Privacy Policy
Effective date: 9 June 2026
Last updated: 26 July 2026
1. Introduction
BUDJINGA (PTY) LTD (Registration number 2026/426535/07) (“Budjinga”, “we”, “us”, “our”) operates the Budjinga budgeting software service at https://www.budjinga.com (the “Service”).
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website, create an account, or use the Service. It is written for users in the Republic of South Africa and is intended to comply with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable laws.
Responsible party: BUDJINGA (PTY) LTD
Registration number: 2026/426535/07
Country: Republic of South Africa
Email: info@budjinga.com
Contact form: Contact Budjinga
Information Officer: Mr. GA Marang
Privacy contact: info@budjinga.com
We do not sell your personal information. We use it to run the Service you signed up for.
2. Scope
This policy applies to:
- Visitors to our marketing website
- Registered users of the Budjinga web application
- People who contact us via email or the contact form
It does not apply to third-party websites linked from our site. Those sites have their own policies.
3. Personal information we collect
We may collect and process the following categories of information:
3.1 Information you provide
| Category | Examples | Why we collect it |
|---|---|---|
| Account & identity | Name, email address, password (stored hashed), or Google account identifiers if you use Google sign-in | Create and secure your account |
| Profile preferences | Avatar icon, accent color, marketing email preference, login notification preference, personalisation choices | Personalize your experience and honor your choices |
| Budget & workspace content | Transactions, amounts, descriptions, categories, budgets, monthly plans, notes, grocery lists, wishlist items, reminders, workspace names | Provide the core budgeting Service |
| Statement imports (eligible plans) | Bank statement files you upload (CSV / Excel / PDF) and mapped or extracted row data used to create transactions | Import transactions you choose to add to your ledger |
| Billing & subscription | Plan selected, billing cycle, invoice records, payment references you or we record | Manage subscriptions and accounts receivable |
| Communications | Messages you send via our contact form, email, or in-app feedback | Respond to enquiries and support requests |
3.2 Information collected automatically
| Category | Examples | Why we collect it |
|---|---|---|
| Technical & usage | IP address, browser type, device/OS summary (from user agent), pages visited on our site, referrer URL, session identifiers | Security, troubleshooting, lightweight first-party analytics, and service improvement |
| Security & audit logs | IP address, user agent, timestamps, actions taken in the app (where logged) | Fraud prevention, account security, and operational records |
| Login alerts (optional) | Sign-in time, device summary, approximate location derived from public IP | Notify you of new sign-ins when you enable this feature |
3.3 Information we do not collect (today)
- We do not require bank login credentials or linked bank accounts in the current version of the Service.
- We do not store full payment card numbers in our application database. When you pay an invoice online, payment details are entered on Payfast’s secure pages; we receive payment status and references, not your full card or banking credentials.
4. How we use personal information
We use personal information for these purposes:
- Providing the Service: account creation, authentication, workspace features, exports, and customer support
- Billing & account management: invoices, payment status, plan limits, suspension/reactivation where applicable
- Security: detecting abuse, verifying registrations (including anti-bot checks where enabled), login notifications, session management
- Communications: essential service emails (verification, password reset, billing, security notices) and, if you opt in, marketing emails
- Improvement & analytics: aggregated or first-party usage trends (e.g. page views) to understand how the site is used
- Legal & compliance: record-keeping, responding to lawful requests, enforcing our Terms of Service
We will not use your personal information for purposes incompatible with those above without telling you and, where POPIA requires, obtaining consent.
5. Legal bases (POPIA)
Depending on the activity, we rely on one or more of the following:
- Contract: processing needed to provide the Service you requested
- Consent: e.g. optional marketing emails, optional login notifications, non-essential cookies if any are added later
- Legitimate interest: security logging, fraud prevention, and minimal analytics, balanced against your rights
- Legal obligation: tax, accounting, or regulatory requirements
6. Financial and sensitive information
You may enter financial details (income, expenses, balances, descriptions) into Budjinga. That content is your data, stored to provide the Service. We treat it as confidential business/personal information and do not use it for advertising or sell it to third parties.
Workspace data is isolated per account/workspace so other Budjinga customers cannot access your entries.
Please use a strong, unique password and keep your login details secure.
