Skip to main content
Back to StuConnectStuConnect — Students Connect

Protection of Personal Information Act 4 of 2013

POPIA Privacy Notice

Version 1.0.0 · Effective 29 September 2026 · Applies to StuConnect — Never walk alone. Never pay the full Price. Students Connect.

StuConnect matches students who are walking the same route at the same time, and lets them rent gear from each other. Both of those need a real identity and a real meeting point, so this notice is specific about what is held, who can see it, how long it stays, and what you can make us do about it.

By ticking the acknowledgement during sign-up and creating a profile you consent to the processing described here. The app records that consent as an instant and a version number on your profile record — the wording below is version 1.0.0, never “the current notice”, so a later revision cannot silently re-consent you. Consent is not the only basis relied on, and section 3 says where it is not.

1. Who is responsible, and who to ask

StuConnect is the responsible party for the personal information described in this notice. It is a student utility open only to holders of a verified institutional address (@myuct.ac.za); it is not affiliated with, and does not act for, the university.

A request, a question or an objection is raised through the trust & safety controls inside the app — the report control on any conversation, or the account controls on your profile page. Every one of those routes is bound to your verified institutional address and your signed-in session, so a request can only ever be made by the student it concerns, and it cannot be spoofed by a third party claiming to be you.

If something is happening right now, or someone is in danger, do not use the app to report it: call Campus Protection Services on 080 650 2222. The SOS control in StuConnect dials that line after a three-second hold.

2. What is collected

To prove you are a student. Your institutional email address, and the six-digit code that proves you control it. The code is stored only as a SHA-256 hash, never as the digits themselves.

To let other students recognise you. Your display name, your gender as recorded on your profile, an optional campus residence, your primary campus zone, and a profile photograph taken with the in-app camera while you are signing up. The camera is the only way a photo can reach a profile — there is no file picker anywhere in the product, because a stock photo or a screenshot of somebody else is exactly how identity spoofing starts.

To run an exchange between two students. What you list (title, description, category, condition, rates, zone and meeting point), what you request, which walk route and departure window you publish, and the state of each handshake. Conversations between the two parties to an exchange are stored as text, and the 3-digit handshake codes are stored as one-way hashes — the readable code exists only in the offline vault on the device that has to read it aloud.

To keep the community safe and to settle disputes. Endorsement tags and the resulting reliability score, safety reports, the resulting strikes and any category lock, and the version of the Campus Safety Code (currently v1.0.0) you accepted.

What is never collected: live GPS or a pin-drop location, your phone number, your identity or student number, your bank details, and any photograph or file inside a conversation. Payments are settled directly between two students — StuConnect never holds money or sees a payment credential — and messaging is text-only precisely so that no image can be passed or intercepted.

3. Why it is processed, and what makes that lawful

Two purposes rest on your consent: creating and maintaining your profile, and connecting you to the other party in an exchange you chose to enter. You may withdraw that consent at any time, and withdrawing it means deleting the account (section 6) — there is no version of this product that works without an identity.

Three purposes rest on a legitimate interest that a student joining a safety product would reasonably expect us to pursue: verifying that an account belongs to a real member of the institution; matching walkers and enforcing the safety rules (reports, strikes, category locks and the reliability score); and preventing abuse by students who would create a second account to escape a penalty. That last one is why a deleted account does not erase the standing held against its address, and it is stated in section 5 rather than implied.

Reports escalated to Campus Protection Services, and the record of a ban, are processed because a law or a lawful request from an authority requires it. Nothing here is ever used to build an advertising profile, and personal information is never sold, rented or traded.

4. Who can see it

Access is decided by row level security policies inside the database, not by the interface. In practice that means:

  • Other students see the parts of your profile an exchange needs: your name, your photo, your reliability score, your campus zone, and the route or meeting point of the items and walks you published. They never see your email address, your residence, your reports, your strikes, or any conversation you were not a party to.
  • The other party to an exchange sees the conversation thread that exchange created, and nothing else of yours. A profile is confirmed to both sides only once both have opted in.
  • Nobody else. There is no cross-student search, no follower graph, no public list of members, and no data API role that can read a profile directly — every API route runs with reduced privileges and resolves each row against the signed-in student.

