Ideation Factory
Privacy Policy and POPIA Notice
- Company
- Ideation Factory
- Contact Email
- info@ideationfactory.co.za
- Jurisdiction
- Republic of South Africa
- Last updated
- 18 June 2026
This Privacy Policy explains how Ideation Factory (Pty) Ltd, also referred to as Ideation Factory, we, us or our, collects, uses, stores, protects, shares and processes personal information.
This policy applies to our website, software platforms, mobile applications, web applications, dashboards, APIs, SaaS services, e-hailing technology, customer support channels, digital forms and related services.
By using our website, submitting information to us, using our software, accessing our platforms, or interacting with any of our services, you acknowledge that you have read and understood this Privacy Policy.
1. About Ideation Factory
Ideation Factory is a South African software and SaaS provider based in Johannesburg, South Africa.
We provide technology services including software development, SaaS platforms, web applications, mobile applications, APIs, backend systems, cloud systems, dashboards, e-hailing technology, support services and related digital solutions.
Where we provide technology to an e-hailing, transport or mobility business, Ideation Factory acts as a technology provider unless otherwise agreed in writing.
2. Purpose of this Privacy Policy
The purpose of this Privacy Policy is to explain:
- 1. what personal information we collect;
- 2. why we collect it;
- 3. how we use it;
- 4. when we share it;
- 5. how we protect it;
- 6. how long we keep it;
- 7. what rights users have under South African law;
- 8. how users can contact us about their personal information; and
- 9. how we comply with the Protection of Personal Information Act, 2013, also known as POPIA.
3. Who this Policy Applies To
This Privacy Policy applies to:
- 1. visitors to our website;
- 2. clients and potential clients;
- 3. users of our SaaS platforms;
- 4. administrators and operators using our dashboards;
- 5. e-hailing passengers using apps powered by our technology;
- 6. e-hailing drivers using apps powered by our technology;
- 7. transport operators, fleet owners and business users;
- 8. employees, contractors and representatives of our clients;
- 9. support users who contact us;
- 10. suppliers and service providers; and
- 11. any person whose personal information is processed through our systems.
4. Important POPIA Roles
4.1 When Ideation Factory is the Responsible Party
We may be the Responsible Party when we decide why and how personal information is processed. This may include personal information collected through our website, business enquiries, client communications, billing, internal administration, marketing and direct relationships with our clients.
4.2 When Ideation Factory is an Operator
We may be an Operator when we process personal information on behalf of a client, such as an e-hailing service, transport operator, business client or platform owner.
In these cases, the client may be the Responsible Party, and Ideation Factory processes personal information according to the client's instructions, our written agreements and applicable law.
4.3 E-Hailing Client Responsibility
Where an e-hailing service uses our technology, the e-hailing operator remains responsible for its own business operations, driver relationships, passenger relationships, vehicle compliance, transport permits, insurance, fare rules, safety procedures, legal compliance and customer-facing privacy notices.
Ideation Factory provides software and technology infrastructure unless otherwise agreed in writing.
5. Personal Information We May Collect
We may collect and process different types of personal information depending on how you interact with us or our platforms.
5.1 Website and Enquiry Information
When you visit our website or contact us, we may collect:
- 1. full name;
- 2. company name;
- 3. email address;
- 4. phone number;
- 5. message or enquiry details;
- 6. service interests;
- 7. website usage data;
- 8. IP address;
- 9. browser type;
- 10. device information;
- 11. referral source; and
- 12. communication history.
5.2 Client and Business Information
For clients and business users, we may collect:
- 1. company registration details;
- 2. company contact details;
- 3. authorised representative details;
- 4. billing information;
- 5. project information;
- 6. platform access details;
- 7. support tickets;
- 8. technical requirements;
- 9. agreements, invoices and records;
- 10. system usage logs; and
- 11. communication records.
5.3 E-Hailing Passenger Information
Where our technology powers an e-hailing or transport application, the platform may process passenger information such as:
- 1. name and surname;
- 2. cellphone number;
- 3. email address;
- 4. profile information;
- 5. pickup location;
- 6. drop-off location;
- 7. live or approximate location data;
- 8. trip history;
- 9. fare information;
- 10. booking details;
- 11. number of passengers;
- 12. support messages;
- 13. ratings or feedback;
- 14. device information;
- 15. app usage data; and
- 16. safety or incident-related information.
