1. About this policy
1.1 This policy explains how Parity Labs handles personal information in connection with FuelSync: the website at fuelsync.co.za, the FuelSync service that diesel resellers use on their own subdomains (for example acme.fuelsync.co.za), and the customer portal that resellers offer their customers.
1.2 We wrote it to meet the Protection of Personal Information Act 4 of 2013 ("POPIA"). Where this policy says "personal information", it has the meaning POPIA gives it. In South Africa that includes information about an existing company or other juristic person, not only about individuals.
1.3 "We", "us" and "our" mean Parity Labs, described in section 2. "You" means the person reading this policy, whichever of the groups in section 4 you belong to.
2. Who we are and how to contact us
2.1 FuelSync is made and run by:
- Legal name: PLACEHOLDER: registered name of the legal entity that trades as Parity Labs
- Registration number: PLACEHOLDER: CIPC registration number
- Physical address: PLACEHOLDER: physical address for service
- Postal address: PLACEHOLDER: postal address, if different
- Email: [email protected]
- Telephone: PLACEHOLDER: telephone number
2.2 Our Information Officer is PLACEHOLDER: name of the Information Officer (and any Deputy Information Officer), as registered with the Information Regulator. You can reach the Information Officer at PLACEHOLDER: Information Officer's email address, or confirm that [email protected] is to be used.
3. Our two roles: responsible party and operator
POPIA distinguishes between a responsible party, who decides why and how personal information is processed, and an operator, who processes it on someone else's behalf under a contract. We act in both roles, depending on the information.
3.1 We are the responsible party for information we collect for our own business: visitors to our website, people who sign up, enquire or talk to our website assistant, the people who use a reseller's FuelSync account (their login details and how they use the service), billing information about resellers, and our own security and audit records.
3.2 We are an operator for the information a reseller captures in FuelSync about its own customers, drivers, pump attendants and other staff: deliveries, slip photos, customer records, portal contacts and the like. The reseller is the responsible party for that information. It decides what to capture and why, and our Terms of Service (section 10, "Operator agreement") set out what we may and may not do with it.
3.3 If your information is in a reseller's FuelSync account (for example because you are one of its customers or drivers), please direct questions and requests about it to that reseller first. If you contact us instead, we will pass your request on to the reseller and help them answer it, as section 12.5 explains.
4. The personal information we process
4.1 Visitors to fuelsync.co.za
- The technical information any website receives: your IP address, browser type and the pages you request. This is handled by our hosting and network providers (section 8) and kept in technical logs for PLACEHOLDER: retention period of web server, ingress and Cloudflare logs.
- If you use the "Talk to us" assistant on the website: what you type and the assistant's replies, and a random visitor identifier held in a cookie (section 7). We store only a scrambled (hashed) form of that identifier, and we do not store your IP address with the conversation.
- If you leave your details through the assistant or the contact form: your name, email address, your phone number and company name if you give them, what you are interested in, and your message.
4.2 People who sign up for FuelSync
- Business name, your name, email address and the subdomain you choose.
- Your password. We never store the password itself, only an argon2id hash of it, which cannot be turned back into the password.
- The version of our Terms of Service and this policy that you accepted, and when.
4.3 People who use a reseller's FuelSync account (administrators, office staff, drivers and pump attendants)
- Name, email address, password hash, role, and which of the reseller's companies the person may work in.
- Records of what the person did in FuelSync where the service needs them to be accountable: for example who captured, corrected, approved or voided a delivery, who closed or reopened a month, and who changed a price. These are part of the reseller's records (section 3.2).
- Questions the person asks the in-console assistant ("Ask FuelSync") and its answers, and a usage record of each question (when it was asked, by whom, and what it cost).
- For a short time, failed sign-in attempts counted against the email address and the connecting IP address (section 10).
4.4 Information resellers capture in FuelSync (we process this as operator)
Depending on how a reseller uses FuelSync, this can include:
- Photos of delivery slips, thermal receipts, delivery notes and signed proofs of delivery. These may show names, signatures, vehicle registrations and other details written or printed on the paperwork. Photos can also carry information the phone camera added, such as the time and, if the phone's location setting was on, where the photo was taken; FuelSync does not read or use that information, and it is removed from most photos when the phone shrinks them before upload, but not from all.
