Privacy Policy
1. Who we are
Kiteview POD is a proof-of-delivery service made up of the Control Center web application (for dispatchers and managers) and the Kiteview POD driver app for Android tablets. It is provided by [Kiteview legal name] (registration number [registration number]), [physical address], South Africa ("Kiteview", "we", "us").
Information Officer: [Information Officer name] · [Information Officer e-mail] · [Information Officer phone] (registered with the Information Regulator under number [IO registration number]).
2. Our role: we are usually the operator, your company is the responsible party
POPIA distinguishes the responsible party, who decides why and how personal information is processed (s1), from the operator, who processes it on the responsible party's behalf under a contract (s1, s20, s21).
Kiteview POD is used by logistics and distribution companies ("our clients"). When a client uses it to dispatch deliveries, track its tablets and capture proof of delivery, the client is the responsible party and Kiteview is its operator. The client decides who its drivers are, what it delivers, whether to use face sign-in or signatory photos, and how long to keep records. Kiteview processes that information only on the client's instructions, under a written operator agreement that requires security safeguards (s21) and prompt notice of any breach (s21(2)).
What this means for you: if you are a driver, a client staff member, a customer contact or a person signing for a delivery, the company you work for or deal with is primarily responsible for your information. Please send requests about it to that company first; we will help them respond. You may also contact our Information Officer.
Kiteview is the responsible party only for: (a) the business contact details of our clients' representatives, for contracting, billing and support; (b) records of our own staff's access to the platform; and (c) the security and service logs we keep to run the service.
3. What personal information the service processes
| Who | What | Why |
|---|---|---|
| Drivers | Name, driver's licence number, code and expiry, phone number; sign-in e-mail and password (stored as a one-way hash); PIN (stored only on the tablet, hashed); runs assigned; vehicle inspections, mileage and odometer photos; deliveries captured; acknowledgements of the tablet's location notice | To assign and run deliveries, check vehicle roadworthiness, and prove delivery |
| Drivers — location | The tablet's GPS position, speed and heading: about every 10 seconds while a driver is signed in (every second while moving and a dispatcher has the live map open, stored at most once every 5 seconds) and about every minute while nobody is signed in — 24 hours a day, whenever the tablet is on, including after a restart and outside working hours. Positions recorded while nobody is signed in are kept for a much shorter period (§8). Derived records: arrivals and departures at stops and depots, trips, speed reports | Dispatch and live tracking, proof of delivery, locating company tablets and vehicles, safety and speed monitoring. See the client's device tracking policy. |
| Drivers — face sign-in (optional) | Photographs of the face and a mathematical representation derived from them (a "face template") | To let a driver sign in by face — see §5 |
| Tablet | Device identifier, model, Android and app version, battery, charging, network type and signal, whether GPS is on, who is signed in and who last used it | To manage the fleet of tablets, deliver app updates, and support drivers |
| Client staff (Control Center users) | Name, e-mail, password hash, role, sign-in sessions | To give access and control what each user may do |
| Customer contacts | Customer name, account code, contact person, phone, e-mail; delivery addresses; delivery notes and items | To plan deliveries and send proof-of-delivery e-mails |
| Signatories (the person receiving goods) | Name, handwritten signature captured on the screen, time and GPS location of signing; where the client has turned it on and the person agrees, a photograph of the signatory | To prove that goods were delivered and to whom |
| Kiteview staff | Name, e-mail, actions taken in the platform console, IP address | To secure and audit support access to client data |
| Everyone using the web app | IP address, browser details, cookies (see §10) | To secure and operate the service |
Where a client imports data from its accounting system (for example Sage Intacct), customer and delivery-note details are received from that system.
4. Lawful basis (POPIA s11)
Processing is based on: the contract between the client and its staff and drivers, and between the client and its customers (s11(1)(b)); the client's and Kiteview's legitimate interests in running, securing and proving deliveries (s11(1)(f)); legal obligations such as tax and road-traffic records (s11(1)(c)); and consent for face sign-in and signatory photographs (s11(1)(a), s27(1)(a)). Where processing relies on legitimate interest you may object (s11(3)).
5. Biometric information — face sign-in
Face images and face templates are special personal information under POPIA s26 (biometric information). They are processed only with the person's consent (s27(1)(a)):
- Face sign-in is optional. A driver can always sign in with a password or PIN instead.
- Before enrolment the driver is shown a versioned consent notice (currently version za-popia-v3). The exact text, the version and the time of consent are stored with the enrolment as evidence of what was agreed to.
- An administrator may enrol a driver from photographs the driver has provided; the same consent applies.
- What is stored, and where: the enrolment photographs and the face templates derived from them, on the service's servers in [hosting location]. So that drivers can sign in by face without signal, an encrypted copy of the face templates of the company's enrolled drivers is also kept on the company's tablets. A tablet stops using that copy after 7 days without contact with the server, and it is wiped when the tablet's credential is revoked.
- How it is used: at sign-in the driver blinks for a liveness check, and a live photo is compared with the enrolled faces of that company's drivers only. The live photo is used for the comparison and is not stored. Face matching runs on our own servers and on the tablet; no external face-recognition service is used.
- Who can see it: the client's administrators. Kiteview staff do not view face data except where strictly needed to support or secure the service, under the operator agreement.
- How long: until the enrolment is replaced or withdrawn, or the driver is deactivated. Then the photos and templates are deleted (and removed from the tablets at their next sync), and only a record of the consent is kept.
