Privacy Policy
Wonke helps you keep your loyalty cards, receipts and everyday spending in one place. This policy explains what data the Wonke mobile app and its backend collect, why, how it is stored and protected, and the choices you have. We keep it deliberately short and only collect what the app needs to work.
Last updated: 8 September 2026
Who we are
Wonke is operated from South Africa. For any privacy question or request, contact us at privacy@wonke.app. This policy is written with the Protection of Personal Information Act (POPIA) in mind.
What we collect, and why
| Data | When | Why |
|---|---|---|
| Email address and password | Only if you create an account (you can use the app as a guest without one) | To sign you in and sync your data across devices |
| Loyalty card details you add (retailer, card number, tier) | When you add or scan a card | To show your cards and their barcodes in the app |
| Receipt photos and details you add (merchant, date, total, items, category) | When you add a receipt | To keep your searchable receipt record and category totals |
| How often you open each card | As you use the app | To auto-favourite your most-used cards on the home screen |
| Diagnostic and crash information (error details, device model, OS version, app version, an anonymous install identifier) | If the app crashes or hits an error | To find and fix bugs |
| The content of a bug or feedback report, and an optional screenshot | Only when you tap "Send Report" | To investigate the issue you reported |
Wonke requests the camera permission to scan loyalty-card barcodes and photograph receipts, and access to photos so you can attach an existing picture of a receipt. Images stay on your device unless you choose to save a receipt, in which case the image is stored with your account.
Wonke does not collect your precise location, contacts, health data, or payment-card / bank-account information. Wonke does not show ads and contains no advertising SDK.
How your data is stored and protected
- All data sent between the app and our servers is encrypted in transit using HTTPS/TLS.
- Account data and the loyalty cards / receipts you save are stored in a managed PostgreSQL database hosted on Microsoft Azure in the South Africa North region.
- Access to the backend is restricted and authenticated; sign-in uses short-lived access tokens.
Who we share it with
We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers that process data on our behalf, under contract, only to run Wonke:
- Microsoft Azure — cloud hosting, database, and transactional email (for example, password-reset messages).
- Sentry — crash and error diagnostics.
- Google Play — app distribution and, if you install from the store, basic install/analytics data collected by Google under its own policy.
How long we keep it
We keep your account data and saved cards / receipts for as long as your account exists. Diagnostic and crash data is retained for a limited period for debugging. Bug and feedback reports are kept for support purposes but are unlinked from your account when you delete it.
Your rights and choices
- Access and correction — you can view and edit your cards, receipts and profile in the app, or email privacy@wonke.app.
- Deletion — you can permanently delete your account and its data from Profile → Privacy & Security → Delete Account in the app, or by request. Full details: wonke.app/data-deletion.
- Use without an account — guest mode lets you use Wonke without providing an email; that data stays on your device.
- Complaints — you may lodge a complaint with the Information Regulator of South Africa.
Children
Wonke is intended for users aged 18 and over and is not directed at children. We do not knowingly collect data from children.
Changes to this policy
If we make a material change we will update this page and the "last updated" date above, and where appropriate notify you in the app.
Contact
Questions, requests or complaints: privacy@wonke.app