- Customer records (business names and codes), customer contact names and email addresses, and the people the reseller invites to its customer portal.
- Staff names and email addresses, and who did what (section 4.3).
- Vehicle registrations, meter and totaliser readings, litres, prices, costs, invoices and invoice batches.
- If the reseller connects accounting software, the details needed to connect to it (stored encrypted, section 11) and the invoice data sent to it.
4.5 People who use a reseller's customer portal
Name, email address, password hash and the customer they belong to. The portal shows that customer's deliveries, slip photos and invoices. The reseller decides who gets access, so the reseller is the responsible party for this information too.
4.6 People who deal with us as a business
If you are a reseller's contact for billing, or you correspond with us, we keep your name, contact details and our correspondence, and the invoices and payments on the reseller's account.
4.7 Information we do not ask for
FuelSync does not ask for identity numbers, bank card details, or special personal information such as health information or biometric information. Resellers should not capture these in FuelSync unless they have a lawful reason to (Terms of Service, section 10.9). FuelSync is a business service and is not directed at children.
5. Why we process personal information, and on what basis
POPIA (section 11) allows processing only on certain grounds. For the information we are responsible for:
| Purpose | Information | Ground under POPIA s 11 |
|---|---|---|
| Creating and running a reseller's account; signing people in; sending service emails (verification, invitations, password resets, trial and billing notices) | Sections 4.2, 4.3, 4.6 | Necessary to conclude or perform the contract with the reseller (s 11(1)(b)) |
| Billing the reseller and keeping financial records | Section 4.6, usage records | Contract (s 11(1)(b)); compliance with tax law (s 11(1)(c)) |
| Answering enquiries and following up on leads | Section 4.1 | Steps you asked us to take before a contract (s 11(1)(b)); our legitimate interest in replying to people who contact us (s 11(1)(f)) |
| Running the website assistant | Section 4.1 | Our legitimate interest in answering visitors' questions (s 11(1)(f)) |
| Keeping the service secure: limiting sign-in attempts, audit records, investigating misuse | Sections 4.1, 4.3 | Our legitimate interest and the reseller's in a secure service (s 11(1)(f)); our duty to secure information (s 19) |
| Meeting legal obligations and defending legal claims | Any | Compliance with law (s 11(1)(c)); legitimate interest (s 11(1)(f)) |
For information we process as operator (section 4.4 and 4.5), we act on the reseller's instructions and the reseller is responsible for having a lawful ground.
We do not sell personal information and we do not use it for advertising. We send marketing email only to people who asked for it or who are our customers, as section 69 of POPIA allows, and every such email lets you opt out. PLACEHOLDER: confirm whether any marketing email will be sent at all; if not, replace this sentence with "We do not send marketing email."
6. Automatic reading of photos, and the assistants
6.1 Slip reading. When a reseller's user captures a delivery or a slip-book page, the photo is sent to an AI service provider (section 8), which reads it and returns what it found (slip number, litres, meter readings, customer name and so on). FuelSync uses that to fill in the capture form and to cross-check the delivery. The reading is advisory: a person always confirms or corrects it, and no delivery is approved, priced or invoiced on the strength of an automatic reading alone. It is not a decision about you made solely by automated means in the sense of section 71 of POPIA.
6.2 The in-console assistant. When a user asks the "Ask FuelSync" assistant a question, the question is sent to the AI service provider. If the question is about the reseller's own records, the assistant looks up only what that user is already allowed to see, and those results (which can include customer names and delivery details) are sent to the provider so it can write an answer. The assistant cannot change anything. A reseller's administrator can switch it off.
6.3 The website assistant. What you type into "Talk to us" on fuelsync.co.za is sent to the AI service provider to produce a reply. Please do not type information you would not want stored for 30 days.
6.4 Improving slip reading. We compare automatic readings with the corrections reviewers make, and may use those corrections and the photos they relate to, inside FuelSync-controlled systems, to test and improve how accurately FuelSync reads slips. PLACEHOLDER: confirm this practice and whether resellers may opt out; see the drafting note in Terms section 10.8.
