Jols Privacy Policy
Effective date: 21 September 2026
This Privacy Policy explains how JOLS (PTY) LTD ("Jols", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Jols mobile application, the Jols website at jols.co.za (including the checkout pages and the venue portal), and related services (together, the "Service").
Jols is a South African social event-discovery app that helps you find parties and events ("jols"), discover venues, and go out with your friends.
We are committed to processing your personal information lawfully, fairly, and transparently in accordance with the Protection of Personal Information Act, 2013 ("POPIA") of South Africa. Where the General Data Protection Regulation ("GDPR") or similar laws apply to you, this Policy is also intended to support those rights (see Section 12).
By creating an account or using the Service, you confirm that you have read and understood this Policy. Where we rely on your consent, we ask for it separately and clearly.
What changed in this version
- Contacts: the "Find Friends from Contacts" feature has been removed. Jols no longer reads your phone's contacts (old Section 2.3 is gone).
- Location: we now describe exactly how location works. Jols only uses your location while the app is open. Your location is shown to friends only as a one-time snapshot when you choose to go out or check in, and only after you agree to appear on the map. New accounts start hidden. Discover now uses your location to sort venues and jols by distance.
- Venues (new Section 5.1a): what venue owners and their staff can see when you join a guest list, buy a ticket, RSVP to a venue's jol, follow a venue or check in.
- Tickets and payments (new Section 2.3): what we collect when you buy a ticket, who receives it, and how refunds work.
- Service providers: the full, current list, including Sentry, Paystack, Google, Apple, Vercel and Upstash, and where they process data.
- Where your data is stored: our main database is hosted in Ireland (European Union), not the United States (see Section 7).
- Moderation and safety (new Section 6): reports, content removal, the 90-day restricted hold for removed content, evidence we keep about banned accounts, and our admin audit trail.
- Retention: a clearer table of how long we keep each kind of information.
- Contact: all privacy requests now go to admin@jols.co.za.
- Wrap-ups: ratings, "vibe tags" and other post-jol voting have been removed from the app, and from this Policy.
1. Who we are (Responsible Party / Controller)
For the purposes of POPIA, the Responsible Party for your personal information is:
- Legal entity: JOLS (PTY) LTD
- Registration number: 2026/572774/07
- Registered address: 11 Audocia Place, Hurlingham Ext 5, Sandton, Gauteng, 2196
- Information Officer: Luca McKay
- Privacy and support email: admin@jols.co.za
Our Information Officer makes sure we comply with POPIA, handles your requests, and deals with the Information Regulator. You can contact the Information Officer using the details above.
2. The personal information we collect
We only collect personal information that we need to provide and improve the Service. The categories below describe what we collect and why.
2.1 Information you give us directly
| Information | Why we collect it |
|---|---|
| Email address | To create and secure your account, log you in, and send essential service messages (for example, sign-in and password-reset emails). |
| Date of birth | To confirm you are 18 or older when you sign up (see Section 11). It is not shown to other users. |
| Profile information | The username, profile photo, and short bio you choose. |
| Phone number (only if you sign in with your phone) | Phone-number sign-in is not currently offered in the app. If we offer it in future and you use it, your number is used to sign you in with a one-time code. Our systems also store a one-way, keyed hash of the number. Jols does not use your phone number to match you with other people. |
| User-generated content | Jols you create, photos you upload to jols, chat messages, polls, rules and other in-jol activity, photo tags, photo likes, friend requests, jol invites and join requests. |
| Guest lists | When you join or ask to join a venue's guest list: the list, how many plus-ones you are bringing, and your status (requested, approved, declined, checked in). See Section 5.1a. |
| Follows and interests | The venues and artists you follow, and the interests you pick, so we can show you relevant jols and notifications. |
| Reports and blocks | When you report content or a user, or block someone: what you reported, the reason you chose, and any details you add; and the list of people you have blocked. |
| Support messages | What you send us by email, and our replies. |
2.2 Location information
Jols asks for location permission only while you are using the app ("When In Use"). Jols never asks for background ("Always") location, and it does not track you while the app is closed.
