Privacy policy
WrenchVerse keeps a record of what has happened to a vehicle. Doing that honestly means holding information about the people attached to it - owners, mechanics, workshops - and being straight with you about what we hold, why, and what you can make us do about it. This policy is our notification under section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA).
1 Who we are
1.1WrenchVerse (Pty) Ltd, registration number 2025/397258/07, a private company incorporated in the Republic of South Africa ("WrenchVerse", "we", "us", "our"), is the responsible party for the personal information described in this policy.
1.2Our registered address is 95 Panorama Road, Rooihuiskraal, Centurion, 0154. That is where the company is registered, not a public office - we do not keep premises open to callers, and anyone needing to come in person should arrange it first. Our telephone number is +27 78 725 3757 and our website is wrenchverse.com.
1.3Our Information Officer is Henrico JC Swanepoel, reachable at [email protected]. POPIA makes the head of a private body its Information Officer automatically, so this is a statement of fact rather than an appointment. Registration with the Information Regulator, which section 55(2) requires before an Information Officer takes up their duties, has not yet been completed. We would rather say so here than claim otherwise. Anything in this policy that asks you to contact us goes to that address.
1.4Our manual under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA) is published at wrenchverse.com/paia, and a copy is available for inspection at our registered address during business hours. It sets out what records we hold, which of them you may ask for, and how to ask.
2 What this policy covers
2.1This policy applies to the WrenchVerse website, the vehicle passport and audited history service, The Bond, the auditor console, and any related interface we operate (together, the "Service").
2.2It sits alongside our Terms of Service and, for business customers, our Terms and Conditions. Where a business customer uploads information about its own staff or clients, that customer is the responsible party for it and we act as its operator under sections 20 and 21 of POPIA.
2.3The Service is intended for people aged 18 or older who are resident in South Africa. We do not knowingly collect the personal information of children. If you believe a child's information has reached us, tell the Information Officer and we will delete it.
3 What information we collect
3.1Account information. Your username, email address, a one-way hash of your password (never the password itself), an optional display name, your role on the platform (owner, mechanic, workshop, auditor or administrator), the date on which you gave consent under POPIA, and a trust score we calculate from your activity.
3.2Vehicle information. The VIN, make, model, year, trim and technical specification of vehicles you add, the name you give a vehicle in The Bond, how the vehicle is used, and the periods over which you have owned it.
3.3Records you submit. Service records and job submissions, including workshop name, a description of the work, mileage and completion date; care logs in The Bond, including category, description and photographs; and the evidence files you attach, together with their content type, a cryptographic hash of the file, and any capture date or other metadata embedded in them.
3.4Technical and session information. Your IP address and approximate location at the time you sign in, the hashed session token, when the session was created, when it expires and when it was revoked, and a salted hash identifying the device you used, along with any device label your browser or app reports.
3.5Information from other people. A mechanic or workshop may submit a record against a vehicle you own, and a previous or subsequent owner's activity may appear in that vehicle's ownership history. We also receive the results of status checks we run with third-party vehicle data providers, described in clause 7.5.
3.6Correspondence. If you contact us, we keep your name, email address and message so that we can answer you and keep a record of what was said.
3.7You are not obliged to give us any of this. But an account cannot be opened without clause 3.1, a vehicle cannot be added without clause 3.2, and a record cannot be audited without clause 3.3 and clause 3.4 - the evidence of who submitted what, from where, is the thing that makes an audited record worth anything.
4 Why we process it
4.1We process personal information only for the purposes set out below, and we do not use it for anything materially different without telling you first.
| PURPOSE | JUSTIFICATION UNDER s11 |
|---|---|
| Creating and running your account | Necessary to perform our contract with you |
| Building and displaying a vehicle passport | Necessary to perform our contract with you |
| Auditing submitted records, and detecting fraudulent ones | Our legitimate interest, and that of buyers relying on the record |
| Keeping device, session and location evidence against a submission | Our legitimate interest in preventing vehicle fraud |
| Running third-party status checks | Your consent, and the legitimate interest of a prospective buyer |
| Securing the Service and investigating abuse | Our legitimate interest |
| Answering your correspondence | Our legitimate interest |
| Meeting tax, company law and other legal obligations | Compliance with a legal obligation |
4.2Where we rely on your consent, you may withdraw it at any time by contacting the Information Officer. Withdrawing consent does not affect processing that already happened, and it does not undo an audit that has already been completed.
