uUniBudz

Privacy Policy

Effective: 17 May 2026 · Last updated: 23 September 2026
Plain English first: UniBudz is a South African app for splitting bills, settling up, finding deals and events, and looking out for your mates on a night out. We keep what those features need and nothing more. We don't sell your data, we don't run ads, and we don't build advertising profiles. UniBudz never moves money: if you save bank or PayShap details, we only show them to people in your groups so they can pay you back (§7). You can delete your account in the app at any time (see unibudz.co.za/delete-account). For anything else, email unibudzapp@gmail.com and we'll act within 30 days.

1. Who we are

UniBudz is operated as a sole proprietorship by Ryan Daniel van Eeden ("we", "us", "our"), based in South Africa. We are the Responsible Party under the Protection of Personal Information Act, 2013 (POPIA) for the personal information described in this policy. Our Information Officer is Ryan Daniel van Eeden.

Contact for any privacy question, request for your data, deletion request or complaint: unibudzapp@gmail.com.

2. What we collect

We collect what the features you use need. Most of it you give us directly. Some of it is created as you use the app.

Your account

WhatDetailsWhy
Account and profileEmail address, first and last name, university, friend code, an optional @handle and an optional profile photoTo create your account and show you to your friends and groupmates. Your university decides which campus you belong to in the app (events, deals and the campus photo feed)
Sign-in codesA one-time 6-digit code we email you each time you sign in. UniBudz doesn't use passwordsTo check it's really you
Age checkWe ask for your date of birth when you sign up and check it on your phone. Your birthday is never sent to us. We store the date and time you confirmed you are 18 or older. If an existing account tells us it is under 18, we store that answer and when it was given, only until we delete that account (§11)UniBudz is for people aged 18 and over (§11)
Activity statusWhen you were last active in the app, and whether it is open right nowTo show your friends "online now" or "active 2h ago"
SettingsNotification choices and quiet hours, location-sharing settings, and a profile visibility settingTo respect what you asked for
Phone number (older accounts only)An earlier version of sign-up asked for a phone number. We no longer ask for it or use itNot used

Groups, expenses and settling up

WhatDetailsWhy
Groups and expensesGroup names, members and the name each member uses in the group, expense titles, amounts, categories, notes and dates, who paid and each person's share, recurring expenses you set up, and the group's activity feed (for example "Ryan added Pizza R120")The core bill-splitting feature
Receipt scanningWhen you tap Scan, the photo is sent through our server to Google Gemini, which reads the line items, and the result comes back to your phone. We don't keep a copy of the scan on our servers. If you then save the expense, the photo is attached to it as proof (next row)To fill in the expense for you. Your first scan is free, after that it is a Pro feature
Proof photosPhotos you attach to an expense or to a payment, such as a receipt or a screenshot from your banking appSo your group can see what was paid
Payment details for settling up (optional)A bank account number and bank, or a PayShap cellphone number, plus an optional account-holder name, and the date you agreed to save themSo people in your groups can pay you back. You only give these if you use settle-up, and you can remove them at any time (§7)
Payments between membersWho paid whom, the amount, an optional note and proof photo, and whether the other person confirmed or disputed itTo keep each group's "who has settled up" record accurate
RemindersPayment reminders sent between group members, including automatic ones if you turn on Debt Autopilot (Pro), and who has muted reminders from whomTo run reminders and stop them being used to spam people
Pro subscriptionWhether you're on the free plan, a free trial or Pro, when it ends, any promotional Pro period, how many free receipt scans you've used, and whether Debt Autopilot is on. We never receive your card details; Google Play takes the paymentTo unlock Pro features for the right people

Friends, location and safety

WhatDetailsWhy
FriendsYour friends and friend requests, nicknames and pins you give friends, people you have blocked, and which friends you have chosen to share your location with and until whenTo run the friends features and your privacy controls
Group live location (optional, off by default)Your GPS position, for groups where you have switched on location sharing. It only updates while you are on the Map tab with the app openSo your group can see each other on the map
Friend live location (optional, off by default)Your GPS position, shared only with the friends you pick, for as long as you choose (until 8am, 1 hour, 3 hours, or until you stop). When you accept a friend's request to see where you are, only that friend sees you, for the hours you pick. It keeps updating with the app closed and your phone locked, and your phone shows a notification the whole time it is on. It stops when the time runs out or you stop itSo the friends you trust can find you on a night out
Location requestsA friend asking to see where you are, and your answerTo run "where are you?" requests
SOS alertsYour position when you start an SOS, and your live position for as long as the alert is on, including with the app closed and your phone locked (your phone shows a notification while it is on). Starting an SOS sends your live position to the people listed in §7 for the length of the alert, even if you normally keep location sharing offTo alert the people around you in an emergency (§7)
Deal redemptionsTo redeem a venue special, your phone sends its position so we can check you are within 250 metres of the venue. We keep a record that you redeemed that special on that night, not your coordinatesTo stop specials being claimed from home and to enforce per-night limits

