)
No cross-border transfer occurs as a result of a shop owner or client being in South Africa and Toker being in South Africa. All transfers identified above are to operators in the US, on the bases stated.
9. How long we keep your personal information
- Account identity: life of account + 30 days (recovery window) → anonymised or deleted
- Soft-deleted account data: 30 days → hard-delete
- Geolocation: your most recent position only — one row per user (latitude, longitude, accuracy and the source of the fix). Each new fix overwrites the previous one, so no location history is kept; a copy is cached for 7 days so we do not re-prompt you. Decline the prompt and we record only that you declined. Retained until replaced or erased on request — there is currently no automatic expiry.
- Service interaction history: life of account → anonymised for platform-wide stats
- Day Pass transactions: 5 years (Income Tax Act s.25(1) + CPA dispute window)
- Web Push subscription: until revoked or account deleted
- Operational logs: 12 months rolling
- Audit log: 7 years (Cybercrimes Act breach-notification window)
- Support communications: 3 years from last contact
- Marketing consent record: until withdrawn + 3 years (POPIA s.14)
10. How we protect your personal information (POPIA s.19)
- Encryption in transit: TLS 1.2+; HSTS preload; Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
- Encryption at rest: Cloudflare D1 at-rest encryption; R2 at-rest encryption; KeePassXC AES-256 for credential vault
- Access control: RBAC (4 roles: client, shop, admin, founder); least privilege; all access logged to audit_log
- Authentication: HMAC-signed session cookies; PBKDF2-SHA-256 password hashing; per-IP rate-limit on writes (10/min) and reads (60/min); CSRF protection (Origin check + SameSite=Lax); Cloudflare Turnstile on registration
- Network protection: Cloudflare WAF + DDoS; CSP with nonce-based script loading; X-Frame-Options: DENY; Referrer-Policy: strict-origin-when-cross-origin; Permissions-Policy: geolocation=(self), camera=(self) — location and camera are available to Toker's own pages only (the camera is used for shop photos and proof-of-payment uploads) and to no embedded third party; your browser still asks you before either is used
- Backup and recovery: Encrypted daily backups of D1; backup integrity verification
- Vendor management: Every operator bound by written DPA; periodic audit
- Staff training: All personnel with access to personal information are trained on POPIA
- Breach response plan: aligned with the Cybercrimes Act 19 of 2020 notification obligations
11. Your rights as a data subject
11.1 Right of access (POPIA s.23)
Request a copy of the personal information we hold by opening a support ticket — tap Help & Support in your profile menu and ask for a "Data Access Request" — or by email to privacy@go-toker.com. There is currently no self-service export in the app; a request by either route is all that is required. We respond within 30 calendar days.
11.2 Right to correction (POPIA s.24)
Self-service from /dashboard/client/profile or /dashboard/shop, or email. 30-day response.
11.3 Right to deletion (POPIA s.25)
Ask us to delete your account by opening a support ticket — tap Help & Support in your profile menu and ask for "Account Deletion" — or email privacy@go-toker.com. There is currently no self-service delete-account control in the app. We process account-closure requests within 7 days (see User Agreement §13.1), and deletion is permanent once processed, with the following exceptions: records we must keep by law (tax, FICA, audit log), anonymised records, and records of transactions for which a dispute window has not yet closed.
11.4 Right to object (POPIA s.11(3))
Object on reasonable grounds; we stop processing unless we can demonstrate a compelling lawful basis that overrides your interests.
11.5 Right to withdraw consent (POPIA s.11(2))
Withdraw at any time. Withdrawal does not affect lawfulness of processing before withdrawal. Channels: marketing — "unsubscribe" link or profile preferences; Web Push — browser notification settings; geolocation — browser permission; optional profile preferences — profile settings.
11.6 Right to lodge a complaint with the Information Regulator (POPIA s.74)
The Information Regulator (South Africa)
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Postal: P.O. Box 31533, Braamfontein, Johannesburg, 2017
- Complaints: enquiries@inforegulator.org.za
- Phone: +27 10 023 5200
- Website: www.inforegulator.org.za
12. Automated decision-making
We do not make any decisions about you based solely on automated processing that produce legal effects (POPIA s.71). The Platform does use automated processing to compute distance from your geolocation to nearby shops, award XP / badges / levels / challenges (cosmetic), and flag suspicious transactions for human review (does not result in automatic decline).
13. Children's personal information
Toker is an information directory that does not require registration to browse. The Platform is not directed at children under 18. We do not knowingly collect personal information from children under 18. If you believe a child under 18 has registered, contact privacy@go-toker.com.
14. Direct marketing
We only send marketing communications with your specific consent (POPIA s.11(1) read with ECTA s.45 — opt-in for unsolicited electronic communications). Opt out at any time: "unsubscribe" in any marketing email, profile preferences, or email privacy@go-toker.com. We honour opt-outs within 5 business days (CPA s.41(8)).
14A. WhatsApp messages and our assistant
If you contact Toker on WhatsApp, or ask us to send you a login code, a pass or an invite there, we keep the messages you send us and the messages we send you, so we can help you and so you can see what was said. Replies you receive may be written by Toker's automated assistant ("Alex"), which we operate and a person supervises. To compose a reply, the text of your conversation is processed on our behalf by an AI service provider under an operator agreement (section 7.3) and is not used to train its models.
We keep WhatsApp message content for 90 days and one-time login codes for one hour; after that only the fact that a message was sent or received remains. We only message people who asked us to, or who gave us their number for that purpose. Reply STOP at any time and you will not hear from Toker on WhatsApp again. You may ask to see or delete your messages under section 11 by writing to privacy@go-toker.com.
15. Changes to this Privacy Policy
Material changes are posted on the Platform and emailed to you at least 30 calendar days before the change takes effect. The previous version is available on request.
16. How to contact us
For any privacy-related question, request, complaint, or withdrawal of consent:
- Privacy email: privacy@go-toker.com
- Operational support: support@go-toker.com
- Information Officer: formal Regulation 4 notice pending appointment and registration with the Information Regulator. Until it is published, direct data-subject requests to privacy@go-toker.com.
- Postal address: 999A Marlin Street, Garsfontein, Pretoria, Gauteng, 0181, South Africa
We acknowledge your request within 5 business days and respond substantively within 30 calendar days.