TrustSquare (trustsquare.co) is an anonymity-first online marketplace operated by Trustsquare (Pty) Ltd. This policy explains what personal information we collect, why, and your rights under the Protection of Personal Information Act, 2013 (POPIA). It is incorporated by reference into our Terms of Use / EULA.
Sellers provide an email address and the content of their listings at registration; proof of address or professional credentials may be requested as verification tiers apply. Buyers can browse without an account; a buyer account is created only when you initiate a seller introduction, using the contact details you provide. We also keep transaction and Tuppence ledger records, support correspondence, and standard technical logs (IP address, device/browser information) needed to run and secure the service.
We process personal information to operate the marketplace and deliver introductions you request (performance of our agreement with you), with your consent where required (for example marketing emails you opted into at account creation), and in our legitimate interest in keeping the Platform secure and preventing fraud. Identity verification follows our deferred-KYC model described in the Terms of Use: browsing is anonymous, and verification applies as engagement deepens.
Card payments are processed by Paystack, our payment service provider. Card details are captured by Paystack and are not stored on TrustSquare servers.
We do not sell personal information. We share it only with service providers who process it on our behalf under written agreements: payment processing (Paystack), cloud hosting and backups (servers hosted in the European Union with Hetzner, encrypted backups on Cloudflare R2 with 14-day retention), email delivery, and AI processing. AI features (listing rewrites and audits, price and yield checks, photo drafting and moderation, identity-document verification, and support email triage) are processed by AI infrastructure providers under written agreements that prohibit them from using your content to train their models: Anthropic (United States), OpenAI (United States) and Scaleway (France, European Union). For reliability, a request may be served by any one of these providers, including automatic failover between them; the content sent is limited to what the feature needs (for example the listing text or photo you submitted, or the document you uploaded for verification). Where information is stored outside South Africa, we rely on jurisdictions and contractual safeguards that provide an adequate level of protection consistent with section 72 of POPIA.
The Platform employs TLS 1.3 encryption in transit, server-side encryption at rest, role-based access controls, and daily encrypted backups with 14-day retention. Security controls are reviewed periodically.
If a breach affecting your personal information occurs we will notify affected users and the relevant supervisory authority as required by the law that applies to you, and always within the shortest period that law requires. Where POPIA applies, notification is made to the Information Regulator as soon as reasonably possible after discovery. Where the UK GDPR applies, notification is made to the Information Commissioner's Office within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the Australian Privacy Act applies, we complete our assessment within 30 days and notify you and the OAIC as soon as practicable after forming the belief that an eligible data breach has occurred. Where the law of a US state applies, notification is made without unreasonable delay and within any outside period that state's law sets.
We keep personal information for as long as your account is active and thereafter only as long as required for legitimate business records, dispute resolution, and statutory retention periods (including tax and financial-reporting laws), after which it is deleted or de-identified.
Under POPIA you may request access to the personal information we hold about you, ask for correction or deletion, object to processing, and withdraw consent to direct marketing at any time. Write to [email protected]. You may also lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za.
By creating an account you opt in to introduction notification emails and Platform updates. Every promotional email contains an unsubscribe link; opt-out requests are processed within 5 business days.
The Platform uses only functional browser storage (session state and preferences). We do not run third-party advertising or tracking cookies.
The Platform is intended for users aged 18 and over.
If you use the Report a problem button, we store what you tell us together with the address of the page you were on, the version of the app you were running, your screen size, your browser's identification string, the last few technical errors your browser recorded, and any screenshot you choose to attach. We store your name and email address so that we can reply to you.
We use this only to reproduce and fix the fault you reported, and to write to you about it. We do not use it for marketing, we do not sell it, and we do not share it with anyone outside TrustSquare except where a fix requires our hosting provider to investigate on our behalf. A screenshot may capture whatever was on your screen when you took it — please look before you attach.
We keep a fault report for as long as the fault is open and for twelve months after it is closed, so that we can tell whether a fault has come back. You may ask us to delete your report at any time by writing to [email protected], and we will do so unless we are required to keep it.
We may update this policy from time to time. The current version always lives at trustsquare.co/privacy; material changes will be announced on the Platform.
The supplements below apply in addition to the policy above if you are in the United Kingdom, the United States, Australia or the European Union, and prevail over it to the extent of any conflict. They correspond to Schedules A, B, C, D and E of the Terms of Use. If you are in South Africa, the policy above already reflects South African law and no supplement applies to you.
A1 · Applicable law and controller. Where you are in the UK, your personal data is processed under the UK General Data Protection Regulation and the Data Protection Act 2018. The controller is Trustsquare (Pty) Ltd, 6 Villa Christiaan, 98 Manie Road, Elarduspark, Pretoria, Gauteng, 0181, South Africa. Privacy contact: [email protected].