Two service providers process personal information on StuConnect's instructions, under contract and for no purpose of their own: Supabase (database, authentication, realtime and storage — the project's system of record) and Resend (delivery of the one-time code email). Profile photographs live in the project's own storage bucket inside a folder named after your user id, with public read — a photograph nobody could view would defeat its purpose — and write access limited to your own folder.

5. How long it is kept

Nothing is kept merely because storage is cheap. An hourly sweep and a daily purge run inside the database, so the windows below hold even if no application request arrives.

Retention windows enforced by StuConnect's database sweeps
InformationKept for
One-time verification codesDeleted 24 hours after they expire (a code itself lives 10 minutes)
3-digit handshake codesDeleted the moment they are used, and at expiry if they never are
Marketplace listingsExpire after 7 days; the row is deleted 30 days after that
Walk requestsClose 2 hours after the departure window; deleted 30 days after that
Conversations between two studentsDeleted 14 days after the exchange they belong to ends
Endorsements and reliability scoreKept while the account is open — this is the trust record other students rely on
Safety reports and strikesKept while an account is open. An adjudicated report is deleted 12 months after it is filed; a report escalated to Campus Protection Services is retained as the law-enforcement record it is
A deleted accountPersonal information, listings, walks, conversations, endorsements and the profile photo are erased in one request. The reliability standing held against the institutional address is retained, and disclosed below, because deleting an account must not launder a ban

Deleting an account removes the profile, its photograph, its listings, its walks, its conversations, its endorsements and its reports from the live database in one request. Two things survive that deletion, and only two: the standing held against the institutional address (score, flags, ban), so that a ban cannot be shed by signing up again with the same address, and safety reports already escalated to Campus Protection Services, which are the record of a matter handed to a law-enforcement authority.

6. Your rights, and how to use them

Under POPIA you may ask what personal information is held about you (section 23), ask for it to be corrected or deleted (section 24), object to processing (section 11(3)), and complain to the Information Regulator (South Africa), whose contact details are published by the Regulator itself.

  • See and correct it. Your profile page shows every field held about you and lets you edit all of them, and your inbox shows every exchange you are a party to. Nothing about you is stored in a place you cannot open.
  • Delete it. “Delete my account” on the profile page erases the account after showing you exactly what goes and what is retained, and after re-proving the request against your password or your address. It is deliberately rate-limited, so nobody can be walked into a deletion loop.
  • Object to it. Objecting to the safety processing described in section 3 while keeping the account is not something this product can offer, because matching two strangers in the dark without it would be unsafe for both. The honest alternative is deletion, and that is offered instead.
  • Withdraw consent. Consent is withdrawn by deleting the account; there is no partial state in which a profile exists but may not be used to identify its owner to the other party in an exchange.

7. How it is protected

Every table is protected by row level security, and each API route re-proves ownership against the signed-in session before it reads or writes a row, so a request naming somebody else's record is refused in the database rather than in the interface. Incoming payloads are validated and stripped of any field the client is not entitled to send, which is what stops a crafted request from granting itself a badge or removing a ban from its own record.

One-time codes, handshake codes and passwords are never stored in a readable form: codes and PINs are hashed, and passwords are handled by the authentication service. Sensitive endpoints are rate-limited per account and per address, so the routes that disclose or change something cannot be walked through at speed.

The offline vault on your device is deliberately smaller than the database. It holds the title, the counterparty label, the meeting point and the 3-digit code of the handshakes you are currently part of; each record is signed with a key generated on that device and stored non-extractably, and the whole vault is wiped when you sign out. A record edited in developer tools fails its signature check and is deleted rather than displayed.

The acknowledgement you make

During sign-up, and again whenever this notice's version changes, the app asks you to accept exactly one sentence:

“I have read the POPIA Privacy Notice and consent to how StuConnect processes my personal information”

Version 1.0.0, effective 29 September 2026. It is stored on your profile as a timestamp plus this version number, so the wording you agreed to can be reproduced exactly.