PRIVACY POLICY
Effective Date: 02 April 2026
Last Updated: 21 July 2026
1. INTRODUCTION
Welcome to Hike, a product of Hike Technologies (Pty) Ltd (“Hike”, “we”, “our”, or “us”). We are committed to protecting your personal information and processing it lawfully, transparently, and in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and all other applicable South African data protection legislation.
This Privacy Policy describes:
What personal information we collect about you;
Why we collect it and how we use it;
Who we share it with;
How long we keep it;
How we protect it;
Your rights as a data subject under POPIA; and
How to contact us.
This Policy applies to:
The Hike User App (iOS and Android);
The Hike Driver App (iOS and Android);
Our websites, including hikeapp.co.za;
Any other related services, platforms, or communications (collectively, the “Services”).
By registering an account or using the Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein. If you do not agree, you must not proceed with registration or use the Services.
2. WHO WE ARE
We are the “responsible party” under POPIA for the personal information processed through the Services. Our details are:
Hike Technologies (Pty) Ltd
Trading as: Hike / HikeApp
Jurisdiction: Republic of South Africa
Email: [email protected]
Phone: +27 68 814 8683
Website: hikeapp.co.za
3. OUR SERVICES
Hike operates a digital platform that connects passengers with transport providers. The Services include:
Rides (Rideshare) – on-demand transport between passengers and independent Rideshare Drivers via the Hike Driver App.
Lifts (Carpooling) – shared ride arrangements where Carpool Drivers offer surplus seating in their private vehicles via the Hike User App.
Safety Features – including women-only driver matching, emergency contact location sharing, in-app emergency (panic) button, and identity verification.
WhatsApp Booking Channel – an optional integrated booking flow via Meta’s WhatsApp Business API.
4. INFORMATION WE COLLECT
We only collect personal information that is adequate, relevant, and not excessive for the purposes described below.
4.1 Passenger Information (Hike User App)
| Category | Examples | Purpose |
|---|---|---|
| Identity & account | Full name, profile photo | Account creation; displayed to matched driver for pickup identification. |
| Contact details | Email address, phone number | Account verification, communications, trip receipts, and WhatsApp channel integration (optional). |
| Age & gender | Date of birth, gender (optional) | Age verification (18+); gender for women-only preference feature and anonymised safety statistics. |
| Trip data | Pickup/drop-off locations, route, fare, timestamp | Trip matching, fare calculation, navigation, and safety tracking. |
| Real-time location | GPS coordinates (while app is active / trip in progress) | Driver matching, live trip tracking, route monitoring. |
| Payment data | Payment method token, transaction history | Processing payments via third-party gateways; billing and dispute resolution. |
| Communications | In-app messages between passenger and driver | Trip coordination and safety record. |
| Ratings & reviews | Star rating, written feedback | Quality and safety management. |
| Device information | Device type, OS, app version, IP address | Diagnostics, security, fraud prevention. |
4.2 Rideshare Driver Information (Hike Driver App)
In addition to the above (where applicable), we collect:
| Category | Examples | Purpose |
|---|---|---|
| Identity documents | SA ID or passport copy, profile photo | KYC verification; passenger identification. |
| Contact & address | Residential address, phone number | Identity corroboration, zoning, regulatory compliance. |
| Driver credentials | Driver’s licence copy, operating licence/permit | Licence verification; NLTA compliance. |
| Vehicle information | Make, model, year, colour, licence plate, registration, roadworthy certificate, interior/exterior images | Vehicle verification and approval; trip matching; safety. |
| Background check | Consent & result of criminal background check | Platform safety; passenger protection. |
| Banking details | Bank account number and branch | Earnings payouts. |
| Trip data | History, earnings, GPS routes | Earnings statements, dispute resolution, performance monitoring. |
| Background location | GPS while “online” (active/inactive) | Dispatch and matching; driver availability. |
4.3 Carpool Driver Information (Hike User App)
Users offering Lifts additionally provide:
Driver’s licence copy.
Vehicle details (make, model, year, colour, licence plate, registration, images).
Real-time and background GPS location during a Lift in progress.
