Privacy policy
Sisonke Alert handles location and emergency information — some of the most sensitive data a person can share. This policy explains exactly what we collect, why, who sees it, and how you get it back or delete it.
Last updated 9 July 2026 · Effective 9 July 2026
The short version. We collect your email, name and phone number so you can sign in and be identified in an emergency. We collect your precise location only while an alert you started is active — not in the background, not when the app is idle. When you raise an alert, your location and emergency type are shared with nearby responders and the trusted contacts you chose. You can delete your account and all of your data at any time.
1. Who is responsible for your information
Tredicik (Pty) Ltd, trading as Sisonke Alert, is the responsible party for the personal information described in this policy, as defined by the Protection of Personal Information Act 4 of 2013 (POPIA).
- Responsible party: Tredicik (Pty) Ltd (South Africa)
- Information Officer: Nkululeko Mbhele
- Privacy enquiries: privacy@sisonkealert.co.za
2. What we collect
| Information | When we collect it | Why |
|---|---|---|
| Email address | When you sign in | We sign you in with a one-time code sent to your email. We do not store a password. |
| Full name and phone number | When you create your profile | So responders and your trusted contacts know who raised the alert and can call you back. |
| Trusted contacts' names and phone numbers | When you add them | So we can notify them when you raise an alert. See section 5. |
| Precise GPS location and accuracy | Only while an alert you started is active | So responders can find you. Recorded roughly every 7 seconds until you resolve the alert. |
| Emergency category and optional note | When you raise an alert | One of crime, medical, fire, gender-based violence, accident or other — so the right help is dispatched. |
| Notification delivery records | When an alert is sent | To confirm whether responders and contacts were actually reached. |
| Pilot signup details | If you submit the form on this website | Name, email, phone and community, so we can invite you to the pilot. |
We do not collect: advertising identifiers, contact-list imports, browsing history, microphone or camera data. We do not run third-party advertising or analytics trackers in the app.
3. Special personal information
An alert's category may reveal information about your health (medical) or about alleged criminal conduct, including gender-based violence. POPIA treats this as special personal information. We process it under section 27(1)(d) of POPIA — processing necessary to protect a vital interest of the data subject — and only for as long as it takes to get you help.
4. Location, specifically
Location is the most sensitive thing we touch, so we are precise about it. The app requests foreground location permission. It reads your position at two moments only:
- Once, at the instant you confirm an alert, to record where the emergency started.
- Repeatedly, roughly every 7 seconds, while that alert is active, so responders can follow you if you move.
Location streaming stops the moment you tap "I'm safe" or an administrator terminates the alert. The app does not track you between emergencies. You can revoke location permission in your device settings at any time — the app will still open, but the panic button cannot summon help without it.
5. Trusted contacts — information about other people
When you add a trusted contact, you give us another living person's name and phone number. You are asking us to contact them on your behalf. Please only add people who have agreed to be your emergency contact. We use their details for nothing except notifying them about your alerts. If a trusted contact asks us to remove their details, we will, and we will tell you.
6. Who receives your information
When you raise an alert, we share your identity, location and emergency category with:
- Registered responders near you, found by searching for active responders within a set radius of your location.
- The trusted contacts you added, by push notification and SMS.
- Sisonke Alert administrators, who monitor active alerts on a live map and can terminate an alert.
We do not sell your personal information. We do not share it for advertising. We will disclose information to law enforcement or a court where the law compels us to.
7. Our processors, and where your data lives
We use third-party operators to run the service. They act on our instructions and are bound to keep your information confidential and secure.
- Supabase — database, authentication and realtime updates.
- Amazon Web Services — hosting for this website and our infrastructure.
- Expo — delivery of push notifications to your device.
Some of these providers store data on servers outside South Africa. Where personal information is transferred across a border, we do so under section 72 of POPIA, relying on contractual terms that require the recipient to uphold protection substantially similar to POPIA.
8. How long we keep it
- Profile and trusted contacts — until you delete your account, then removed as set out in section 10.
- Alert and location records — retained after an alert resolves so that an incident can be reviewed or evidenced. Deleted with your account unless we are required by law to keep a record, or the record is needed for pending legal proceedings.
- Pilot signups — until the pilot ends or you ask us to remove you, whichever is sooner.
9. How we protect it
Traffic between your device and our servers is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers. Database access is governed by row-level security policies, so one user's account cannot read another's alerts, contacts or location history. Administrator access is limited to the people who need it to operate the service.
No system is perfectly secure. If we become aware of a compromise affecting your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.
10. Your rights
Under POPIA you have the right to:
- Ask what personal information we hold about you, and get a copy of it.
- Correct or update anything that is inaccurate, out of date or incomplete.
- Delete your account and your personal information — see Delete your account for how.
- Object to our processing of your information, on reasonable grounds.
- Withdraw your consent, though this means the panic button can no longer summon help.
- Complain to the Information Regulator of South Africa if you believe we have mishandled your information.
To exercise any of these, email privacy@sisonkealert.co.za. We will respond within 30 days. We may ask you to verify your identity first, so that nobody else can request your data.
The Information Regulator can be reached at inforegulator.org.za.
11. Children
Sisonke Alert is not directed at children under 18. If a child needs to use the app for their safety, a parent or guardian must set up and consent to the account. If we learn we hold a child's information without that consent, we will delete it.
12. Changes to this policy
If we materially change how we handle your information, we will update the date at the top of this page and notify you in the app before the change takes effect.
13. Contact us
Privacy questions: privacy@sisonkealert.co.za
Everything else: support@sisonkealert.co.za