Privacy Policy
Last updated: 10 September 2026
1. Who we are and what our role is
PeerUp is a peer tutoring platform for South African high schools, operated from Cape Town, South Africa. Your school is our client; you (the student) are the user.
Under the Protection of Personal Information Act, 2013 (POPIA), your school is the responsible party for your student information — it decides that PeerUp is used and who at the school may access it. PeerUp acts as the school's operator, processing that information on the school's instructions under a written data processing agreement. For the small amount of information we process for our own purposes (security logs, error reports, and keeping the service running), PeerUp is the responsible party.
Privacy questions, requests, and complaints go to our Information Officer at support@peerup.co.za.
2. Information we collect
- Account data: name, school email address, grade, profile photo (if provided by your school OAuth provider).
- Profile data you add: phone number, bio, subjects (tutor and tutee), and the grades you are willing to tutor.
- Session data: scheduled sessions, start/end times, duration, subject, location, check-in (QR or code) events, cancellations, and session notes written by your tutor.
- Availability data: which time slots (before school, after school, after extra-curriculars) you mark as available, and how many sessions per week you want.
- Attendance data: whether you attended, cancelled, or missed a session, a running count of recent missed sessions, and — if you are automatically paused from booking — the reason recorded for that pause.
- Ratings and notes: post-session thumbs up/down feedback and optional written notes. Feedback is not anonymous — the person you rate can see the note you wrote about them.
- Messages: chat messages and shared checklists you exchange with your tutor/tutee are stored so your conversation history works.
- Academic marks (optional): if your school has mark tracking and you choose to log them, your term marks and goal marks per subject.
- Matching history: which tutor and tutee were paired, in which subject and slot, and for how many consecutive weeks — used to keep pairings consistent.
- Badges, hours, and vouchers: tutoring hours logged, badges earned, and vouchers issued or claimed.
- Notifications: in-app notifications we send you, and the emails we send to your school address.
- Device data: if you opt in to push notifications, your browser push subscription details are stored so we can send them.
- Activity and security logs: an append-only audit log of session actions (who started, cancelled, or ended a session and when), and short-lived rate-limit records used to block abuse.
- Error and performance data: when something breaks, our error monitoring records the page involved, technical details of the fault, and your account ID so we can trace and fix it.
- QR poster scans: if you reach PeerUp by scanning a launch poster QR code, we record which poster was scanned and your browser type. No name or account is attached.
We do not ask you for payment information, ID numbers, health information, religious or political information, or any other special personal information as defined by POPIA, and we have no field for it. Some parts of PeerUp are free text — chat messages, bios, session notes, feedback notes, and checklists. Please do not type sensitive personal information about yourself or anyone else into those fields.
3. Why we collect it, and our lawful basis
- To match tutees with suitable tutors at their school.
- To schedule, start, and record tutoring sessions.
- To let you and your session partner arrange and prepare a session (contact details, chat, checklists).
- To send reminders and notifications about your sessions.
- To award badges and vouchers based on tutoring hours.
- To track attendance so the programme stays reliable, and to pause repeat no-shows.
- To provide school administrators with usage reports and, where mark tracking is enabled, subject-level progress reporting.
- To keep the platform secure and working (rate limiting, error monitoring, backups).
- To improve the matching algorithm using aggregated session data.
Our lawful bases under POPIA section 11 are: your school's mandate and our agreement with your school (section 11(1)(b) and 11(1)(e) — processing necessary to carry out the school's tutoring programme), your consent given at onboarding (section 11(1)(a)) for optional features such as adding a phone number, logging marks, and push notifications, and our legitimate interests (section 11(1)(f)) in keeping the platform secure and functioning. You may withdraw consent for the optional features at any time by removing the data or turning the feature off, and for everything else by asking us to delete your account.
4. Who can see your data
- Your session partner: can see your name, grade, email address, and phone number (if you added one) for a session you share. The contact card appears when the session is booked and stops working 7 days after the session's time slot. It is not shown at all for cancelled sessions.
- Other students at your school: can see your name, grade, bio, subjects, the grades you tutor, and whether your account is currently paused or suspended (so they know not to book you). They cannot see why you were paused, nor your email, phone number, marks, messages, session notes, or feedback.
- Your tutee (if you are a tutor): can read the session notes you write on a shared session. Notes are not private to the tutor.
- The person you rate: can read the feedback note you wrote about them.