Carpool drivers are not required to submit operating licences or background checks, but Hike reserves the right to request them with consent.
4.4 Information Collected Automatically
We automatically collect:
Device type, operating system, and app version.
IP address and approximate city-level location derived from it.
App usage data (features accessed, session duration).
Crash logs and error reports.
Push notification delivery status.
4.5 Information from Third Parties
We may receive information about you from:
Payment processors – transaction status, fraud alerts.
Mapping/navigation providers – route and geocoding data.
Background check bureaus – with your explicit consent.
Meta (WhatsApp) – message delivery status for the booking channel.
5. LAWFUL BASIS FOR PROCESSING
We process your personal information based on one or more of the following legal grounds under POPIA:
| Lawful Basis | When We Rely on It |
|---|---|
| Contractual necessity | To create and manage your account, match trips, process payments, and provide the core Services. Without this processing, we cannot deliver the Services. |
| Consent | For optional features: WhatsApp booking channel; women-only gender processing; future biometric ID verification; promotional communications (e.g., birthday offers). You may withdraw consent at any time. |
| Legitimate interest | Fraud detection, platform safety, app diagnostics, analytics for service improvement – balanced against your privacy rights. |
| Legal obligation | Compliance with POPIA, NLTA, FICA (where applicable), tax legislation, and valid law enforcement requests. |
| Vital interest | In emergencies where processing is necessary to protect life or physical safety. |
Special Personal Information: Gender is classified as special personal information under POPIA Section 26. We process gender solely to enable the women-only driver preference feature and for anonymised statistical analysis. This is based on your explicit consent. You are not required to disclose your gender; if you do not, the women-only feature will be unavailable.
6. HOW WE USE YOUR INFORMATION
We use your personal information for the following specific purposes:
Creating, managing, and securing your Hike account.
Verifying your identity, age, and (for Drivers) professional credentials before account activation and continuously.
Matching passengers with available drivers or carpoolers.
Enabling Trip booking via the app and the optional WhatsApp channel.
Processing payments and distributing driver earnings.
Displaying profile photos and limited details to matched parties for identification at pickup.
Enabling the women-only driver preference safety feature.
Sending service communications: booking confirmations, receipts, safety alerts, and policy updates.
Sending optional promotional messages and birthday offers where you have consented.
Detecting, investigating, and preventing fraud, abuse, and safety incidents.
Conducting driver and vehicle vetting, including criminal background checks with consent.
Complying with our legal and regulatory obligations.
Improving the Platform through analytics using aggregated or anonymised data where possible.
Managing disputes, complaints, and insurance claims.
We do not use your personal information for automated decision-making that produces legal effects or significantly affects you without human intervention, except as disclosed (e.g., driver rating-based account suspension, which includes human review). We will provide meaningful information about the logic involved upon request.
7. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or trade your personal information. We only share it as follows:
7.1 Between Users on the Platform
To enable Trips, the following limited information is shared:
Passengers see: Driver’s first name, profile photo, vehicle make/model/colour, licence plate, and rating.
Drivers see: Passenger’s first name, profile photo, pickup location, and destination.
We do not share full contact details (phone number or email) directly between users. In-app messaging is routed through our Platform.
7.2 Service Providers (Operators)
We engage trusted third parties who process personal information on our behalf under strict data processing agreements. These agreements mandate that the service providers:
Process data only on our documented instructions.
Implement appropriate security measures.
Do not use the data for their own purposes.
Assist us in fulfilling data subject rights requests.
Comply with POPIA’s operator obligations.
Categories of operators include:
Payment processors (secure transaction handling)
Cloud infrastructure providers (data storage and compute)
Mapping and navigation providers (route and geocoding)
WhatsApp / Meta Business API (message transmission)
Customer support platforms
Background check bureaus (with your explicit consent)
Analytics providers (aggregated/ anonymised data only)
7.3 Regulatory and Law Enforcement
We may disclose personal information where necessary to:
Comply with a legal obligation or court order.
Respond to valid requests from law enforcement or regulatory authorities (e.g., the Information Regulator, SAPS).
