Privacy Policy
Wonke helps you keep all your South African loyalty cards in one place and pull up a scannable barcode at the till. This policy explains what data the Wonke mobile app and its backend collect, why, how it is stored and protected, and the choices you have. We keep it deliberately short and only collect what the app needs to work.
Last updated: 9 September 2026
Who we are
Wonke is a South African mobile app. The responsible party for your personal information under POPIA can be contacted at privacy@wonke.app for any privacy question or request.
What we collect, and why
| Data | When | Why |
|---|---|---|
| Email address and password | Only if you create an account (you can use the app as a guest without one) | To sign you in and sync your data across devices |
| Loyalty card details you add (retailer, card number, membership tier, notes) | When you add or scan a card | To show your cards and their barcodes in the app, and sync them to your account if you are signed in |
| How often and how recently you open each card | As you use the app | To auto-favourite your most-used cards on the home screen |
| The report type and description you write in a bug or feedback report | Only when you tap "Send Report" | To investigate the issue you reported |
Wonke requests the camera permission only to scan a loyalty-card barcode when you add a card by scanning. If you add a card from a picture instead, Wonke opens your device's photo picker so you can choose an image; that image is read on your device and is not uploaded.
Wonke does not collect your precise location, contacts, health data, or payment-card / bank-account information. The current release does not collect analytics or crash-diagnostics data. Wonke does not show ads and contains no advertising SDK.
How your data is stored and protected
- All data sent between the app and our servers is encrypted in transit using HTTPS/TLS.
- Account data and the loyalty cards you save are stored in a managed PostgreSQL database hosted on Microsoft Azure in the South Africa North region.
- Access to the backend is restricted and authenticated; sign-in uses short-lived access tokens.
- Account emails (such as password-reset messages) are sent through Azure Communication Services, which processes the recipient email address on infrastructure located in the United States.
Who we share it with
We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers that process data on our behalf, under contract, only to run Wonke:
- Microsoft Azure — cloud hosting and database (South Africa North), and transactional email via Azure Communication Services (United States).
- Google Play — app distribution and, if you install from the store, basic install/analytics data collected by Google under its own policy.
How long we keep it
We keep your account data and saved cards for as long as your account exists. Bug and feedback reports are kept for support purposes but are unlinked from your account when you delete it.
Your rights and choices
- Access and correction — you can view and edit your cards and profile in the app, or email privacy@wonke.app.
- Deletion — you can permanently delete your account and its data from Profile → Privacy & Security → Delete Account in the app, or by request. Full details: wonke.app/data-deletion.
- Use without an account — guest mode lets you use Wonke without providing an email; that data stays on your device.
- Complaints — you may lodge a complaint with the Information Regulator of South Africa.
Children
Wonke is intended for users aged 18 and over and is not directed at children. We do not knowingly collect data from children.
Changes to this policy
If we make a material change we will update this page and the "last updated" date above, and where appropriate notify you in the app.
Contact
Questions, requests or complaints: privacy@wonke.app