Version 2. This version supersedes the 10 May 2026 version with no material reduction in your rights. Material changes are listed at the bottom of this document.
This Privacy Policy explains what personal information TradeJot ("we", "us") collects, why we collect it, how we protect it, and what rights you have. We comply with the South African Protection of Personal Information Act 4 of 2013 ("POPIA").
TradeJot is a service provided by Dewald du Toit (sole trader), operating from the Free State, South Africa. For the purposes of POPIA, the Responsible Party in respect of our own data processing is Dewald du Toit.
Our Information Officer is Dewald du Toit, contactable at support@tradejot.co.za with the subject line "POPIA Enquiry". A manual prepared in terms of the Promotion of Access to Information Act 2 of 2000 ("PAIA Manual") is available on request.
Full contact and legal details, including our physical address for service of legal documents, appear in our Terms of Service.
| Field | Why we need it |
|---|---|
| Phone number | To deliver the Service; identifies your account |
| Business email address | Required. For account recovery and critical service notices |
| Name, business name, trade | To populate invoices and quotes |
| Business address (optional) | For invoice headers if you choose to include it |
| VAT number (optional) | For tax-compliant invoicing if applicable |
| Banking details (optional) | To print on invoices if you choose to include them |
| Subscription / payment status | To manage your plan and billing |
| Message history with the bot | To process your commands and improve parsing accuracy |
| Your handwritten signature (only if you sign a document) | Drawn on-screen when you sign a quote, invoice or lay-by agreement. Stored as an image. See the note below — this is special personal information. |
| Field | Why we need it |
|---|---|
| Name | To address the invoice or quote |
| Phone number | To send the invoice via Telegram if the tenant has Pro+ and the client has consented |
| Address | If the job involves a physical site |
| Job description and amount | To produce the invoice |
| Handwritten signature (only if the client signs a document) | Drawn on-screen when a client signs a quote, invoice or lay-by agreement. Stored as an image. See the note below — this is special personal information. |
If a quote, invoice or lay-by agreement is signed, the signature is drawn on-screen and saved as an image file on our server, alongside the signer's typed name and the date and time they signed. Both the tenant and the client can sign the same document, so a signature we hold may belong to either.
A handwritten signature records how a person writes, so we treat it as biometric information — "special personal information" under POPIA section 26, the most protected category. Because of that:
We do not sell, rent, or share your personal information for marketing purposes. We do not show advertising in TradeJot.
TradeJot does not perform automated decision-making that produces legal effects concerning data subjects or similarly significantly affects them, as described in section 71 of POPIA.
To provide the Service we use specialist third-party providers ("sub-processors"). This involves transferring personal information outside of South Africa. In accordance with section 72 of POPIA, we ensure that such transfers are lawful by relying on the following safeguards (in this order of preference):
For your own data (Tenant): by using the Service, you consent to these transfers as necessary to deliver the Service.
For your clients' data (End-clients): we process and transfer client data strictly on your documented instruction as Responsible Party. You — not TradeJot — are responsible for ensuring you have a lawful ground under POPIA section 72 to permit the transfer of your clients' information out of South Africa (typically necessity for the performance of your contract with that client). You authorise us to rely on that lawful ground when we engage the sub-processors listed above. We maintain the safeguards described in this section to protect that data in transit.
| Service | Country | Purpose |
|---|---|---|
| Hetzner Online (hosting) | Germany / EU | Server hosting and backups |
| Telegram (messaging) | Global (Telegram FZ-LLC) | The Telegram channel runs on the Telegram Bot API. Telegram's own privacy terms apply to message delivery. |
| Payments provider (subscription billing) | South Africa | A South African PCI-DSS Level 1 payment processor handles subscription billing via hosted checkout. Card data is entered on the provider's secure page and never touches TradeJot. The active provider is Paystack (Paystack Payments South Africa). Card data is entered on Paystack's secure page and never touches TradeJot. If we change provider we will update this table; you can re-confirm the current provider at any time by emailing support@tradejot.co.za. |
| Anthropic (parsing) — primary | USA | Parses your text messages into structured invoice data using the Claude family of models, accessed via OpenRouter. Phone numbers and other direct identifiers are masked before being sent. |
| DeepSeek via OpenRouter (parsing) — secondary | USA / EU | Used as a fallback parser and for our internal cross-vendor review process. Same masking rules apply. |
| Groq (voice transcription) | USA | Transcribes voice notes you send to the bot. Audio is deleted immediately after transcription; only the resulting transcript metadata (length, cost) is retained. |
| Google (photo scanning) | USA / Global | Reads photographs you send to the bot: till slips and receipts, and photos of stock items, labels or barcodes. The whole photograph is sent, and unlike our text parsing nothing in it is masked first — a photo cannot be selectively redacted, so whatever is visible on the slip is sent, including the shop, the date, the items and any card digits printed on it. Google returns the extracted details plus the full text read off the slip. The photo itself stays on our server, attached to the expense record it created. |
| Zoho SMTP (transactional email) | Global | Sends account-recovery and critical service emails. |
By using the Service you consent to these transfers. They are necessary to deliver the Service.