Protect the safety, rights, or property of Hike, our users, or the public.
Report serious incidents to the police.
7.4 Business Transfers
If Hike is involved in a merger, acquisition, restructuring, or sale of assets, your personal information may be transferred to the acquiring entity. The recipient will be bound by obligations at least equivalent to this Policy, and we will notify you via email or in-app notification if such a transfer occurs.
7.5 With Your Consent
We will share your information for any other purpose not listed here only with your explicit prior consent.
8. WHATSAPP BOOKING CHANNEL
If you opt in to the WhatsApp-based booking channel:
Your registered Hike phone number is linked to your WhatsApp account via the Meta WhatsApp Business API.
Booking requests, confirmations, and related messages are transmitted through WhatsApp and processed by our systems.
Message content is used solely to process your Trip request and is retained in accordance with Section 10.
Meta processes message delivery under its own Privacy Policy. Hike is not responsible for Meta’s data practices.
You may deactivate this channel at any time via in-app settings or by contacting [email protected].
9. LOCATION AND BACKGROUND TRACKING
Location data is essential to the Services. By using the Platform:
Passengers: We collect foreground GPS location only when you have the app open to book a trip, and continuously during an active trip for live tracking and safety monitoring. Background location is not collected for passengers except when you explicitly enable the optional Emergency Contact Location Sharing feature (see below).
Emergency Contact Location Sharing (future): When introduced, this opt-in feature will share your live location with your nominated emergency contacts during an active trip. Background location access for this feature will be requested separately with your explicit consent.
Rideshare Drivers: We collect foreground location while the Driver App is active, and background location while you are “online” (available to receive Trip requests). Background location is used solely to broadcast your position to the dispatch system and ceases when you set yourself “offline.”
Carpool Drivers: We collect foreground location while the User App is active for managing a Lift, and background location while a Lift is in progress. This stops automatically when the Trip ends.
You can manage location permissions through your device settings. Disabling location services will prevent core functionality.
10. DATA RETENTION
We retain personal information only for as long as necessary for the purposes it was collected, or as required by law:
| Data Category | Retention Period |
|---|---|
| Active account data | For the duration of your account. |
| Trip and transaction records | 7 years from the date of transaction (tax and regulatory compliance). |
| Driver verification documents (ID, licence, permits, vehicle docs) | Duration of driver account, plus 5 years after last Trip or account closure (regulatory requirements). |
| Criminal background check results | Duration of driver account, plus 2 years after account closure. |
| Identity verification data (future biometric) | Duration of account, plus 1 year after closure. |
| Support tickets and complaint records | 3 years from closure of the matter. |
| Crash logs and diagnostics | 90 days (rolling). |
| Account data after deletion | Personal profile and preferences deleted or irreversibly anonymised within 30 days. Retained records limited to what is legally required (as above) and isolated from active processing. |
When data is no longer needed, we securely delete or anonymise it.
11. DATA SECURITY
We implement appropriate, reasonable technical and organisational measures to protect your personal information against unauthorised access, accidental loss, destruction, or damage. These include:
Encryption in transit (TLS 1.2+) and at rest where appropriate.
Role-based access controls and strict internal access policies.
Regular security assessments, vulnerability scanning, and penetration testing.
Intrusion detection and prevention systems.
Secure software development lifecycle with regular updates.
Data processing agreements with all operators that mandate equivalent security.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. In the event of a data breach that is likely to result in a high risk to your rights, we will notify you and the Information Regulator without undue delay as required by POPIA.
12. YOUR RIGHTS UNDER POPIA
As a data subject, you have the following rights:
Access – Request confirmation of whether we hold your personal information and a copy of it.
Correction – Request that we correct or update inaccurate or incomplete information.
Deletion – Request deletion of personal information we no longer have a lawful basis to retain.
Objection – Object to processing based on legitimate interest or for direct marketing.
Restriction – Request that we limit processing in certain circumstances.
Withdrawal of consent – Withdraw consent for processing that is based on consent (e.g., WhatsApp channel, gender processing). This does not affect the lawfulness of processing done before withdrawal. Withdrawing consent for essential processing (e.g., location for a Trip) will prevent delivery of those specific Services.
