CrocBookings CrocBookings

Privacy Policy

Last updated: July 2026  ·  Effective immediately

Contents

  1. Overview
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. Third-Party Services
  6. Data Retention
  7. Security
  8. Children's Privacy
  9. Your Rights (POPIA)
  10. International Transfers
  11. Changes to This Policy
  12. Contact Us
01

Overview

CrocCodes ("we", "us", "our") operates the CrocBookings application ("App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the App.

We are committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa and other applicable privacy laws.

By using the App, you consent to the practices described in this Policy. If you do not agree, please do not use the App.

02

Information We Collect

Information you provide directly

Data When collected
Name Account registration
Email address Account registration and email verification
Phone number Account registration
Business name and description When registering a business
Service and pricing information When creating services on the platform
Profile and logo images When uploading photos to provider or business profiles
Booking details When making or managing appointments

Information collected automatically

Data Purpose
Device push notification token (FCM) To send booking and status notifications
App theme preference To remember your light/dark mode setting
Subscription status To enforce the correct plan limits for business accounts

Information from third parties

When you subscribe to a paid plan, Apple or Google processes your payment and notifies us of your subscription status. We do not receive or store your full payment card details.

03

How We Use Your Information

We use your personal information to:

  • Create and manage your account
  • Facilitate bookings between clients and service providers
  • Send booking confirmations, updates, and reminders via push notification and email
  • Send email verification and password reset emails
  • Enforce subscription plan limits for business accounts
  • Display your name, phone, and email to businesses you book with (and vice versa)
  • Improve the App and diagnose technical issues
  • Comply with our legal obligations

We do not use your information for advertising, and we do not sell your personal data to any third party.

04

How We Share Your Information

Between users on the platform

When you make a booking as a Client, the Business Owner and relevant service provider can see your name, phone number, and email address in order to manage your appointment.

When you are a Business Owner, your business name, description, address, and service listings are visible to all users of the App.

Service providers

We share data with third-party service providers who help us operate the App, including:

  • Google Firebase — authentication, database, cloud storage, and push notifications
  • Apple App Store / Google Play — subscription and payment processing
  • Our SMTP email provider — delivery of transactional emails

These providers are contractually bound to handle your data securely and only for the purposes we specify.

Legal requirements

We may disclose your information if required to do so by law or in response to valid legal requests from public authorities.

05

Third-Party Services

The App uses the following third-party services. Each has its own privacy policy:

We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.

06

Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Specifically:

  • Account data — retained until you delete your account
  • Booking records — retained for 12 months after the booking date, then deleted
  • Push notification tokens — updated or removed automatically when the device token changes or becomes invalid

When you delete your account via the App, we permanently delete your profile, bookings, and associated data within 30 days. Some anonymised aggregate data (e.g. booking counts) may be retained for statistical purposes.

07

Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • All data is stored on Google Firebase infrastructure with encryption at rest and in transit
  • Authentication is managed by Firebase Authentication with email verification
  • Firestore security rules restrict access so users can only read their own data
  • SMTP credentials and other secrets are stored in Google Cloud Secret Manager

No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

08

Children's Privacy

The App is not directed to children under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without parental consent, please contact us and we will take steps to remove that information.

09

Your Rights (POPIA)

Under the Protection of Personal Information Act (POPIA), you have the following rights regarding your personal information:

  • Right of access — request a copy of the personal information we hold about you
  • Right to correction — request correction of inaccurate or incomplete information
  • Right to deletion — request deletion of your personal information (subject to legal retention obligations)
  • Right to object — object to the processing of your personal information in certain circumstances
  • Right to data portability — request your data in a structured, commonly used format

To exercise any of these rights, contact us at support@croccodes.co.za. You may also delete your account directly from the Profile screen in the App.

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

10

International Transfers

Your data is stored on Google Firebase servers which may be located outside South Africa. Google is certified under internationally recognised data protection frameworks. By using the App you consent to your information being transferred to and processed in countries outside South Africa, provided that adequate protections are in place.

11

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify you through the App. Your continued use of the App after changes are posted constitutes your acceptance of the revised Policy.

12

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact our Information Officer: