Light Background
Table of Contents

PRIVACY POLICY

ACUITY INNOVATIONS (Pty) Ltd, trading as KourtKulture

Effective: 1 January 2026Last Updated: 30 December 2025

1. INTRODUCTION

ACUITY INNOVATIONS (Pty) Ltd, trading as KourtKulture (“KK”, “we”, “us”, “our”), is committed to protecting your personal information and your right to privacy.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform — including the KourtKulture iOS app, Android app, and web platform at kourtkulture.co.za — in compliance with the Protection of Personal Information Act, 4 of 2013 (POPI Act).

By using KourtKulture, you consent to the data practices described in this policy.

2. INFORMATION OFFICER

In accordance with the POPI Act, we have appointed an Information Officer responsible for ensuring compliance with data protection laws:

Information Officer: Michael Bezuidenhout

Email: info@kourtkulture.co.za

Phone: 082 877 7084

Address: 11 Fick Street, Upington, 8801, South Africa

3. INFORMATION WE COLLECT

3.1 Personal Information You Provide

We collect information that you voluntarily provide when you:

  • Register for an account
  • Subscribe to a membership tier
  • Make purchases in the KourtKulture shop
  • Participate in leagues and matches
  • Contact us for support
  • Apply to become a partner court

This information includes:

  • Identity Information: Name, username, date of birth
  • Contact Information: Email address, phone number, physical address
  • Payment Information: Credit/debit card details (processed securely by PayFast for web subscriptions; iOS and Android payments are processed by Apple Inc. and Google LLC respectively via their app stores — we do not receive or store your card details for in-app purchases)
  • Profile Information: Profile picture, player level, preferred courts, location
  • Activity Information: Match history, league participation, court bookings, referrals
  • Shop Information: Purchase history, shipping addresses, product preferences

3.2 Information Automatically Collected

When you use our platform, we automatically collect certain information:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages and screens viewed, features used, time spent on platform, tap and click patterns
  • Location Data: Precise GPS location when you use the court discovery map feature (permission requested at runtime and can be revoked at any time in your device settings). Approximate geographic location based on IP address for all other features.
  • Error and Performance Data: Crash reports and performance metrics collected via Sentry to help us identify and fix technical issues
  • Analytics Data: Anonymised usage events collected via PostHog to help us understand how features are used and improve the platform
  • Cookies and Tracking: See Section 10 for details

3.3 Information from Third Parties

We may receive information from:

  • Apple Sign In: If you sign in with Apple, we receive your name (if shared) and email address (or Apple-relayed email address)
  • Google Sign In: If you sign in with Google, we receive your name, email address, and profile picture
  • PayFast: Payment confirmation and transaction details for web subscriptions
  • Apple App Store / RevenueCat: Subscription status and entitlement confirmation for iOS in-app purchases
  • Google Play Store / RevenueCat: Subscription status and entitlement confirmation for Android in-app purchases
  • Partner Courts: Match results and booking confirmations

4. HOW WE USE YOUR INFORMATION

We process your personal information for the following purposes:

4.1 Account Management

  • Create and maintain your account
  • Verify your identity and email address
  • Provide customer support
  • Send important account notifications

4.2 Loyalty Program Administration

  • Allocate Kredits based on your membership tier
  • Track Points earned from activities
  • Process Rewards and Voucher redemption
  • Verify match results and league participation
  • Calculate XP levels and player rankings

4.3 Payments and Subscriptions

  • Process shop orders and payments via PayFast
  • Process iOS subscription payments via Apple App Store
  • Process Android subscription payments via Google Play Store
  • Manage subscription status via RevenueCat
  • Fulfill orders and arrange shipping
  • Handle refunds and returns
  • Prevent fraud and unauthorized transactions

4.4 Service Improvement

  • Analyze usage patterns via PostHog to improve features
  • Monitor errors and crashes via Sentry to maintain stability
  • Conduct research and analytics
  • Develop new features and services
  • Test and troubleshoot technical issues

4.5 Marketing and Communications

  • Send newsletters and promotional emails (with your consent)
  • Notify you about new features, rewards, and events
  • Conduct surveys and request feedback
  • Display personalized content and offers

4.6 Legal Compliance and Safety

  • Comply with legal obligations (POPI Act, tax laws, court orders)
  • Enforce our Terms and Conditions
  • Protect against fraud, abuse, and security threats
  • Resolve disputes and investigate complaints

6. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information. We may share your data with:

6.1 Service Providers

  • PayFast — Payment processing for web subscriptions (PCI-DSS compliant)
  • Apple Inc. — iOS in-app purchase processing
  • Google LLC — Android in-app purchase processing
  • RevenueCat — Subscription management and entitlement verification for iOS and Android
  • Resend — Email delivery service
  • Neon Database — Secure cloud database hosting
  • Vercel — Website and API hosting and infrastructure
  • Sentry — Error and crash reporting (anonymised device and error data)
  • PostHog — Product analytics (anonymised usage data)
  • Apple Sign In — Authentication service
  • Google Sign In — Authentication service

All service providers are contractually bound to protect your data and use it only for specified purposes.