What happens with your location:
- On your device: with your permission, the app reads your location to centre the map on you and to find jols, venues, and friends near you.
- Sent with a request, not saved: to show what is nearby, the app sends your current coordinates to our servers with each map or Discover request. Discover uses your location to sort venues and jols by distance, nearest first, and to show how far away each one is. If nothing is near you, Discover shows Johannesburg content instead and tells you so. We use these coordinates to answer the request. We do not save them to your profile. Discover uses your device location only to sort and filter results by distance; it is not stored.
- Shared with friends only when you choose to: your location is only shown to others when you tap Going Out or check in at a venue. Each time, the app takes one location reading (a snapshot) and saves it to your profile. It does not keep updating it as you move. The pin stays where it was until you share again.
- Explicit map consent first: the first time you go out or check in, Jols asks whether you agree to be shown on your friends' map. If you say no, nothing is shared. You can withdraw this consent in Profile → Settings → Privacy at any time. Withdrawing it also hides you and deletes your saved snapshot.
- Hidden by default ("Ghost Mode"): new accounts start Hidden. While you are Hidden, nobody else sees your map pin, your presence at a venue, or that you are going out. Switching to Hidden also deletes your saved snapshot and ends any active "going out" status. (Hidden never limits what you can see.)
- Who can see it: only people you are friends with, only while your "going out" or check-in status is active and has not expired, and never anyone you have blocked or who has blocked you. When you stop going out or check out, we delete the saved snapshot.
- Venue presence: while you are checked in or going out to a venue and you are not Hidden, your friends may see your profile photo on that venue's page. Other users only see a general "how busy" indicator, never who you are.
You can turn off location permission at any time in your device settings. Map, "near me" and distance features will not work without it, but you can still use the rest of Jols.
2.3 Tickets and payments
When you buy a ticket to a jol:
- In the app you choose tickets and create an order. The app then opens a secure checkout page on jols.co.za, where you pay through Paystack.
- We collect: your order (the jol, ticket types, quantities, prices, order reference, status, and the time it was placed, paid or refunded), the tickets issued to you, and each ticket's entry status (valid, scanned, refunded). We use the email address on your account for your payment receipt. If your account has no email, the checkout page asks for one.
- We do not collect or store your card details. You enter them directly with Paystack, which processes the payment. Paystack is a regulated payment provider and handles card data under its own security standards and privacy notice.
- Refunds: if an organiser cancels a jol, we record the refund request, the Paystack refund reference, and the refund outcome, and we send you notifications about it.
- Who receives ticket data: see Section 5.1a. The venue that runs the jol sees your username against your order and tickets. It does not receive your email address, phone number, or card details from us.
2.4 Information we collect automatically
| Information | Why |
|---|---|
| Push notification token | A device identifier (via Expo) that lets us send you the notifications you have turned on, such as friend requests, chat messages, jol updates, and ticket and refund updates. |
| Crash and diagnostic data | If the app or website crashes, Sentry receives a technical report: device type, operating system, app version, and the error. Reports from the app also include your internal Jols account ID (a random identifier, not your name or email). We set Sentry not to collect personal information by default (such as IP addresses or cookies). |
| Authentication and security data | Session and sign-in data handled by our authentication provider. For rate limiting on the website, we also briefly use the IP address a request comes from (see Section 5.2). |
| Activity in the Service | For example check-ins, RSVPs and "going out" statuses, and when you last read a jol chat. We need these for the features to work. |
2.5 Information from third-party sign-in
If you sign in with Sign in with Apple or Google, we receive basic profile information (such as your name and email address) from that provider, according to the permissions you grant. With Apple, this may be a private relay address if you choose "Hide My Email". We never receive your password for those accounts.
2.6 Venue owners, venue staff, and artists
If you run a venue on Jols, or are added to a venue's team:
- Account and role: your Jols account, the venues you manage, and your role (owner, manager, or door).
- Venue business details: the venue's profile, hours, menu, jols, guest lists, and broadcasts. For payouts, Paystack receives the business name and bank details you give during payout setup. Jols stores only the Paystack reference for that payout account, not your bank account number.
