What this policy covers.
This policy explains how personal information is collected, used, shared, stored, and protected on the Kultiflo platform — the Admin Portal, Point of Share, Farmer Hub, and Front Desk applications — and on this website, kultiflo.com. It is written to meet the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”).
When you register at a club, you are asked for four consents: the Terms & Conditions, this Privacy Policy, data processing, and (optionally) marketing communications. The data-processing consent is described in the dedicated Data Processing Notice and the marketing consent in the Marketing Consent Notice; this policy is the full account both of them rest on.
Who is responsible for your information.
Your club is the responsible party for the personal information it collects about its members and day-pass visitors. The club decides who to admit, what it needs from you, and how long it keeps your membership records.
Kultiflo is the operator — we process that information on the club's behalf, on its instructions, under a written agreement, and only for the purposes described in this policy. POPIA requires an operator to process personal information with the responsible party's authorisation and to secure it; that is the role we hold for member data.
Kultiflo acts as the responsible party in its own right for the account information of club staff and farmers who hold platform accounts, and for any information you send us directly — for example, by emailing hello@kultiflo.com.
What we collect.
Members and day-pass visitors
- Identity — first name, surname, and your South African identity number or passport number. Your date of birth is read from your SA identity number to verify that you are 18 or older.
- Identity documents — a photograph of your identity document and a profile photograph, captured during registration; and your digital signature, captured at day-pass sign-in.
- Contact details — email address and phone number.
- Membership records — your club, membership number, role (member or day pass), application status, joining date, validity dates, and for day passes the name of the member accompanying you.
- Sharing transactions — what was shared with you at the Point of Share, when, the amounts involved, and the payment method, kept as part of the club's transaction and audit record.
Club staff and farmers
- Account details — name, surname, email, phone number, identity number, profile photograph, role, and approval status.
- Farmer details — cultivation licence number, years of experience, and the location (coordinates and place name) of the growing operation, used for consignment and settlement records.
- Settlement records — consignments, stock sold, amounts paid and outstanding.
Device and technical data
- Error reports — when something fails in the apps, the error, where it occurred, and the identifier and name (or email address) of the person most recently signed in on that device; see § 7.
- Usage analytics — screens viewed and session information, linked to your account identifier.
We do not collect biometric templates (no fingerprint or face data is stored by the platform), and we do not track your location as a member — location data exists only where a farmer registers a growing operation or a club records its address.
Why we process it.
Personal information on the platform is processed for these purposes, each resting on a lawful basis under POPIA:
- Age and identity verification — confirming you are 18 or older and that your identity document matches your registration. With a South African identity number your age is read from the number automatically; with a passport, the platform cannot read your date of birth, and confirming your age is your club's responsibility. Basis: legal obligation and the club's legitimate interest in lawful operation.
- Membership administration — maintaining the club's membership register, approvals, renewals, day passes, and check-ins. Basis: performance of your membership agreement with the club, and consent.
- Sharing and settlement records — recording transactions at the Point of Share, reconciling cash-ups, and settling farmers, with an audit trail. Basis: contract, legal obligation (financial and tax records), and legitimate interest.
- Operational communication — service messages about your membership, such as approval or expiry notices. Basis: performance of the membership agreement.
- Marketing communication — only if you opted in; see § 6. Basis: consent, which you may withdraw at any time.
- Security and fault-fixing — protecting accounts, investigating misuse, and diagnosing crashes. Basis: legitimate interest.
We do not use personal information for any purpose beyond these. In particular: we never sell it, never use it for third-party advertising, and never train AI models on it.
Consent at registration.
When you register as a member, four consents are recorded against your profile. The registration screen links each one to the document it refers to:
The first three are required to register, because the platform cannot maintain a lawful membership register without them. Marketing consent is voluntary and registration does not depend on it. You may withdraw any consent by contacting your club or emailing hello@kultiflo.com; withdrawing the consents the membership register depends on may mean your club can no longer maintain your membership.
Marketing communications.
If — and only if — you ticked the marketing consent at registration, your club may send you news and offers about the club: events, new products available for sharing, and membership notices. These may reach you by email or message from your club using the contact details you provided.
You can opt out at any time by telling your club's front desk, or by emailing hello@kultiflo.com, and the marketing flag on your profile will be turned off. Opting out never affects your membership or the service messages your membership requires.
Who we share it with.
Your information is shared only with the service providers (operators under POPIA) the platform needs to run:
- Google Cloud / Firebase — authentication, database, file storage (identity photographs and signatures), app usage analytics (Google Analytics for Firebase, linked to your account identifier), app-integrity checks (Firebase App Check, which uses Google reCAPTCHA in the web apps), and configuration. This is the infrastructure the entire platform runs on.
- Algolia — search indexing, so that club catalogues, platform user accounts and club membership registers are searchable.