- School administrators: can see all students and tutors at their school, including names, school email addresses, sessions, hours, badges, vouchers, attendance and missed-session counts, the session audit log, and — where mark tracking is enabled — logged marks and goals. They can also export a list of student names and school email addresses in order to email students about the programme. They cannot read your chat messages or your phone number through the admin tools, with one exception: from 24 September 2026, if a student reports a concern about a chat or session, a copy of the last 50 messages of that chat is shared with the school's staff administrators (never with students who also have admin rights) so they can look into it. Reports, and that copy, are kept even if either account is later deleted, so a safeguarding record can't be erased. Your school can also choose to have named staff emailed automatically when a student reaches a set number of missed sessions, so that it can follow its own attendance procedures; those emails go only to school addresses.
- PeerUp (us): our support and engineering access can reach all data stored on the platform, including message content, in order to operate, back up, and support the service. We only do so when necessary to run or fix the service, or when the school instructs us to.
We do not sell your data. We do not share personal data with advertisers, and we do not use your data to train third-party AI models.
5. Third-party services (our operators)
We use the following service providers to operate PeerUp. Each processes data on our instructions and has its own privacy policy:
- Supabase — database, authentication, and file storage, hosted in London, United Kingdom. Holds all platform data.
- Vercel — web hosting and CDN. Handles all requests to peerup.co.za, including IP addresses and session cookies.
- Vercel Analytics and Speed Insights — aggregated, cookie-free page-view and page-speed measurement. No account identifiers are attached.
- Sentry — error and performance monitoring. Receives fault reports that may include the page you were on and your account ID.
- Resend — email delivery. Receives the recipient address and the content of the emails we send (session requests, reminders, attendance notices, and invitations sent by your school administrator).
- Push services (Google, Apple, Mozilla, Microsoft) — deliver push notifications to your device if you opt in. The notification content is encrypted so that only your browser can read it.
- Microsoft / Google — OAuth sign-in. We only receive your name, school email address, and profile photo from these providers.
- GitHub — stores our nightly database backups, encrypted, for 30 days, and runs our scheduled jobs.
- cron-job.org — triggers our scheduled jobs (reminders, matching). It receives no personal data.
If we add or replace a provider that handles personal information, we will update this list and note it in the change record at the bottom of this page.
6. Where your data is stored (cross-border transfers)
PeerUp's database is hosted in London, United Kingdom. Our hosting, email, error monitoring, backup, and push-delivery providers are based in or route through the United Kingdom, the European Union, and the United States. This means your personal information is transferred outside South Africa.
We rely on POPIA section 72 for these transfers: each provider is bound by a written data processing agreement requiring a level of protection substantially similar to POPIA, and the transfers are necessary for the performance of the service your school has asked us to provide. We do not transfer your data to any recipient for their own purposes.
7. How long we keep your data
- Your account and everything linked to it: kept for as long as your school uses PeerUp and you are a user of it.
- When you leave school: at the start of each school year, students who have finished Grade 12 are moved out of matching and every list. You can still sign in to download your certificate for 12 months, after which your account is deleted automatically.
- Concern reports: kept by your school while it uses PeerUp, including after the accounts involved are deleted.
- Accounts that never finish signing up: if you sign in but never complete setup, we email you after 5 days and delete the account after 7. You can sign in again any time and start over.
- Notifications you have read: deleted automatically after 90 days.
- Notifications you never opened: deleted automatically after 12 months.
- Rate-limit and abuse-prevention records: deleted automatically after 24 hours.
- Backups: nightly backups of the database are kept for 30 days and then destroyed.
- Error reports: kept by our monitoring provider for up to 90 days.
- QR poster scans: anonymous counts with no account attached, deleted after 12 months.
A chat can be archived (hidden from your own list) but not deleted on its own; it is only removed when one of the two accounts is deleted. If you delete your account, your profile, contact details, messages, checklists, marks, ratings, availability, subjects, notifications, badges, and vouchers are deleted from the live platform immediately. Session records are kept in anonymised form (no name or account attached) so the school's totals stay correct. Copies in our nightly backups are overwritten within 30 days. If your school stops using PeerUp, we delete or anonymise its student data within 90 days of the account closing, unless the school asks for an export first.
8. Cookies and local storage
PeerUp uses only strictly necessary cookies and local storage: a secure sign-in cookie that keeps you logged in, and a stored preference for light or dark mode. We use no advertising cookies, no cross-site trackers, and no third-party marketing pixels. Because these are strictly necessary for a service you asked to use, we do not show a cookie consent banner. Clearing your browser storage will sign you out.
