SSFD card analytics: privacy statement
1. What this is
SSFD counts how often a digital business card is opened and which buttons on it are tapped. The point is to show the business whether the card is being used and which contact routes its customers use.
2. What we record, per event
- When: the time our server received it.
- Which card: an internal card reference.
- What happened: "card opened", or which button was tapped (call, WhatsApp, website…).
That's everything.
3. What we deliberately don't record
- No IP address, device, browser or location.
- No cookies, and nothing that recognises a returning visitor.
- No visitor phone numbers, names, messages or call content.
We don't know who a visitor is and can't work it out from this data. The figures are opens and taps, not people.
4. Why we collect it
- To show the client whether their card is used, and through which channels.
- To improve the card.
No advertising, no profiling. It's never sold, and never shared beyond the client it belongs to.
5. Whose information this is
- Visitors: nothing that identifies them is recorded.
- The card holder: a card belongs to a named person, so "how often this person's card was used" is information about them. Analytics is switched on for a card only with the card holder's written consent and the client business's agreement.
- The client business: POPIA also protects juristic persons, so a business's usage figures are its information. Each client sees only its own figures.
6. Who is responsible
- Responsible party: Christo van Schanke t/a SSFD. Information Officer: Christo van Schanke.
- Operator: Cloudflare runs the collector and stores the events for SSFD. As the host, Cloudflare handles visitors' network connections, including IP addresses, in transit; the collector itself doesn't store or log them.
- Access: SSFD reads the counts with a key held on SSFD's own computer. People with access to SSFD's Cloudflare account can also see the stored events.
7. Where it's stored
- Cloudflare's database (D1), restricted to the European Union. The data is stored outside South Africa (Cloudflare's database has no African region), in the EU, under the EU's data-protection law (GDPR).
- A summary on SSFD's computer. It holds daily counts per card and per action, plus the time of the most recent event and the time of the last update. It's replaced on every update.
8. How long we keep it
- Individual events: 13 months, then deleted automatically every day. 13 months allows a year-on-year comparison.
- No long-term totals are kept.
- On request: a client or card holder can ask us to stop analytics for their card and delete its data. We delete that card's events, remove the card from the approved list, and refresh the summary.
9. Security
- Events are accepted only for approved cards, and events from other websites are rejected.
- Reading the counts needs a secret key held only by SSFD.
- We don't store visitor data, so the events we keep contain nothing that identifies a visitor.
Talk to us