Data portability – Where technically feasible, request your data in a structured, commonly used format.
Complaint – Lodge a complaint with the Information Regulator of South Africa.
To exercise your rights, email us at [email protected] with the subject line “POPIA Request.” We will respond within a reasonable time, and no later than the timeframe required by law. We may need to verify your identity before acting on certain requests.
Information Regulator contact details:
Website: www.inforegulator.org.za
Email: [email protected]
Phone: +27 (0)10 023 5207
13. CHILDREN’S PRIVACY
The Services are strictly not intended for individuals under 18 years of age. We collect date of birth at registration to enforce this restriction. We do not knowingly collect personal information from minors. If we become aware that a person under 18 has registered, we will immediately delete their information and terminate the account. If you believe a minor has gained access, please contact us at [email protected].
14. INTERNATIONAL DATA TRANSFERS
Your personal information may be stored or processed in countries outside South Africa, including where our cloud service providers (e.g., Amazon Web Services, Google Cloud) or sub-processors maintain data centres. Such transfers are only made to countries with an adequate level of protection as determined by the Information Regulator, or where we have put in place appropriate safeguards, such as:
European Union Standard Contractual Clauses (SCCs), or
Binding corporate rules, or
Contractual obligations that impose conditions substantially similar to POPIA Section 72.
By using the Services, you acknowledge that your data may be transferred internationally, but only with the safeguards described here. We will provide further details upon request.
15. THIRD-PARTY SERVICES
The Services integrate with third-party platforms (payment gateways, mapping, WhatsApp). These third parties have their own privacy policies, which we encourage you to read. Hike is not responsible for the privacy practices of any third party, even if their services are accessed through our Platform.
16. PAYMENT INFORMATION
Payment processing is handled by secure, PCI-DSS certified third-party payment processors. We do not store full credit/debit card numbers, CVV codes, or internet banking credentials on our own servers. We retain only transaction metadata (amount, date, trip reference, payment method type) for billing, dispute, and tax purposes.
17. ACCOUNT DELETION
You may request account deletion at any time:
Via the in-app “Delete Account” function, or
By emailing [email protected].
Upon deletion:
Your personal profile, preferences, and credentials will be deleted or irreversibly anonymised within 30 days.
Certain data will be retained for the periods specified in Section 10 where we have a legal obligation (e.g., transaction records, driver documents).
Retained data will be isolated from active processing and used only for legal compliance purposes.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Policy from time to time. Material changes will be communicated via:
In-app notification,
Email to your registered address, and
An updated “Last Updated” date on this document.
Unless a change is required by law or addresses an urgent security matter (in which case it takes effect immediately), material changes will take effect 14 days after notification. Your continued use after that date constitutes acceptance. If you do not agree, you must stop using the Services and may request account deletion.
19. POPIA COMPLIANCE SUMMARY
We are committed to the eight processing conditions under POPIA:
Accountability – We take responsibility for compliance.
Processing limitation – We collect for specific, lawful purposes.
Purpose specification – We do not use data for incompatible purposes.
Further processing limitation – Further processing is compatible.
Information quality – We take steps to keep data accurate.
Openness – We maintain this Policy and notify you of changes.
Security safeguards – We protect your data with appropriate measures.
Data subject participation – We honour your rights.
20. CONSENT
By registering and using the Services, you:
Confirm you are 18 years or older.
Acknowledge you have read and understood this Privacy Policy.
Consent to the collection, use, and sharing of your personal information as described herein.
Provide specific consent (where prompted) for processing of special personal information (gender), for promotional communications, and for the WhatsApp booking channel.
You may withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Withdrawal for certain essential processing may limit your ability to use the Services.
21. CONTACT US
For any questions, concerns, or to exercise your data protection rights, please contact:
Hike Technologies (Pty) Ltd
Email: [email protected]
Phone: +27 68 814 8683
Website: hikeapp.co.za
© 2026 Hike Technologies (Pty) Ltd. All rights reserved.