If you add PeerUp to your home screen, a copy of your upcoming sessions is also stored on your device so the app can show your week when you have no connection. That copy holds only the date and time, the subject, and your session partner's first name and surname initial. It holds no contact details and never leaves your device. It is cleared when you sign out or delete your account, and it stops being shown after seven days.
9. Automated decisions
Some things on PeerUp happen automatically, without a person deciding:
- Weekly matching: our matching engine pairs tutees with tutors using subjects, grades, availability, tutor capacity, and past pairing history.
- Attendance pauses: if you miss several sessions in a short period without cancelling, your account can be paused from booking automatically, and your upcoming sessions cancelled.
- Session auto-close: a session left running for more than three hours is closed automatically and logged as one hour.
None of these decisions have legal consequences for you, and none are based on a profile of your personality or performance. You always have a human to go to: if you think an automatic pause or a session record is wrong, ask your school administrator to review and reverse it, or email us at support@peerup.co.za.
10. Minors and consent (POPIA sections 34 and 35)
Most users of PeerUp are under 18, and POPIA requires the consent of a competent person (normally a parent or guardian) to process a child's personal information. PeerUp does not collect that consent directly. Your school does: PeerUp is provided to you as part of your school's programme, under the school's existing parental consent and acceptable-use framework, and under a written agreement in which the school confirms it has that authority. PeerUp is only available to students at schools that have signed that agreement, and only with an official school email address.
By signing in, you confirm that you are a registered student at your school. The consent checkbox at onboarding records that you have read these terms — it is not a substitute for your parent or guardian's consent, which your school holds.
If you are a parent or guardian and you object to your child using PeerUp, or you want to see or delete their data, contact your school administrator, or email us directly at support@peerup.co.za and we will act on it with the school.
11. Your rights under POPIA
- Access: ask what personal data we hold about you and get a copy. You can download most of it yourself at any time from Profile → Export my data. For anything not in that file, email us.
- Correction: update your name, grade, phone, bio, subjects, and availability from your profile pages, or ask us. Your school email address comes from your school's system and can only be changed there.
- Deletion: delete your account and its personal records from Profile → Delete account, or by contacting us. Suspension does not remove this — the same download and delete options are on the suspended-account screen, and if you cannot sign in at all, email us and we will action it for you.
- Objection: object to a particular use of your data by contacting us. You can turn push notifications off yourself at any time.
- Complaint: complain to us first — but you may complain directly to the Information Regulator at any time (see section 15).
To exercise any right, email support@peerup.co.za from your school email address, or, if you are a parent or guardian, tell us the student's name and school. We may ask a question or two to confirm who you are before releasing or deleting anything. We will respond within 30 days, free of charge. POPIA access requests may also be made on the prescribed Regulator form; we accept plain email either way. Where your school is the responsible party, we will pass your request to the school and help them answer it.
Notification emails from PeerUp are service messages about your own sessions, not marketing, so there is no unsubscribe link on them. We never send marketing email to students. Your school administrator can turn email notifications off for the whole school, and you can turn push notifications off yourself.
12. Security
We take the safeguards POPIA section 19 requires, appropriate to the fact that our users are school children:
- All traffic is encrypted in transit (HTTPS, with HSTS), and data is encrypted at rest by our database and hosting providers.
- Sign-in is delegated to your school's Microsoft or Google account — we never see or store your password.
- Row-level security is enabled on every database table, plus column-level restrictions so that contact details are never readable by other students' browsers.
- Session check-in codes are cryptographically signed and expire within a minute.
- Expensive and irreversible actions are rate limited, and administrative keys are held server-side only.
- Backups are taken nightly, encrypted with AES-256 before they are stored, and destroyed after 30 days.
No system is perfectly secure. If you spot a security problem, please report it to support@peerup.co.za rather than testing it further.
13. If there is a data breach
If personal information is accessed or acquired by an unauthorised person, POPIA section 22 requires us to act. We will notify the affected school and the Information Regulator as soon as reasonably possible after establishing what happened, and we will notify affected students (and, through the school, their parents or guardians) by email and in-app notice, describing what happened, what data was involved, and what to do about it.
14. Changes to this policy
We may update this policy as the platform evolves. Material changes will be communicated via in-app notification at least 14 days before they take effect, and the "last updated" date above will change. Continued use after that notice period constitutes acceptance. If you want a copy of a previous version, email us.
15. Contact and complaints
Questions, requests, or complaints: email our Information Officer at support@peerup.co.za.
You also have the right to complain to South Africa's Information Regulator: inforegulator.org.za, complaints.IR@justice.gov.za.