| Data type | Retention |
|---|---|
| Raw messages to the bot | 30 days, then deleted (rolling) |
| Tenant and client records | While your account is active |
| Invoices and financial records | 5 years after issue (SARS minimum for tax records) |
| Handwritten signatures (images, signer name, signing time) | Kept for as long as the document they sign is kept. On erasure the image files are deleted from disk and the signature details are cleared from the document. |
| Photographs you send (till slips, stock items) | Kept with the expense or stock record they created. Deleted when that record is erased. |
| Audit logs | 12 months (rolling deletion) |
| Backups | 30 days, then overwritten |
| On account cancellation | Your account and associated personal information are scheduled for deletion after a 30-day grace period. However, specific records we are legally required to retain — such as financial invoices held for SARS purposes — will be retained for the statutory period (typically 5 years) and will be anonymised or pseudonymised where possible to disassociate them from your deleted account. All other data is permanently deleted. |
You have the right to:
To exercise any of these rights, contact our Information Officer at support@tradejot.co.za with the subject line "POPIA Data Subject Request". We may require you to verify your identity before proceeding. Further detail on the request process is available in our PAIA Manual on request.
If you are an end-client who has received a message from TradeJot, you have rights you can exercise directly by replying to the TradeJot bot on Telegram:
We process personal information on the following lawful bases under section 11 of POPIA, in approximate order of how often each applies:
When a tenant sends an invoice to an end-client for the first time via TradeJot, the bot's message includes a privacy notice and an explicit STOP instruction.
If a client replies STOP, we record the opt-out at the platform level. No further messages from any TradeJot tenant will be sent to that number until they reply START.
If a tenant uses the automatic invoice-delivery feature, before TradeJot sends any message to a client, the bot will:
The client can revoke consent at any time by replying STOP (which triggers the global opt-out described in section 10).
Your registered email is used for a magic-link recovery flow. If you lose access to your account you can trigger recovery; we send a single-use recovery link with a 1-hour expiry to your email. Your new login is bound to your tenant record on successful confirmation. Every recovery event is recorded in the audit log.
Premium tenants can add staff members to their account by phone number. The tenant is responsible for obtaining each staff member's consent. Staff members can use the bot to log jobs, mark invoices paid, run reports, and similar operational tasks on the tenant's behalf. Staff cannot access sensitive controls — they cannot delete the account, change branding, manage other staff, change the subscription plan, or perform POPIA deletion requests. All actions taken by staff members are recorded in the account's audit log against the staff member's own phone number.
We maintain a secure audit log of all privileged actions on your account. This includes plan changes, staff being added or removed, data deletions, account recovery events, and refunds. Audit logs are retained for 12 months for security and compliance purposes. The audit log is accessible to the account owner via the bot's audit command.
The Service is not intended for users under 18. We do not knowingly collect personal information from children. POPIA defines a child as a person under 18.
This website does not use cookies for tracking, and we run no advertising or third-party analytics scripts on tradejot.co.za. We count page views with our own first-party beacon: it stores no cookies and nothing else in your browser, collects no names, contact details or account information, honours your browser's Do Not Track setting, and never contacts a third party. It records only the page path, the referring site's hostname and any campaign tag in the address, on our own server in aggregate form.
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will act as soon as reasonably possible after the discovery of the compromise, in accordance with section 22 of POPIA.
We will notify you and the Information Regulator as soon as reasonably possible, and provide sufficient information for you to take protective measures.
Under POPIA, the Operator is obliged to notify the Responsible Party of any compromise of personal information being processed on their behalf. We will therefore notify the affected tenant(s) as soon as reasonably possible. The tenant, as the Responsible Party, is then responsible for any further notification to the Information Regulator and to affected end-clients, as required by section 22 of POPIA. We will provide reasonable assistance — including the information required to support the tenant's own notification — to enable that obligation to be met without delay.
We may update this Policy from time to time. Material changes will be notified via the bot and on this page at least 30 days before they take effect.
For all questions — privacy, billing, support — email support@tradejot.co.za.