This Privacy Policy explains how CompMetrics, operated by [LEGAL ENTITY NAME] (registration number [COMPANY REGISTRATION NUMBER]) of [PHYSICAL/REGISTERED ADDRESS], collects, uses, shares and protects personal information in connection with the Platform, in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
1. Who we are & POPIA roles
For account data, payment records, and platform-level operation of the service, CompMetrics acts as the responsible party under POPIA. For event-specific participant data collected on behalf of an Event Owner (for example, an athlete’s registration details for that Owner’s event), CompMetrics processes information as an operator acting on the Event Owner’s instructions, while the Event Owner independently determines the purpose of collecting information specific to running their event. In practice this means both CompMetrics and the relevant Event Owner have privacy obligations, and a request about event-specific participation may need to involve the Event Owner as well as CompMetrics. This section describes the practical relationship as we understand it; the exact legal characterisation for every data flow has not been confirmed by an attorney and should be treated as subject to legal review.
2. Information we collect
We collect only what a given flow actually requires. Depending on how you use the Platform, this can include:
Account data
- Name, email address, and authentication/account identifiers.
Athlete data
- Date of birth, sex (used for category/division eligibility), mobile number, club/gym affiliation, emergency contact name and mobile number (where the event requires or offers this), team membership, registration and payment records, competition results, and QR check-in status. Not every field is collected for every registration — each event configures which of phone, club and emergency-contact fields are required.
Volunteer data
- Application details, role/shift preferences and assignment, attendance/check-in, and, where an event configures it, kit/apparel sizing (fit and size fields) to prepare, order or issue your volunteer apparel.
Spectator data
- Contact and order details, and ticket/admission (QR check-in) status.
Vendor data
- Business and contact information, application details, and payment/status records.
Prize payout data
- Where you are eligible for a cash prize and choose to supply payout details: account holder name, bank name, account number, branch code, account type, and payout status/reference (see section 9).
Technical data
- Standard web request/log data (such as IP address, browser/device information and timestamps) generated by our hosting and security infrastructure, and audit-log entries for actions taken on the Platform. We do not currently use any separate third-party analytics or advertising tracking (see section 15).
We do not collect information the Platform has no field or flow for — if a category above isn’t relevant to how you use CompMetrics, it isn’t collected from you.
3. Special personal information & minors
POPIA treats certain categories (such as health information, race, religious/philosophical beliefs, and criminal behaviour) as special personal information with additional restrictions. CompMetrics collects sex as a category-eligibility field for competition divisions, which we treat as ordinary personal information used for a clear, disclosed sporting purpose — not as an inference about health or sex life. We do not ask about or infer health/medical conditions from competition participation. Whether a demographic category field like this could be treated as special personal information in any circumstance is a genuine legal question we have flagged for attorney review, rather than resolved ourselves.
Minors: the Platform does not enforce a platform-wide minimum age for account creation, athlete registration, volunteering or ticket purchase — age eligibility for a specific competition category (for example, a youth/teen division) is set by the event’s own age classifications and organiser policy, not by CompMetrics. Where an event permits participants under 18, the Event Owner is responsible for obtaining any required parental/guardian consent for that event; a general checkbox acceptance on this Platform is not, by itself, sufficient consent for a minor’s participation. If you are a parent/guardian with a concern about a minor’s registration, contact the event organiser directly, or us at the address in section 19.
4. How we use your information
We use personal information to: operate your account; process registrations, applications and payments; issue and verify QR credentials; run scoring, standings and results; communicate with you about your registration/application/order (see section 10); administer prize eligibility and payouts; maintain security, audit trails and legal-acceptance evidence; and comply with our legal obligations.
5. Organiser enquiries
If you submit an enquiry via /for-organisers, we collect your name, email, phone, organisation and event information, and your message. We use this only to respond to your enquiry, evaluate a possible event setup, and communicate with you about CompMetrics’ services. Submitting an enquiry does not create a CompMetrics account or grant any access — it is reviewed by our team before anything further happens.
6. Legal & consent evidence
Where you accept an event waiver or other versioned document, or give explicit consent (such as authorising an Event Owner to see your prize payout details for a specific event), we retain evidence of what you accepted, its document version, the timestamp, and the registration/application it relates to. A later update to a document’s wording does not rewrite this historical acceptance record.
7. What’s public
Some event information is intentionally public: an athlete or team’s display name, category, ranking and results on a public leaderboard; facility name on aggregate facility standings; a confirmed vendor’s public listing (business name, category, description, links they choose to provide); and general event information the organiser publishes. We do not make your full athlete profile, contact details, banking information or payment records public.
8. QR credentials
An athlete or spectator QR credential is an opaque, single-use admission code, not a readable record of your personal or payment information. Protect it as you would a ticket — sharing the image may let someone else use it to gain admission in your place.
9. Prize payout banking information
If you become eligible for a cash prize, you may choose to supply banking details (account holder name, bank, account number, branch code, account type) to a master payout profile tied to your account, used to facilitate payment of event prize money. Access works as follows:
- You own your master payout profile; it is not shared with any organiser by default.
- An Event Owner/Admin can only see your banking details for a specific event after you explicitly authorise sharing for that event, at which point an event-specific snapshot is created.
- Event Staff (a role below Owner/Admin) do not receive access to banking details.
- Every time an organiser reveals your banking details, that reveal is recorded (audited) — who, when, and for which event.
- Your full banking details are not displayed publicly, and are not included in ordinary notification emails.
- Historical payout records (including a past event-specific snapshot) may be retained after payment for legitimate legal, accounting and audit purposes, even if you later update your master profile — this does not rewrite what a specific organiser was actually shown for a completed payout.