7. Cookies and similar technologies
7.1 FuelSync uses only the cookies it needs to work. We do not use advertising cookies, analytics cookies or third-party tracking.
| Cookie | What it is for | How long it lasts |
|---|---|---|
| Sign-in session (set by Auth.js, the sign-in library FuelSync uses) | Keeps you signed in to a reseller's console, the customer portal or our platform console | Up to 12 hours |
| Auth.js security cookies | Protect the sign-in form against cross-site request forgery and remember where to return you after signing in | Until you close the browser |
fs_company | Remembers which of the reseller's companies you were working in | 12 months |
fuelsync-fuel-alert-dismissed | Remembers that you dismissed a fuel price notice, so it is not shown again | 60 days |
Website visitor cookie (fuelsync_visitor) | A random identifier that lets the "Talk to us" assistant keep your conversation together. We store only a hash of it. | 30 days |
7.2 FuelSync also stores two things in your browser's own storage (not cookies): a draft of a delivery you are capturing, so it is not lost if signal drops, which is cleared when you submit it; and a note that you have read the assistant's notice.
7.3 Our network provider, Cloudflare, may set its own strictly necessary cookies to protect the site from abusive traffic. PLACEHOLDER: confirm whether Cloudflare bot or security features that set cookies are enabled on fuelsync.co.za.
7.4 Because these cookies are strictly necessary for the service you asked for, we do not ask for consent to them. You can block cookies in your browser, but you will not be able to sign in.
8. Who we share personal information with
8.1 We use the following service providers (operators, or "sub-operators" where we ourselves act as operator for a reseller). Each processes personal information only to provide its service to us.
| Provider | What it does for us | Information involved | Where |
|---|---|---|---|
| Hosting and database provider: PLACEHOLDER: name of the hosting provider; the deployment runs on the "ServerArmour" cluster with the database at db.serverarmour.com. Confirm whether this is a related party of Parity Labs or a third party. | Runs the FuelSync application, database, and the storage volumes that hold slip photos and other evidence files; also runs the short-lived store used to limit sign-in attempts | All information in sections 4.2 to 4.6 | PLACEHOLDER: country and, if known, city of the data centre |
| Cloudflare | Manages FuelSync's domain names (DNS) and sits in front of the website as a network proxy | Network traffic, including IP addresses and the content passing through it | Global network; may be outside South Africa |
| Resend | Sends transactional email (sign-up verification, invitations, password resets, trial and billing notices) | Recipient name and email address, and the content of the email | United States of America |
| An AI service provider | Reads slip photos and answers questions put to FuelSync's assistants (section 6) | Slip photos and what is on them; assistant questions and the data looked up to answer them | United States of America |
8.2 Accounting software. If a reseller connects FuelSync to its accounting software, FuelSync sends invoice data to that software on the reseller's instruction. The reseller's own agreement with its accounting provider governs what happens to it there.
8.3 Platform staff. Parity Labs staff can see a reseller's records only by opening a support session for that reseller, which requires a stated reason, expires automatically (after 8 hours at most) and is recorded. Platform staff can also issue a temporary password to a reseller's user to help them back in; that is recorded too.
8.4 Others, only where needed. Our professional advisers under a duty of confidence; a buyer or successor of our business, who must honour this policy; and a court, regulator or law-enforcement body where the law requires us to disclose information.
9. Information sent outside South Africa
9.1 Some of our providers (section 8.1) process information outside South Africa, mainly in the United States of America. Section 72 of POPIA allows this only on certain conditions.
9.2 We send information abroad only to providers who are bound by a law, binding corporate rules or a binding agreement that gives protection substantially similar to POPIA (s 72(1)(a)), or where the transfer is needed to perform our contract with you or with the reseller (s 72(1)(c) and (d)). PLACEHOLDER: confirm which data processing agreements or transfer clauses are in place with Cloudflare, Resend and the AI service provider, and that the hosting provider keeps data in South Africa.
