1. Who we are
This Privacy Policy explains how Yebowork (Pty) Ltd, trading as YeboWork (registration number 2023/636663/07), of 9 McAdam Street, Newton Park, Port Elizabeth, Eastern Cape ("we", "us"), collects, uses, shares and protects your personal information when you use https://yebowork.co.za and our services (the "Platform"). We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"). This Policy forms part of our Terms & Conditions. For complete contact details, visit our Contact page.
2. Information we collect
- Account & identity: name, display name, email, mobile number, role (buyer/seller), and — where identity verification applies — your ID/passport number and verification documents.
- Identity & business verification: when you choose to verify, we capture a selfie (a biometric facial image) and your ID/passport details via our verification provider, Smile ID; for business verification we also process your company registration details. Your verification selfie is used as identification and may be shown to a counterparty (see "Who we share information with").
- Location: your base location and service areas; for a posted job, a job location. Exact street addresses are shared with a counterparty only after an engagement is accepted, and are never shown publicly.
- Listings & profile: services, specialties, business hours, photos, bio, links and reviews.
- Transactions & wallet: bookings, quotes, jobs, orders, credit purchases and ledger, packages, premium features and advertising bookings. We receive payment references from our gateway but do NOT store your card or bank-account numbers.
- Communications: in-app messages, notifications, and support correspondence.
- Technical & usage: device, browser, IP address, pages viewed and similar analytics data, and cookies (see clause 6).
3. How we use your information
To create and manage your account; operate the marketplace (discovery, bookings, quotes, jobs, messaging); process credit purchases and payments; verify identity where required; detect and prevent fraud and abuse; provide support; send transactional messages and — with your consent — marketing; improve the Platform; and comply with legal obligations.
4. Legal basis and consent
We process personal information where it is necessary to provide the Platform and perform our agreement with you, to comply with the law, to pursue our legitimate interests (such as security and improving our services), or with your consent (for example marketing and non-essential cookies). You may withdraw consent at any time, subject to legal or contractual restrictions.
5. Who we share information with
We share personal information with operators and partners that help us run the Platform, under appropriate agreements, only as needed:
- Hosting, database, authentication and storage (Supabase);
- Email delivery (Resend);
- Maps and location search (Mapbox);
- SMS one-time-PIN delivery (SMS provider);
- Identity verification (SmileID, when enabled);
- Payment gateway(s) (PayFast and Paystack);
- Advertising (Google AdSense — see clause 6);
- Authorities or third parties where required by law, or to protect rights, property or safety.
Some of these operators may process information outside South Africa. Where this occurs, we take reasonable steps (including contractual safeguards) to ensure a level of protection comparable to POPIA.
Verification selfie shown for safety
Once a job is accepted between a buyer and a service provider, your verification selfie is shown to that counterparty (and theirs to you) so both parties can confirm each other's identity in person. It is shown only to the accepted counterparty — never publicly, and never before an engagement is accepted.
6. Cookies and advertising
We use cookies and similar technologies for essential functionality (keeping you signed in), analytics, and advertising. You can control non-essential cookies through our cookie banner and your browser settings; disabling some cookies may affect functionality.
Google AdSense: we may display third-party advertising through Google AdSense. Google and its partners use cookies (including the Google advertising cookie) to serve ads based on your prior visits to this and other websites. This enables Google and its partners to serve personalised ads. You can opt out of personalised advertising via Google Ads Settings (https://adssettings.google.com) and learn more at https://policies.google.com/technologies/ads. You can also opt out of some third-party vendors' use of cookies for personalised advertising by visiting https://www.aboutads.info. Third-party vendors' use of advertising cookies is subject to their own privacy policies.
7. Your rights under POPIA
You have the right to: access the personal information we hold about you; ask us to correct or delete it; object to processing (including direct marketing); and lodge a complaint. To exercise these rights, contact our Information Officer (clause 11). You may also complain to the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001; https://inforegulator.org.za.
7.1 How to submit a data subject request (step by step)
- Send your request by email to our Information Officer, Ettienne Gerwel, at admin@yebowork.com with the subject line "POPIA data subject request", or through our Contact page.
- Tell us who you are: your full name, the email address and mobile number on your YeboWork account, and a copy of your ID or passport so we can verify that the request is really from you (we use this only to verify you and then delete it).
