Privacy Policy

Last updated 1 August 2026. This is a template written with South Africa's Protection of Personal Information Act (POPIA) in mind — have a lawyer review it before relying on it for a live, paying userbase.

1. What we collect

Account details you provide directly: name, email, and password (stored as a salted hash, never in plain text). Vehicle details you add to your garage. Workshop details a workshop owner provides (address, services, operating hours). Booking and review history generated by using the platform. Optionally, a profile or vehicle photo you upload.

2. Why we collect it

To operate the marketplace: matching motorists with workshops, processing bookings, tracking warranty coverage, and showing service history. To communicate with you about bookings, warranty claims, and disputes — via in-app notifications and, where you've enabled it, email. To improve the product, using aggregated, privacy-respecting product analytics that is entirely inert unless a project maintainer configures an analytics key.

3. Who we share it with

A motorist's name and booking details are shared with the workshop they book with — that's necessary to complete the service. We don't sell personal information to third parties. Where a payment processor is integrated, payment details are handled directly by that processor and are never stored on My Bonnet's own servers.

4. Your rights under POPIA

You have the right to access the personal information we hold about you, request correction of inaccurate information, and request deletion of your account and associated data, subject to information we're required to retain for legal, warranty, or dispute-resolution purposes (for example, records of a completed booking during its warranty period). To exercise any of these rights, contact privacy@mybonnet.app.

5. Data retention

Account and booking data is retained for as long as your account is active, plus a reasonable period afterward to resolve any open warranty claims or disputes and to meet financial record-keeping obligations.

6. Security

Passwords are hashed, sessions are signed, and access to platform-wide data is restricted to admin accounts. No system is perfectly secure, and we'll notify affected users without undue delay in the event of a data breach affecting their personal information, as required by POPIA.

7. Cookies and analytics

My Bonnet uses a session cookie to keep you signed in. If product analytics is enabled by the operator of this platform, it captures anonymized usage events (page views, key actions like a booking or review) to understand how the product is used — it does not track you across other websites.

8. Changes to this policy

We may update this policy from time to time. Material changes will be notified in-app before they take effect.

9. Contact

Questions about this policy, or requests relating to your personal information, can be sent to privacy@mybonnet.app.