Privacy Policy
Effective date: 2 April 2026
1. Introduction
GlowSquare (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights in relation to it. It applies to all users of the GlowSquare platform — customers, service providers (“Providers”), and visitors.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African law.
2. Information We Collect
Information you provide
- Name and email address (collected when you sign in via Google)
- Phone number (optional — provided in your profile settings)
- Business name, description, location, and service details (Providers only)
- Bank account details for payment payouts (Providers only, stored by Paystack)
- Booking details including selected services, dates, and notes
- Reviews and ratings you submit
Information collected automatically
- Log data including IP address, browser type, and pages visited
- Device information and operating system
- Usage patterns and feature interactions (via Vercel Analytics)
- Core Web Vitals performance data (via Vercel Speed Insights — anonymised)
Google Calendar data (Providers only)
If you choose to connect your Google Calendar, we request access to create, update, and delete calendar events on your behalf. We use this access solely to sync your GlowSquare bookings with your Google Calendar. We do not read, store, or share the contents of your existing calendar events. You can revoke this access at any time from your Google Account settings or from your GlowSquare integrations page.
3. How We Use Your Information
- To create and manage your account
- To facilitate bookings between customers and Providers
- To send booking confirmations, reminders, and status updates
- To process deposits and refunds via Paystack
- To notify Providers of new bookings and cancellations
- To send onboarding emails to newly approved Providers
- To display your public Provider profile to customers
- To sync bookings with your Google Calendar (if connected)
- To improve Platform performance and user experience
- To comply with our legal obligations
We do not use your information for automated decision-making or profiling beyond what is described above.
4. Legal Basis for Processing
We process your personal information on the following grounds:
- Contract performance — to deliver the booking services you request
- Legitimate interest — to operate and improve the Platform, prevent fraud, and communicate about your bookings
- Consent — for Google Calendar access and optional marketing communications
- Legal obligation — to comply with South African law including POPIA and tax regulations
5. Third-Party Services
We share your information with the following third-party services only to the extent necessary to operate the Platform:
- Google (OAuth & Calendar) — used for authentication and optional calendar sync. Governed by Google's Privacy Policy.
- Paystack — used to process deposit payments and vendor payouts. Your payment card details are processed and stored directly by Paystack and never by GlowSquare. Governed by Paystack's Privacy Policy.
- Resend — used to deliver transactional emails (booking confirmations, reminders, etc.). Only your email address and name are shared.
- Cloudinary — used to store and serve images you upload (Provider logos, banners, service photos).
- Vercel — hosts the Platform. May process request logs and anonymised analytics data.
- Upstash — used for rate limiting. Processes only IP addresses or session identifiers, not personal data.
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
6. Data Retention
- Account data is retained for as long as your account is active.
- Booking records are retained for 5 years after the booking date to comply with South African financial record-keeping requirements.
- If you request account deletion, we will delete your personal data within 30 days, except where retention is required by law.
- Google Calendar tokens are deleted immediately when you disconnect your calendar or delete your account.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse. These include encrypted connections (HTTPS), hashed credentials, access controls, and regular security reviews. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
8. Cookies
GlowSquare uses session cookies strictly necessary for authentication (managed by NextAuth.js). We do not use third-party advertising cookies or tracking pixels. Analytics data collected by Vercel Analytics is anonymised and does not use cookies.
9. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request that we correct inaccurate or incomplete information
- Deletion — request that we delete your personal information (subject to legal retention obligations)
- Objection — object to the processing of your information for legitimate interest purposes
- Withdraw consent — withdraw consent for Google Calendar access or any consent-based processing at any time
- Lodge a complaint — with the Information Regulator of South Africa at inforegulator.org.za
To exercise any of these rights, contact us at info@glowsquare.co.za. We will respond within 30 days.
10. Children
The Platform is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected such information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The effective date at the top of this page will be updated accordingly. Continued use of the Platform after any changes constitutes your acceptance of the updated Policy.
12. Contact
For any privacy-related questions, access requests, or complaints, please contact us:
- Privacy & legal enquiries: info@glowsquare.co.za
- Customer support: support@glowsquare.co.za