Privacy Policy

Last updated: 18 September 2026 · Version 1.2

This policy explains how Digital Blast Media (Pty) Ltd, trading as FreightOps ("we", "us") handles personal information on this website (freightops.co.za) and in the FreightOps application (app.freightops.co.za and the FreightOps driver app), in line with the Protection of Personal Information Act 4 of 2013 ("POPIA").

1. Who we are

Digital Blast Media (Pty) Ltd t/a FreightOps (registration number 2016/387590/07), a private company registered in South Africa. Our Information Officer is registered with the Information Regulator (registration number 2026-061664). Contact: sales@digitalblastmedia.co.za · 079 695 4062. Our registered address is given in full on request and in every agreement we sign.

2. What we collect, and why

Roles under POPIA: for driver and operational data, the transport company using FreightOps is the responsible party and Digital Blast Media is the operator — we process that data only on the client's instructions, under a written operator agreement.

3. Cookies and browser storage

We do not use tracking cookies — in fact, we set no cookies at all. There are no analytics, advertising, or social-media trackers on this website or in the FreightOps dashboard.

If we ever introduce analytics or marketing tools that use cookies, we will ask for your consent first.

4. Where your data is stored

FreightOps data is hosted on Supabase in the European Union (Ireland, AWS eu-west-1). This is a transfer of personal information outside South Africa as contemplated by section 72 of POPIA. We rely on section 72(1)(a): the EU provides an adequate level of protection through the GDPR, which imposes obligations substantially similar to (and in many respects stricter than) POPIA. This is supported by our data-processing terms with Supabase and the operator agreements we sign with each client.

Every night we copy the database and uploaded files to a second location so that the service can be rebuilt if Supabase fails. That copy is encrypted before it is stored, with a key only we hold, and kept in Cloudflare storage in the European Union. The copy is made by a job that runs on GitHub's hosted computers, whose location GitHub does not publish; the data is encrypted on that computer in the same run and is not kept there.

Application error reports (technical diagnostics, not operational data) are processed by Sentry in the EU (Germany), configured not to send personal information by default.

Emails we send — password resets, tracking links and delivery notifications — go through Resend, a United States company. Those emails carry names, email addresses and load references, never location records or receipt photos. Resend keeps its account records and email logs in the United States. For this transfer we rely on Resend's data-processing terms under section 72(1)(a) of POPIA.

The place names typed on a load (for example a depot or a border post) are sent to Google's geocoding service to find their map coordinates. Place names are not personal information.

Receipt photos sent for automated reading are processed by Anthropic, PBC in the United States. This is a second transfer outside South Africa under section 72 of POPIA. The United States does not have a general adequacy standing like the EU, so for this transfer we rely on section 72(1)(a)'s binding agreement limb: Anthropic's commercial terms and data-processing addendum bind it to confidentiality, purpose limitation and security safeguards substantially similar to POPIA's conditions. Under those terms Anthropic does not use our data to train its models, and keeps it only for a limited period for safety monitoring. Only the receipt photo goes to Anthropic — never GPS locations, account details or load records — and only when a user chooses to have it read.

5. Service providers we use

We do not sell personal information, and we do not use it for advertising.

6. Your rights

Under POPIA you may:

To exercise any of these rights, contact our Information Officer, Revendran Pillay, at sales@digitalblastmedia.co.za. If your request concerns data processed on behalf of one of our client companies (for example, driver location data), we will assist and refer you to that company, which is the responsible party for that data.

7. How long we keep it

Operational data is kept for as long as the client company's account is active. When an account ends, the client may ask for an export or deletion within 30 days; if they do not, we delete the data within 90 days. Copies in our encrypted backups are overwritten within 35 days after that. Website contact-form messages are kept only as long as needed to respond.

8. Changes to this policy

We will update this page when our practices change and revise the "Last updated" date and version above.