ThusaFund

Privacy policy

Last updated 28 August 2026. Written to be read, not to be survived.

This is a working draft, not legal advice. It describes what the app genuinely does today, but it has not been reviewed by a lawyer. Before ThusaFund handles real donations at scale, have an attorney familiar with POPIA review this page and the Terms.

Who we are

ThusaFund is a South African crowdfunding platform. For the purposes of the Protection of Personal Information Act (POPIA), we are the responsible party for the personal information described here.

What we collect

If you create an account: your name, email address, and an encrypted form of your password. We never store your password itself.

If you run a campaign: the above, plus whatever you publish in your campaign, and — where verification is required — identity document details and bank account details for payouts.

If you donate: the amount, your name and email if you provide them, and any message you write. Your card details are entered on PayFast’s own systems and never reach us. We receive only a reference and a confirmation that payment succeeded.

If you just browse: standard server logs, including IP address, for security and abuse prevention.

What is public, and what is not

Being specific matters more here than anywhere else on this page.

Public to anyone, no account needed: a published campaign’s title, story, images, goal, stages, its spend ledger (dates, descriptions, amounts, vendors), approved receipt images, and the organiser’s display name and verification tier.

Public if you donate: your name, the amount, and your message — unless you tick “Give anonymously”, in which case your name is withheld from the donor list.

Never public: your email address, your bank details, your identity documents, and your password. Donor email addresses are not visible to organisers, other donors, or the public.

Anonymity is applied in the database view that serves the donor list, not merely hidden in the page — so a bug in one screen cannot expose a name you asked us to withhold.

A warning about receipts

Receipts uploaded by an organiser are published. If you are an organiser, black out identity numbers, bank account numbers, medical diagnoses and anything else personal before uploading.

If something personal is exposed, tell us and we will withhold the image while keeping the ledger line itself public.

Who we share it with

We do not sell your personal information, and we do not share it for advertising.

We share only what is necessary with:

  • PayFast — to take payments. They receive what a payment requires.
  • Supabase — our database and authentication provider.
  • Vercel — hosting.
  • Law enforcement — where we are legally obliged, or where we believe it is necessary to address fraud.

Some of these providers process data outside South Africa. POPIA permits this where the receiving jurisdiction offers comparable protection or the provider is contractually bound to equivalent standards.

How long we keep it

Account and campaign information is kept while your account exists. Donation and payout records are kept for at least five years after the transaction, because financial and tax law requires it — these are not deleted on request, and we would rather say so plainly than imply otherwise.

A published spend ledger is part of the public record of a campaign that took donations. We do not delete it simply because an organiser would prefer it gone.

Your rights

Under POPIA you may ask us to:

  • tell you what personal information we hold about you
  • correct anything inaccurate
  • delete information we no longer have a lawful reason to keep
  • stop using your information for a particular purpose

You may also complain to the Information Regulator of South Africa. Contact us first if you can — most issues are faster to fix directly.

Security

Access to data is enforced in the database itself through row-level security, not only in the application, so a bug in one screen cannot expose another person’s records. Receipt images are stored privately and served through short-lived links rather than permanent public URLs.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the Information Regulator as POPIA requires.

Contact

For any privacy question, or to exercise the rights above, email privacy@thusafund.com.