- Tell us what you want us to do — choose one or more: access (a copy of your information), correction of inaccurate details, deletion/erasure, objection to processing or direct marketing, restriction of processing, or a portable copy of your data.
- Be specific where you can — for example "all messages and job records for job #1234" or "my verification documents" — this helps us answer faster.
- We acknowledge your request within 5 business days and respond in full within 30 days of receipt (POPIA / PAIA timeframe). If the request is complex we may extend this once, by up to 30 further days, and will tell you why in writing.
- Outcome: access requests are answered with a copy of your information (a prescribed PAIA fee may apply to access requests for records other than your own routine account data). Correction and deletion requests are actioned free of charge. Where we cannot delete information because the law requires us to keep it (for example tax, company-law or fraud-prevention records), we will tell you which information we are retaining and why.
- Not satisfied? You may complain to the Information Regulator using their Form 5 complaint at https://inforegulator.org.za or by email to their complaints address.
Many corrections can be made instantly yourself — update your name, contact details, address, listings and marketing preferences in your account settings, and you can request account deletion from the same place.
8. Security
We apply technical and organisational safeguards including database Row-Level Security, role-based access controls, encryption in transit (HTTPS) and for sensitive data, restricted access to verification documents, access logging, and server-side controls for sensitive operations. We do not store banking details. No system is perfectly secure, but we take reasonable steps to protect your information.
8.1 Payment security
- We never see or store your card details. Card and bank details are entered on, and processed by, our registered payment gateways — PayFast and Paystack — who maintain applicable PCI DSS compliance as payment service providers. Paystack states that it is PCI DSS Level 1 certified. YeboWork stores only a payment reference, the amount, the status and the date.
- Encryption: all traffic to and from the Platform is served over HTTPS using TLS 1.2 or higher; sensitive at-rest fields and verification documents are stored in access-restricted, encrypted storage.
- Fraud prevention: identity verification (Smile ID), mobile OTP verification, CAPTCHA on authentication screens, rate limiting, server-side validation of every payment event, signed gateway callbacks (ITN/webhook signature checks), access logging and admin review of reported activity.
- Retention: transaction and payment-reference records are kept for the period required by tax and company law (generally five years). No card, CVV or bank-account numbers are retained at any point.
- Third-party compliance: our gateways are regulated South African payment providers and process personal information as our operators under written agreements; their own privacy and security terms apply to the payment step.
Our Payment Terms explain online processing and settlement.
8.2 Electronic transactions (ECTA)
We comply with the Electronic Communications and Transactions Act 25 of 2002. Our full supplier details are published in our Terms & Conditions (section 43 information); electronic agreements and on-platform actions such as accepting a quote constitute valid electronic signatures; you are always shown a summary and a chance to correct errors before confirming; electronic records of your transactions are retained and accessible in your account; and marketing messages always carry an opt-out. Section 27 and 28 of the Terms set out these rights in full.
8.3 Communications privacy (RICA)
We comply with the Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002 ("RICA"). Specifically:
- We do not intercept, monitor or record your communications unlawfully. In-app messages between users are not read for marketing, profiling or resale.
- As the provider of the messaging service and a party to the system, we may access message content only where it is necessary and lawful — for example when a user reports a message, when investigating fraud, abuse or a safety risk, when mediating a dispute you have escalated to us, or where the law or a valid court direction requires it.
- We disclose communication content or communication-related information to law enforcement only on a lawful direction, court order or interception direction issued under RICA or another applicable law (including reports we are obliged to make under our Child Safety & CSAM Policy).
- Messages travel over encrypted TLS/HTTPS channels and are stored with database Row-Level Security so only the participants in a conversation (and, where necessary, authorised administrators) can access them.
- Access by administrators is restricted, role-based and logged. Unlawful interception is a criminal offence and any staff member who attempts it will be dismissed and reported.
9. Retention
We keep personal information only as long as necessary for the purposes above or as required by law (for example, tax and company-law records). Verification documents are purged within 12 months after an account is closed, unless the law requires otherwise.
10. Children
The Platform is intended for persons 18 years or older. We do not knowingly collect personal information from children.
11. Changes and contact
We may update this Policy from time to time; the latest version is posted on the Platform. Questions or requests: our Information Officer, Ettienne Gerwel, at admin@yebowork.com. General support: support@yebowork.com.