5.4 E-Hailing Driver Information
Where our technology powers a driver application or operator platform, the platform may process driver information such as:
- 1. name and surname;
- 2. cellphone number;
- 3. email address;
- 4. profile photo;
- 5. vehicle details;
- 6. driver status;
- 7. location while using the app;
- 8. trip history;
- 9. earnings or fare-related information;
- 10. ratings or feedback;
- 11. driver documents uploaded to the platform;
- 12. support messages;
- 13. app usage data;
- 14. device information;
- 15. operational status, such as online or offline status; and
- 16. safety or incident-related information.
5.5 Location Information
Our e-hailing and mobility technology may process location information to support features such as:
- 1. pickup location;
- 2. drop-off location;
- 3. driver navigation;
- 4. passenger-driver matching;
- 5. estimated arrival times;
- 6. trip progress;
- 7. trip completion;
- 8. route history;
- 9. safety and dispute resolution;
- 10. fraud prevention; and
- 11. platform analytics.
Location information may be processed when the app is active, when a trip is in progress, or where required for platform functionality.
5.6 Payment and Transaction Information
Where payment, billing or transaction functionality is used, we or our third-party service providers may process:
- 1. fare amounts;
- 2. payment status;
- 3. transaction references;
- 4. invoice information;
- 5. billing records;
- 6. wallet or account balances where applicable;
- 7. payment method type; and
- 8. transaction history.
We do not intentionally store full card details unless expressly stated and lawfully handled through a compliant payment provider.
5.7 Technical and Usage Information
We may collect technical data such as:
- 1. IP address;
- 2. device type;
- 3. operating system;
- 4. browser type;
- 5. app version;
- 6. login records;
- 7. error logs;
- 8. crash reports;
- 9. system activity logs;
- 10. API activity;
- 11. security logs;
- 12. cookies and similar technologies; and
- 13. performance analytics.
6. Special Personal Information
We do not intentionally collect special personal information unless it is necessary, lawful, authorised by the user, required by a client's platform configuration, or required by law.
Special personal information may include information relating to health, biometrics, criminal behaviour, religious beliefs, race, trade union membership, political persuasion or similar sensitive categories under POPIA.
Where special personal information is processed, we will take appropriate steps to protect it and process it only where permitted by law.
7. Children's Personal Information
Our services are not intended for use by children without appropriate consent from a parent, guardian or legally authorised person.
We do not knowingly collect children's personal information through our website or platforms unless permitted by law, required for a lawful purpose, or authorised by the appropriate person.
Where an e-hailing or transport platform processes information relating to minors, the relevant e-hailing operator or client must ensure that appropriate consent, safety measures and legal requirements are in place.
8. How We Collect Personal Information
We may collect personal information:
- 1. directly from you;
- 2. when you submit a website enquiry;
- 3. when you register an account;
- 4. when you use an app or platform;
- 5. when you book, request or complete a trip;
- 6. when a driver uses the driver app;
- 7. when an operator uses the admin dashboard;
- 8. when you contact support;
- 9. when our clients upload or submit information;
- 10. from system logs and analytics;
- 11. from third-party service providers;
- 12. through cookies or similar technologies; and
- 13. where required or permitted by law.
9. Why We Process Personal Information
We process personal information for legitimate, specific and lawful purposes, including:
- 1. providing our website and services;
- 2. responding to enquiries;
- 3. creating and managing user accounts;
- 4. providing SaaS access;
- 5. operating mobile apps and web platforms;
- 6. enabling e-hailing bookings and trip management;
- 7. matching passengers with drivers;
- 8. displaying pickup and drop-off locations;
- 9. assisting with navigation and trip tracking;
- 10. processing fares, invoices or transactions;
- 11. providing customer support;
- 12. managing client relationships;
- 13. maintaining platform security;
- 14. detecting fraud, abuse or misuse;
- 15. troubleshooting bugs and technical issues;
- 16. improving platform performance;
- 17. creating reports and analytics;
- 18. complying with legal obligations;
- 19. enforcing our agreements and policies;
- 20. protecting users, drivers, passengers, clients and the public;
- 21. communicating service updates;
- 22. sending marketing communications where permitted; and
- 23. maintaining business records.
