Back to Gathivo

Gathivo Privacy Policy

Effective date: 13 September 2026 Last updated: 14 September 2026

1. Who we are

Gathivo is an event discovery and ticketing platform for South Africa. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it.

Responsible party Gathivo
Trading as Gathivo
Registered address South Africa
Information Officer Gathivo Support
Contact for privacy matters [email protected]
General support [email protected]

This policy is issued in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA").

2. The two different roles we play

This is the most important section in this policy, because our obligations differ depending on which one applies.

As the responsible party. For your Gathivo account — your name, email address, phone number, password, notification settings and the record of your bookings — we decide why and how that information is processed. We are accountable to you for it.

As an operator. Event organisers build their own registration forms and decide what to ask you. When you answer an organiser's registration questions, the organiser decides what is collected and why; we process and store those answers on their behalf. For those answers the organiser is the responsible party and we are their operator.

In practice: questions about your account come to us, and questions about why a particular event asked you something go to that event's organiser. We will always help you reach them.

3. What we collect, and why

3.1 Information you give us when you create an account

Information Required? Why we need it
Name Yes To identify you to organisers whose events you attend
Email address Yes Sign-in, booking confirmations, account security notices
Password Yes To secure your account. Stored only as a cryptographic hash — we never see or store the password itself
Phone number No Optional contact detail, shared with an organiser only where you have booked
Profile picture No Shown on your profile
Time zone Set automatically Defaults to Africa/Johannesburg so event times display correctly

3.2 Information created when you book

When you book, we create a booking record containing the event, your chosen ticket type, a booking reference and its status.

If you book for other people, we store the name and, optionally, the email address of each additional attendee so that each person gets their own ticket and can be admitted at the door. If you supply another person's details, you confirm that you are entitled to do so and that you have told them their details are being given to us and to the organiser of that event.

3.3 Payment information

We do not accept card payments and we never receive, process or store card numbers. Events on Gathivo are paid for by electronic funds transfer (EFT) directly to the organiser.

So that an organiser can confirm your payment, you upload proof of payment — for example a screenshot from your banking app or a transfer confirmation. Please be aware of what that image may contain:

  • It is visible to the organiser of that event, and to Gathivo staff reviewing a dispute.
  • It may show your bank account details, your balance and unrelated transactions. We recommend you obscure anything not needed to prove the payment.
  • Because it is the evidence behind a financial record, South African record-keeping expectations require us to keep it for five years. After five years the image is deleted automatically; the payment amount, reference and who verified it remain as an accounting record.

We also store the payment amount, currency, method, status, your payment reference and the review outcome.

Buying promoted placement. Organisers can pay Gathivo to promote an event. That purchase goes through the Apple App Store or Google Play, and they take the payment — so here too we never see your card details. We receive a confirmation from RevenueCat, the service we use to check the purchase is real, containing your Gathivo user ID, the product bought, a transaction identifier, the price and country, and whether it was a test purchase. We store the amount, currency, transaction identifier and the placement window it paid for, as the record of a sale.

3.4 Organiser registration questions

Organisers may add their own questions to an event's registration form. These can be free text, numbers, dates, choices, or a file or document upload.

This means an organiser could ask you for sensitive information — dietary requirements, accessibility needs, an identity number, or a document. POPIA treats some of that as special personal information, which generally requires your explicit consent.

You are never obliged to answer. If a question seems excessive or irrelevant to attending the event, you may decline to book and you may report it to us at [email protected]. Our Terms require organisers to collect only what they genuinely need and to have a lawful basis for it, and we act on reports.

3.5 Tickets and entry

Each admission gets a ticket with a QR code. We do not store the QR code's secret — only a one-way hash of it — so a copy of our database cannot be used to manufacture working tickets.

When your ticket is scanned at a door we record the time, the scanning method, the device label and which organiser team member scanned it.

3.6 Your device

Information Why
Device name and model So you can recognise and sign out of your own sessions
Push notification token To deliver notifications you have asked for
IP address and browser/app identifier Written to our security audit log

The app requests camera access only so that organisers can scan tickets at a door. Scanning happens on the device; we do not store, transmit or retain any image from your camera. The app does not request location access and does not track your location.

3.7 What we do not do

As at the effective date of this policy:

  • We do not use advertising networks and we do not show you ads. Organisers can pay to have their own event promoted inside Gathivo, which is not the same thing: no third party buys space, and nothing about you is used to decide what you are shown.
  • We do not use third-party analytics, behavioural tracking or advertising identifiers. RevenueCat, which confirms promoted-placement purchases, reports those sales back to us — that is a record of transactions, not a record of what you look at or do in the app.
  • We do not sell your personal information to anyone, ever.
  • We do not make automated decisions that have legal or similarly significant effects on you. Bookings, payment deadlines and waitlists follow published rules, not profiling or scoring.

