Privacy policy
Last updated 30 August 2026
This policy explains what Intwined does with personal information: what we collect, why, who sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
Who we are
Intwined (Pty) Ltd operates Intwined, a South African platform with two sides: a public marketplace where anyone can discover local businesses, and a private workspace where those businesses run their operations.
We are the responsible party for personal information collected through the marketplace and for the accounts of businesses using the workspace. Where a business uses Intwined to manage its own customers, staff and records, that business is the responsible party for the information it puts in, and we act as its operator under the Protection of Personal Information Act, 2013 (POPIA).
Information we collect
What we hold depends on how you use the platform.
- Browsing the marketplace: no account is required and we do not ask you to create one. We record anonymous daily view counts per storefront. These are totals, not profiles, and are not linked to you.
- Messaging a business: when you contact a business without an account we collect your name, email address, phone number and the message you write, so the business can reply. This is passed to that business and to no one else.
- Business accounts: name, email address, and a hashed password. We never store passwords in a readable form.
- Business profile: trading name, category, description, city, storefront copy, brand colours, logo and banner images, and the products and services published to the storefront.
- Operational records a business chooses to enter: customers, quotes, invoices, payments, bookings, orders, jobs, stock, suppliers, staff records and uploaded documents.
- Technical records: session cookies to keep you signed in, a CSRF token cookie to protect form submissions, and an audit log of significant actions taken inside a business workspace.
Why we use it
- To show the marketplace and let people find and contact local businesses.
- To deliver an enquiry to the business it was addressed to.
- To operate business workspaces and keep each business's data separate from every other business's.
- To authenticate users, protect accounts, and investigate abuse or fraud.
- To keep an audit trail of consequential actions, which we need for security and for resolving disputes.
- To communicate about the service itself, such as verification and password reset emails.
What we do not do
- We do not sell personal information.
- We do not build advertising profiles, and we do not run third-party advertising or tracking scripts on the marketplace.
- We do not read the contents of a business's records to market to their customers.
- We do not require a customer account to browse or to contact a business.
How long we keep it
Enquiries sent to a business are kept for as long as that business keeps them, since they form part of that business's customer records. Business account and operational records are kept while the account is active, and for a period afterwards where tax or company law requires it. Audit records are kept for security purposes. You may ask us to delete information sooner and we will do so unless we are legally required to keep it.
Your rights
Under POPIA you may:
- Ask what personal information we hold about you and request a copy.
- Ask us to correct anything inaccurate or incomplete.
- Ask us to delete information we no longer have grounds to keep.
- Object to a particular use of your information.
- Complain to the Information Regulator of South Africa if you believe we have handled your information unlawfully.
Security
- Passwords are hashed, never stored in a readable form.
- Sessions use signed, HTTP-only cookies, and form submissions carry a CSRF token.
- Uploaded files are checked against their actual file signature, not just their filename, so a disguised file is rejected.
- Every workspace request is checked against the tenant it belongs to, so one business cannot read another's records.
- Consequential actions inside a workspace are written to an audit log.
- No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator as POPIA requires.
Cookies
We use only the cookies the service needs to function: one to keep you signed in, and one to protect forms against cross-site request forgery. We do not use advertising or analytics cookies, so there is no tracking to opt out of.
Children
The platform is intended for people running or buying from businesses. We do not knowingly collect information from children under 18 without the consent of a parent or guardian. If you believe we have, contact us and we will remove it.
Changes to this policy
If we change this policy we will update the date at the top, and where the change is significant we will tell account holders directly before it takes effect.