How we handle your information.
Last updated: 30 September 2026
Who is responsible
HustleHub is operated by Oratilwe Sehlahla under Sehlahla Apps. Oratilwe Sehlahla is responsible for how HustleHub handles personal information. Send privacy requests and questions to oratilesehlahla13@gmail.com.
What we collect
- Account details: your email address and password (passwords are handled by Firebase Authentication and are never visible to us).
- Profile details: your name, phone number and campus.
- Marketplace activity: orders you place or receive (item, quantity, total, delivery details, phone number), saved listings, blocked sellers, reviews, reports and support requests.
- Seller details: store name, category, description, WhatsApp number, area, opening hours, optional public pickup map coordinates, optional payment link, listings, public listing photos and picture promo statuses.
- Seller verification files, when you apply to open a store: government ID, student card and proof of payment. During review an administrator may enter your ID and student number to check for duplicate applications.
- Security records: records of moderation changes and administrator requests to access private documents, and bot-protection checks (Firebase App Check and Google reCAPTCHA) when enabled.
- Data stored on your device: cached app files and, where available, previously loaded listings. Placing orders, logging in and uploading files require an internet connection.
Why we use it
To run the marketplace, let buyers and sellers contact each other, verify sellers, prevent fraud and repeat applications, handle reports and disputes, keep the service secure, and meet legal obligations. We do not sell your information.
Your choices
Account details are needed to sign in. Seller verification documents and payment evidence are needed to assess a store application; without them we cannot approve the store. Reviews, report descriptions and optional profile details are your choice. Only submit information needed for the request, and do not include passwords, card PINs or OTP codes.
When you open WhatsApp or a seller payment link, that provider processes the information you choose to send under its own privacy terms.
Who can see it
- Signed-in users can see store pages, listings and the seller contact number so they can place and arrange orders.
- A seller sees the name, phone number and delivery details you enter when ordering from them.
- Private verification files are restricted through storage access permissions and reviewed by authorised administrators for age, student status and payment checks.
- Listing photos are public. Never upload identity documents or payment proof as listing photos.
Service providers and transfers abroad
We use Google Firebase (authentication, database, hosting and bot protection) and Supabase (file storage). Their servers may be outside South Africa, so your information may be processed in other countries to provide the service. Contact us if you want more information about the relevant providers and safeguards.
Pictures, promos and support
Product pictures and promo pictures use public photo storage. A promo stops appearing to customers after 24 hours, or earlier when removed or hidden. Expiry does not automatically erase its image from storage; someone with the photo URL may still access it. Contact support to request removal of an uploaded public image.
Support requests, replies and status updates are visible to the person who submitted the request and authorised administrators. They are used to handle reports, refunds, account problems and privacy requests. Do not send sensitive documents through a report.
How long we keep it
- A daily cleanup job deletes private verification files older than 30 days, up to 300 per run; larger backlogs take additional runs.
- Private keyed fingerprints of ID and student numbers are retained while needed to detect repeated seller applications and prevent abuse. Raw numbers are not kept in that registry; uploaded verification files may contain them until those files are deleted. You may ask support to review whether a fingerprint still needs to be retained.
- Account and marketplace records are kept while needed to provide your account, manage orders, resolve disputes, prevent abuse or meet legal record-keeping requirements. Once no longer needed, they should be deleted or de-identified. Deletion of these records is handled through support; it is not currently automatic.
Your rights
You may ask to see, correct or delete your information, or object to how we use it, by emailing oratilesehlahla13@gmail.com. We may verify that the request is from you before releasing or changing information. Self-service account deletion is not available yet. We will respond as soon as reasonably possible and explain if a record must be retained for a lawful purpose. You can also complain to the Information Regulator of South Africa.
Security
We protect information with access permissions and private document storage. No online system can promise absolute security, so use a unique password and keep reset links private.
Changes
If we change this policy we will update the date above and, for significant changes, tell you in the app.
Order conversations and alerts
Order messages are stored in Firestore and readable by the buyer, seller and authorised support admins for dispute handling. Messages cannot be edited or deleted through the app. Read markers track unread conversations and order updates across devices. Do not include ID documents, passwords, OTPs or card information. Push notifications require your permission. Firestore stores device registration tokens; Supabase processes a private delivery queue through Firebase Cloud Messaging. Alerts contain general order updates, without message contents or payment details. Disable push before handing a shared device to someone else. Sent and failed delivery records are removed after 30 days. Optional order email alerts use your verified Firebase account email through Brevo. Supabase stores private delivery metadata, without message contents. You can disable email alerts in Settings. Automatic WhatsApp delivery is not connected. Contact support for access or deletion requests, subject to necessary dispute records.
Follows, carts and disputes
Followed stores, alert preferences and carts are private to your account. Live followed-store updates are derived from published listings and promotions; optional browser alerts work while the app is open. Cart orders record their line items, discount and pickup slot with the order. Dispute statements and responses are visible only to the buyer, seller and authorised administrators; responses cannot be edited or deleted through the app. Admin review notes are retained with the dispute. These records follow the account and marketplace retention policy above. Public seller response indicators use order decision timestamps without buyer names, phone numbers or message text. Contact support for access or deletion requests.
Pickup maps
Sellers may publish a public pickup point. Device location is requested only when a seller presses “Use my current location”; the app saves only the chosen pin when the store form is saved. Customers can choose to load an OpenStreetMap map or open Google Maps directions. These providers receive connection information such as your IP address when used. Do not publish a private home or room location. A seller-selected pin is not proof that the seller or meeting point is verified.