If any of this changes we will update this policy and tell you before the change takes effect. See section 10.

4. Who we share it with

4.1 Event organisers

When you book an event, that event's organiser receives your name, email address, ticket type, booking status, your answers to their questions and your proof of payment. They need it to admit you, to verify payment and to contact you about their event. Organisers can export this to a spreadsheet.

Organisers are bound by our Terms to use it only to run that event, and not for unrelated marketing.

4.2 Service providers

Provider What they receive Purpose
Google Firebase Cloud Messaging Your device's push token and the content of each notification Delivering push notifications
RevenueCat Your Gathivo user ID, and the purchase details the app store reports — product, transaction identifier, price, country and whether it was a test purchase Confirming that a promoted-placement purchase really happened, before we act on it
Apple / Google Whatever their payment systems collect when you buy promoted placement. We never see your card details Taking payment for promoted placement
Transactional email provider Your email address and the message Sending transactional email
Hosting provider All platform data, as our hosting provider Running the service
Cloud object storage Uploaded files — avatars, event images, proof of payment, registration documents File storage

RevenueCat and the app stores are only involved if you buy promoted placement, which only organisers can do. If you never buy it, nothing about you is sent to them.

4.3 Cross-border transfer

We host primarily in South Africa, and our file storage is configured to the af-south-1 (Cape Town) region. However, Google Firebase, RevenueCat, the app stores and our email provider process data outside South Africa. POPIA section 72 permits this where the recipient is subject to comparable protection, which these providers are contractually bound to. If you would prefer notification data not to be sent abroad, you can turn push notifications off in the app and in your device settings.

4.4 Legal

We may disclose information where the law requires it, or to establish, exercise or defend a legal claim.

5. How long we keep it

Data Retained
Account details Until you delete your account
Proof-of-payment images 5 years, then deleted automatically
Payment records (amount, reference, outcome) 5 years, then deleted — South African tax and company record-keeping obligations
Promoted-placement purchases (amount, transaction id, window) 5 years, then deleted — South African tax and company record-keeping obligations
Bookings, tickets and check-ins 5 years — they are the organiser's attendance and capacity record
Attendee exports Deleted 7 days after expiry
Uploads never attached to anything Deleted after 24 hours
Security audit log As long as reasonably needed for security, fraud prevention and legal compliance

6. Deleting your account

You can delete your account from the app: Profile → Delete account.

When you do, we immediately delete your sign-in tokens, push tokens, saved events, notification preferences, notifications and profile picture, and we overwrite your name, email address and phone number so the account can no longer identify you.

What survives, and why. Your bookings, payments and tickets remain, because they are the organiser's record of who attended and what was paid, and because financial records must be retained by law. They are no longer linked to a name or contact details.

You cannot delete your account while you are the organiser of a live event with attendees depending on it. Cancel or hand over the event first.

The records we keep are held for 5 years and then deleted. For the full detail — including how to ask us to delete or correct specific information without closing your account — see Delete your account.

7. Your rights under POPIA

You have the right to:

  • Know what we hold about you, and ask for a copy.
  • Correct anything inaccurate, or delete anything we hold without a lawful basis.
  • Object to processing, and withdraw consent at any time — although without the information necessary to issue a ticket we cannot complete a booking.
  • Not receive unsolicited direct marketing. Notification categories are individually switchable in the app, except for a small number of essential messages about a booking you made.
  • Complain. Tell us first at [email protected] and we will respond within 30 days. If you are not satisfied you may complain to:

The Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 [email protected] https://inforegulator.org.za

8. How we protect it

  • Passwords are stored as one-way hashes and are never recoverable.
  • Ticket QR secrets are stored only as hashes.
  • Uploaded files are private, reachable only through short-lived signed links after a permission check.
  • All traffic is encrypted in transit (HTTPS/TLS).
  • Sign-in credentials are held in the device's secure keychain or keystore.
  • Sensitive actions are written to an append-only audit log.
  • Requests are rate-limited to frustrate brute-force attempts.

No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator as POPIA section 22 requires.

9. Children

Gathivo is not intended for children under 18. A child may be named as an attendee on a booking made by a parent or guardian, who is responsible for that consent. We do not knowingly allow under-18s to create accounts. If you believe a child has created one, contact [email protected] and we will remove it.

10. Changes

If we change this policy we will update the date above. Where a change materially affects your rights, we will notify you in the app or by email before it takes effect.

11. Contact

[email protected] · [email protected] · South Africa