Privacy Policy
This Policy explains how The House Edge (Pty) Ltd processes personal information through DealerStack, in line with the Protection of Personal Information Act 4 of 2013 (POPIA) and the Electronic Communications and Transactions Act 25 of 2002 (ECTA).
Draft pending lawyer review
This Policy has not yet been reviewed by a South African tech lawyer. It reflects current product behaviour but should not be relied on as final legal text until that review is complete.
Last updated: 25 April 2026
1. Who is the responsible party
The House Edge (Pty) Ltd is the responsible party for personal information collected through the DealerStack marketing site, signup flow, dealer admin, and supporting communications.
Where DealerStack processes personal information on a dealer's behalf — for example dealer staff login data and anonymised analytics on the dealer's public site — DealerStack acts as an operator under POPIA, and the dealer is the responsible party for that data.
Responsible party information
- Legal name
- The House Edge (Pty) Ltd
- Legal status
- Private company registered in South Africa
- Registration number
- 2025/950798/07
- Physical address
- 105 Bokmakierie Street, Rooihuiskraal, Centurion, 0157, South Africa
- Information Officer
- privacy@dealerstack.co.za
- Telephone
- +27 67 129 2258
2. Information Officer
POPIA requires every responsible party to designate an Information Officer. The Information Officer for The House Edge (Pty) Ltd is the company director, contactable at privacy@dealerstack.co.za.
The Information Officer is registered (or in the process of being registered) with the Information Regulator of South Africa as required by POPIA.
3. What personal information we collect
We collect different categories of personal information depending on how a person interacts with DealerStack.
Visitors to the marketing site (www.dealerstack.co.za)
- Information you give us when you start a signup or contact us: dealership name, contact name, email address, phone number, and anything you choose to add in a free-text field.
- Anonymous browsing information collected by analytics tools (where enabled): hashed IP address, browser type, referring URL, pages viewed, and a randomly generated session identifier. This is used to understand how the site is used in aggregate, not to identify individual visitors.
Dealer staff with a DealerStack account
- Account information: name, work email address, role within the dealership, and a securely hashed password.
- Activity logs that record administrative actions taken in DealerStack (for example creating a vehicle listing, changing a price, or inviting a colleague), together with a timestamp and the account that performed the action.
- Support communications you send us by email or other channels.
Buyers visiting a dealer's public DealerStack site
- Anonymous click-event information when you tap a WhatsApp, telephone, or vehicle action: a hashed IP address, user-agent string, referring URL, and a randomly generated session identifier.
- DealerStack does not capture your name, phone number, email address, or the contents of any WhatsApp message. WhatsApp links open the WhatsApp app on your device and route the conversation directly to the dealer.
Information from third parties
- Payment status, billing reference numbers, and the last four digits of a card from PayFast or another payment provider when a dealer subscribes. We do not receive or store full card numbers or card security codes.
4. Why we process personal information
We process personal information for these purposes:
- To provide, secure, and improve DealerStack and its features.
- To create and manage dealer accounts, authenticate users, and keep audit records of administrative actions.
- To respond to signup enquiries and provide customer support.
- To process subscription payments and send transactional emails such as password resets and signup confirmations.
- To produce anonymised analytics that help dealers understand activity on their public sites.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with our legal, tax, accounting, and regulatory obligations in South Africa.
- To send service announcements (such as planned downtime or material changes to these Terms or this Policy). Marketing emails, where we send them, are sent only with consent and can be opted out of at any time.
5. Lawful basis under POPIA
Processing is justified under one or more of the following grounds in POPIA Section 11:
- Performance of a contract with the dealer (for example, providing the service the dealer has subscribed to).
- Compliance with a legal obligation (for example, retaining tax invoices).
- Our legitimate interests, balanced against the rights of the data subject (for example, securing the platform against fraud or abuse, or producing anonymised analytics).
- Consent, where required (for example, optional marketing emails).
6. Who we share information with
We share personal information only with carefully selected service providers who help us run DealerStack. These currently include:
- Hosting and infrastructure providers used to operate the DealerStack platform and database.
- Resend for sending transactional emails such as password resets and signup confirmations.
- PayFast for processing subscription payments.
- Google Analytics for anonymised website analytics (only when enabled).
We may also share information with our professional advisors (including lawyers, accountants, and auditors), or with regulatory or law-enforcement authorities where we are legally required to do so.
DealerStack does not sell personal information.
7. Where we store and process information
DealerStack data is hosted on infrastructure based in or near South Africa where reasonably practical. Some service providers (such as email delivery and analytics) may process personal information outside South Africa. Where this happens we rely on the cross-border transfer grounds in POPIA Section 72, including provider commitments to a comparable level of data protection.
8. How long we keep information
We keep personal information for as long as we have a relationship with the dealer or visitor, and for the period after that needed to meet our legal, tax, accounting, security, and audit obligations.
Anonymised analytics events are kept for product analytics purposes. Account records are typically kept for at least five years after the end of the dealer relationship in line with South African tax-record rules. We delete personal information that we no longer need.
9. Your rights as a data subject
Under POPIA, you have the right to:
- be told what personal information we hold about you;
- request a copy of that information;
- ask us to correct or delete inaccurate or out-of-date information;
- object to processing on grounds permitted by POPIA, including processing for direct marketing;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Information Regulator (see Section 13).
To exercise any of these rights, email privacy@dealerstack.co.za. We may need to verify your identity before acting on a request.
10. Cookies and similar technologies
DealerStack uses a small number of cookies and similar storage to run the service.
- Essential session cookies are used to keep dealer staff logged in to the admin and to keep the public dealer site working correctly. These cannot be turned off without breaking the service.
- Analytics cookies and identifiers are used to record anonymised page views and click events. Where Google Analytics is enabled, IP addresses are anonymised before storage.
Most browsers let you control or block cookies through their settings. Blocking essential cookies will prevent the service from working properly.
11. Security
We take reasonable technical and organisational steps to protect personal information against loss, unauthorised access, alteration, and disclosure. These include encrypted transport (HTTPS), hashed passwords, access controls on production systems, regular dependency updates, and monitoring of unusual activity.
No system is completely secure. If we become aware of a security compromise that affects personal information, we will notify the Information Regulator and affected data subjects as required by POPIA Section 22.
12. Changes to this Policy
We may update this Policy from time to time. The updated version will be posted on this page with a new last-updated date. Continued use of DealerStack after a change means you accept the updated Policy.
13. Complaints and the Information Regulator
If you have a privacy concern, please contact us first at privacy@dealerstack.co.za so we can try to resolve it.
You also have the right to lodge a complaint with the Information Regulator of South Africa: inforegulator.org.za.
14. Contact
Privacy queries: privacy@dealerstack.co.za.
General queries: support@dealerstack.co.za.
Telephone: +27 67 129 2258.