- Withdrawing consent: ask your administrator to remove your face data at any time; it is deleted and you continue with password or PIN.
The tablet's own fingerprint or face unlock (Android's biometric prompt) is handled entirely by Android; the app receives only a yes/no answer and never receives or stores that biometric.
6. Who receives personal information
- The client that the information belongs to, and its authorised users.
- Customers of the client receive proof-of-delivery e-mails with a PDF showing the recipient's name, signature, time, place and, where captured, the signatory's photograph. These e-mails are transactional, not marketing.
- Kiteview's authorised staff, to operate and support the service (all cross-client access is logged).
- Service providers we use — see §7.
- Authorities, where the law requires it.
We do not sell personal information and do not use it for advertising.
7. Service providers and transfers outside South Africa (s72)
| Provider | What it receives | Where |
|---|---|---|
| Hosting — [hosting provider] | All service data (database, signature and photo files, backups) | [hosting location] |
| E-mail relay — the client's own mail server if configured, otherwise [e-mail provider] | Recipient e-mail address, POD e-mail and PDF | [e-mail provider location] |
| OpenStreetMap Foundation — Nominatim geocoding | Delivery addresses (street, suburb, city) sent from our server to turn an address into map coordinates. No names are sent. | United Kingdom |
| OpenStreetMap Foundation — map tiles | The Control Center user's IP address and the map area being viewed (loaded by the browser) | United Kingdom / global network |
| Google Fonts (Google LLC) | The Control Center user's IP address and browser details, when the typeface loads | United States / global |
| Sage Intacct (only for clients who connect it) | Delivery and invoice data exchanged with the client's own Sage account | As per the client's Sage contract |
| Google Play Services (on the tablet) | Android's location service is used to obtain GPS fixes; Google's own device settings govern what Google collects | Global — per Google's terms and the tablet's settings |
Where information is transferred outside South Africa, we rely on POPIA s72(1): the recipient is subject to law, binding corporate rules or a binding agreement giving adequate protection, or the transfer is necessary for the contract with the client.
8. How long information is kept (s14)
| Record | Retention |
|---|---|
| GPS positions while a driver is signed in (server) | 365 days, then deleted automatically |
| GPS positions while nobody is signed in, including off duty (server) | 30 days, then deleted automatically |
| GPS positions held on the tablet | 7 days after upload |
| Failed-sync records that may contain signatures or photos | 90 days, then deleted automatically |
| Proofs of delivery, signatures, delivery and signatory photos | [retention period] |
| Customer and delivery-note data | [retention period] |
| Face data | See §5 |
| User accounts | [retention period] |
| Security and audit logs | [retention period] |
| Backups | [backup retention] |
At the end of a client's contract we return or delete the client's data as the operator agreement requires.
9. Security (s19)
Measures include: encrypted connections (HTTPS/TLS, HSTS); passwords and PINs stored only as salted one-way hashes; per-company isolation enforced in the database itself (row-level security), not just in the application; per-device credentials that can be revoked; one active device per user session; audit logs for Kiteview staff access to client data; a strict browser content-security policy; encryption of stored third-party credentials and of face templates held on tablets; append-only capture of proofs of delivery; and backups of evidence files. No system is perfectly secure; if a security compromise affects your information, the responsible party will notify you and the Information Regulator as POPIA s22 requires.
10. Cookies and similar technologies
The Control Center uses only cookies that are strictly necessary for it to work. We do not use analytics, advertising or tracking cookies, and we do not load third-party analytics or advertising scripts.
| Cookie | Purpose | Lifetime |
|---|---|---|
| .AspNetCore.Cookies | Keeps you signed in (encrypted) | Until you close the browser or sign out; expires after 14 days of inactivity at the latest |
| .AspNetCore.Antiforgery.* | Protects forms against cross-site request forgery | Until you close the browser |
| .AspNetCore.Mvc.CookieTempDataProvider | Shows a one-time confirmation message after you save something | Until the message is shown or you close the browser |
Because these cookies are essential, they cannot be switched off in the service; you can block them in your browser, but then you will not be able to sign in. Loading the Control Center also contacts Google Fonts (typeface) and OpenStreetMap (map tiles), which receive your IP address as described in §7; neither sets cookies for our service.
The driver app does not use cookies. It stores sign-in tokens, a hashed PIN and a device credential in Android's secure storage, and keeps an offline copy of the run sheet, unsent deliveries, recent location points and (if face sign-in is used) encrypted face templates on the tablet until they are sent or replaced.
11. Your rights
Subject to POPIA you may: be told whether we hold your information and get a copy (s23; the procedure is in our PAIA manual, [PAIA manual link]); ask for correction or deletion (s24); object to processing based on legitimate interest (s11(3)); withdraw consent for face sign-in or photos at any time (s11(2)(b)); and not be subject to a decision based solely on automated processing that has legal or similarly significant effects (s71). Because we are usually the operator, we will pass your request to the relevant client and help them answer it.
Complaints: contact our Information Officer first. You may also complain to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · complaints.IR@inforegulator.org.za · enquiries@inforegulator.org.za · www.inforegulator.org.za.
12. Children
The service is for businesses and is not intended for children. A signatory should be an adult receiving goods on behalf of a business.
13. Changes
We will post changes here and notify clients of material changes. The version and date above show the current version.