Privacy Policy
Last updated: 5 August 2026
This policy explains how Kinara Consulting (Pty) Ltd (registration number 2025/871359/07, "Kinara," "we," "us"), operating Qlaim, collects, uses, and protects personal information in connection with the Qlaim platform (qlaim.co.za and white-labeled deployments of it), in line with the Protection of Personal Information Act, 4 of 2013 ("POPIA").
Qlaim is used by several kinds of business, and what we hold about you depends on which part you use. Qlaim currently comprises Qlaim Merchants (buying and collecting items at a market or fair), Qlaim Rentals (renting and returning items), Qlaim Organiser (running a fair or market), Qlaim Reserve (booking seats or places at an event, and signing people in and out of an operator's care), and Qlaim Member (a personal membership you carry across all of them).
Kinara's other products (Nahshon SPLT, Iddan PFT) and the Kinara Consulting corporate website each have their own privacy policy.
Who is responsible for your information
Responsible party: Kinara Consulting (Pty) Ltd
Company registration number: 2025/871359/07
Registered address: Sandton, Gauteng, 2191
Information Officer: The appointed Information Officer, Kinara Consulting (Pty) Ltd
Information Regulator registration number: 2026-062429
Businesses using Qlaim — a merchant, a rental operator, a fair organiser, a dance studio — decide what to ask you for and why, within what the platform allows. Kinara treats itself as responsible for the personal information held on the Qlaim platform, and each business is separately responsible for how it uses what it collects through Qlaim. If your question concerns why a particular business asked you for something, they can usually answer it fastest; you are entitled to come to us either way, and we will not turn you away.
What we collect
What we collect depends on how you use Qlaim:
- Business accounts (merchants, fair organisers, rental operators, reserve operators) — name, email, phone where provided, business or company name, and a password held by Supabase Auth. Where the business accepts payment through Qlaim, we hold the credentials that route money to their own payment account (for example a PayFast merchant ID and key, or a Yoco secret key). Businesses may also set a PIN used to confirm sensitive actions such as changing where their payments are sent.
- Customers buying, booking or reserving — name, email and phone number. For rentals, an operator may ask for details needed to fit or issue an item, such as a height or head measurement. Operators can also add their own questions to a booking form, so the exact information asked for varies from one business to another; you can see everything being asked before you submit it.
- Qlaim Members — your name, email address, phone number where you give it, a member number that identifies you across every Qlaim business, and, if you create or join one, the household you belong to. We also record which events you have asked to join, who you have asked to be allowed to collect, and the appearance you have chosen for your own membership pages.
- People in an operator's care, including children — where a business uses Qlaim to sign people in and out of its care, we hold the name of that person and the operator's own reference for them, such as a class or group. This is dealt with separately below.
- Identity documents — some rental operators verify identity at handover, or accept an identity document as a deposit. Where they do, a photograph of that document may be stored. These images are held in private storage, never published, and are only made visible to that operator through a short-lived link generated at the moment they view it.
- Records of what happened — purchase, collection, return, check-in and handover timestamps, QR code identifiers, payment references, and the outcome of each step. Qlaim does not collect or store your card details; payment is processed by a third-party payment gateway.
- Technical information attached to sensitive actions — where an action needs to be provable later, such as signing a person out of an operator's care or a business changing its billing plan, we record the IP address, browser user-agent and device identifier associated with it, alongside who performed it. We do this to make the record defensible, not to build a profile of you, and we do not use it for tracking or advertising.
- Agreement records — when you accept our Terms and this policy at registration, we record that you did so, when, and which version you accepted.
- AI Business Summary (optional, businesses only) — if a business explicitly consents, aggregated figures from their own dashboard may be sent to Anthropic to generate a written summary. This never includes individual customers' personal information, and consent can be withdrawn at any time.
Why we collect it
- To process purchases, bookings and reservations, and to let a business recognise you when you arrive to collect, return or attend.
- To verify and reconcile payments, and to issue refunds where they are due.
- To operate business dashboards, reporting and billing.
- To keep an accurate and tamper-evident record of who handed a person into an operator's care and who collected them, so that this can be relied on afterwards.
- To let you carry one membership across several businesses instead of registering separately with each.
- To respond to your enquiries and requests, including requests made under this policy.
- To meet our obligations under tax, financial and other record-keeping law.
- Only with consent, to generate optional AI-assisted business summaries.
Children and people in an operator's care
Some businesses use Qlaim to record that a person — often a child — has been handed into their care and later collected by someone authorised to collect them. A dance studio signing dancers in at a backstage door is the clearest example. This replaces a paper sign-in sheet, and it exists so that nobody is handed to the wrong adult.
