Legal

PrivacyPolicy

What we collect, why we collect it, and what you can do about it.

Placeholder — not legally reviewed

This page contains placeholder text and details that have not yet been finalised or reviewed by an attorney. It should not be relied upon as a statement of your rights or our obligations, and it is not legal advice. The final version will replace it before the app and festival launch.

Effective: [EFFECTIVE DATE — e.g. 1 November 2026]

This policy explains what personal information rAge Nation collects through its website and mobile app, why, who we share it with, and the rights you have under South Africa's Protection of Personal Information Act. We have written it in plain language; if anything is unclear, tell us and we will fix the wording.

1. Who we are

rAge Nation is operated by [OPERATING COMPANY NAME] (Pty) Ltd (registration number [COMPANY REGISTRATION NUMBER]), trading as rAge Nation ("rAge Nation", "we", "us"). Our address is [PHYSICAL ADDRESS FOR SERVICE OF LEGAL DOCUMENTS].

We are the responsible party for your personal information under the Protection of Personal Information Act 4 of 2013 ("POPIA"). Our Information Officer is [INFORMATION OFFICER NAME], who can be reached at [INFORMATION OFFICER EMAIL]. For anything else, write to info@ragenation.gg.

2. What this policy covers

This policy covers the rAge Nation website at ragenation.gg, the rAge Nation mobile app for iOS and Android, and the services behind them. It does not cover Howler, which sells festival tickets under its own privacy policy, or any partner or exhibitor website you visit from the app.

3. What we collect

We collect only what the app and website need to work:

  • Account details: your email address, username and password. The password is stored only as a one-way cryptographic hash. If you sign in with Apple or Google, we receive your email address and an account identifier from them instead of a password.
  • Your date of birth, so we can apply the age gate, whether you are under 18, and whether a parent or guardian has approved your account.
  • A record of every consent you give or refuse: what it was for, the version of the wording you saw, where you gave it (onboarding or settings), when, and the IP address and device type it came from. We keep refusals too, because without them we cannot tell someone who said no from someone we never asked.
  • What you save in the app: favourite sessions and exhibitors. Reminders for saved sessions are scheduled on your device and do not leave it.
  • Check-ins: when you scan a code at a stand or stage, the code you scanned, when you scanned it, an identifier for your device, and how long the scan waited offline before it reached us. We use these to verify the check-in and to detect cheating.
  • XP, quests and your leaderboard position, and the reasons behind each XP award or adjustment.
  • Quickdraw duels: the motion-sensor readings from your phone at the moment of the shot (tilt, rotation and reaction time), the height and distance settings you chose, the result, and your opponent's username.
  • Crew check-ins: when festival crew scan the personal code in your app, a record of which crew member scanned you, where and when.
  • Your ticket, if you verify one for XP: you enter the code printed on your Howler ticket, and we send it to Howler to check that it is a genuine, valid ticket. We keep Howler's reference for that ticket, its type, the days it is valid and its status — so that one ticket earns XP on only one account. We do not keep the ticket code itself, and the app does not store or display your ticket: Howler's own ticket is what gets you in.
  • Notifications: a push notification token for your device, if you allow notifications, and your notification preferences.
  • Diagnostics: app version, device model, operating system, and crash reports, which include your account identifier and email address so we can help you if something breaks.
  • Analytics about how the app is used, such as which screens are opened — only if you have agreed to it (see section 8).
  • Anything you send us, such as a support email.

4. What we do not collect

We do not track your location. The venue map is a floorplan measured in its own units, not a geographic map, and the app does not read your device's GPS.

The camera is used only while a scanning screen is open, to read QR codes. No photos or video are stored or sent to us.

We never see your payment details. Tickets are sold by Howler on the web; the app contains no in-app purchases and takes no payment.

We do not sell your personal information, and we do not share it with advertisers.

5. Why we use it, and on what basis

POPIA allows personal information to be processed only for a lawful reason. Ours are:

  • To provide the service you signed up for (POPIA s11(1)(b)): your account, schedule, saved items, reminders, tickets, check-ins, XP, quests, duels and the venue map.
  • Our legitimate interests (s11(1)(f)): keeping accounts secure, verifying check-ins and detecting cheating so a leaderboard with real prizes is fair, fixing crashes, and running the festival safely.
  • Your consent, which you may withdraw at any time (s11(1)(a)): product analytics and direct marketing. For anyone under 18, consent comes from a parent or guardian (see section 6).
  • Legal obligations (s11(1)(c)): keeping records the law requires, and responding to lawful requests from authorities.

6. Children and young attendees

You must be at least 13 years old to create an account. If you are under 13, you cannot use the app's account features, and we delete any account we learn belongs to someone under 13.

If you are 13 to 17, POPIA treats you as a child, and we process your personal information only as the law allows for children (POPIA s34 and s35), including with the consent of a parent or guardian where it is required. Until a parent or guardian has approved your account, the app does not offer you analytics or marketing consents at all — they stay off.

A parent or guardian may ask to see, correct or delete the personal information of a child in their care, or withdraw any consent given for them, by writing to [INFORMATION OFFICER EMAIL].