10. Lawful Grounds for Processing
We may process personal information where:
- 1. the user has consented;
- 2. processing is necessary to perform a contract;
- 3. processing is necessary to take steps before entering into a contract;
- 4. processing is required by law;
- 5. processing protects a legitimate interest of the user;
- 6. processing is necessary for our legitimate business interests or the legitimate interests of our clients;
- 7. processing is necessary for platform security, fraud prevention, support or service delivery; or
- 8. processing is otherwise permitted under POPIA.
11. How We Use E-Hailing Information
Where our technology is used for e-hailing or transport services, personal information may be used to:
- 1. register passengers;
- 2. register drivers;
- 3. manage driver and passenger profiles;
- 4. request trips;
- 5. allocate trips to drivers;
- 6. calculate estimated fares;
- 7. display pickup and drop-off points;
- 8. provide live trip tracking;
- 9. enable communication between passengers, drivers and operators;
- 10. confirm trip status;
- 11. record trip completion;
- 12. resolve complaints or disputes;
- 13. assist with safety investigations;
- 14. manage ratings and feedback;
- 15. produce operational reports;
- 16. detect fraud or misuse;
- 17. provide technical support; and
- 18. improve platform functionality.
12. Sharing of Personal Information
We do not sell personal information.
We may share personal information where necessary with:
- 1. our clients, where we process information on their behalf;
- 2. authorised platform administrators;
- 3. drivers, where needed to complete a passenger trip;
- 4. passengers, where needed to identify an assigned driver or vehicle;
- 5. support teams;
- 6. hosting providers;
- 7. cloud service providers;
- 8. SMS, email or notification providers;
- 9. payment service providers;
- 10. mapping, location or navigation providers;
- 11. analytics and monitoring providers;
- 12. professional advisors;
- 13. law enforcement or regulators where required by law;
- 14. third parties involved in a business transfer, merger or restructuring; and
- 15. any other party where authorised by the user or permitted by law.
We require service providers to process personal information only for authorised purposes and to apply appropriate security measures.
13. Driver and Passenger Visibility
In an e-hailing environment, certain information must be shared between passengers, drivers and operators for the service to function.
For example:
- 1. a driver may receive a passenger's name, pickup location, drop-off location and trip details;
- 2. a passenger may receive the driver's name, vehicle details, location and estimated arrival time;
- 3. an operator may view trip, passenger, driver and support information through the admin dashboard; and
- 4. support staff may access information required to resolve a query, complaint or incident.
This sharing is necessary for the operation of the e-hailing platform.
14. Cross-Border Transfers
Some of our technology providers, hosting providers, cloud providers, analytics providers or support tools may store or process personal information outside South Africa.
Where personal information is transferred outside South Africa, we will take reasonable steps to ensure that the information is protected in a manner consistent with POPIA, including through contracts, appropriate safeguards or lawful transfer mechanisms.
15. Data Security
We take reasonable technical and organisational measures to protect personal information against loss, unauthorised access, misuse, alteration, destruction or disclosure.
These measures may include:
- 1. access controls;
- 2. password protection;
- 3. user authentication;
- 4. encryption where appropriate;
- 5. secure hosting;
- 6. firewalls;
- 7. system monitoring;
- 8. audit logs;
- 9. backups;
- 10. restricted administrative access;
- 11. staff and contractor confidentiality obligations;
- 12. vulnerability management;
- 13. platform maintenance;
- 14. security updates; and
- 15. incident response procedures.
No system can be guaranteed to be completely secure. Users must also protect their own devices, passwords, login details and accounts.
16. Security Compromises
If we become aware of a security compromise affecting personal information, we will take reasonable steps to investigate, contain and address the incident.
Where required by law, the Responsible Party must notify the Information Regulator and affected data subjects.
Where Ideation Factory acts as an Operator, we will notify the relevant client or Responsible Party as soon as reasonably possible after becoming aware of a security compromise affecting information processed on their behalf.
17. Data Retention
We keep personal information only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law.
Retention periods may depend on:
- 1. legal requirements;
- 2. accounting and tax obligations;
- 3. contractual obligations;
- 4. operational needs;
- 5. support and dispute resolution;
- 6. fraud prevention;
- 7. safety and incident records;
- 8. platform backup cycles;
- 9. client instructions; and
- 10. legitimate business purposes.
When personal information is no longer required, we will delete, destroy, de-identify or archive it in accordance with applicable law and reasonable business practices.