- Plan and billing: your plan, its dates, and payment status (from Paystack, or from your EFT arrangement with us).
- Business contact sheet: our team may keep a contact name, phone number, and email for the venue so we can support it. Only our admin team can see this.
2.7 Visitors to jols.co.za
- Sign-up and interest forms: if you register interest as a venue (venue name, email, optional phone number, venue type), as an artist (name, email, optional phone number, type of act, links), or join the waitlist (email), we keep what you submit so we can contact you about Jols.
- Cookies and similar technologies: the venue portal uses strictly necessary cookies to keep you signed in. The website also uses Vercel Web Analytics in its default, cookieless configuration to count page views in aggregate so we can see which pages are used; it does not set cookies or use a per-visitor identifier. We do not use advertising or cross-site tracking cookies.
We do not intentionally collect special categories of personal information (such as health, religion, or political views). Please do not post such information in your content.
3. How we use your personal information (Purpose)
We process your personal information for the following purposes:
- To provide the core service: create your account, show jols and venues on the map and in Discover (sorted by distance when you allow location), let you create and join jols, chat, share and tag photos, follow venues and artists, join guest lists, and buy tickets.
- To connect you with friends: friend requests, jol invites and suggestions, "going out" statuses, check-ins, and "you're both out" nudges. All of these follow your Hidden / Visible setting.
- To send notifications: friend requests, messages, jol updates, guest-list decisions and reminders, ticket and refund updates, and (only if you have them switched on) news from venues you follow and from Jols. You can turn each type on or off in Profile → Settings → Notifications.
- To sell tickets for organisers: take payment, issue your tickets, let the venue's door staff scan them, and process refunds when a jol is cancelled.
- To provide venue tools: guest lists, door check-in, ticket sales reports, aggregated analytics, and broadcasts for venues on a Jols plan.
- To keep the Service safe and secure: review reports, remove content, suspend or ban accounts, prevent fraud, abuse, spam, and unauthorised access, and enforce our Terms of Service.
- To fix and improve the Service: diagnose crashes and understand which features are used.
- To comply with the law: meet our legal, tax, and regulatory obligations.
We will not use your personal information for a new, incompatible purpose without telling you and, where required, getting your consent. We do not use your personal information for advertising, and we do not build advertising profiles.
4. Lawful basis for processing (POPIA)
We process your personal information only where we have a lawful basis to do so under POPIA. Depending on the activity, we rely on:
- Your consent: for optional features such as location, appearing on your friends' map, push notifications, and news from Jols. You can withdraw consent at any time (see Section 10).
- Performance of a contract: to deliver the Service you signed up for, including your account, the app's core features, and tickets you buy.
- Our legitimate interests: to keep the Service secure, moderate content, prevent abuse, and improve our features, balanced against your rights.
- Legal obligation: where the law requires us to process or keep information (for example, financial records of ticket sales).
When you accept our Terms of Service and this Policy (at sign-up, and again whenever we publish a new version), we keep a timestamped record of which version you accepted, as evidence of your agreement.
We also follow the eight conditions for lawful processing under POPIA: accountability; processing limitation; purpose specification; further-processing limitation; information quality; openness; security safeguards; and data-subject participation. This Policy is designed to give effect to those conditions.
5. How we share your information
We do not sell your personal information. We share it only as described below.
5.1 With other users
Some information is shared with other users as part of how the app works:
- Your profile (username, photo, bio) is visible to other users.
- Your content (jols you create, chat messages, photos, photo tags, polls) is visible to the relevant audience in the app, for example the people in a jol.
- Your location snapshot and "going out" status are visible to your friends only, and only as described in Section 2.2. Nothing is shown while you are Hidden.
- Whether you are going to or interested in a jol may be visible to other people in that jol.
