DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication.
This document is a working draft prepared for review by a qualified South African attorney before it is submitted to Apple or published.
Items requiring attorney confirmation are marked [ATTORNEY-REQUIRED].
Missing or unconfirmed operational details are marked [TBD].
All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.
This summary must remain exactly consistent with the Privacy Policy and the Google Play Data Safety form.
This page reproduces the data disclosures required by the Apple App Store privacy "nutrition label" format for the eRunna mobile application. It reflects the data practices described in full in our Privacy Policy. The eRunna app is used by four distinct persona types: customers (placing errands and orders), runners (delivering errands), merchants (listing goods on the marketplace), and partners/affiliates. The data types below cover the superset of what is collected across all personas; not every data type is collected from every user.
Data Linked to You
The following data types are collected and linked to your identity (your Apple Account or eRunna account). Apple App Store categories are shown in italics; purpose codes follow in parentheses.
Contact Information
- Name — full name (account creation, KYC, service delivery)
- Email address — (account creation, support, direct marketing where consented)
- Phone number — mobile number (account creation, OTP verification, runner contact, support)
Identity & Sensitive Government IDs
-
Government ID — South African identity number (SA ID), collected from runners during
KYC onboarding for identity verification, fraud prevention, and regulatory compliance.
The SA ID is treated as high-sensitivity personal information under POPIA and is subject to the Act's security-safeguards obligations; it is used only for the stated purpose.
Persona: runners only (not collected from customers, merchants, or partners at the app level).
[ATTORNEY-REQUIRED: confirm App Store "Sensitive Info > Government ID" category is the correct Apple label for SA ID numbers and confirm the mapping survives the App Store review process.]
Biometric Data
-
Sensitive Info — Biometrics — a facial image or liveness capture (selfie) collected during
runner KYC identity verification via our KYC provider. This is biometric information and
special personal information under POPIA, processed on the basis of explicit, specific, informed consent
[ATTORNEY-REQUIRED: confirm citation for the applicable special-PII consent basis under POPIA s27], obtained separately from the general Terms of Service at the point of KYC capture.
Persona: runners only.
[ATTORNEY-REQUIRED: confirm correct Apple App Store privacy label category for KYC biometric/selfie; confirm s57 prior-authorisation position with the Information Regulator before the KYC flow goes live.]
Financial Information
-
Payment Info — Paystack-issued payment tokens and authorisation codes processed to complete
in-app payments and charge-before-dispatch flows. eRunna does not store full card numbers, CVVs, or PINs.
Raw payment credentials are handled exclusively by Paystack and the in-app Paystack WebView; see the
Subprocessors list.
Persona: customers (payment for errands and marketplace orders). -
Financial Info — Bank account details — bank account number and branch code collected from
runners and merchants for payout processing via Paystack Transfer.
Persona: runners and merchants (via onboarding portal, not the customer app, but disclosed here for completeness).
Location
- Precise Location (foreground) — real-time GPS coordinates used for customer pickup/drop-off, runner navigation, ETA calculation, route display, and runner-to-customer matching. Collected while the app is in use. Persona: customers and runners.
-
Precise Location (background) — GPS coordinates collected while the app is in the background
or closed, used exclusively for customer-visible runner tracking during active deliveries.
Background location is requested for runners only, at the start of an active delivery, and stops when that delivery ends or is cancelled.
See the Background Location Disclosure for the prominent disclosure
required by Apple and Google.
[ATTORNEY-REQUIRED: confirm the POPIA s18 notice and s11(1)(a) consent basis for background-location processing is correctly characterised here; confirm Apple's “Always” location permission usage string matches this disclosure.]
User Content
- Photos or videos — optional profile photos, KYC identity-document images and selfie/liveness captures, item/reference photos, chat image attachments, runner pickup/drop-off/receipt proof, and expense receipt images. Not collected automatically.
- Customer support — content of support messages and in-app chat transcripts.
Identifiers
- User ID — eRunna account identifier and Firebase UID (account management, fraud prevention, audit trail).
- Device ID — device-binding identifier (IDFV on iOS, equivalent on Android) used for session security, device binding, and fraud prevention.
Usage Data
- Product interaction — in-app navigation, feature usage, errand/order lifecycle events (placed, accepted, en route, delivered) used for service delivery, analytics, and product improvement.
- Advertising data — [TBD: confirm whether any ad-network SDK is integrated; if none, remove this row. Do not include if not collected.]
Diagnostics
- Crash data — crash reports, exception logs, and stack traces used to diagnose and fix app defects. Collected via Google Firebase Crashlytics.
- Performance data — app launch times, response latencies, and memory metrics used for service improvement.
- Other diagnostic data — device OS version, app version, and connectivity state collected alongside crash/performance data.
Data Not Linked to You
- Analytics — aggregated or de-identified usage metrics that cannot be traced back to an individual user. These are used for platform performance analysis and product improvement only.
