This Privacy Policy explains what personal information Integreet ("Integreet", "we", "us", "our") collects, why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights and choices you have. It applies to our iOS app, Android app, website, and related services (together, the "Service"). Please read it together with our Terms of Service, Acceptable Use Policy, and Child Safety Standards.
We are committed to complying with South Africa's Protection of Personal Information Act, 2013 (POPIA), the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Apple App Store and Google Play data policies, and other applicable data-protection laws. Where a specific region grants you additional rights, those are set out in Section 18 (Region-specific notices).
1. Introduction and scope
1.1 This Policy covers personal information we process when you create an account, use the app or website, buy or sell in the marketplace, subscribe to a paid plan, buy credits, go live, message other users, or use our AI-assisted features.
1.2 It does not cover third-party services that you separately choose to use (for example, Apple's App Store, Google Play, or a link you follow to another website), which are governed by their own privacy policies.
1.3 "Personal information" (POPIA) and "personal data" (GDPR) are used interchangeably in this Policy and mean information relating to an identified or identifiable person.
2. Who we are (Responsible Party / Controller)
2.1 Responsible Party / Data Controller. Integreet is the responsible party (POPIA) and data controller (GDPR) for the personal information described in this Policy.
2.2 Information Officer. Our Information Officer under POPIA is James Ndou, contactable at support@integreet.com, 1108 Copperleaf Country Estate, Mnandi, Centurion, Pretoria 0157, South Africa.
2.3 Contact for privacy matters. For any privacy question, request, or complaint, email support@integreet.com. Full contact and complaint details are in Section 20.
3. The personal information we collect
We collect the categories below. Not every category applies to every user — it depends on which features you use.
3.1 Information you give us
- Account details: full name, email address, password (stored only in hashed form), phone number, date of birth (to confirm you meet the minimum age), and profile photo.
- Profile content: username, bio, interests, gender (if you choose to add it), and any location you choose to display.
- Content you create: posts, reels, stories/statuses, comments and replies, reactions, direct messages, events, marketplace listings, reviews, and any images or videos you upload.
- Business-verification data (business accounts only): business name, registration number, tax number, and a representative's identity document. This is sensitive information and is used only to verify the business and combat fraud (see Section 6 for facial images and Section 12 for security).
- Payment and transaction data: the items you buy or sell, order references, delivery details you enter, and payout details for sellers. Card details are entered directly with our payment processors — we never see or store full card numbers (see Section 8).
- Support and correspondence: messages you send us, and reports you submit about content or other users.
3.2 Information we collect automatically
- Device data: IP address, device identifier, device model, operating system, browser, and app version.
- Usage data: pages and screens viewed, features used, search queries, interactions (follows, likes, views), and timestamps.
- Diagnostics: crash and performance data used to keep the app working and to fix problems.
- Session and security data: login events and an approximate location derived from your IP address, used to detect suspicious sign-ins and protect your account (see Section 8, ipapi.co).
- Push-notification token: a device-specific token issued by Firebase Cloud Messaging so we can deliver notifications you opt in to. On its own it does not identify you.
- Cookies and similar technologies on our website (see Section 17).
3.3 Device permissions
We access the following only when you grant the operating-system permission, and only for the specific feature that needs it. We never run these sensors in the background:
- Camera — to record reels and videos, go live, take photos for posts and your profile, and capture business-verification documents.
- Microphone — for voice messages, audio in reels/videos, live streaming, and calls.
- Photo library — to let you pick images and videos to share.
- Location — used only while you are using the app, to show events near you, set an event's location, and share your location in chat when you choose to. We do not track your location in the background.
3.4 Information from third parties
- Sign-in providers: if you sign in with Google or with Apple, we receive your name, email, and (for Google) profile picture. With Apple, you may choose Apple's private "Hide My Email" relay, in which case we receive only a relay address.
- Payment processors: confirmation of payment status and a purchase reference (never your full card number).