5.1a With venues you interact with
Venues on Jols (the venue owner, and staff the owner adds as managers or door staff) can see some of your information when you interact with their venue:
| When you… | What the venue's staff can see |
|---|---|
| Join or ask to join a guest list | Your username, how many plus-ones you are bringing, your status (requested / approved / declined), and whether you have been checked in at the door. Door staff only see approved names. |
| Are added to a VIP guest list by the venue | The name (and, if the venue adds one, a phone number) that the venue itself typed in. Jols never gives venues the phone number on your account. |
| Say you're going to, or interested in, a jol that the venue runs | Your username, profile photo, and whether you are going or interested. This applies even if you are Hidden, because you RSVP'd to that venue's own jol. |
| Buy a ticket to the venue's jol | Your username against your order, what you bought and paid, the order status (paid, refund requested, refunded), and whether each ticket has been scanned at the door. |
| Follow the venue | Only the total number of followers. Venues cannot see who follows them. |
| Check in at the venue | Only totals in the venue's analytics (for example check-ins per day, unique visitors, busiest hours). Venues cannot see who checked in through analytics. |
| Read a venue's broadcast | Only the total number of people who received and opened it. |
Venue staff can only see this through Jols' venue tools, and only for their own venue. Their access depends on their role and the venue's plan. Venues must use this information only to run their guest lists, door, and events, and in line with POPIA.
Messages from venues. If you follow a venue, it can send you up to two broadcasts a week under "Messages from venues you follow", and you may get a notification when it posts a new jol under "Venues you follow". That second notification also goes to people who checked in at the venue in the last 90 days while Visible. Both are on by default, and you can switch either off in Profile → Settings → Notifications. Venues never get your contact details to send these messages; they go through Jols.
5.2 With our service providers (Operators / Processors)
We use trusted third parties to run the Service. They process personal information on our behalf and under our instructions:
| Provider | Role | What they process | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage, realtime and server functions | Account data, content, uploaded photos, tickets and orders, location snapshots, authentication data | Ireland (EU) |
| Mapbox | Maps | Map display and map requests from your device, which include your approximate location and device information | United States |
| Sentry | Crash and error diagnostics | Technical crash reports and your internal account ID. No names, emails or IP addresses by default | European Union (Germany) |
| Paystack | Payments (ticket checkout on jols.co.za; venue plan billing) | Payment details you enter with Paystack, your receipt email, order amounts and references, refunds; for venues, payout and subscription details | Paystack's own infrastructure |
| Apple (Sign in with Apple; Apple Push Notification service) | Sign-in; delivering notifications to iPhones | Sign-in identifiers and email; push tokens and notification content | Apple's infrastructure |
| Google (Google Sign-In; Firebase Cloud Messaging on Android) | Sign-in; delivering notifications to Android devices | Sign-in identifiers and email; push tokens and notification content | Google's infrastructure |
| Expo | App updates and the push-notification relay | Push tokens and notification content; app update requests | United States |
| Vercel | Hosting of jols.co.za (website, checkout pages, venue portal) and aggregated page-view analytics | Website requests, including IP address and browser information, and aggregated page views | United States (Vercel's default region for new projects, Washington, D.C. — iad1; no custom region is set in our project) |
| Upstash | Rate limiting on the website to stop abuse | The IP address of requests to sign-in, forms and checkout, kept briefly as a counter | Ireland (EU) |
| Email provider | Sending service emails such as receipts and sign-in links | Your email address and the message content | We do not yet use a separate email provider. Sign-in and account emails are sent through Supabase Auth's built-in mailer (Ireland, EU — see the Supabase row above). We will update this Policy when we add another provider. |
| Twilio | Not currently used | — | Phone sign-in is switched off in the app, so Twilio is not currently used. |
5.3 For legal and safety reasons
We may disclose information where we reasonably believe it is necessary to comply with the law, respond to lawful requests from authorities, enforce our Terms, or protect the rights, safety, and property of users, the public, or Jols.
5.4 Business transfers
If Jols is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in the Responsible Party.
5.5 No selling, no advertising tracking
- We do not sell or rent your personal information.
- We do not use your information for targeted advertising, and we do not share it with advertisers or data brokers.
- The app does not track you across other companies' apps or websites, and it does not access your device's advertising identifier (IDFA).