4.3We do not sell your personal information. We do not use it to train machine learning models belonging to anyone else.
5 Device and location information
5.1South Africa has a real problem with stolen vehicles and fabricated service histories. A record that says "cambelt replaced at 142 000 km" is worth very little on its own; a record that also shows it was submitted by a known workshop, from a device that workshop has used before, in the town that workshop operates in, is worth considerably more.
5.2So we record, against submissions and sign-ins, a device identifier and an approximate location. We keep this deliberately minimal:
- Device identifiers are salted and hashed in our application before they reach the database. We store the hash, not the raw identifier, and the hash cannot be reversed back into your device.
- Location is stored at approximate, town-level granularity. We do not track you continuously, and we do not build a movement history.
- The device label ("Samsung S25", say) is whatever your browser or app reports. It is unverified, we use it only to give a human investigator context, and we never make a security decision on it.
5.3This information is used for audit, fraud investigation and account security. It is not used for advertising, and it is not shown to other users on a passport.
5.4Where the approximate location comes from. One of two places, and we record which:
- The network. Where our hosting provider tells us which country a request arrived from, we record the country and nothing finer. This is less specific than the IP address we already record beside it under clause 3.4, and we never send your address to anyone to ask - see clause 13.2.
- Your device, if you choose. When you submit work, or apply for a role, the form offers a button that asks your browser where you are. Nothing is read unless you press it, your browser will ask you again itself, and pressing it a second time takes it back off. The submission is treated no differently either way, and refusing costs you nothing.
5.5A position your device shares is rounded to roughly the nearest kilometre before it is stored, and the exact figure your browser reported is never written down. That is enough to show a submission came from the town a workshop operates in, and not enough to identify a house or a street.
5.6We do not record where you are for the private side of the app. Care logs, photographs in your garage and fuel entries carry no location at all. Those are yours, nobody audits them, and a record of where you wash your car or buy fuel would be the movement history clause 5.2 says we do not build.
6 Who can see your records
6.1The platform has two sides and they behave very differently. This is the clause worth reading twice.
Sealed records form the vehicle's permanent history and are visible to anyone you share the passport with, and to future owners of that vehicle. That is the entire point: the history has to survive the sale.
Care logs, photographs and milestones are private to you by default. They are not audited, they are not part of the vehicle's provenance, and they do not transfer to a new owner unless you choose to share them.
6.2A sealed record shows what was done, when, at what mileage, and by which workshop or role. It does not show your email address, your contact details, your IP address, your device hash or your precise location.
6.3Our auditors see the full submission, including the evidence files and the device and location signals, because that is what they are reviewing. Auditors are bound to confidentiality and may only use what they see to carry out the audit.
6.4When a vehicle changes hands through the Service, the new owner receives the audited passport. They do not receive your account, your Bond, your contact details or your correspondence with us.
8 Where your information lives
8.1On hardware we own, in a building we control, in South Africa. WrenchVerse does not run on rented servers, in a cloud region, or on a managed database. The physical machines your vehicle history sits on belong to us.
8.2That is a deliberate choice rather than a cost decision. It means no third party holds a copy of the database, no provider can be compelled to hand it over without us knowing, and there is no routine transfer of personal information outside the Republic for section 72 of POPIA to govern.
8.3Backups are encrypted and kept on infrastructure we control, in South Africa.