- App stores: for in-app purchases, a purchase receipt, product identifier, and transaction status from Apple or Google.
3.5 CCPA categories
For California residents, the above maps to the CCPA categories: identifiers; customer records; commercial information; internet/network activity; geolocation data; audio, visual, and similar information (photos, videos, live streams, voice messages); professional/business information (business accounts); and inferences drawn for personalisation. Sensitive personal information we handle is limited to account credentials and, for business accounts, a government identity document. See Section 9.
4. How we collect it
4.1 Directly from you — when you register, complete your profile, create content, transact, or contact us.
4.2 Automatically — through your use of the Service, as described in Section 3.2, using cookies and similar technologies on the web and standard mobile identifiers in the app.
4.3 From third parties — from the sign-in, payment, and app-store providers in Section 3.4. The source of that data is the relevant provider you chose to use.
5. Why we use your information and our legal basis
We rely on the following legal bases under GDPR Article 6 (and the corresponding POPIA Section 11 grounds). For California business purposes, see Section 9.
- To provide and operate the Service (create your account, show your feed, run the marketplace, deliver messages, host your content). Basis: performance of a contract.
- To authenticate you, send one-time verification codes, and prevent fraud and abuse. Basis: contract, our legitimate interests in securing the Service, and legal obligation.
- To personalise your feed and recommendations using your interests and interactions. Basis: our legitimate interest in a relevant product, or your consent where required.
- To process payments, subscriptions, credits, and marketplace transactions, including escrow for marketplace orders. Basis: performance of a contract.
- To keep the platform safe — content moderation, automated detection of prohibited content (including child sexual abuse material), and enforcing our Terms. Basis: legal obligation and our legitimate interest in user safety.
- To run AI-assisted features you choose to use. Basis: your consent (see Section 6).
- To send transactional emails (verification, receipts, account notices) and, only with your consent, occasional product updates. Basis: contract; consent for marketing.
- To comply with legal obligations and respond to lawful requests. Basis: legal obligation.
Where we rely on legitimate interests, our interest is operating, securing, and improving a social and marketplace platform; we balance this against your rights, and you may object (Section 15).
6. Face Data and the Beauty AI image editor
This section explains, in full, how the optional Beauty AI feature handles photographs that may contain a face. It is written to meet Apple's requirements for "Face Data" (Apple Developer Program License Agreement §3.3.3), and the equivalent requirements of GDPR Article 9 and POPIA Sections 26–27.
6.1 What is covered
Apple defines "Face Data" broadly to include a photograph that a user uploads which may contain a face. Beauty AI is an optional photo editor that lets you upload an ordinary 2D photograph — which may include your face — to be visually edited (for example, smoothing skin or adjusting lighting). We therefore treat those uploaded photographs as Face Data and apply the strict limits below.
6.2 We do not create biometric identifiers
Integreet does not create, extract, derive, or store a faceprint, face template, face mesh, facial-geometry map, facial landmarks, or any other biometric identifier. We do not use Apple's TrueDepth camera, ARKit face tracking, or any facial-recognition technology. We never use your photograph to identify, authenticate, verify, or recognise you or any other person.
6.3 What happens to your photo
When you choose to use Beauty AI and accept the one-time consent prompt, the photograph you upload is handled as ordinary image content, the same as any other photo you post. It is sent to our image-processing partner fal.ai, Inc. (United States) solely to produce the edit you requested, and only for the duration of that transformation. The edited result is returned to you. The photo you uploaded and the edited result are stored by our media host BunnyWay d.o.o. (Bunny.net) so that you can view and re-download your creations.
6.4 No advertising, marketing, profiling, or sale
We do not use Face Data for advertising, marketing, authentication, or to build a profile of you, and we do not sell, share, or transfer Face Data to advertising platforms, analytics providers, data brokers, information resellers, or any similar party.
6.5 No model training
Under fal.ai's API terms, the images you submit are not used to train any AI model. We do not use your Face Data to train models either.