6. User content, reports, and moderation
Your content. Photos and other content you upload are stored with our hosting provider (Supabase). Content you share may be seen by other users. Do not upload photos of other people without their consent, and follow our Terms of Service rules on content. We remove location data (EXIF) from photos in the app before they are uploaded. Videos you upload may still contain metadata (such as where they were recorded) that we do not currently remove; consider turning off location tagging in your camera settings before sharing a video.
Reporting and blocking. You can report users, jols, photos, chat messages, and other content in the app, and block other users. When you report something, we record who reported it, what was reported, the reason, and any details you add. We do not tell the reported person who reported them. Blocking hides you and the blocked person from each other in the app.
Review and removal. Our team reviews reports. If content breaks our Terms, we remove it and may suspend or ban the account. When we remove a photo, message, or jol:
- a copy of it (and closely linked data, such as tags on a removed photo) is moved into a restricted, admin-only store, separate from the app. Removed files go to a private storage area. Other users, and the person who posted it, can no longer see the content;
- we keep it there for up to 90 days, so we can reverse a mistake, deal with an appeal, or meet a legal obligation. After that it is permanently deleted by an automatic nightly process. We keep only a short record that something was removed, when, why, and by whom.
Banned accounts. If we ban an account:
- the account can no longer sign in or use the Service. Its public profile is replaced with a placeholder and hidden from the map, and its push-notification tokens are deleted;
- its photos, messages, and the jols it hosted are removed as described above (and deleted after 90 days);
- we keep the account's identifying information (email address, phone number and its hash, and a copy of the original profile: username, photo, and bio) as evidence for as long as the ban stands. This is not on the 90-day timer, so that a ban can be reviewed or reversed;
- you cannot delete a banned account from the app while the ban stands. You can still email us to ask for your information to be erased. We will decide each request by weighing it against our need to keep evidence (for example, to stop the same person coming back, or where there is a legal claim or a request from authorities).
If a ban is lifted, the account and profile are restored.
Admin audit trail. Every moderation action (removal, restore, ban, unban) is logged: which admin acted, what they did, to what, when, and why. This keeps our own team accountable. Only our admin team can see this log.
Today, every removal is a decision made by a person after a report. We do not use automated scanning of your content.
7. Cross-border transfers
Our main database, authentication, and file storage are hosted by Supabase in Ireland (European Union). Some of our other service providers process personal information in the United States (Mapbox, Expo, Vercel), the European Union (Sentry, in Germany), and elsewhere, as listed in Section 5.2.
Where your information is transferred outside South Africa, we take reasonable steps to make sure it is protected to a standard consistent with POPIA (section 72). We use providers that are subject to laws, binding corporate rules, or binding agreements that give adequate protection. Where the law requires it, we ask for your consent.
By using the Service, you consent to your personal information being transferred to these countries for processing by our service providers as described in this Policy.
8. How long we keep your information (Retention)
We keep personal information only as long as necessary for the purposes in this Policy, or as long as the law requires.
| Information | How long |
|---|---|
| Account and profile | While your account is active. When you delete your account, it is deleted right away (see Section 9), except as listed below. |
| Content (jols, messages, photos, polls) | While your account is active and the content is still relevant to the Service. Content you delete, and content in your account when you delete it, is removed. |
| Location snapshot | Until you share a new one, stop going out, check out, switch to Hidden, withdraw map consent, or delete your account, whichever comes first. |
| "Going out" status | It expires after the time you chose, and is shown to no one after that. |
| Removed content (moderation) | Up to 90 days in the restricted store, then permanently deleted. A short record of the removal is kept. |
| Banned accounts | Identifying information and the profile copy are kept while the ban stands (see Section 6). |
| Admin audit trail | 5 years from the action it records, then deleted. |
| Ticket orders and payment records | Kept after you delete your account, with the link to your account removed, because they are financial records we must keep. |
| Records of your acceptance of the Terms and this Policy | While your account is active. Deleted with your account. |
| Reports you made | Deleted when your account is deleted. Reports about content are kept as long as needed to act on them. |
| Push-notification tokens | Until you sign out, delete your account, or your account is banned. |
| Crash reports (Sentry) | Up to 90 days, then deleted by Sentry. |
| Website interest forms | 12 months after our last contact with you, then deleted, unless your venue has become a Jols customer (then the venue agreement applies). You can ask us to remove them sooner. |
| Backups | Kept by our hosting provider for up to 7 days, then overwritten. |
9. Deleting your account and data
You can delete your Jols account at any time:
- in the app: Profile → Settings → Privacy → Delete Account; or
- by emailing admin@jols.co.za from the email address on your account.
