Privacy Policy
Last updated: 29 August 2026
The short version: Your activities, photos and locations are stored on your device and backed up to our cloud servers, so losing or changing your phone doesn't lose your record. You can pause photo uploads at any time in Settings, and delete your account — and everything we hold for you — from inside the app. We don't track you, sell your data, or hand it to anyone. Your data reaches another person in two ways: when you tag them in an activity, or they tag you and you accept (see Section 2.4), and when the Party has authorised somebody — normally your Constituency Head — to oversee your constituency (see Section 3a). You can see who has looked.
1. Who we are
DA Activity Tracker (the "App") is operated independently and is not officially affiliated with or endorsed by the Democratic Alliance political party. This Privacy Policy explains how we collect, use, and protect your personal information in compliance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa.
For the purposes of POPIA, the operator of the App is the Responsible Party for the limited personal information we collect on our authentication servers.
2. Information we collect
2.1 Information stored on your device only
The following information is created and stored entirely on your phone in a local SQLite database. It is not transmitted to our servers or anywhere else:
- Photos taken via the in-app camera or selected from your gallery to document activities.
- Location data — GPS coordinates and reverse-geocoded addresses captured when you log an activity (only with your permission).
- Activity data — titles, descriptions, categories, and dates you enter for each logged activity.
- App preferences — in-app settings such as whether photo uploads are paused.
2.2 Information stored on our servers
The following limited information is stored on our authentication provider (Supabase, see Section 6) so that you can sign in across devices and so we can verify your identity:
- Email address (used as your sign-in identifier)
- Phone number (collected for record-keeping and future features such as SMS notifications — never sold or shared)
- Password (stored as a salted, irreversible hash by our authentication provider — we cannot read your password)
- Account metadata (account creation date, last sign-in timestamp)
2.3 Information stored on our cloud backup
The following data is also synced to our private cloud backup so you can switch devices without losing your work. This applies to every account — it is not a paid extra and there is nothing to opt into:
- Activity rows — title, description, category, GPS, address, date, and timestamps.
- Compressed activity photos — both the original and the watermarked version, downscaled to a maximum 1280-pixel longest edge as JPEG.
Cloud-synced data is hosted by Supabase (in the EU region) and routed through PowerSync Cloud. See Section 6.
2.4 Information other members can see
The App lets you tag a colleague in an activity you were both at, so they can add it to their own record. That needs two things other members can reach:
- Your name — the only field other members can search. Anyone signed in to the App can look you up by name and see your name and your constituency. Your email address and phone number are never shown.
- A notification token for each device you sign in on, so we can tell you when somebody tags you. It is deleted when you sign out on that device.
Tagging is the one way an activity reaches somebody else, and it is always your choice:
- When you tag someone, they see your name and the activity's title, date and category — never your photo, notes or location — and they choose whether to accept.
- If they accept, they receive a copy of that activity: its title, description, category, date, location and original photo. The copy is theirs from that point on, and deleting yours does not delete theirs.
- If they decline, you are told, and that activity cannot be used to tag them again.
- A tag you are sent lapses after 30 days if you do not answer it.
Apart from this, per-row access is enforced by Postgres row-level security tied to your account: nobody else can read your activities, photos or locations.
3. How we use your information
Your information is used solely to:
- Let you record and track your DA-related activities on your own device.
- Generate proof-of-attendance PDF documents that you can share or hand to your branch.
- Display your activity locations on an in-app map.
- Authenticate you when you sign in to the App.
- Send you a one-time verification code at sign-up.
- Let colleagues find you by name so they can tag you in an activity you were both at, and let you do the same.
- Send you a notification when somebody tags you, or accepts a tag you sent.
- Show the activities recorded in a constituency to the person the Party has authorised to oversee it — see section 3a.
We do not use your data for advertising, profiling, analytics, marketing, or sale to any third party.
3a. Constituency oversight
The Party may authorise a person — normally a Constituency Head — to see the activities recorded in a constituency. Where that has been done, and only where it has been done, that person can see, for every member allocated to that constituency:
- The activities you have planned and the activities you have logged.
- The title, category, date, venue or address, and any notes you wrote on each one.
- The watermarked photo of a logged activity. That photo has your GPS co-ordinates printed on it, so opening it shows them where you were.
