Distinct-app Privacy Notice
Last updated: 18 August 2026
Who this notice covers
This notice explains how the Distinct-app platform — DNF Financial Services (Pty) Ltd (Companies and Intellectual Property Commission (CIPC), registration 2025 / 778485 / 07) — handles personal information across its apps (Distinct-app business applications such as Rental Ease, Event Hub, and the rest of the platform). It is a company-level notice; an individual app may publish a shorter, app-specific notice for details unique to it, which this notice sits behind, not replaces. DareToFish, run by the same company, is a separate consumer product with its own notice at daretofish.com.
Our roles
Depending on the app and the information involved, Distinct-app acts in different roles:
- When a business uses a Distinct-app app to manage its own customers, staff or bookings, that business is the Responsible Party for that information under POPIA, and Distinct-app is an Operator processing it on the business's behalf and instruction.
- For account, billing, security, platform administration, and information collected directly by Distinct-app for its own purposes (such as who has a login, or platform usage logs), Distinct-app is itself the Responsible Party.
Categories of information
Depending on which app you use, we may process:
- Names, surnames, email addresses, telephone numbers
- Account and business information (login, role, business name)
- Booking, rental, event, and ticket information
- Transaction references, payment status, and invoices (never full card numbers)
- Employee/staff information, where an app is used for staff management
- Marketing preferences and communications
- Support enquiries
- IP address and device information, and security logs
- Location information, where an app's function requires it (e.g. venue locations)
- Uploaded files and photos, where an app's function requires it
- General usage information about how an app is used
Not every app processes every category above — see an individual app's own Privacy Notice for what it actually collects.
Why we process it, and on what basis
We do not treat every use of your information as consent-based. Depending on the purpose:
- Performance of a contract — creating your account, running a booking, rental, or ticket purchase you asked for, invoicing, and customer support are necessary to provide the service you requested.
- Legal obligation — accounting records, tax-related information, and responding to lawful requests from authorities.
- Legitimate interest — security monitoring, fraud prevention, and keeping the platform working reliably, balanced against your rights.
- Consent — direct marketing communications specifically.
Marketing vs. transactional communications
A booking confirmation, receipt, waiver copy, security notice, or other message needed to deliver a service you requested is a transactional communication and is never conditional on marketing consent. Direct marketing — special offers, newsletters, event news — is sent only if you've actively opted in; that box is never pre-ticked, and opting in to one business's marketing does not opt you in to another business's marketing, or to Distinct-app's own marketing. You can withdraw consent at any time via the Data Request form.
Sharing information
We share information with service providers who help run the platform (hosting, database, storage, payments, email/SMS delivery) under appropriate instructions, with the relevant business you're transacting with, where required by law, or with your consent. See the Subprocessors page for the current list of providers.
International transfers
Some of our service providers process or store information outside South Africa. Confirmed examples include Supabase (database, authentication and file storage — hosted in Sweden) and Resend (outbound email — processed in the United States); a shared file-storage bucket is also hosted in Western Europe. We have not yet confirmed the specific hosting region for every provider we use — see the Subprocessors page for the current status of each. Where information crosses borders, we apply appropriate safeguards under POPIA section 72. If you are in the EU/EEA or UK, note that POPIA compliance does not by itself mean GDPR or UK GDPR compliance — see the app-specific notice or contact us for details relevant to your jurisdiction.
Retention
We keep information for as long as needed to provide the service, meet accounting and legal obligations, and resolve disputes, then delete or anonymise it. See the Data Retention Schedule for the current, category-by-category detail.
Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or outdated information
- Request deletion of information, where legally possible
- Object to processing
- Withdraw consent, including for marketing, at any time
- Complain to us, and if unresolved, to South Africa's Information Regulator
Submit any of these requests through our Data Subject Request form.
Security
We take reasonable technical and organisational safeguards to protect personal information, appropriate to the sensitivity of what we hold. We do not claim specific certifications, encryption standards, or audit outcomes here unless we can back them up — see our internal security-verification notes if you need specifics as a business customer.
Contact and Information Officer
For privacy questions or to exercise your rights, contact privacy@distinct-app.com. Our Information Officer is registered with the Information Regulator — see the Legal hub for the current published contact details.