When you delete your account in the app, it is deleted right away: your profile, content, location snapshot, push tokens, and uploaded photos are removed. Deletions by email request are completed within 30 days. The exceptions are:
- ticket orders and payment records, which we keep with the link to your account removed (Section 8);
- a banned account, which cannot be deleted while the ban stands (Section 6);
- copies in backups, which are overwritten on our normal cycle;
- a VIP guest-list name the venue typed in itself, which stays on that venue's list;
- anything the law requires us to keep.
Some content you shared with others is not deleted, because it is still needed for the jol or the other people in it: for example, messages you sent in a jol chat stay visible to the other participants, but are no longer linked to your account and are shown with the sender name "Unknown" instead of your username. Tickets and orders are kept as described in Section 8, with the link to your account removed.
10. Your rights (POPIA)
As a data subject under POPIA, you have the right to:
- Be informed about how we process your personal information (this Policy).
- Access the personal information we hold about you.
- Correct or update information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.
- Delete or destroy your personal information in the circumstances allowed by law (see Section 9).
- Object to processing in certain circumstances, including for direct marketing.
- Withdraw consent at any time, where we rely on consent. For example, you can turn off location permission, withdraw map consent, switch to Hidden, turn off notifications, or contact us. Withdrawing consent does not affect processing already carried out.
- Complain to the Information Regulator (see Section 14).
To exercise any of these rights, contact our Information Officer at admin@jols.co.za. We may need to verify your identity before acting. We will respond within the timeframes required by law.
11. Children and minimum age
Jols is for adults. You must be at least 18 years old to use Jols. When you sign up, we ask for your date of birth. The app and our database both refuse accounts where it shows you are under 18.
We chose 18+ because Jols helps people find and attend real-world parties and nightlife events. These often take place at licensed venues that serve alcohol and are not suitable for minors.
We do not knowingly collect personal information from anyone under 18. Under POPIA, the personal information of children (anyone under 18) may generally only be processed with the consent of a competent person (such as a parent or guardian), and within strict limits. If we learn that we have collected information from a person under 18 without the required consent, we will delete it. If you believe a minor has given us personal information, contact us at admin@jols.co.za.
12. Visitors outside South Africa (GDPR and similar laws)
If you use Jols from the European Union, United Kingdom, or another region with similar data-protection laws, you may have additional or equivalent rights. These include the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to complain to your local supervisory authority. We aim to honour these rights in line with the principles in this Policy. Contact admin@jols.co.za to exercise them.
13. Security
We take reasonable technical and organisational measures to protect your personal information against loss, unauthorised access, and misuse. These include:
- secure hosting;
- encryption of data in transit;
- row-level access controls in our database, so each user can only reach what they are allowed to see;
- restricted, admin-only storage for moderation evidence;
- an audit trail of moderation actions;
- rate limiting against abuse;
- keyed hashing of phone numbers.
No system is perfectly secure. If we become aware of a security compromise affecting your personal information, we will notify you and the Information Regulator as POPIA (section 22) requires.
14. Complaints and the Information Regulator
If you have a concern about how we handle your personal information, please contact our Information Officer first at admin@jols.co.za so we can try to resolve it.
You also have the right to complain to the Information Regulator of South Africa:
- Website: https://inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- POPIA complaints: POPIAComplaints@inforegulator.org.za
15. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will tell you in the app or by other reasonable means and update the "Effective date" above. When we publish a new version, the app and the venue portal ask you to accept it again the next time you sign in.
16. Contact us
- Privacy, data requests, and general support: admin@jols.co.za
- Information Officer: Luca McKay
- Responsible Party: JOLS (PTY) LTD (registration number 2026/572774/07), 11 Audocia Place, Hurlingham Ext 5, Sandton, Gauteng, 2196