7. Direct marketing

We send marketing — news and offers from rAge Nation and its partners — only if you have opted in (POPIA s69). The choice starts switched off, and you can change it at any time in the app under Settings, or by using the unsubscribe link in any marketing email. We record both a yes and a no so we can prove which you chose.

Messages about your account, your ticket, or changes to sessions you saved are not marketing and are sent as part of the service.

8. Analytics, crash reporting and tracking

Product analytics (PostHog) run in the app only after you agree to them, and on iOS only if you also allow App Tracking Transparency. Until then the analytics service is not started at all. Events are linked to your account identifier and username so we can tell one person's session from another's, not to follow you across other apps or websites.

Crash reporting (Sentry) is used to find and fix faults. Crash reports include your account identifier and email address.

You can switch analytics off at any time in the app under Settings, and on iOS also in the system Settings under Privacy & Security → Tracking.

The website uses PostHog analytics, which stores an identifier in cookies or your browser's local storage to recognise returning visitors. Session recording is switched off. You can clear or block these in your browser settings.

9. Automated decisions

Check-ins, quests and duels are checked automatically for signs of cheating — for example, shared codes, impossible travel between stands, one device used by several accounts, or scans that arrive long after they were made. Based on that, a check-in may be accepted, held for review, or refused, and XP may be withheld from the leaderboard. Because this can affect whether you win a prize, you may ask for any such decision to be reviewed by a person, and make representations about it (POPIA s71), by writing to us.

10. Who we share it with

We share personal information only with service providers (operators) who process it for us under contract, and only what each one needs:

  • Fly.io — runs our API servers, in Johannesburg.
  • Amazon Web Services — our database and file storage, in the European Union (Ireland).
  • Resend — sends account emails such as password resets.
  • PostHog — product analytics, only with your consent.
  • Sentry — crash and error reporting.
  • Expo — delivers push notifications to your device.
  • Apple and Google — only if you choose to sign in with them, and only to authenticate you.
  • Howler — to check that a ticket code you enter is a genuine, valid ticket.
  • Festival crew at the event, who see your username when they scan your personal code to check you in.

11. What other attendees can see

Your username appears on the leaderboard and to your opponent in a Quickdraw duel. Your email address, date of birth and ticket are never shown to other attendees. Choose a username you are happy for other people to see.

12. Information sent outside South Africa

Some of the operators above store or process information outside South Africa, including in the European Union and the United States. We transfer information across borders only where POPIA s72 allows it — to recipients bound by laws, binding corporate rules or contractual terms that give protection substantially similar to POPIA, or where the transfer is necessary to provide the service you asked for.

13. Keeping it secure

We protect personal information with reasonable technical and organisational measures (POPIA s19). Connections to our API are encrypted and certificate-pinned, passwords are hashed, ticket codes are checked with Howler and never stored, session tokens are kept in your device's secure storage, and you can add a biometric lock to the app in Settings.

No system is perfect. If we have reasonable grounds to believe your personal information has been accessed or acquired by someone unauthorised, we will notify the Information Regulator and you as soon as reasonably possible, as POPIA s22 requires, and tell you what we are doing about it.

14. How long we keep it

We keep personal information only as long as we need it for the purposes above, or as the law requires (POPIA s14):

  • Your account and the data attached to it: while your account exists. When you delete your account we delete or de-identify it within [30] days.
  • Consent records: [5] years after your account is deleted, as evidence of what you agreed to or refused.
  • Leaderboard and prize records, including the check-in evidence behind a prize: [3] years after the competition closes.
  • Server logs: [90] days. Backups: [35] days, after which deleted data is gone from them too.
  • Anonymous statistics that can no longer identify you may be kept longer.

15. Your rights

Under POPIA you have the right to:

  • Ask whether we hold personal information about you, and for a copy of it (s23). In the app: Settings → Your data → Export my data.
  • Ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (s24).
  • Delete your account and its personal information (in the app: Settings → Your data → Delete account). This is permanent.
  • Object to processing based on our legitimate interests, and to direct marketing, at any time (s11(3)).
  • Withdraw a consent you gave earlier, without affecting processing that happened before you withdrew it.
  • Not be subject to a decision based solely on automated processing without being able to make representations about it (s71).
  • Complain to the Information Regulator (see section 17).

16. How to exercise your rights

Most of this is available directly in the app. For anything else, write to our Information Officer at [INFORMATION OFFICER EMAIL]. We may need to confirm your identity before acting, and will respond within a reasonable time. Requests for records are also handled under the Promotion of Access to Information Act 2 of 2000 (PAIA); our PAIA manual is available at [URL OF PAIA MANUAL].

17. Complaints

If you are unhappy with how we have handled your personal information, please tell us first at [INFORMATION OFFICER EMAIL] and we will try to put it right. You also have the right to lodge a complaint with The Information Regulator (South Africa): https://inforegulator.org.za, POPIAComplaints@inforegulator.org.za (complaints) or enquiries@inforegulator.org.za (general enquiries), [VERIFY CURRENT ADDRESS ON inforegulator.org.za].

18. Changes to this policy

We may update this policy when the app, the website or the law changes. The effective date at the top changes when we do. If a change affects how we use information you have already given us, we will tell you in the app and, where the law requires it, ask for your consent again.