POPIA Privacy Policy
Effective February 2026 · Mind Money Movement (Pty) Ltd trading as PeakRank Digital
1. Introduction
Mind Money Movement (Pty) Ltd (trading as PeakRank Digital, “we”, “us”, or “our”) is committed to protecting the privacy and personal information of our clients, website visitors, and platform users.
This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the Protection of Personal Information Act, 2013 (Act 4 of 2013) (“POPIA”) and the conditions for lawful processing of personal information as set out in the Act.
By using our website at peakrank.co.za or our SaaS platform, you consent to the collection and processing of your personal information as described in this policy.
2. Responsible Party
In terms of POPIA, the responsible party for the processing of your personal information is:
- Company: Mind Money Movement (Pty) Ltd
- Trading as: PeakRank Digital
- Website: peakrank.co.za
- Information Officer: [email protected]
- General enquiries: [email protected]
3. Personal Information We Collect
We collect personal information that is necessary for the purposes of providing our services. This may include:
3.1 Information You Provide
- Full name and surname
- Email address
- Phone number (if provided)
- Company or business name
- Website URL(s) for SEO and GEO auditing
- Billing and payment information (processed securely via our payment provider)
- Any information submitted via contact forms, onboarding, or support requests
3.2 Information Collected Automatically
- IP address and approximate geolocation
- Browser type, device, and operating system
- Pages visited, time on site, and referral source
- Cookies and similar tracking technologies (see Section 9)
4. Purpose of Processing
We process your personal information for the following purposes:
- To create and manage your account on the PeakRank platform
- To deliver our SEO, GEO, and digital marketing services
- To generate reports, audits, and recommendations for your domains
- To process payments and manage subscriptions
- To communicate service updates, billing notifications, and support responses
- To send marketing communications (only with your explicit opt-in consent)
- To improve our platform, services, and user experience
- To comply with legal and regulatory obligations
5. Lawful Basis for Processing
We process your personal information based on one or more of the following lawful grounds as defined in POPIA:
- Consent: You have given explicit consent for us to process your information for a specific purpose.
- Contract: Processing is necessary to fulfil a contract with you (e.g., your subscription agreement).
- Legal obligation: Processing is required to comply with South African law.
- Legitimate interest: Processing is necessary for our legitimate business interests, provided your rights are not overridden.
6. Direct Marketing
In terms of Section 69 of POPIA and the April 2025 amendments, we will only send you electronic marketing communications if you have given us your explicit prior opt-in consent.
You may withdraw your consent at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Emailing us at [email protected] with the subject "Opt Out"
- Updating your communication preferences in your account settings
We maintain and honour do-not-contact requests in compliance with the National Do-Not-Contact database.
7. Sharing of Personal Information
We do not sell, rent, or trade your personal information. We may share your information with the following categories of third parties, only to the extent necessary to provide our services:
- Payment processors: To process subscription payments securely.
- Cloud hosting providers: Our platform is hosted on Vercel and Supabase, with data stored in secure data centres.
- Email service providers: For transactional and marketing emails (e.g., Resend).
- Analytics tools: To understand how our platform is used and improve user experience.
All third-party service providers are contractually obligated to protect your personal information and may only process it for the purposes we specify.
8. Your Rights as a Data Subject
Under POPIA, you have the following rights in relation to your personal information:
- Right to access: Request confirmation of what personal information we hold about you.
- Right to correction: Request that we correct or update inaccurate personal information.
- Right to deletion: Request that we delete your personal information (subject to legal retention requirements).
- Right to object: Object to the processing of your personal information on reasonable grounds.
- Right to withdraw consent: Withdraw previously given consent at any time.
- Right to lodge a complaint: Lodge a complaint with the Information Regulator if you believe your rights have been infringed.
To exercise any of these rights, please contact our Information Officer at [email protected]. We will respond to your request within 30 days as required by POPIA.
9. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and understand user behaviour.
Types of Cookies We Use
- Essential cookies: Required for the platform to function (e.g., authentication, session management).
- Analytics cookies: Help us understand how visitors interact with our website.
- Preference cookies: Remember your settings and preferences.
You can manage your cookie preferences through your browser settings. Please note that disabling essential cookies may affect the functionality of our platform.
10. Data Security
We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, destruction, or damage. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with password hashing and optional multi-factor authentication
- Role-based access controls limiting who can access personal information
- Regular security reviews and vulnerability assessments
- Hosting on infrastructure with SOC 2 compliance (Vercel, Supabase)
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Regulator as soon as reasonably possible, in accordance with Section 22 of POPIA.
11. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law.
- Active accounts: Personal information is retained for the duration of your subscription.
- Cancelled accounts: Data is retained for 90 days after cancellation, then archived to cold storage.
- Deletion requests: Processed within 30 business days. Anonymised aggregate data may be retained for benchmarking.
- Legal requirements: Certain records (e.g., invoices, tax records) may be retained for up to 5 years as required by South African law.
12. Cross-Border Data Transfers
Some of our service providers may process or store your data outside of South Africa. In such cases, we ensure that:
- The recipient country has adequate data protection laws, or
- Appropriate contractual safeguards are in place to protect your information, or
- You have provided consent to the transfer.
This is in accordance with Section 72 of POPIA, which governs the transborder flow of personal information.
13. Information Regulator
If you believe that we have violated your right to privacy or that we are not processing your personal information lawfully, you have the right to lodge a complaint with the Information Regulator:
- The Information Regulator (South Africa)
- Phone: 012 406 4818
- Email: [email protected]
- Website: inforegulator.org.za
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. Material changes will be communicated to active subscribers via email at least 14 days before taking effect.
The latest version of this policy will always be available at peakrank.co.za/popia. Continued use of our platform after changes take effect constitutes acceptance of the revised policy.
Privacy Questions or Requests?
Contact our Information Officer to exercise your data subject rights or ask any questions about how we handle your personal information.
Email [email protected]