8.4Two narrow exceptions, stated plainly rather than buried. When a status check runs we send a VIN out to the providers named in clause 7.5, and where a provider is outside South Africa that is a transfer - of a vehicle number, never of your name or contact details. And if you hold a paid business account, your card details go to the payment provider in clause 7.4 rather than to us. Nothing else leaves our infrastructure.
8.5Email is worth being precise about. We send automated messages only when something has happened that you need to know about or asked us to do: a link to reset your password, a link to confirm a new address, and a notice when your password changes. There is no newsletter and nothing promotional unless you have separately asked for it on your account page.
8.6Our mail comes from [email protected] and you can reply to it - a person reads [email protected]. We say the address here so that you have something to check a suspicious message against: we will never ask you for your password, and a link we send always points at wrenchverse.com.
8.7It is sent from mail infrastructure in South Africa that we pay for and control, rather than handed to a third-party delivery service. Your address is not given to anybody to send on our behalf, so there is no transfer outside the Republic for section 72 to govern - which is the same reason clause 8.1 gives for where the database lives.
8.8Our messages carry no images and no tracking pixels, so opening one tells us nothing. We do not record whether you read it, and we cannot. Once a message leaves us it passes through your own mail provider, and that part is outside our control.
8.9A password reset link works once and expires an hour after it is asked for; a confirmation link works once and expires after a day. Asking for a reset on an address that has no account here sends nothing at all, and the page says the same thing either way - so nobody can use that form to find out whether you have an account.
9 How long we keep it
9.1We keep account information for as long as your account is open, and for one calendar month after you close it, so that we can deal with disputes about records you submitted.
9.2Session records are deleted one calendar month after the session expires or is revoked. Device hashes are kept for as long as the account is open.
9.3Care logs, photographs and other Bond content are kept until you delete them or close your account, whichever comes first.
9.4Sealed records attached to a vehicle are kept indefinitely, in the form described in clause 10.
9.5We keep records for longer where section 14(1) of POPIA allows it - where retention is required by law, required by a contract, or reasonably required for our lawful functions.
10 Sealed records and deletion
10.1There is a genuine tension at the heart of this Service and we would rather set it out than bury it. POPIA gives you the right to have your personal information deleted. WrenchVerse exists because a vehicle's history cannot be quietly rewritten. Both of those things have to be true at once.
10.2Our position is that the two are reconciled by separating the person from the vehicle. When you ask us to delete your information, or when you close your account:
- Your name, username, display name and email address
- Your password hash and all sessions
- Your device hashes and device labels
- The IP addresses and locations recorded against your submissions
- Your Bond: care logs, photographs and milestones
- Your correspondence with us
- The sealed event itself - what was done, when, at what mileage
- That it was reviewed and approved by an auditor
- The role the submitter held at the time (owner, mechanic, workshop)
- The cryptographic seal proving the record has not been altered
- The period of ownership, without identifying who the owner was
10.3What survives is a fact about a vehicle, not a record about you. It is retained under section 14(1)(b) of POPIA because we reasonably require it for a lawful function of our business - maintaining an auditable vehicle history that a future buyer can rely on - and because deleting it would harm a third party who has done nothing wrong.
10.4If you believe a sealed record about your vehicle is inaccurate, we will not silently edit it, because a history that can be edited is not a history. Under section 24(2)(d) of POPIA we will instead attach a notation recording your objection, which is displayed alongside the record. Where an auditor finds the record was obtained fraudulently, we will annul it and mark it as annulled rather than remove it.
10.5If you disagree with this position, you may object under section 11(3) of POPIA and, failing agreement, complain to the Information Regulator under clause 16. We would rather you did that than that we pretended the tension did not exist.
11 Your rights
11.1Under POPIA you have the right to: be told what personal information we hold about you and who has had access to it (section 23); have inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained information corrected or deleted (section 24); object to processing we base on legitimate interest (section 11(3)); object to direct marketing (section 11(3) and section 69); withdraw consent where we rely on it; and complain to the Information Regulator (section 74).
