Privacy Policy
Effective Date: [INSERT DATE] · Last Updated: [INSERT DATE]
Our Commitment
Focus Loop is built with a privacy-first approach. We collect only what we need to run the service. We do not monetise your data. We do not sell or share your data with advertisers. Your data belongs to you.
1. Who We Are
Focus Loop is a digital signage platform operated by [INSERT LEGAL ENTITY NAME], a company registered in South Africa. For the purposes of the Protection of Personal Information Act (POPIA), we are the "responsible party" for the personal information we process.
2. What Data We Collect
Data we collect directly from you
| Data | Purpose | Collected via |
|---|---|---|
| Email address | Account creation, login, communication | Clerk |
| Full name | Account identification | Clerk |
| Organisation name | Account setup, multi-user context | Clerk |
| Uploaded videos | Core service functionality | Cloudflare R2 |
| Loops and screen configurations | Core service functionality | Supabase |
Data collected automatically
| Data | Purpose | Collected via |
|---|---|---|
| Screen activity status | Showing which screens are online | Supabase |
| Last-seen timestamps | Monitoring screen connectivity | Supabase |
| Authentication session cookie | Keeping you logged in | Clerk |
Data we do NOT collect
- No tracking cookies beyond the authentication session
- No analytics or telemetry on end viewers
- No advertising identifiers
- No location data
- No biometric data
- No special personal information as defined by POPIA
3. How We Use Your Data
We use your personal information only for:
- Providing the service: storing videos, managing loops, displaying content
- Authentication: verifying your identity and keeping your account secure
- Billing: processing subscription payments through Paystack
- Communication: service-related emails
- Support: responding to your questions and resolving issues
We do not use your data for advertising, marketing profiling, selling to third parties, or automated decision-making.
4. Legal Basis for Processing (POPIA)
- Consent: You provide consent when you create an account
- Contract: Processing is necessary to provide the service
- Legitimate interest: Processing for our legitimate business interests, provided they do not override your rights
5. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication | Email, name, auth session |
| Paystack | Payment processing | Billing details (direct to Paystack) |
| Cloudflare R2 | Video storage | Uploaded video files |
| Supabase | Database hosting | Account data, loops, configs |
| Vercel | Application hosting | Request data (IP in logs) |
We do not share your data with any other third parties. We do not sell your data.
6. Cross-Border Data Transfers
Some of our third-party service providers may process data outside of South Africa. Under POPIA Section 72, we ensure that any cross-border transfer is only made to recipients subject to laws or binding agreements that provide an adequate level of protection comparable to POPIA.
7. Data Retention
| Data | Retention period |
|---|---|
| Account information | Duration of account + 30 days |
| Uploaded videos | Until deleted, or 30 days after account closure |
| Loops and screen configs | Until deleted, or 30 days after account closure |
| Billing records | 5 years (SA tax law) |
| Server logs (Vercel) | Subject to Vercel's retention policy |
8. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Access: Request confirmation of whether we hold your personal information and request a copy
- Correction: Request that we correct or update inaccurate information
- Deletion: Request that we delete your personal information
- Object: Object to processing on reasonable grounds
- Data portability: Request your data in a structured, commonly used format
- Withdraw consent: Withdraw your consent at any time
- Complain: Lodge a complaint with the Information Regulator
To exercise any of these rights, contact us at [INSERT EMAIL]. We will respond within 30 days.
Information Regulator (South Africa): inforegulator.org.za · complaints.IR@justice.gov.za
9. Data Security
We take reasonable technical and organisational measures to protect your personal information, including:
- All data transmitted is encrypted using TLS/HTTPS
- Authentication managed by Clerk with industry-standard security
- Payment information handled by Paystack (PCI-DSS Level 1 certified)
- Database access restricted and requires authentication
- Videos stored on Cloudflare R2 with access controls
No system is 100% secure. In the event of a data breach, we will notify you and the Information Regulator as required by POPIA Section 22.
10. Cookies
Focus Loop uses only essential cookies required for the service to function — specifically the authentication session cookie managed by Clerk. We do not use analytics, advertising, third-party tracking, or social media cookies.
11. Children's Privacy
Focus Loop is a business-to-business service and is not directed at children under 18. We do not knowingly collect personal information from children. Focus Loop does not collect any data from viewers watching screens in waiting rooms.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date, notify you by email for material changes, and post the updated policy on our website.
13. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:
- Information Officer: [INSERT NAME]
- Email: [INSERT EMAIL]
- Address: [INSERT PHYSICAL ADDRESS]