Jols (night-out photos)

Jols is being rolled out and may not be in your version of the app yet.

WhatDetailsWhy
Your jolsThe photos you post, their caption, the venues you tag, the audience you pick (your crew or your whole campus), when you posted and your campusTo show your night out to the people you chose (§7)
Likes and reportsWhich jols you like, and any jol you report, including that it was you who reported itLikes are shown to the person who posted. Reports go to us for review
Venue reposting (optional)Whether you ticked "Tagged spots can repost this photo" on a jolSo we only ever offer a photo to a venue with your permission (§7)
ModerationWhether a jol has been hidden, and why (for example someone in the photo asked for it to be taken down)To keep the feed safe

Community content and help

WhatDetailsWhy
ReviewsYour rating and review of a venueTo help other students. Reviews are screened by automated moderation when you submit them in the app (§5)
Suggestions and reportsVenues, deals and events you suggest, problems you report about a venue, and reviews you report. We record who sent each oneTo keep venue and event information accurate and to handle abuse
Saved eventsEvents you saveSo you can find them again
Help messagesIf you contact us through Help: your name, email address and message, plus the app version, your phone's browser details, your account ID and the screen you were on. We also record that you sent a messageSo we can answer and fix the problem. The record stops the form being used to spam us

Behind the scenes

WhatDetailsWhy
Usage eventsWhich venues you open on the map; whether you tap for directions, to call them, or to visit their website or Instagram; when you read a venue's reviews or rate it; and which events you open or click through to buy tickets. These are recorded against your accountTo learn which venues and events are useful. We only ever share totals with venues and event organisers, never names or account IDs (§7)
Push notificationsA push token for your phone from Firebase Cloud MessagingTo send you notifications you have allowed
Sign-in and securityThe IP address and phone or browser details of each signed-in session, and short-lived server logs kept by our hosting providerTo keep your account secure, stop abuse and fix problems
Abuse limitsCounts of certain actions, such as joining groups, starting an SOS or scanning receiptsTo stop the app being abused

The website

WhatDetailsWhy
WaitlistIf you join the waitlist on unibudz.co.za: your email address, your university, the page or link that brought you there, your browser details and the time. This is kept separately from app accountsTo tell you when UniBudz reaches your campus
Page analyticsCloudflare Web Analytics counts visits to our website without cookies: the page visited, the site that sent you, your browser type and your countryTo see which pages and posters bring people to us

We do not collect your contacts, microphone, calendar, browsing outside UniBudz, advertising IDs or any biometric data, or any photo you don't choose to upload. We never see a payment happen and never see your bank balance.

3. How we use it

We do not use your personal information for advertising and we don't build advertising profiles. We do not sell or rent your data to anyone.

4. Legal basis for processing

Under POPIA, we process your personal information on these bases:

5. Service providers (Operators under POPIA)

We use a small number of service providers to run UniBudz. They process personal information on our behalf and under their own security and privacy commitments:

OperatorWhat they doWhere
SupabaseDatabase, sign-in, file storage and server-side functionsDatabase and files in the EU (Ireland). Server-side functions run on Supabase's global network and may run in a region near you
Google Gemini (Google)Reads receipt photos when you tap Scan. Also reads public venue websites, menus and public Google reviews of venues to find deals, which involves none of your dataGoogle global infrastructure
OpenAIScreens venue reviews, and the captions of jols posted to your campus, for abuse when you submit them in the app, and tidies deal text people submit. OpenAI does not use this data to train its models and may keep it for up to 30 days to monitor for abuseUSA
Firebase Cloud Messaging (Google)Delivers push notifications. Google's servers carry the content of each notification, such as a friend's first name or an expense title and amount, and for an SOS the sender's first name, account ID and positionGoogle global infrastructure
ResendSends sign-in codes by email, and forwards messages you send through Help to our inboxUSA / global
RevenueCatKeeps track of Pro subscriptions. The app connects to RevenueCat whenever you are signed in on Android, so RevenueCat holds a record under your account ID with your phone's IP address and basic device and app details, plus, if you subscribe, the subscription events Google Play reports (plan, price, currency and dates). Never receives card detailsUSA
Google Play Billing (Google)Takes the Pro subscription payment and runs the free trial. Your card details stay with GoogleGoogle global infrastructure
CloudflareHosts our website and admin dashboard, runs the cookie-free website analytics, and routes email sent to unibudz.co.za addresses to our inboxGlobal edge network
GitHub (Microsoft)Runs our scheduled maintenance jobs, such as the event sync, the deal finder and the daily clean-up of unused files. The clean-up sees file names, which include account IDsUSA