11.2To exercise any of these, contact the Information Officer at [email protected]. We will respond within 30 days, which is the period section 25(1) of PAIA allows, and sooner where we can. Access requests must be made on the prescribed PAIA form, and a fee may be payable for a copy of the record.
11.3We may ask you to verify your identity before we act, so that we do not hand your vehicle history to someone impersonating you.
11.4Where we cannot fully comply - clause 10 being the main case - we will tell you which part we have done, which part we have not, and why.
12 Security
12.1Section 19 of POPIA requires us to secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures. The measures we take include: keeping the servers on premises we control, so that physical access to the machines is ours to grant rather than a provider’s; encrypting traffic in transit; storing passwords only as salted one-way hashes; salting and hashing device identifiers before storage; holding sessions server-side so that they can be revoked immediately rather than remaining valid until a token expires; restricting auditor access to the queue an auditor is assigned; and sealing approved records with a cryptographic signature so that later tampering is detectable.
12.2No system is perfectly secure. Keep your password to yourself, use one you have not used elsewhere, and tell us immediately if you think someone else has got into your account.
12.3If personal information under our control is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and every affected person as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved, what we are doing about it, and what you should do. We will delay telling you only if the Regulator or a public body investigating the incident tells us that notifying you would impede that investigation.
14 Direct marketing, and notifications
14.1Section 69 of POPIA prohibits electronic direct marketing unless you have consented, or you are an existing customer and the narrow conditions in section 69(3) are met.
14.2We will send you service messages - an audit result, a security alert, a change to these documents - because those are necessary to the Service and are not marketing.
14.3We will send you marketing only if you have asked for it, or if you are an existing customer and the message concerns our own similar products or services. Every such message carries an unsubscribe link, and unsubscribing takes effect immediately.
14.4We do not sell or rent your contact details to anyone for their own marketing.
14.5Notifications in your browser. You can ask us to show a notice on a device when something happens that concerns you - an auditor answering a submission, a role application being decided, a workshop naming you on a part. Nothing is shown unless you turn it on from the notifications page, turning it off again is the same button, and refusing changes nothing about how anything is treated. We never send marketing this way.
14.6The notice itself carries nothing. A browser notification is delivered by a service run by whoever made your browser - Google for Chrome, Mozilla for Firefox, Apple for Safari - and we cannot avoid using it. So we send it empty. It tells them that your device has something waiting and nothing else: not which vehicle, not which workshop, not what was decided. Your device then asks us for the wording, over your existing signed-in session, and we answer only your device. The same reasoning as clause 13.2.
14.7Every marketing message carries a link that stops them, and it does not expire. You do not need to sign in to use it and you do not need to find the most recent message - a link from any of them works, because it is signed rather than stored. Following it turns marketing email off and does nothing else; it cannot turn anything on, and it cannot read or change anything about your account.
14.8Service email is not covered by that link. Audit results, security alerts and changes to these terms are part of holding an account rather than marketing, so they continue while you hold one - they are also the messages you would want if somebody signed in as you. To stop those, close the account.
14.7What we keep to make this work is the delivery address your browser issues and, where we have it, which device it belongs to. It is not evidence of anything and we treat it accordingly: it is deleted when you close your account, when you turn notifications off, and when the delivery service tells us it has stopped working. Everything you are told is also listed for you on the notifications page, whether or not you ever turn this on.
15 Changes to this policy
15.1We may update this policy. The version number and date at the top of this page always reflect the current version.
15.2If a change materially affects how we process your personal information, we will email you at least one calendar month before it takes effect. Continuing to use the Service after that means you accept the updated policy.
16 Complaints
16.1Come to us first, at [email protected]. Most problems are faster to fix that way.
16.2If we do not resolve it, you may complain to the Information Regulator. You do not need our permission and you do not need to tell us first.
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
POPIA complaints: [email protected]
PAIA complaints: [email protected]
Complaints are lodged in writing through the Regulator's eServices portal at eservices.inforegulator.org.za
wrenchverse