Data Used to Track You
eRunna does not use data to track you across apps or websites owned by other companies, and does not share data with data brokers or advertising networks for cross-app tracking purposes.
[ATTORNEY-REQUIRED / [TBD]: if any third-party analytics or advertising SDK is added in future that meets Apple's definition of "tracking" under ATT, this section must be updated and an ATT prompt must be shown before data collection begins. Attorney to confirm the current SDK inventory does not trigger ATT obligations.]
Data Use Purposes
Data collected by the eRunna app is used for the following purposes, mapped to Apple's standard purpose categories:
- App Functionality — errand matching, routing, delivery tracking, marketplace order fulfilment, runner navigation, notifications, and payment processing.
- Account Management — creating and managing your eRunna account; authenticating your identity; managing profile, payout, and notification preferences.
- Payments — processing payment authorisations (customers); routing payouts to runners and merchants via Paystack Transfer; refund processing.
- Identity Verification & Fraud Prevention — runner KYC (SA ID number + biometric selfie match via KYC provider); device-binding security checks; abuse detection and platform-integrity monitoring.
-
Legal & Regulatory Compliance — compliance with POPIA (Protection of Personal Information Act 4 of 2013) obligations; FICA / AML-CFT customer due diligence and suspicious-transaction reporting obligations where eRunna is an accountable institution; record-keeping as required by applicable South African law.
[ATTORNEY-REQUIRED: confirm the accountable-institution category under FICA Schedule 1 that applies to eRunna's payment and marketplace activities, and the precise CDD/record-keeping obligations.] - Safety — incident investigation; emergency-contact use; runner and customer safety monitoring during active deliveries.
- Customer Support — diagnosing and resolving support requests; dispute resolution; responding to data-subject access or deletion requests.
- Analytics & Product Improvement — aggregated or de-identified performance monitoring; A/B testing; service improvement research.
- Direct Marketing (where consented) — sending product updates, offers, and promotions via email, SMS, or push notification, subject to POPIA's direct-marketing consent requirements or the existing-customer exemption [ATTORNEY-REQUIRED: confirm citation for the applicable POPIA direct-marketing basis under s69]. See the Privacy Policy §8 for opt-out instructions.
Special Categories of Personal Information (POPIA)
Under the South African Protection of Personal Information Act (POPIA s26), two data types collected by eRunna qualify as special personal information requiring a heightened lawful basis:
- Biometric data (runner KYC selfie/liveness): processed on the basis of explicit and specific consent [ATTORNEY-REQUIRED: confirm citation for the applicable special-PII consent basis under POPIA s27], obtained at the point of KYC capture and separately from the general Terms of Service. Runners may withdraw consent, subject to the consequence that runner onboarding cannot be completed without identity verification.
- SA identity number: treated as high-sensitivity information; collected solely for identity verification, fraud prevention, and compliance purposes; minimised, secured in line with POPIA's security-safeguards obligations, and not used for any other purpose.
[ATTORNEY-REQUIRED: attorney to confirm the complete s27(1)(a)–(h) basis mapping for each special-PII category; confirm whether s57 prior authorisation from the Information Regulator applies before biometric processing commences; confirm SA ID minimisation and retention limits.]
Data Retention and Deletion
We retain personal information for no longer than is necessary to fulfil the purposes for which it was collected, or as required by South African law (including FICA record-keeping obligations for AML-CFT records [ATTORNEY-REQUIRED: confirm the applicable minimum FICA record-retention period] and applicable tax-record retention periods).
- You can request deletion of your eRunna account and associated personal information from within the app (Account › Settings › Delete account) or by contacting us at info@erunna.app.
- Certain records may be retained beyond account deletion where required by law (e.g. FICA, tax records, dispute resolution).
- Biometric KYC data is deleted once the stated verification purpose is fulfilled and no legal obligation requires retention.
For full retention periods per data category, see the Data Retention Policy.
Cross-Store Consistency Note
This Apple App Store privacy nutrition-label disclosure is maintained in alignment with the Google Play Data Safety form and the full Privacy Policy. Any change to data collection or processing practices must be reflected consistently across all three documents before submission to either app store. See Background Location Disclosure for the store-specific prominent-disclosure text required by both Apple and Google.
[TBD: prior to each app-store submission, a named DRI must sign off that this disclosure, the Google Play Data Safety form, and the Privacy Policy are consistent and reflect the then-current state of the app's data collection.]
Related Policies
- Privacy Policy — the POPIA processing notice, lawful bases, special-PII handling, and data-subject rights.
- Google Play Data Safety — corresponding Android disclosure; must remain consistent with this document.
- Background Location Disclosure — prominent disclosure for background location processing.
- Data Retention Policy — specific retention periods for each data category.
- Subprocessors List — current operators (GCP/Firebase, Paystack, KYC provider, messaging provider) and cross-border transfer safeguards.
- Terms of Service — the agreement governing use of the Services.