6.6 Consent
Beauty AI requires clear, opt-in, in-app consent before any photo is processed, and it is never required to use Integreet. You can decline and continue using every other part of the Service. You may withdraw consent at any time as described in Section 6.7 and Section 7.
6.7 Retention and deletion
Beauty AI uploads and results are retained only while your account is active. You can delete any Beauty AI creation at any time from the Beauty AI screen, and deleting your account removes them.
6.8 Legal basis
Because a photograph may reveal features some laws treat as sensitive, we process Beauty AI images on the basis of your explicit consent (GDPR Article 9(2)(a); POPIA Section 27) and only for the purpose you consented to.
7. Other AI-assisted features
7.1 Besides Beauty AI, we offer an in-app assistant, caption suggestions, and automated content moderation. When you use one of these, only the specific text or image needed for that request is sent to the relevant provider (see Section 8) — never your full profile, contact list, or message history.
7.2 Per their published API terms, our AI providers do not use Integreet's inputs to train their models.
7.3 AI inputs and outputs pass through the same safety-moderation pipeline as user uploads, so that generative content cannot be used to produce prohibited material. Every AI-generated image, caption, and assistant reply has a Report button, and reports are reviewed by our trust & safety team.
7.4 AI features are optional and never required to use the core Service.
7.5 Your consent to third-party AI processing. AI features are opt-in. By choosing to start an AI feature and submitting your text or image to it, you consent to that specific input being shared with the relevant third-party AI provider named in Section 8 (for example, OpenAI or fal.ai) solely for that request. If you do not use these features, none of your data is shared with those providers. The Beauty AI photo editor additionally requires a separate, one-time in-app consent before any image is processed (see Section 6).
8. How we share data, and our service providers
8.1 How we share. We share personal information only as follows:
- With other users: your profile, public posts, reels, and public interactions are visible to other users and may be viewable by anyone, including outside the app.
- With service providers (operators / processors): the named providers below process data on our behalf, only for the purpose we instruct, under contract.
- For legal reasons: when required by law, court order, or to protect the rights, property, or safety of users, the public, or Integreet.
- In a business transfer: in connection with a merger, acquisition, or sale of assets, with notice to you where required.
8.2 We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising (see Section 9).
8.3 Equal protection. We require every third party with whom we share user data — including any analytics tools, third-party SDKs, and any parent, subsidiary, or related entity — to provide the same or equal protection of user data as stated in this Privacy Policy, and to use it only for the purposes we specify.
8.4 Named service providers (sub-processors)
- Supabase Inc. (United States / EU) — application hosting, PostgreSQL database, authentication, and file storage. Receives account data, profile content, posts, reels, messages, listings, and related records. This is our primary data store.
- BunnyWay d.o.o. — Bunny.net (Slovenia / EU, global CDN) — media storage, video streaming, and content delivery for images and videos, including photos you upload, Beauty AI source and result images, reel videos, and cover images.
- Cloudinary Ltd. (United States / EU) — media storage and delivery for certain images and videos and for legacy content. Receives the relevant media files.
- fal.ai, Inc. (United States) — image transformation for Beauty AI and generative photo features. Receives the source image you upload (which may include your face) for the duration of the transformation only, solely to produce the edited image. Does not use your image to train AI models, and does not perform facial recognition or create a faceprint.
- OpenAI, L.L.C. (United States) — the in-app assistant, caption suggestions, and content categorisation. Receives only the specific text or image you submit for the requested feature. Does not use API inputs to train its models.
- Sightengine S.A.S. (France / EU) — automated moderation of user photos and videos for nudity, child sexual abuse material, graphic violence, and weapons. Receives the media file briefly at upload so it can be classified before publishing.
- Agora.io, Inc. (United States) — real-time audio and video for live streaming and calls. Receives your audio/video stream while a session is active; streams are not stored by Agora, and any replay you save is stored on our media host.
