Privacy Policy
PRIVACY POLICY
1. Introduction
Welcome to bunnihop (operated legally as Bunnihop, "we," "us," or "our"). We provide decentralized campus micro-mobility services. We are committed to protecting your personal information and respecting your right to privacy.
This Privacy Policy explains how we collect, use, store, and safeguard your information when you access or use our mobile application, website platform, and related services, in strict compliance with the Protection of Personal Information Act (POPIA) of South Africa.
2. Information We Collect & How We Collect It
We limit the data we collect strictly to what is required to provide safe, reliable campus mobility.
A. Authentication & Account Data (Google Single Sign-On)
When you register or sign in on either our mobile application or our website, you authenticate via Google Single Sign-On (SSO) using your official university email address (uXXXXXXXX@tuks.co.za).
Through Google SSO, we automatically receive and store:
- University Email Address: Used to verify your active student/staff status.
- Student Number: Extracted directly from your university email identifier (
uXXXXXXXX). - Full Name: As provided on your Google profile.
- Profile Picture: Displayed in your app and website profile dashboard.
B. Location Data
We access device location services strictly to power real-time mapping and trip logistics:
- In-App & Web Map Browsing: We process your device's current location while using our application or website to render nearby bicycles on the map and display your position relative to dedicated dropoff zones.
- Trip Completion & Storage: Your location is only permanently recorded at the exact moment you end a ride. When ending a rental session, your device's GPS coordinates are captured and sent alongside your parking verification photo to update the bicycle object's location on our backend servers.
Note: We do NOT track, trace, or store continuous background location data when you are not actively using the service, nor do we record live GPS route histories while you are riding.
C. Camera & Parking Verification Photos
- Camera Access: The mobile application requests permission to access your device's camera.
- Photo Submissions: At the end of every trip, you must capture and upload a photograph of the parked bicycle. This photo and its associated timestamp are uploaded to our secure server to verify proper hub parking, inspect hardware condition, and prevent vandalism or theft.
D. Payment Information & Saved Card Management (Paystack Integration)
Financial transactions on bunnihop are processed securely via our payment gateway partner, Paystack.
- Data Stored on Paystack: Paystack handles all sensitive card credentials, full Primary Account Numbers (PAN), and CVV security codes in compliance with PCI-DSS standards.
- Data Stored on Our Servers: To provide a seamless checkout experience across our web and mobile apps (showing your saved cards and handling billing for rentals, trip passes, or penalties), we store only non-sensitive card metadata on our servers:
- Card Brand/Type (e.g., Visa, Mastercard)
- Last 4 digits of the card number
- Expiration Month and Expiration Year
- Issuing Bank Name
- Tokenized Payment Keys provided by Paystack
- Removal of Saved Payment Methods: You are always permitted to remove or delete a saved payment method from your account through the app, unless you currently have at least one active ride in progress. To ensure trip charges and pre-authorizations can be executed properly, payment methods cannot be deleted until all active rental sessions are concluded and resolved.
E. Web & Mobile Analytics, Performance & Technical Logs
When accessing our web platform or mobile application, our servers automatically collect standard technical telemetry, including:
- Device hardware model, web browser type, operating system version, and screen resolution.
- IP addresses, API request logs, crash reports, and performance metrics.
- Essential Cookies & Session Tokens: We use secure local storage and essential cookies on our website to maintain your authenticated login session and remember your account preferences.
3. How We Use Your Information
We process your personal information under POPIA lawful conditions for the following specific purposes:
- Service Operations: Authenticating your student identity across web and mobile platforms, enabling bicycle unlocks, and updating fleet locations upon trip completion.
- Accountability & Safety: Verifying that bicycles are locked inside dedicated dropoff zones via uploaded parking photos.
- Billing & Payments: Processing rental charges, wallet top-ups, trip passes, and applying applicable overtime or out-of-zone fees via Paystack.
- Platform Security: Preventing fraudulent accounts, account sharing, hardware theft, or unauthorized non-student access.
- Customer Support & Service Alerts: Reaching out via your student email for critical trip receipts, security notifications, or customer support inquiries.
4. How We Share & Disclose Information
We do not sell, rent, or trade your personal information to third-party marketers. We only share data in the following limited circumstances:
- Payment Processors: Sharing transaction details securely with Paystack to authorize payments and handle wallet balances.
- Third-Party Infrastructure Services: Hosting and database partners (e.g., cloud web hosting, database management, and error tracking tools) operating under strict confidentiality obligations.
- University Authorities & Security: In severe cases involving physical hardware destruction, stolen bicycles, reckless campus collisions, or safety threats, we reserve the right to share relevant account details (Name, Student Number, and Trip Photos) with campus security or university administrative bodies.
- Legal Compliance: Disclosing information if mandated by South African law enforcement, court subpoenas, or regulatory requirements under POPIA.
5. Data Retention & Security
- Data Retention: We retain account data, transaction metadata, and trip completion logs for as long as your account remains active or as needed to comply with financial record-keeping laws and operational security needs.
- Security Measures: We implement industry-standard encryption protocols (HTTPS/TLS) across both our mobile app and website. Non-sensitive card details stored on our servers are isolated from payment execution workflows.
6. Your Rights & Data Choices (POPIA Framework)
As a data subject under South African privacy law (POPIA), you have the right to:
- Access Your Personal Information: Request details on what personal data we hold regarding your account.
- Request Correction or Deletion: Request the correction of inaccurate data or the deletion of your account and associated personal information (subject to settling active balances or ongoing hardware loss investigations).
- Manage Saved Payment Methods: Delete or replace saved payment cards at any time via your account dashboard in the mobile app, provided there are no active bicycle rental sessions tied to your account.
- Object to Processing: Object to the processing of your data on reasonable grounds, provided it does not prevent the core execution of an active rental contract.
- Device Permission Controls: Revoke camera, location, or cookie permissions at any time via your smartphone or web browser settings (note that revoking camera or location permissions will prevent unlocking or ending rentals).
7. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect operational, software, or legal adjustments across our web and mobile services. Any revisions will be published here with an updated "Last Updated" date. Continued use of the bunnihop app or website after modifications constitutes acceptance of the updated policy.
8. Information Officer & Contact Details
If you have questions, concerns, or wish to exercise your legal data rights under POPIA, please contact our Information Officer:
- Support Channel: Official Discord Community
- Email:
bunnihopadmin@gmail.com