7. Who we share information with
We share personal information only where necessary:
| Recipient type | Purpose |
|---|---|
| Hosting & infrastructure providers | Run the website, database, email delivery, and backups |
| Email delivery (SMTP) providers | Send transactional and optional marketing emails |
| Google (if you use Google sign-in) | Authenticate you via OAuth; we receive basic profile and email identifiers from Google |
| Cloudflare Turnstile (if enabled) | Verify registrations and reduce automated abuse |
| IP geolocation lookup (e.g. IP-API) | Approximate location text in optional login alert emails |
| Payfast (when you pay an invoice online) | Process invoice payments; card and banking details stay with Payfast |
| Professional advisers | Legal, accounting, or audit services, under confidentiality |
| Authorities | When required by law or to protect rights, safety, and security |
We do not sell personal information to data brokers or advertisers.
If we use an operator (processor) to handle personal information on our behalf, we require appropriate contracts and security measures as POPIA expects.
8. Cross-border transfers
Our primary hosting may be in South Africa. Some service providers (for example Cloudflare or IP lookup services) may process data in other countries. Where personal information is transferred outside South Africa, we will take steps required by POPIA, such as ensuring the recipient country has adequate protection or using appropriate safeguards. Details can be provided on request.
9. Cookies and similar technologies
We use essential cookies (such as session cookies) so you can log in and use the Service securely. These are necessary for the Service to function.
We do not use third-party advertising cookies on the marketing site today. Our first-party page analytics record visits server-side (URL path, hashed session identifier, optional logged-in user id, referrer), not a full third-party analytics suite like Google Analytics.
If we add non-essential cookies or similar technologies in future, we will update this policy and, where required, ask for consent.
You can control cookies through your browser settings. Blocking essential cookies may prevent you from logging in.
10. Marketing communications
Marketing emails are optional. You can opt in at registration or in your profile and opt out at any time.
Even if you opt out of marketing, we may still send essential messages about your account, security, billing, or legal notices.
11. How long we keep information
We keep personal information only as long as needed for the purposes above, including:
| Data type | Typical retention |
|---|---|
| Active account data | While your account exists and as needed to provide the Service |
| Billing & invoice records | As required for tax and accounting laws (often several years) |
| Contact form messages | As long as needed to handle the enquiry and for reasonable business records |
| Security / activity / page-view logs | For a limited operational period |
| Deleted account data | Removed or anonymized within a reasonable period after confirmed deletion, subject to legal retention |
Exact retention schedules may be defined in internal records-management policies.
12. Security
We use reasonable technical and organizational measures to protect personal information, including:
- HTTPS encryption for data in transit between your browser and our servers
- Hashed passwords (we do not store plain-text passwords)
- Access controls on servers and databases
- Workspace isolation so customer data is scoped to the correct account
No online service can guarantee absolute security. Standard application databases store most fields in readable form unless additional encryption is enabled. In the event of a serious breach affecting your personal information, we will notify you and the Information Regulator where POPIA requires.
13. Your rights under POPIA
Subject to POPIA and applicable exceptions, you may have the right to:
- Access personal information we hold about you
- Correct inaccurate or incomplete information
- Delete information where retention is no longer justified (subject to legal holds)
- Object to certain processing
- Withdraw consent where processing is based on consent
- Complain to the Information Regulator (South Africa)
Information Regulator: inforegulator.org.za
To exercise your rights, email info@budjinga.com with enough detail for us to verify your identity and locate your account. We will respond within the timeframes POPIA allows.
14. Children and younger users
Our marketing is aimed primarily at adults aged 18 and over. Budjinga is not directed at children under 13.
Users aged 13 to 17 may use the Service only with the consent and supervision of a parent or legal guardian where required by law. We do not knowingly collect personal information from children under 13 without appropriate consent.
If you believe that a child has provided us with personal information in circumstances where such information should not have been collected, please contact us and we will take appropriate steps to investigate and, where necessary, delete the information.
15. Third-party links
Our website may link to external sites (for example pricing references or support resources). We are not responsible for their privacy practices.
16. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be notified by email or in-app notice where appropriate.
Continued use of the Service after an update means you accept the revised policy, to the extent permitted by law.
17. Contact us
BUDJINGA (PTY) LTD (Reg. 2026/426535/07)
Email: info@budjinga.com
Contact form: Contact Budjinga
Information Officer: Mr. GA Marang