Privacy Policy
This Privacy Policy explains how HASH3D (Pty) Ltd, trading as HASH3Dconnect ("we", "us", "our"), collects, uses, stores, and protects personal information when you use our website (hash3d.co.za), our NFC/QR digital business card service, and related dashboard, calendar, invite, and booking features (together, the "Service"). We are committed to handling personal information responsibly, in line with South Africa's Protection of Personal Information Act, 2013 ("POPIA").
1. Who We Are
HASH3D (Pty) Ltd (Registration No. 2026/548373/07) is a South African company operating the HASH3Dconnect platform, with its registered address at 20 Herta Louw, Shirley Park, Bellville, 7530, Cape Town, South Africa. For any privacy-related queries, or to exercise any of the rights set out below, you can reach us at support@hash3d.co.za or via WhatsApp at +27 83 387 7270.
2. Information We Collect
2.1 Information you give us
- Account and profile information, if you sign up as a HASH3Dconnect customer: full name, email address, phone number, business or company name, job title, a securely stored password, your profile photo, social media handles, price list content, and an optional access PIN for your card.
- Enquiry information, if you submit our "Get Started" form or otherwise contact us: your name, phone number, and optionally your email address, business name, location, and any message you send us.
- Visitor information collected on a customer's behalf: if you are a HASH3Dconnect customer, visitors who tap or scan your card may voluntarily submit their name, phone number, email address, and any message, via the lead-capture form, RSVP forms, or appointment request form on your card. This information belongs to you as the card owner. You act as the responsible party for this information under POPIA, and you are responsible for how you use it — see our Terms of Service.
2.2 Information collected automatically
- Tap and scan activity: when a card is tapped or scanned, we record the date, time, and which physical tag was used, so the card owner can see their own traffic.
- Approximate location: with a visitor's device permission, we may record an approximate location at the moment of a tap, for the card owner's own analytics.
- Basic technical information (such as browser type) may be logged for security and abuse-prevention purposes, such as rate-limiting.
- A random, non-identifying device ID stored in your browser, used only to prevent duplicate star ratings from the same device.
- Information generated through your continued use of the Service, including dashboard activity, support requests, feature usage statistics, and communications between you and HASH3Dconnect.
2.3 Information we do not collect
We do not collect or store payment card details. Payments are currently made by manual EFT, with proof of payment shared directly with us; we do not store banking details beyond what you choose to share with us for this purpose.
3. How We Use Your Information
We use personal information to:
- Create and manage your HASH3Dconnect account and digital card(s)
- Operate the features you've chosen to use, such as lead capture, price list, ratings, calendar, invites, and booking requests
- Send you service-related communications, such as password reset emails and renewal reminders
- Respond to enquiries submitted through our website
- Maintain and improve the Service, including basic security and abuse prevention
- Comply with our legal obligations
Where visitor information is submitted through a customer's card, HASH3Dconnect merely hosts and processes this information on behalf of the customer and does not determine the purpose or means of processing such information; the customer acts as the responsible party for that information under POPIA, as described in Section 2.1 above and in our Terms of Service.
4. Legal Basis for Processing
We process personal information where it is necessary to perform our contract with you (providing the Service), where you have given consent (for example, by submitting a form), where we have a legitimate interest in operating and securing the Service, or in compliance with legal obligations — in each case consistent with the conditions for lawful processing set out in POPIA.
5. Sharing Your Information
We do not sell personal information. We share information only with trusted service providers who help us operate the Service, including:
- Railway — application hosting and database
- Vercel — dashboard hosting
- GitHub Pages — static card page hosting
- Cloudinary — photo and image hosting
- Google (Gmail API) — used only to send transactional emails, such as password resets and lead notifications; we do not use this access to read or manage your Gmail account
These providers only process personal information on our instructions, for the purposes described in this Policy, and are not permitted to use it for their own purposes. We may also disclose information where required by law.
Personal information may be processed or stored on servers located outside South Africa where our service providers operate. We take reasonable steps to ensure such providers maintain appropriate safeguards consistent with POPIA and applicable data protection laws.
6. Data Retention
We retain personal information for as long as your account is active, and for a reasonable period afterward where necessary for legal, accounting, or dispute-resolution purposes. Visitor lead information remains available to the relevant card owner until they choose to delete it from their dashboard.
7. Your Rights
Under POPIA, you have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate or outdated information
- Request deletion of your information, subject to any legal retention requirements
- Object to certain processing of your information
- Lodge a complaint with South Africa's Information Regulator (inforegulator.org.za) if you believe your rights have been infringed
Further information is available from the Information Regulator's office: Information Regulator (South Africa) — Website: inforegulator.org.za, Email: POPIAComplaints@inforegulator.org.za.
To exercise any of these rights, contact us using the details in Section 1.
8. Security
We take reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures include, where appropriate:
- The use of encrypted HTTPS connections (encryption in transit) for data transmitted between your device and our systems
- Secure hashing of user passwords using industry-standard cryptographic algorithms, so that passwords are not stored in plain text
- Role-based access controls and restricted administrative access to personal information
- Authentication mechanisms designed to ensure that only authorised users can access customer accounts and personal information
- Regular software updates, security patches, and ongoing maintenance of our systems to address known vulnerabilities
- Monitoring and logging of system activity, where appropriate, to assist with the detection and prevention of unauthorised access or abuse
Where we become aware of a security compromise affecting personal information, we will take reasonable steps to investigate and, where required by applicable law, notify affected persons and the Information Regulator.
While we take reasonable steps to safeguard personal information, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security, but we continually review and improve our security measures to maintain an appropriate level of protection.
9. Cookies and Local Storage
Our website and dashboard use limited local browser storage — not third-party advertising or tracking cookies — to keep you logged in and to prevent duplicate star ratings from the same device.
10. Children's Privacy
Our Service is intended for business use by adults. We do not knowingly collect personal information from children.
11. Direct Marketing
We will only send marketing communications where you have consented or where otherwise permitted by law. You may opt out at any time.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The date shown at the top of this page reflects the most recent update. We encourage you to review this page periodically.
13. Contact Us
HASH3D (Pty) Ltd, trading as HASH3Dconnect
Registration No. 2026/548373/07
20 Herta Louw, Shirley Park, Bellville, 7530, Cape Town, South Africa
Email: support@hash3d.co.za
WhatsApp: +27 83 387 7270
Website: hash3d.co.za