- Yoco Technologies (Pty) Ltd (South Africa) — card payment processing on the web for marketplace listings, physical goods, event tickets, and digital goods (subscription plans, credits, and boost credits). Receives the payment amount, order reference, and the data Yoco needs to charge your card. We do not see or store full card numbers.
- Apple Inc. (United States) — on iOS, App Store in-app purchases (subscriptions, credits, boost credits) and "Sign in with Apple". Processes the purchase and returns a receipt and transaction status; for sign-in, returns your name and email or an Apple private relay address.
- Google LLC — Google Play Billing (United States) — on Android, in-app purchases. Returns the product identifier and a purchase token we use only to verify the purchase.
- RevenueCat, Inc. (United States) — validates in-app purchase receipts and manages subscription entitlements across Apple and Google. Receives a purchase receipt, product identifier, and an app-specific user identifier.
- Google LLC — Firebase Cloud Messaging (United States) — push-notification delivery. Receives your device push token and the notification payload.
- Google LLC — Sign in with Google (United States) — optional social sign-in. We receive your name, email, and profile picture from Google.
- Resend, Inc. (United States) — transactional email delivery (verification codes, receipts, account notices, password resets). Receives your email address and the email contents at send time.
- ipapi.co (IP geolocation) — converts an IP address into an approximate location so we can flag suspicious sign-ins. Receives an IP address only.
- Vercel Inc. (United States) — hosting and content delivery for our website. Processes standard web request data (including IP address) to serve the site.
8.5 We maintain this list and update it when our providers change. To request the current list, email support@integreet.com.
9. Selling, sharing, and California privacy rights
9.1 No sale or sharing. In the last 12 months we have not sold personal information and have not "shared" it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of anyone.
9.2 Purposes. We collect the categories in Section 3 for the business purposes in Section 5 (operating the Service, security and fraud prevention, personalisation, payments, safety and moderation, support, and legal compliance).
9.3 California rights. California residents may request to know, access, delete, and correct their personal information, opt out of any sale/sharing (we do neither), and limit the use of sensitive personal information, without discrimination. We honour Global Privacy Control (GPC) browser signals. To exercise these rights, use the channels in Section 15.
10. International data transfers
10.1 We are based in South Africa, and several providers in Section 8 process data in the United States, the EU, or other countries. This means your information may be transferred across borders.
10.2 Where required, we rely on approved transfer mechanisms — such as the EU Standard Contractual Clauses, adequacy decisions, and the POPIA Section 72 conditions for trans-border information flows — to ensure your information continues to be protected. You may request details of the safeguards that apply by emailing support@integreet.com.
11. Data retention and deletion
11.1 Retention. We keep personal information for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. Some records are kept longer where the law requires it — for example, transaction records for tax purposes, and reports of child sexual abuse material, which are retained and reported as required by law.
11.2 Deleting your account. You can delete your account at any time from within the app (Settings), or request deletion at our account-deletion page without signing in. Deleting your account removes your profile and content from the live Service, including your Beauty AI creations.
11.3 Backups and residual copies. Deleted data may persist for a short period in encrypted backups before being overwritten on our standard backup cycle, and content you shared with others (for example, a message another user received) may remain visible to them.
11.4 Exporting your data. You can request a copy of your data (see Section 15); our export includes your profile, posts, comments, reactions, follows, messages, and related records.
12. Security
12.1 We use encryption in transit (TLS), encryption at rest for sensitive fields, row-level security on our database, restricted staff access on a need-to-know basis, and payment processing through PCI-DSS-compliant providers so that we never handle full card numbers.
12.2 No system is perfectly secure. Please choose a strong, unique password and enable two-factor verification. You are responsible for keeping your login credentials confidential.
13. Data-breach notification
If a security compromise affects your personal information, we will notify the relevant supervisory authority (including South Africa's Information Regulator) and affected users as required by POPIA Section 22, GDPR Articles 33–34, and other applicable laws, and we will describe what happened and the steps you can take.
