Privacy policy

Last updated: [DATE]

ServiceTok exists to get municipal problems fixed. To do that we need to know what the problem is and where it is — and almost nothing else. This page says exactly what we collect and what happens to it.

The short version: reports are public by default, shown with a street or suburb but never an exact location, and never with your name. You can switch that off for any report before you send it.

Who we are

ServiceTok is operated by [COMPANY NAME], [COMPANY REGISTRATION NUMBER], [ADDRESS]. We are the responsible party for the personal information described here, as defined in the Protection of Personal Information Act, 2013 (POPIA).

Information Officer: [NAME], [EMAIL].

You do not need an account

Most people use ServiceTok without registering. We do not ask for your name, your address or your identity number, and we never require them.

What we collect

A device identifier

When you first open the app we create a random identifier for your phone and store it as a one-way hash. We use it to rate-limit submissions, to reduce abuse, and to show you your own reports.

It is not an advertising identifier and it does not follow you to any other app or website.

Location

We read your location only when you tap a button that asks for it — never in the background, and never while the app is closed. You can type an address instead.

The precise location is sent to your municipality with the report, because a crew needs to know where to go. If you choose to share a report publicly, only the suburb or municipality is shown, never the exact position.

Photographs

Photographs you attach are sent to your municipality as evidence. Before a photo leaves your phone we remove the embedded metadata, which would otherwise include the camera location and device details.

Your report

The category, description, location and status of what you report.

Contact details, only if you give them

If you choose to register, we store your phone number so you can sign in and keep your reports if you change phones. Municipal staff accounts also hold a name and email address.

What we do not collect

Who your information goes to

Your municipality

Reports are sent to the municipality responsible for the area. They hold that report under their own record-keeping rules, which we do not control. If you report anonymously, your contact details are not included.

Automated screening

Reports are checked automatically before they reach a municipality, to keep abusive and irrelevant content out. The text and any photograph may be sent to Anthropic PBC (United States), which provides this screening service on our behalf and does not use the content to train its models.

This is a transfer of personal information outside South Africa. It happens under contractual safeguards that require the recipient to protect the information to a standard comparable with POPIA.

If a screening decision goes against you, you can appeal it and a person will look at it.

The public feed

Reports appear on our public feed by default. That is the point of ServiceTok: a problem several neighbours can see is harder for a municipality to leave. You are told this before you send, and you can switch it off for any report.

What appears publicly:

What never appears:

Turning off public visibility does not affect your report reaching the municipality. It only keeps it off the feed.

Anyone can also say "this affects me too" on a public report. We record that as a count only — we do not store who did it.

Nobody else

We do not sell your information, and we do not show advertising. We share information with law enforcement only where the law requires it.

How long we keep it

Your rights

Under POPIA you may ask us to show you what we hold, correct it, or delete it. Two of those are buttons in the app, under Profile:

Both work whether or not you registered.

Deleting your data does not delete the reports themselves. A report about a burst pipe is the municipality's work record, and a crew may already be on the way — cancelling that would not be your data being deleted, it would be someone else's work being destroyed. What we remove is every link between those reports and you.

Security

Traffic is encrypted in transit. Passwords are stored hashed with bcrypt, and sign-in tokens are stored hashed and rotated on every use. We do not store your device identifier or your sign-in codes in a form that can be read back.

Children

ServiceTok is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has submitted personal information, contact our Information Officer and we will remove it.

Complaints

Contact our Information Officer first — we would rather fix it. You also have the right to complain to the Information Regulator (South Africa), inforegulator.org.za.

Changes

If we change what we collect or who we share it with, we will update this page and change the date at the top. Material changes will be shown in the app.