TrustSquare (trustsquare.co) is an anonymity-first online marketplace operated by Trustsquare (Pty) Ltd. This policy explains what personal information we collect, why, and your rights under the Protection of Personal Information Act, 2013 (POPIA). It is incorporated by reference into our Terms of Use / EULA.
Sellers provide an email address and the content of their listings at registration; proof of address or professional credentials may be requested as verification tiers apply. Buyers can browse without an account; a buyer account is created only when you initiate a seller introduction, using the contact details you provide. We also keep transaction and Tuppence ledger records, support correspondence, and standard technical logs (IP address, device/browser information) needed to run and secure the service.
We process personal information to operate the marketplace and deliver introductions you request (performance of our agreement with you), with your consent where required (for example marketing emails you opted into at account creation), and in our legitimate interest in keeping the Platform secure and preventing fraud. Identity verification follows our deferred-KYC model described in the Terms of Use: browsing is anonymous, and verification applies as engagement deepens.
Card payments are processed by Paystack, our payment service provider. Card details are captured by Paystack and are not stored on TrustSquare servers.
We do not sell personal information. We share it only with service providers who process it on our behalf under written agreements: payment processing (Paystack), cloud hosting and backups (servers hosted in the European Union with Hetzner, encrypted backups on Cloudflare R2 with 14-day retention), email delivery, and AI processing. AI features (listing rewrites and audits, price and yield checks, photo drafting and moderation, identity-document verification, and support email triage) are processed by AI infrastructure providers under written agreements that prohibit them from using your content to train their models: Anthropic (United States), OpenAI (United States) and Scaleway (France, European Union). For reliability, a request may be served by any one of these providers, including automatic failover between them; the content sent is limited to what the feature needs (for example the listing text or photo you submitted, or the document you uploaded for verification). Where information is stored outside South Africa, we rely on jurisdictions and contractual safeguards that provide an adequate level of protection consistent with section 72 of POPIA.
The Platform employs TLS 1.3 encryption in transit, server-side encryption at rest, role-based access controls, and daily encrypted backups with 14-day retention. Security controls are reviewed periodically.
If a breach affecting your personal information occurs, we will notify affected users and the Information Regulator as required by POPIA, and in any event within 30 days of becoming aware of the breach.
We keep personal information for as long as your account is active and thereafter only as long as required for legitimate business records, dispute resolution, and statutory retention periods (including tax and financial-reporting laws), after which it is deleted or de-identified.
Under POPIA you may request access to the personal information we hold about you, ask for correction or deletion, object to processing, and withdraw consent to direct marketing at any time. Write to [email protected]. You may also lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za.
By creating an account you opt in to introduction notification emails and Platform updates. Every promotional email contains an unsubscribe link; opt-out requests are processed within 5 business days.
The Platform uses only functional browser storage (session state and preferences). We do not run third-party advertising or tracking cookies.
The Platform is intended for users aged 18 and over.
If you use the Report a problem button, we store what you tell us together with the address of the page you were on, the version of the app you were running, your screen size, your browser's identification string, the last few technical errors your browser recorded, and any screenshot you choose to attach. We store your name and email address so that we can reply to you.
We use this only to reproduce and fix the fault you reported, and to write to you about it. We do not use it for marketing, we do not sell it, and we do not share it with anyone outside TrustSquare except where a fix requires our hosting provider to investigate on our behalf. A screenshot may capture whatever was on your screen when you took it — please look before you attach.
We keep a fault report for as long as the fault is open and for twelve months after it is closed, so that we can tell whether a fault has come back. You may ask us to delete your report at any time by writing to [email protected], and we will do so unless we are required to keep it.
We may update this policy from time to time. The current version always lives at trustsquare.co/privacy; material changes will be announced on the Platform.