Privacy notice
Version 2026-09, in force from 2026-09-14. Responsible party: SportSA. Information Officer: Information Officer, privacy@sportsa.online.
This notice says what SportSA does with your personal information, why, and what you can do about it. It is written under the Protection of Personal Information Act 4 of 2013 (POPIA).
1. What we collect and why
| What | Why | On what basis |
|---|---|---|
| Name, email, phone, date of birth, gender, nationality | To hold your account and your entries, and to put you in the right age and gender category | Performing the contract you asked for |
| Emergency contact | So the event can reach somebody if you are hurt | Performing the contract, and your interest in being safe |
| Health information you choose to give | So event medical staff can treat you | Your explicit consent, asked for separately (section 26 of POPIA) |
| Payment references and amounts | To take payment, refund it and keep the financial records the law requires | Performing the contract, and a legal duty |
| Answers to an organizer's own questions | Whatever the organizer needs to run the event, for example club, shirt size, predicted time | Performing the contract |
| The IP address and browser you used to accept something | So we can show what you agreed to and when | Our legitimate interest in a reliable record |
| Marketing preferences | To send you event news if you asked for it | Your consent, which you can withdraw in one tap |
We do not collect special personal information beyond health information, and we do not process your data to make automated decisions about you.
2. A child's information
A participant under 18 on event day may only be entered with the consent of a parent or legal guardian, as section 34 requires. We record the guardian's name, their relationship to the child, the words they agreed to and when. An entry for a minor without that consent is refused.
3. Who else sees it
- The organizer of the event you enter. They receive the details they need to run it, on the terms of
the data sharing schedule. They are a separate responsible party for that event.
- Our payment provider, to take your payment. We never see or store your full card number.
- Our hosting, email and error tracking providers, who process data on our instruction only.
- Nobody else. We do not sell personal information and we do not share it for anybody else's marketing.
Where a provider is outside South Africa, section 72 of POPIA applies and we rely on the safeguards in our contract with them. The current list of providers is available from the Information Officer on request.
4. How long we keep it
- Your account and entries: while your account exists.
- Financial records (orders, payments, refunds, ledger, invoices): as long as the law requires us to keep
them, currently five years from the end of the financial year, even after you delete your account.
- Health information: with the entry it belongs to, and deleted when the entry's personal detail is.
- The consent and request logs: kept, because they are the proof that we did what you asked.
5. What you can do
You can do all of this from Privacy and data in your account, or by writing to the Information Officer:
- See it: ask for a copy of everything we hold. You get a file, and the link lasts seven days.
- Correct it: change your profile yourself at any time, and your entry details until the event's edit
cut-off. Ask us for anything you cannot change yourself.
- Delete it: deleting your account erases your name, contact details, profile and the personal detail
on your entries. It does not erase the payment records behind them, because we are required to keep those; what stays no longer identifies you.
- Object to processing, and withdraw any consent you gave, including marketing.
We answer within 30 days. If you are not satisfied, you can complain to the Information Regulator of South Africa: complaints.IR@justice.gov.za.
6. Keeping it safe
Passwords are hashed. Health information, emergency contacts and identity numbers are encrypted at rest. Access to production data is limited to the people who need it, and administrative actions are logged. If personal information is compromised we notify the Regulator and the people affected as soon as we reasonably can.
7. Changes
A change to this notice is a new version with its own date. Earlier versions stay published so you can see what applied when. We tell you about a change that affects you rather than quietly replacing the page.
Version 2026-09, in force from 2026-09-14.