6.2 Partner Courts

  • Share your username and voucher codes for redemption verification
  • Share match results submitted by court staff
  • Share booking details for court reservations

6.3 Legal Requirements

We may disclose your information if required by law:

  • Court orders or subpoenas
  • Law enforcement requests
  • Tax authorities (SARS)
  • Consumer protection agencies

6.4 Business Transfers

If KK is involved in a merger, acquisition, or sale of assets, your information may be transferred to the new entity. You will be notified via email before any such transfer.

6.5 With Your Consent

We may share your information for other purposes with your explicit consent (for example, featuring you in marketing materials).

7. DATA RETENTION

We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy.

Data TypeRetention Period
Account InformationUntil account deletion + 1 year (legal claims)
Payment Records7 years (tax law requirement)
Shop Orders7 years (Consumer Protection Act)
Match HistoryUntil account deletion (or anonymised)
Marketing ConsentUntil opt-out + 6 months
Support Tickets3 years from resolution
Error and Analytics Data90 days (Sentry and PostHog rolling window)
iOS/Android Subscription Records7 years (financial records)

After the retention period, we securely delete or anonymise your data.

8. DATA SECURITY

We implement industry-standard security measures to protect your information.

8.1 Technical Safeguards

  • Encryption: HTTPS/TLS encryption for all data transmission
  • Database Security: Encrypted data storage via Neon Database (SOC 2 Type II compliant)
  • Password Protection: Bcrypt hashing for password storage
  • Access Controls: Role-based access (members and admins only)
  • Payment Security: PCI-DSS Level 1 compliance via PayFast. We do not store credit or debit card details. iOS and Android payments are handled entirely by Apple and Google respectively.
  • Mobile Security: In-app purchase receipt validation via RevenueCat

8.2 Organisational Safeguards

  • Employee training on data protection
  • Limited access to personal data on a need-to-know basis
  • Regular security audits and vulnerability assessments
  • Incident response procedures for data breaches

8.3 Data Breach Notification

If a data breach occurs that is likely to result in a high risk to your rights and freedoms, we will:

  • Notify the Information Regulator within 72 hours
  • Notify affected users via email without undue delay
  • Provide details about the breach, data affected, and remedial actions taken

9. YOUR RIGHTS UNDER THE POPI ACT

You have the following rights regarding your personal information:

9.1 Right to Access

Request a copy of all personal data we hold about you.

How to exercise: Email info@kourtkulture.co.za — Subject: “Data Access Request”

9.2 Right to Correction

Request correction of inaccurate or incomplete data.

How to exercise: Update your profile in the app, or email us with corrections.

9.3 Right to Deletion (Right to be Forgotten)

Request deletion of your data where:

  • Data is no longer necessary for the purpose collected
  • You withdraw consent and there is no other legal basis for processing
  • Data was unlawfully processed

Limitations: We may retain data required by law (tax records, legal claims).

How to exercise: Settings → Account → Delete Account, or email info@kourtkulture.co.za — Subject: “Data Deletion Request”

9.4 Right to Object to Processing

Object to processing based on legitimate interests or for direct marketing.

How to exercise: Email info@kourtkulture.co.za or unsubscribe from marketing emails.

9.5 Right to Data Portability

Request your data in a structured, machine-readable format (JSON).

How to exercise: Email info@kourtkulture.co.za — Subject: “Data Portability Request”

9.6 Right to Restrict Processing

Request restriction of processing (for example, while we verify data accuracy).

How to exercise: Email info@kourtkulture.co.za with details.

9.7 Right to Withdraw Consent

Withdraw consent at any time for marketing emails, location access, or cookies.

How to exercise: Click “Unsubscribe” in emails, revoke location permission in device settings, or adjust cookie preferences.