A2 · UK representative. We have not appointed a representative in the UK under Article 27. We have assessed that we are not required to, because our processing of UK residents' data is occasional, does not include special-category data, and is unlikely to result in a risk to your rights and freedoms. In particular, our identity checks read the name and document number printed on a document you upload and compare them with what you told us: we do not perform facial recognition, biometric matching, or liveness checks, and we hold no biometric template of you. We keep this assessment under review and will appoint a UK representative, and say so here, if any part of it stops being true.
A3 · Our lawful bases. Operating your account and delivering Introductions you request — contract, Article 6(1)(b). Marketing emails you opted into — consent, Article 6(1)(a), withdrawable at any time. Securing the Platform, preventing fraud and defending claims — legitimate interests, Article 6(1)(f). Identity and credential verification — legal obligation and contract, Article 6(1)(c) and (b). Retaining records after your account closes — legal obligation, Article 6(1)(c). Where we rely on legitimate interests you may object at any time.
A4 · Identity documents. Documents you upload for verification are used only to verify you, are never used to train any AI model, are never shown to other users, and are kept only as long as the verification and our statutory record-keeping require.
A5 · Your rights. You have the right to be informed; to access your data; to have inaccurate data rectified; to erasure where Article 17 applies; to restrict processing; to data portability; to object to processing based on legitimate interests and, absolutely and at any time, to direct marketing; and to withdraw consent without affecting processing already carried out. Write to [email protected]. We answer within one month, extendable by two further months for complex requests, in which case we will tell you inside the first month. There is no charge unless a request is manifestly unfounded or excessive.
A6 · Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone. AI is used for listing assistance, moderation, pricing guidance and support triage; where an outcome affects your account, a human reviews it before it takes effect.
A7 · International transfers. Your data is processed in South Africa, in the European Union (hosting and backups) and, for AI features, in the United States and France. The UK has not issued adequacy regulations for South Africa, so transfers out of the UK are made under the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You may request a copy of the safeguards used.
A8 · Cookies. The Platform uses only functional browser storage. We run no advertising or third-party tracking cookies, so no consent banner is required under the Privacy and Electronic Communications Regulations. If that changes, we will ask for your consent first.
A9 · Complaints. Please raise concerns with us first. You also have the right to complain to the Information Commissioner's Office — ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
B1 · We do not sell or share your personal information. TrustSquare does not sell your personal information and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding 12 months. We run no advertising or tracking cookies. Because we neither sell nor share, there is no "Do Not Sell or Share My Personal Information" link; if that ever changes we will add one before it does.
B2 · What we collect, and why. Identifiers (name, email, account ID, IP address) — from you and your device, to run your account, deliver Introductions and keep the Platform secure. Customer records and payment status — from you and our payment processor, for payments and support. Commercial information (your listings, Introductions, Tuppence ledger) — from your use of the Platform, to operate the marketplace. Internet activity (device and browser information, logs, error reports) — from your device, for security and fault diagnosis. Coarse geolocation only — the city or suburb you type on a listing. Government identifiers and identity documents — from you, at verification, for fraud prevention and legal compliance. Audio-visual material — listing photos and any screenshot you attach to a fault report. Inferences — your Trust Score only, from your conduct on the Platform, and we disclose it to no one. We do not collect biometric information. We do not knowingly collect personal information from anyone under 18.
B3 · Sensitive personal information. Government identifiers and identity documents are sensitive personal information under the CPRA. We use them solely to verify identity or a credential, to prevent fraud, and to meet legal obligations — purposes for which the CPRA provides no right to limit. We do not use sensitive personal information to infer characteristics about you, and never for advertising.
B4 · AI providers are service providers. Listing rewrites and audits, price checks, photo drafting and moderation, identity-document verification and support triage are performed by our AI providers under written contracts that restrict them to performing the service, prohibit use of your content to train their models, and prohibit retention or disclosure for any other purpose. Disclosure to a service provider under such a contract is neither a sale nor a share.
B5 · Your California rights. You have the right to know what we collect and why; to obtain a copy of the personal information you gave us, in a portable form; to correct inaccurate information; to delete your personal information, subject to the exceptions the statute allows; to opt out of sale or sharing (which we do not do); and to limit the use of sensitive personal information (which we use only for exempt purposes, as set out in B3).
B6 · How to exercise them, and non-discrimination. Email [email protected] from the address on your account, or write to the postal address above. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days where reasonably necessary, in which case we will tell you. We verify requests against the account before acting. An authorised agent may submit a request with your written permission and proof of identity. We will not discriminate against you for exercising any of these rights — no denial of service, no different price, no reduced quality.
B7 · Electronic contracting and auto-renewal. You consent to transact electronically under the E-SIGN Act and applicable state UETA. Where a subscription renews automatically, the renewal terms are disclosed clearly and conspicuously before purchase and you may cancel online at least as easily as you subscribed.