We picked these providers because they offer industry-standard security and data processing terms, including protections for data sent outside South Africa.

Services your phone contacts directly, or that use data under their own terms

These are not our operators. They receive the information below under their own privacy policies, not on our instructions:

ServiceWhat they receiveWhere
OpenStreetMap FoundationMap images for the Map tab are fetched by your phone straight from OpenStreetMap, so their servers see your IP address and the area you are looking at, never your accountUK / global
QuicketWe get public event listings from Quicket. Event poster images load straight from Quicket's image server, so Quicket sees your IP address and which events you are looking at, never your account. Tapping to buy tickets opens Quicket's own websiteSouth Africa
Google Maps / Places (Google)We use Google Places for venue locations and details, which involves none of your data. Tapping "Get directions" opens the Google Maps app, which Google runs under its own privacy policyGoogle global infrastructure
Gmail (Google)Our inbox is a standard Gmail account, so emails you send us, including privacy and deletion requests and Help messages, are held by Google under Google's own termsGoogle global infrastructure

6. Sending data outside South Africa

Because most of the providers above are based outside South Africa, some of your personal information leaves the country. Under POPIA section 72 we only send personal information abroad where the recipient is subject to laws, binding corporate rules or an agreement that give it comparable protection, where you have agreed, or where it is necessary to provide the service you asked for. For our operators we rely on their data processing agreements and standard contractual clauses. The services in the second table in §5 act under their own terms: map images and event posters are fetched by your phone directly, and emails you send us are held by Google as part of a standard Gmail account.

7. Who can see what

Other UniBudz users

Venues and event organisers

We never touch your money. UniBudz is not a bank, a payment processor or a money-transfer service. We only show the payment details you chose to save and record what people tell us they have paid. The payment itself always happens directly between you and the other person, in your own banking app. We have no access to your bank account and we never move funds.

8. How long we keep it

9. Your rights under POPIA

We answer every request within 30 days. We may ask you to email us from the address on your account, so we know the request really comes from you.

10. Security

Profile photos are the one kind of data protected only by a hard-to-guess link (§7). No system is completely secure. If we discover a breach that puts your information at risk, we will tell you and the Information Regulator as soon as reasonably possible, as POPIA section 22 requires.

11. Age: UniBudz is 18+

UniBudz is for people aged 18 and over, because under POPIA a person under 18 is a child and because the app shows drink specials. When you sign up we ask for your date of birth before anything else and don't let anyone under 18 create an account. The date is checked on your phone and never sent to us.

If someone tells us during the age check on an existing account that they are under 18, we sign them out and delete the account and its data within 30 days. If you believe someone under 18 is using UniBudz, please email unibudzapp@gmail.com and we will look into it and delete the account where appropriate.

12. Cookies, trackers and our website

The app does not use cookies, advertising trackers or analytics SDKs. It includes two service SDKs that the features need: RevenueCat (Pro subscriptions) and Firebase Cloud Messaging (notifications). Fonts and code libraries are built into the app, so opening UniBudz does not contact any font or code service.

Our website at unibudz.co.za does not set cookies. It uses Cloudflare Web Analytics to count visits without cookies (§2). Like any web server, Cloudflare sees your IP address to deliver the page. The website's fonts are served from our own site, and the waitlist form sends what you enter to our database (§2).

13. Changes to this policy

We update this policy when the app changes. If we make a material change, we will tell you in the app and update the date at the top. If you keep using UniBudz after a change, the updated policy applies.

14. Contact

Privacy questions, requests for your data, deletion requests or complaints:
unibudzapp@gmail.com

How to delete your account: unibudz.co.za/delete-account