Privacy Policy
Last Updated: 17 March 2026
1. Overview
LuckyFlo (operated by JustBenjamin) ("us", "we", or "our") operates the LuckyFlo platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.
We are committed to compliance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and process your personal information lawfully and responsibly.
2. Information We Collect
We collect the following types of information:
2.1 Personal Data (Provided by You)
- Account Information: Email address, first and last name, phone number, password (encrypted).
- Business Information: Business name, address, operating hours, services offered, branding assets (logos, gallery photos).
- Booking Data: When clients book appointments, we collect their name, phone number, email address, and service preferences.
- Reviews: Star ratings, written feedback, and associated service details.
2.2 Usage Data (Collected Automatically)
- Browser type and version
- Pages visited and time spent on those pages
- Device type and operating system
- Referring URL
2.3 Payment Data
We do not store your credit card details, bank account numbers, or other financial instrument data on our servers. All payment processing is handled by our third-party payment processor, PayFast (Network International). We receive only transaction confirmations, subscription status, and payment identifiers necessary to manage your account.
3. How We Use Your Data
We use the collected information for the following purposes:
- Service Delivery: To provide, maintain, and improve the LuckyFlo platform, including appointment scheduling, calendar management, and business analytics.
- Transactional Communications: To send booking confirmations, reminders, cancellation notices, and review requests via email and/or WhatsApp.
- Account Management: To manage your subscription, process payments, and provide customer support.
- Security: To detect and prevent fraud, abuse, and unauthorized access to the Service.
- Legal Obligations: To comply with applicable laws, regulations, and legal processes.
We do not sell your personal information to third parties. We do not use your data for targeted advertising.
4. Third-Party Services
We use the following third-party services to operate the platform. Each processes data in accordance with their own privacy policies:
- Google Firebase (Google LLC) — Authentication, database, cloud functions, and file storage. Firebase Privacy Policy
- PayFast (Network International) — Payment processing for subscriptions. PayFast Privacy Policy
- Resend — Transactional email delivery (booking confirmations, password resets, verification emails). Resend Privacy Policy
- Meta (WhatsApp Business API) — Booking confirmations, reminders, and cancellation notices via WhatsApp. WhatsApp Privacy Policy
- Vercel — Website hosting and deployment. Vercel Privacy Policy
5. Data Retention
- Active accounts: We retain your personal information for as long as your account is active or as needed to provide you the Service.
- After cancellation: Upon account deletion or subscription cancellation, we retain basic records (name, email, transaction history) for up to 5 years as required by South African tax and commercial law.
- Booking records: Business appointment data is retained for the duration of the business account and for 12 months after account closure to support dispute resolution.
- Reviews: Published reviews remain visible unless the reviewer requests removal or the review is moderated by the business owner.
6. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Access: Request confirmation of whether we hold your personal information and obtain a copy of it.
- Correction: Request that we correct or update inaccurate or incomplete personal information.
- Deletion: Request that we delete your personal information, subject to legal retention requirements.
- Objection: Object to the processing of your personal information on reasonable grounds.
- Withdraw Consent: Withdraw any consent you have previously given for data processing.
- Complaint: Lodge a complaint with the Information Regulator (South Africa) if you believe your rights have been violated.
To exercise any of these rights, contact us at support@luckyflo.com. We will respond within 30 days.
7. Cookies & Tracking
LuckyFlo uses functional cookies only. These are session cookies required by Firebase Authentication to maintain your login state. We do not use marketing cookies, advertising trackers, or third-party analytics cookies.
You can disable cookies in your browser settings, but this may prevent you from using certain features of the Service (such as staying logged in).
8. Data Security
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Firebase Security Rules restricting database access to authorized users
- Role-based access controls within the platform
- Regular review of access permissions and security practices
While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, your personal information, or wish to exercise your POPIA rights, please contact us:
- Email: support@luckyflo.com
- Company: JustBenjamin (trading as LuckyFlo)
- Jurisdiction: Republic of South Africa
You may also contact the Information Regulator (South Africa) at inforegulator.org.za if you have a complaint about how we handle your personal information.