B8 · Other US states. If you live in a state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and Delaware — you have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. We do not conduct targeted advertising, do not sell personal data, and do not profile in that way. We honour access, correction, deletion and portability requests on the same terms as B5 and B6. If we decline a request, you may appeal: reply to our decision and a different reviewer will reconsider it within 45 days and tell you the outcome in writing, together with how to contact your state Attorney General.
C1 · Applicable law. Where you are in Australia we handle your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy and this supplement together are our APP 1 privacy policy. Privacy enquiries: [email protected].
C2 · What we collect and why (APP 3, APP 5). As set out in sections 2 and 3 above, and collected directly from you. If you do not provide it, we may be unable to create your account, verify you, or deliver an Introduction.
C3 · Sensitive information (APP 3.3). We do not seek sensitive information as the Privacy Act defines it. Where an identity document you upload happens to disclose sensitive information, we collect it only with your consent — given by uploading it for verification — and use it only to verify you.
C4 · Anonymity and pseudonymity (APP 2). The Platform is anonymity-first by design: you may browse without an account, and sellers stay unidentified to buyers until both parties accept an Introduction. This is how we give practical effect to APP 2.
C5 · Direct marketing (APP 7). Every promotional email carries an unsubscribe facility and we act on opt-outs within 5 business days. You may ask us at any time not to use your information for direct marketing, and to tell you where we obtained it.
C6 · Cross-border disclosure (APP 8). Your personal information is stored and processed outside Australia — in South Africa, in the European Union, and for AI features in the United States and France. Before disclosing we take reasonable steps to ensure each overseas recipient does not breach the APPs, by written agreement. Under APP 8.1 we remain accountable to you for their handling of your information as though we had handled it ourselves — so if an overseas provider mishandles it, your recourse is with us, and you do not have to pursue them.
C7 · Access and correction (APP 12, APP 13). You may ask for access to the personal information we hold about you and ask us to correct it. We respond within 30 days. Access is free and we never charge for correction. If we refuse access or correction we will tell you in writing why, and how to complain.
C8 · Notifiable data breaches. If we suspect an eligible data breach we assess it within 30 days. If we conclude one has occurred and it is likely to result in serious harm, we notify you and the Office of the Australian Information Commissioner as soon as practicable.
C9 · Complaints. Write to us first; we respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner — oaic.gov.au, 1300 363 992, GPO Box 5218, Sydney NSW 2001.
This supplement applies if you are in the European Union or the EEA, and corresponds to Schedules D (France) and E (Portugal) of the Terms of Use.
D1 · Applicable law and controller. Your personal data is processed under the General Data Protection Regulation (EU) 2016/679, together with the French Loi Informatique et Libertés or the Portuguese Lei n.º 58/2019 as applicable. The controller is Trustsquare (Pty) Ltd at the address above. Privacy contact: [email protected].
D2 · EU representative. We have not appointed a representative in the Union under Article 27. We have assessed that we are not required to, on the same basis set out in A2: our processing of EU residents' data is occasional, does not include special-category data — our identity checks read the name and document number printed on a document you upload and compare them with what you told us, and we do not perform facial recognition, biometric matching, or liveness checks — and is unlikely to result in a risk to your rights and freedoms. We keep this assessment under review and will appoint a representative, and say so here, if any part of it stops being true.
D3 · Lawful bases. As set out in A3, read as references to Article 6 GDPR.
D4 · Business contact details obtained from public sources. Where we have obtained your professional contact details from a publicly accessible source and write to you at a professional address for reasons connected with your professional activity, we rely on legitimate interests (Article 6(1)(f)) and we tell you in that message where we got them. You may object at any time, without giving reasons, and we will stop.
D5 · Your rights. Access, rectification, erasure, restriction, portability, and objection — including an absolute right to object to direct marketing — together with the right to withdraw consent without affecting processing already carried out. We answer within one month, extendable by two further months for complex requests, in which case we tell you inside the first month. You also have the right to give directives on the fate of your data after your death under French law.
D6 · Automated decision-making (Article 22). We do not make decisions producing legal or similarly significant effects about you by automated means alone; a human reviews any outcome affecting your account before it takes effect.
D7 · International transfers. Data is processed in South Africa and, for AI features, in the United States, as well as within the EU. South Africa is not the subject of an adequacy decision, so transfers out of the EEA are made under the Standard Contractual Clauses together with a transfer impact assessment. You may request a copy of the safeguards.
D8 · Breach notification. Where the GDPR applies, we notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to your rights and freedoms.
D9 · Complaints. Raise it with us first. You may also complain to your national supervisory authority — in France the CNIL (cnil.fr), in Portugal the CNPD (cnpd.pt), or the authority of your own country of residence.