14. Automated decision-making and profiling
14.1 We use automated processing to rank your feed and recommendations, to detect fraud and suspicious sign-ins, and to automatically screen uploaded content for prohibited material (such as child sexual abuse material and nudity) before it is published.
14.2 Automated screening may block or restrict content that appears to violate our rules. These decisions do not produce legal effects on you, and you can appeal a moderation decision or contact us for a human review at support@integreet.com. We do not use automated decision-making that produces legal or similarly significant effects without a lawful basis and appropriate safeguards.
15. Your rights and how to exercise them
15.1 Depending on where you live, you have some or all of the following rights:
- Access a copy of the personal information we hold about you (GDPR Art. 15; POPIA §23).
- Correction / rectification of inaccurate information (GDPR Art. 16; POPIA §24).
- Deletion / erasure of your information, subject to records we must keep (GDPR Art. 17).
- Restriction of processing, and objection to processing based on legitimate interests or to direct marketing (GDPR Arts. 18, 21; POPIA §11(3)).
- Portability — receive your data in a portable format (GDPR Art. 20).
- Withdraw consent at any time, without affecting processing already carried out (GDPR Art. 7(3)). For AI features, you can stop using them and delete your creations at any time.
- Not be discriminated against for exercising your rights (CCPA/CPRA).
15.2 How to make a request. Use the tools in the app (Settings, and our account-deletion page for deletion), or email support@integreet.com. We may need to verify your identity. We respond within the timeframes required by law (generally within 30 days).
15.3 Complaints. You may lodge a complaint with a supervisory authority — in South Africa, the Information Regulator (see Section 20); in the EEA/UK, your local data-protection authority.
16. Children's privacy
16.1 Integreet is not directed to children under 13, and you must be at least 13 to create an account. Some features that involve payments or contracts (for example, the marketplace and paid subscriptions) require you to have legal capacity to transact under the law of your country.
16.2 We collect date of birth at sign-up and block accounts for anyone under the minimum age. If we learn we have collected personal information from a child under 13 without the required consent, we will delete it. Where a higher digital-consent age applies (for example, under the GDPR in certain EU member states, or POPIA Section 34 for children in South Africa), we apply that higher standard.
16.3 Our commitments against child sexual abuse and exploitation, the safeguards built into the platform, and how to report concerns are set out in our Child Safety Standards.
17. Cookies, SDKs, and tracking technologies
17.1 On our website we use cookies and similar technologies for session management, saving your preferences, and basic analytics. You can control cookies through your browser settings; disabling them may affect functionality.
17.2 In the app, we use standard mobile SDKs for the features described in this Policy (for example, push notifications and payments). We do not use third-party advertising networks or cross-app tracking, and we do not request permission to track you across other companies' apps and websites.
18. Region-specific notices
18.1 South Africa (POPIA). Integreet is the responsible party; our Information Officer is named in Section 2. Providing your information is generally voluntary, but some information is necessary to create an account or transact, and without it those features will not be available. You have the rights in Section 15 and may complain to the Information Regulator (Section 20). This Policy supports our obligations under the eight POPIA processing conditions, and a PAIA manual is available on request.
18.2 EEA / UK (GDPR). The controller is identified in Section 2; legal bases are in Section 5; transfer safeguards are in Section 10; your rights and the right to complain to your local authority are in Section 15.
18.3 California (CCPA/CPRA). See Section 9 for the categories we collect, our no-sale/no-share commitment, and your California rights.
19. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will notify you in-app or by email. The "Last updated" date at the top reflects the latest revision. Your continued use of the Service after a change takes effect means you accept the updated Policy.
20. Contact us and complaints
Integreet
Information Officer: James Ndou
1108 Copperleaf Country Estate, Mnandi, Centurion, Pretoria 0157, South Africa
Email: support@integreet.com
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za