9.8 Right to Lodge a Complaint

If you believe we are not complying with the POPI Act, lodge a complaint:

Information Regulator (South Africa)

Website: www.justice.gov.za/inforeg/

Email: inforeg@justice.gov.za

Phone: 012 406 4818

Response Time: We will respond to all requests within 30 days. We may request identity verification before processing requests.

10. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies to enhance your experience.

Types of cookies we use:

  • Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
  • Analytics Cookies: Track anonymised usage patterns (PostHog) to improve services.
  • Performance Cookies: Capture error and crash data (Sentry) to maintain stability.
  • Preference Cookies: Remember your settings such as theme and language.

You can manage cookie preferences in your browser settings or via our Cookie Consent banner. Disabling non-essential cookies will not affect core platform functionality.

11. CHILDREN'S PRIVACY

KourtKulture is not intended for children under 18 without parental consent.

We do not knowingly collect data from children under 18 without parental or guardian consent. If we discover we have collected data from a child without consent, we will delete it immediately. Parents and guardians can contact us at info@kourtkulture.co.za to request deletion of a child's data.

12. INTERNATIONAL DATA TRANSFERS

Your data is primarily stored in South Africa. Some service providers store data internationally:

  • Neon Database — Data centers in USA and EU (SOC 2 Type II compliant)
  • Vercel — Global CDN infrastructure (GDPR compliant)
  • Resend — Email servers in USA (GDPR compliant)
  • Sentry — Error data servers in USA (GDPR compliant, data processing agreement in place)
  • PostHog — Analytics servers in EU (GDPR compliant, EU Cloud option used)
  • RevenueCat — Subscription data servers in USA (SOC 2 Type II compliant)

All international transfers comply with POPI Act requirements for cross-border data flows with adequate safeguards in place.

14. MARKETING COMMUNICATIONS

14.1 Opt-In

We will only send marketing emails if you have opted in via the checkbox during signup or in account settings.

We may also contact you via WhatsApp for marketing communications where you have provided your phone number and consented to receive such messages. You can opt out by replying STOP to any WhatsApp message or updating your preferences in Settings → Notifications.

14.2 Content

Marketing emails may include:

  • New features and platform updates
  • Exclusive rewards and promotions
  • League announcements and events
  • KourtKulture shop sales and new products

14.3 Opt-Out

You can unsubscribe at any time:

  • Click the “Unsubscribe” link in any marketing email
  • Update preferences in Settings → Notifications
  • Email info@kourtkulture.co.za — Subject: “Unsubscribe”

Note: Unsubscribing from marketing emails does not affect transactional emails such as order confirmations and account security alerts.

15. AUTOMATED DECISION-MAKING

We use automated systems for certain processes:

15.1 Kredits Allocation

Monthly Kredits are allocated automatically based on your membership tier. No human intervention is required for standard allocations.

15.2 Points and XP Calculation

Points are calculated automatically based on verified activities. XP levels are updated via algorithm after each qualifying event.

15.3 Subscription Management

Subscription status is verified automatically via RevenueCat on app launch and in the background. Entitlement changes (upgrades, renewals, cancellations) are applied automatically without human intervention.

15.4 Fraud Detection

Automated systems flag suspicious activity such as duplicate accounts and unusual voucher usage. Flagged accounts are reviewed by human admins before any action is taken.

You have the right to request human review of any automated decision that significantly affects you.

16. HOW TO EXERCISE YOUR RIGHTS

To exercise any of your POPI Act rights, contact us:

Email: info@kourtkulture.co.za

Subject Line: Specify the request type (e.g., “Data Access Request”, “Data Deletion Request”)

Include: Your full name, email address, username, and details of your request

Verification: We may ask for proof of identity before processing requests.

Response Time: We will respond within 30 days of receiving your request.

Fees: Requests are generally free. A reasonable fee may apply for excessive or repetitive requests.

17. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our data practices, new features or services, or legal and regulatory requirements.

For material changes, we will:

  • Update the “Last Updated” date at the top of this page
  • Send an email notification to registered users
  • Display a notice in the app for 30 days

Continued use of KourtKulture after the updated policy takes effect constitutes acceptance. If you do not agree, you may delete your account before the changes take effect.

INFORMATION OFFICER (POPI ACT)

Michael Bezuidenhout

ACUITY INNOVATIONS (Pty) Ltd

Email: info@kourtkulture.co.za

Phone: 082 877 7084

Address: 11 Fick Street, Upington, 8801, South Africa

By using KourtKulture, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.