19. Direct Marketing
We may send marketing communications where permitted by law or where the user has consented.
Users may opt out of marketing communications at any time by using the unsubscribe option, replying to the communication or contacting us directly.
We may still send non-marketing communications relating to accounts, services, billing, security, support or legal matters.
20. User Rights Under POPIA
Subject to applicable law, users may have the right to:
- 1. know what personal information we hold about them;
- 2. request access to their personal information;
- 3. request correction of inaccurate, outdated, incomplete or misleading information;
- 4. request deletion or destruction of personal information where legally permitted;
- 5. object to the processing of personal information;
- 6. withdraw consent where processing is based on consent;
- 7. object to direct marketing;
- 8. request reasons for automated decisions where applicable; and
- 9. lodge a complaint with the Information Regulator.
Some requests may be subject to identity verification, legal limitations, client instructions, operational requirements or retention obligations.
21. Access, Correction and Deletion Requests
A user may contact us to request access to, correction of or deletion of personal information.
Requests should be sent to: info@ideationfactory.co.za
We may require proof of identity before processing a request.
Where we process personal information on behalf of a client, we may refer the request to the relevant client as the Responsible Party or assist the client in responding to the request.
22. Information Regulator
Users may contact the South African Information Regulator if they believe their personal information has been processed unlawfully or if they are not satisfied with how a privacy request has been handled.
- 1. Information Regulator South Africa;
- 2. Website: www.inforegulator.org.za;
- 3. Email: enquiries@inforegulator.org.za;
- 4. Telephone: 010 023 5200; and
- 5. Toll-free: 0800 017 160.
23. Accuracy of Personal Information
Users must provide accurate, complete and up-to-date information.
Clients, operators, drivers and passengers are responsible for updating their information where required.
Ideation Factory is not responsible for losses or errors caused by inaccurate information supplied by users, clients, drivers, passengers or third parties.
24. Automated Processing and Platform Decisions
Our platforms may use automated systems to support functionality such as:
- 1. driver-passenger matching;
- 2. fare estimates;
- 3. route calculations;
- 4. trip allocation;
- 5. fraud detection;
- 6. system alerts;
- 7. operational reporting; and
- 8. platform analytics.
These automated processes are used to operate and improve the platform. Where required by law, users may request information about automated decisions that significantly affect them.
25. Third-Party Platforms and Services
Our services may integrate with third-party providers such as hosting services, cloud platforms, app stores, payment providers, SMS providers, email providers, analytics tools, maps, navigation systems and support tools.
These providers may process personal information according to their own privacy policies and contractual obligations.
We take reasonable steps to use reputable service providers, but we are not responsible for the privacy practices of third-party websites, apps or services that are not controlled by Ideation Factory.
26. Client Responsibilities
Where a client uses our technology to operate an e-hailing service or other digital platform, the client is responsible for:
- 1. ensuring it has a lawful basis to process personal information;
- 2. providing its own privacy notices to passengers, drivers and users where required;
- 3. obtaining consent where required;
- 4. ensuring drivers, passengers and staff understand how their information is used;
- 5. managing user requests where it is the Responsible Party;
- 6. ensuring operational compliance with applicable transport and data protection laws;
- 7. ensuring uploaded documents are collected lawfully;
- 8. ensuring only authorised staff access personal information;
- 9. notifying Ideation Factory of privacy or security issues; and
- 10. complying with any data processing agreement entered into with Ideation Factory.
27. Confidentiality
We treat personal information and client information as confidential.
Access to personal information is limited to authorised persons who require access for legitimate business, technical, support, security, legal or operational purposes.
28. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
The latest version will be published on our website.
Continued use of our website, platforms or services after publication of an updated policy means that users acknowledge the updated policy.
Where changes are material, we may take reasonable steps to notify affected clients or users.
29. Contact Details
For privacy questions, POPIA requests, access requests, correction requests, deletion requests, objections or complaints, contact:
- 1. Ideation Factory;
- 2. Johannesburg, South Africa;
- 3. Email: info@ideationfactory.co.za; and
- 4. Website: www.ideationfactory.co.za.
Get in touch
For questions about these privacy policy and popia notice, our services or legal notices, contact us at:
- Ideation Factory
- Jurisdiction:
- Republic of South Africa
- Contact Email:
- info@ideationfactory.co.za