POPIA gives a child's personal information particular protection. We apply the stricter reading of it:
- A parent or guardian must consent first. The business must obtain the consent of a competent person — normally a parent or legal guardian — before adding a child to Qlaim, and must be able to show it did. We provide the record; the business obtains the consent.
- We collect the least we can. A name and the operator's own reference for the child, such as a class or cast group. Nothing about health, and no identity numbers.
- We do not collect photographs of children. No part of Qlaim stores an image of a child. If that ever changes it will require a separate, explicit opt-in and this policy will be updated before it does.
- The roster is never browsable. A parent asking to be linked to their child types that child's name; they are never shown a list of the other children at the event. An operator must confirm each link individually, and a parent being approved for one child gives them no access to any other.
- A parent or guardian may exercise the child's rights under this policy on the child's behalf, subject to the limits described under "Your rights" below.
The same protections apply where the person in an operator's care is an adult who depends on someone else to collect them.
How we share it
We share personal information only with the processors needed to run Qlaim:
- The business you are dealing with — a merchant, operator, organiser or studio sees the information you give them and the records of your transactions with them. They do not see your dealings with any other business on Qlaim.
- PayFast and Yoco — to process payments. Each business chooses one of these, and payment goes directly to that business's own account. The gateway handles your card details; Qlaim never sees or stores them.
- Supabase — our database and authentication provider, which stores the platform's data.
- Vercel — our hosting provider, which serves the Qlaim website and processes the requests your browser makes to it.
- Resend — to deliver transactional email such as confirmations, invitations and security notifications.
- Anthropic — only when a business has consented to the AI Business Summary feature, and only aggregated business data, never individual customer records.
We do not sell or rent personal information to third parties, and we do not use it for advertising.
International data transfers
Our database infrastructure (Supabase) stores data in Ireland, within the European Union, where it is protected under the EU General Data Protection Regulation (GDPR) — a data protection framework substantially similar to POPIA. Some other processors we use (including Vercel, Resend and, where the AI Business Summary feature is used, Anthropic) are also based outside South Africa. Where personal information is transferred outside South Africa, we only do so where the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or another ground permitted under section 72 of POPIA (for example, where the transfer is necessary for the performance of a contract between you and us, such as processing your booking or payment).
How long we keep it
We retain account and transaction records for as long as the account is active, and afterward for as long as required by applicable tax and financial record-keeping legislation. Enquiry-only data not tied to a transaction is retained only as long as reasonably necessary to respond to you.
Photographs of identity documents are retained with the rental or deposit record they belong to. If you would like the image of your identity document removed once the rental it relates to has been completed and settled, ask us using the form below and we will remove it.
Records of handovers cannot be deleted, including by us.
Where Qlaim records that a person was handed into a business's care and later collected, each entry is written once and sealed. The record cannot be edited or removed afterwards by the business, by us, or by anyone else — this is enforced by the database itself, and each entry is cryptographically linked to the one before it so that any tampering would be detectable. That is the whole point of the record: an account of who took responsibility for a person, and when, is only worth having if nobody can quietly change it later. It also means we cannot delete it on request, and we keep it for as long as it may be needed as evidence of what happened.
Your rights under POPIA
- Confirm what personal information we hold about you and request a copy of it
- Ask us to correct inaccurate information, or delete it where there is no lawful reason for us to keep it
- Object to processing, or withdraw consent (for example for the AI Business Summary feature) at any time
- Lodge a complaint with the Information Regulator if you believe we have not handled your information properly
Two limits are worth stating plainly rather than leaving you to discover them. First, some records we are obliged to keep by law — tax and financial records in particular — cannot be deleted on request until that obligation has run its course. Second, as described above, entries in a handover record cannot be deleted at all. Where we cannot delete something, we will tell you why. Where a handover entry is wrong, we cannot alter it — but under section 24(2) of POPIA you may ask us to attach a statement of the correction you sought, and we will keep that statement with the record and provide it alongside the entry whenever the entry is disclosed.
To exercise any of these rights, use the request form below.
Submit a request
Security
We take reasonable technical and organisational measures to protect personal information. These include row-level access controls in our database that deny access by default, writes performed only through server-side code rather than from the browser, encrypted transmission, private storage for document images with access only through short-lived generated links, rate limiting and lockout on PIN checks, and a step-up PIN confirmation before a business can change where its payments are sent.
Complaints to the Information Regulator
The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision.