- Google Maps — location services for club and farm locations. Addresses typed into the location search are passed to Google through a relay function hosted on Google Cloud in the United States.
- Peach Payments — processes online payments: club subscription billing and, where they are available at your club, your own membership subscription and online orders. Peach receives the payer's name, email address and mobile number. Card details are entered on Peach's own secure payment page and are never held by Kultiflo. Payments you make in person at the Point of Share (cash or card) are processed by your club, not by Kultiflo; we record the transaction, not your card details.
- SendGrid (Twilio) — delivers Kultiflo's email. Most of it goes to clubs: subscription invoices and payment receipts, some sent automatically — an invoice on a monthly schedule, and a receipt when a payment is recorded. Where your club makes your own membership subscription available to you, SendGrid also delivers one service message to you: a notice that your membership has lapsed, sent if the payment for it cannot be collected. SendGrid receives each recipient's email address and the contents of the message — for a club, that can include the club's name, its contact person's name and the club's address; for you, your email address, your first name, your club's name, the name of your membership plan and the amount that could not be collected — and keeps a log of each send, which can include whether a message was opened or a link in it followed.
- Discord — receives automated error reports from the apps, so that faults can be traced and fixed. Each report contains the error message and technical details of where it occurred, together with the user identifier and display name — or, where no name is recorded, the email address — of the person most recently signed in on that device. Reports are sent directly from the device, so Discord also receives its IP address.
Beyond these operators, personal information leaves the platform only when the law compels it — a court order, or a lawful demand by a public authority — or with your consent.
Where it is stored.
The platform's database, and the file storage that holds identity-document photographs and signatures, are hosted on Google Cloud in South Africa (Johannesburg).
Some personal information is stored or processed outside South Africa. The platform's server-side functions, including the process that keeps the search index up to date, run on Google Cloud in the United States; other Google services the apps use, including sign-in, app analytics and app-integrity checks, may also process information outside South Africa; and some of the operators listed in § 7 — among them Algolia, which holds the search index, SendGrid (Twilio) and Discord — are based outside South Africa. Where personal information is transferred across borders — to Google Cloud or to any operator in § 7 based outside South Africa — it remains protected as POPIA section 72 requires: each operator is contractually bound to safeguards that uphold a standard of protection substantially similar to POPIA, which for Google Cloud include its data-processing terms and certifications such as ISO 27001 and ISO 27018.
How it is secured.
In summary: every connection is encrypted in transit with TLS 1.2+, all stored data is encrypted at rest with AES-256, access in the apps is gated by role, and POS voids, stock removals and settlement payments are written to an audit trail.
The full account of how the platform protects member data is published on our Security page. If we ever have reason to believe personal information has been accessed by an unauthorised person, we will notify the Information Regulator and the affected data subjects as POPIA section 22 requires.
How long we keep it.
Membership records are kept for as long as your membership with the club is active, and thereafter only as long as the club needs them to meet its legal obligations. Transaction, settlement, and financial records are retained for the periods South African law prescribes for accounting and tax records, even after a membership ends.
When records are no longer required, they are deleted or de-identified. You may request deletion at any time under § 11 — we will honour it except where a law requires the record to be retained, and in that case we will tell you which law and for how long.
Your rights under POPIA.
As a data subject you have the right to:
- Access — ask whether we hold personal information about you, and request a copy of it (also under the Promotion of Access to Information Act 2 of 2000).
- Correction — have inaccurate or outdated information corrected.
- Deletion — have your information deleted or destroyed, subject to legal retention duties.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — including marketing consent, at any time.
- Complain — lodge a complaint with the Information Regulator if you believe your information has been mishandled.
To exercise any of these rights, contact your club's front desk or email hello@kultiflo.com. We respond to data-subject requests within a reasonable time and never charge for a first request for access to your own information.
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Enquiries: enquiries@inforegulator.org.za
Complaints: POPIAComplaints@inforegulator.org.za
inforegulator.org.za
This website.
kultiflo.com collects nothing about you. There are no analytics, no tracking pixels, no advertising tags, no cookies set by us, and no forms — the only way to contact us from this site is email. Standard web-server logs exist at our hosting provider (Google) for security and operational purposes only.
No one under 18.
The platform is strictly for adults. Where you register with a South African identity number, your age is verified automatically and anyone under 18 is refused; where you register with a passport, the platform cannot read your date of birth, and confirming your age is your club's responsibility. We do not knowingly process the personal information of children; if you believe a child's information has been captured, contact us immediately and it will be removed.
Changes to this policy.
We may revise this policy from time to time. The current version, with its effective date, is always published at kultiflo.com/privacy. If this policy changes, the updated version will be presented to you again when the change takes effect.
Information Officer & contact.
Questions about this policy, and all data-subject requests, go to Kultiflo's Information Officer:
Information Officer — Kultiflo
Pretoria, South Africa
hello@kultiflo.com