9.3 Where we act as operator, the reseller authorises these transfers in our Terms of Service (section 10.7).
10. How long we keep personal information
We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires (POPIA s 14).
| Information | How long |
|---|---|
| Sign-up requests that were never verified | The verification link is valid for 24 hours. The request is deleted 7 days after the link expires. |
| Details of a verified sign-up | Become the reseller's account (next row). |
| Reseller account and user details, and the reseller's operational records (section 4.4) | For as long as the reseller's subscription runs, then as set out in Terms of Service section 17 (export and deletion on termination). |
| In-console assistant conversations | Deleted 30 days after the last message. A user can delete a conversation sooner. |
| In-console assistant usage records | For as long as the reseller's account exists, for billing. They record who asked, when and the cost, not the question. |
| Website assistant conversations | Deleted 30 days after the last message. |
| Website assistant usage records | 13 months. They record cost and time, not what was said. |
| Leads from the website assistant or contact form | 24 months from when you contacted us. |
| Failed sign-in counters (email address, IP address) | 15 minutes. |
| Support-session and other audit records | For as long as the reseller's account exists. PLACEHOLDER: confirm, or set a retention period |
| Billing records (invoices to resellers, payments) | As long as tax law requires. PLACEHOLDER: confirm the period, for example under the Tax Administration Act and the VAT Act |
| Technical logs at our hosting and network providers | PLACEHOLDER: retention period |
Copies in backups may outlast these periods for a short time until the backup is overwritten. PLACEHOLDER: describe the backup arrangement, if any, and how long backups are kept; none is documented in the codebase.
11. How we protect personal information
11.1 Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. Ours include:
- Separation between resellers. Each reseller's records are kept apart by row-level security in the database itself, so one reseller's account cannot read another's, even through a fault in the application.
- Passwords are stored only as argon2id hashes. Password-reset and sign-up links are stored only as hashes and expire.
- Accounting credentials are encrypted with AES-256-GCM, and disconnecting destroys them.
- Sign-in limits. Repeated wrong passwords pause sign-in for an account or a connection.
- Encryption in transit. FuelSync is served over HTTPS only.
- Limited staff access. Platform staff reach a reseller's records only through an audited, time-limited support session with a stated reason (section 8.3).
- Least privilege. Separate database roles for the reseller console, the platform console, the public website and fuel price updates, each able to reach only what it needs.
11.2 No system is perfectly secure. If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will:
- where we are the responsible party, notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires; and
- where we are the operator, tell the reseller immediately, as section 21(2) requires, and help the reseller meet its own notification duties.
12. Your rights
12.1 Under POPIA you have the right to:
- ask whether we hold personal information about you, and ask for a record of it and of who has had access to it (s 23);
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or to destroy or delete a record we are no longer allowed to keep (s 24);
- object, on reasonable grounds, to processing based on our legitimate interests (s 11(3)(a));
- object to direct marketing at any time (s 11(3)(b) and s 69), and withdraw any consent you have given (s 11(2)(b));
- complain to the Information Regulator (section 12.6).
12.2 To use these rights, email [email protected] or our Information Officer (section 2.2). We may ask you to prove who you are before we act.
12.3 We respond within a reasonable time and will tell you if we cannot do what you ask and why (for example, because the law requires us to keep a record).
12.4 Requests for access to records are handled under the Promotion of Access to Information Act 2 of 2000 (section 13). A prescribed fee may apply to some access requests; there is no charge for asking us to correct or delete information.
12.5 If your information is in a reseller's account, the reseller is the responsible party (section 3.2). Please contact the reseller. If you contact us, we will pass your request to the reseller without delay and help it respond; we will not act on it ourselves unless the reseller instructs us or the law requires it.
12.6 The Information Regulator. You may lodge a complaint with the Information Regulator (South Africa). Its website is https://inforegulator.org.za, where its current complaint forms and contact details are published. PLACEHOLDER: the Regulator's complaints email address and physical address, checked against inforegulator.org.za on the date of publication We would appreciate the chance to resolve your concern first.
13. Access to information (PAIA)
Our manual under section 51 of the Promotion of Access to Information Act 2 of 2000 explains how to request access to records we hold. PLACEHOLDER: link to the PAIA manual, or, if Parity Labs is exempt from compiling one, a statement to that effect and how to request records.
14. Changes to this policy
When we change this policy in a way that matters, we will update the version and date at the top, and tell resellers by email or in FuelSync before the change takes effect. The version in force when a reseller signed up is recorded against its account.
15. Contact
Questions about this policy: [email protected], or our Information Officer at PLACEHOLDER: Information Officer's contact details.