We do not describe the underlying database structure here beyond what’s needed to understand this access model.
10. Direct marketing & transactional email
Emails you receive from CompMetrics for actions you’ve taken — registration confirmation, volunteer application decisions, ticket confirmation, vendor application status, prize notifications, and responses to an organiser enquiry — are transactional/operational communications necessary to deliver the service you requested, not optional marketing, and are not a newsletter subscription. CompMetrics does not currently send marketing/promotional email campaigns; if this changes in future, any such marketing communication will require your prior opt-in consent and a clear opt-out, in line with POPIA section 69.
11. Who we share information with
We share personal information with:
- the relevant Event Owner/Admin/Staff, scoped to the event you’re participating in and their role’s access level;
- our payment provider, Paystack, to process and verify payments;
- our hosting/database provider, Supabase, and application hosting provider, Vercel, who host the Platform and its data;
- our transactional email provider, Resend, to deliver the emails described in section 10;
- a regulator, court, or other authority where required by law.
We do not sell personal information.
12. Cross-border transfers
Some of the providers listed in section 11 may process or store information outside South Africa. Where this happens, we rely on the transfer being necessary for performing our contract with you (for example, processing your registration or payment) or on the provider being subject to data-protection obligations that provide a comparable standard of protection, consistent with POPIA section 72. The specific adequacy of each provider’s safeguards has not been independently verified by an attorney for this notice and should be treated as an item for legal review.
13. Security
We use reasonable technical and organisational safeguards appropriate to the information involved, including: authentication and role-based access control; database-level event isolation (so one event’s data is not accessible from another); audit logging of privileged actions; restricted, audited access to banking data; opaque/hashed admission credentials rather than readable tokens; and HTTPS encryption in transit. Our third-party providers maintain their own security programmes. No system is completely secure, and we do not claim the Platform is 100% secure.
14. Security compromises
If a security compromise occurs that has compromised the confidentiality, integrity or availability of your personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with POPIA section 22, including enough detail for you to take protective steps. We do not commit to a specific notification timeline beyond what the law requires, since the appropriate timing depends on the nature of the incident.
15. Cookies
See the dedicated Cookie Policy. In short: we use only the cookies necessary to keep you signed in and to operate the Platform securely — we do not currently use analytics or advertising/marketing cookies.
16. Retention
We keep different categories of information for different lengths of time, depending on their purpose:
- accounts, registrations and event results;
- payment records;
- legal/consent acceptance evidence;
- audit logs;
- volunteer and vendor history;
- prize payout records;
- organiser enquiries.
We have not adopted a fixed retention schedule with exact periods for each category. As a general principle, we keep records only for as long as reasonably required for operational, contractual, legal, accounting, dispute or audit purposes, subject to any applicable legal requirement. Adopting a formal, documented retention schedule is flagged as a legal/governance follow-up item, not yet completed.
17. Your rights
Under POPIA, you have the right to: be informed that we process your information; access the personal information we hold about you; request correction of inaccurate information; object to processing on reasonable grounds, including for direct marketing; request deletion or destruction of personal information we no longer have a lawful basis to hold; withdraw consent where processing is based on consent; and lodge a complaint with the Information Regulator. We cannot delete information we are legally or contractually required to retain (for example, financial or audit records within their retention period), but we will act on a valid request to the extent the law allows. To exercise a right, contact us using the details in section 19.
Information Regulator of South Africa — complaints: inforegulator.org.za.
18. Changes to this policy
We may update this Privacy Policy from time to time; the “Last updated” date above reflects the current version. This does not change how any prior, specific consent or legal acceptance you already gave is recorded (see section 6).
19. Contact & Information Officer
General privacy queries and requests: support@compmetrics.co.za.
Information Officer: Gavin Perch — support@compmetrics.co.za. Registration of the Information Officer with the Information Regulator is an outstanding governance action, not yet confirmed as complete — see the PAIA page for status.
20. Organiser / business verification
If you become an Event Owner/Admin for a paid event, CompMetrics operates its own Organiser Verification / Business Verification process before that event can go commercially live. This is CompMetrics’ own commercial-governance process for verifying who an organiser is, that they are authorised to act for their organisation, and that a settlement bank account is valid — it is not represented as formal compliance with the Financial Intelligence Centre Act unless separately confirmed by legal review, and it is separate from Paystack’s own merchant KYC/verification process.
As part of this process, we may collect:
- business/organisation identity data (legal and trading name, registration number, VAT number, organisation type, business contact and address details);
- authorised representative data (name, contact details, role, relationship to the organisation);
- identity documents, where the organiser type requires them;
- business documents (for example, registration or authority evidence);
- settlement bank details (account holder name, bank, account number, branch code, account type);
- a mandatory proof-of-bank-account document reconciling those settlement details;
- review/status information and internal reviewer notes about the verification outcome.
This information is used only to verify the organiser and their organisation, confirm authority to act, validate the settlement destination, reduce fraud, and satisfy CompMetrics’ own commercial-governance and provider requirements before enabling live paid-event functionality. It is stored using the same restricted-access pattern as prize payout banking information (section 9): identity and bank-proof documents are held in private storage with no public URL, are not accessible to Event Staff or unrelated Event Admins, and any deliberate reveal of full settlement bank details by an authorised internal reviewer is audited. Full account numbers and full ID numbers are never included in that audit metadata, in ordinary exports, or in notification emails. We have not adopted fixed retention periods for these records; as with section 16, a formal retention schedule for this category is flagged for legal review, not yet finalised.