- Your name, your Party role and your ward.
They can also send you a notification asking you to add your activities for a week. The wording of that notification is fixed by us; they cannot write their own message to you through the App.
We record who has looked. Every time somebody opens your activities this way we record who they were and when, and you have the right to ask us for that record (section 7).
This authorisation is held on our servers and is granted by us, on the Party's instruction, after checking who the person is. It is not something a user of the App can give themselves, and changing your own role or constituency in the App does not grant it. It can be withdrawn, and when it is, access stops.
An activity is attributed to the constituency and ward you were allocated to at the time you recorded it, and that attribution does not change if you move later.
4. Permissions we request
- Camera — to take photos of your activities. You can decline; in that case you can still upload existing photos from your gallery.
- Photo Library — to let you select existing photos to attach to an activity.
- Location (When In Use) — to GPS-tag your activities at the moment you log them. You can decline; in that case activities will be saved without coordinates.
- Notifications — to tell you when a colleague tags you. You can decline; in that case tags still appear in the App, you are simply not told about them until you open it.
5. Data retention
Your activity data, photos, and location data are kept on your device for as long as you keep the App installed. Uninstalling the App will delete this data permanently from your device.
Your account information (email, phone, hashed password) is kept on our authentication servers until you delete your account. When you delete your account from inside the App (Settings → Delete Account), your record is permanently and immediately removed from our authentication servers.
Cloud backup: your cloud copy is kept for as long as your account exists. Settings → Delete Account removes every cloud-backed activity row and photo we hold for you, along with the account itself. You can also pause photo uploads at any time in Settings, which stops photos leaving your device.
6. Third-party services we use
We use a small number of trusted third-party services to operate the App. Each is bound by their own privacy obligations:
- Supabase — handles user authentication and cloud backup of activities and photos. Stores your email, phone, hashed password, and your activity data. Hosted in the EU. Privacy policy.
- PowerSync Cloud — sync engine. Routes data between your device and Supabase. Stores no user data of its own. Privacy policy.
- Resend — delivers the one-time verification code email at sign-up. Receives only your email address and the code itself. Privacy policy.
- Expo — delivers push notifications. Receives the notification token for your device, the name of the member who tagged you, and the activity's title. Nothing else, and nothing at all if you decline the notification permission. Privacy policy.
- Sentry — anonymous crash reporting. When the app encounters an error, an anonymous report is sent containing the error details, device type, and OS version. No personal information, photos, activity data, or location data is included in crash reports. All text and images in error replays are masked. Privacy policy.
- Apple App Store / Google Play — distribute the App. They may collect aggregate download statistics.
We do not use any analytics, advertising, or tracking SDKs.
7. Your rights under POPIA
As a data subject under POPIA, you have the following rights regarding the personal information we hold about you:
- Right of access — you may request confirmation of what personal information we hold about you.
- Right to correction — you may ask us to correct inaccurate or incomplete personal information.
- Right to deletion — you may delete your account at any time directly inside the App (Settings → Delete Account), which removes your record from our servers permanently.
- Right to object — you may object to the processing of your personal information.
- Right to lodge a complaint — you may lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za).
8. Children's privacy
The App is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
9. Security
We take reasonable technical and organisational measures to protect your personal information:
- All data on our authentication servers is encrypted in transit (TLS) and at rest.
- Passwords are hashed using industry-standard one-way hashing — even we cannot read them.
- Your sign-in session is held in the device keychain (iOS) or keystore (Android), where the operating system protects it.
- You stay signed in until you sign out. Settings → Sign Out ends the session on that device; Settings → Delete Account ends it everywhere, along with the account itself.
Despite these measures, no system is completely secure. You are responsible for keeping your sign-in credentials and device safe.
10. International data transfers
Our authentication and email-delivery providers may store your information on servers located outside South Africa (typically in the EU or US). By using the App, you consent to this transfer. Both providers comply with GDPR and equivalent data protection standards that meet POPIA's cross-border transfer requirements.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App and an updated "Last updated" date will appear at the top of this page. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
12. Contact us
If you have questions about this Privacy Policy or wish to exercise any of your rights under POPIA, you can reach us at:
- Email: privacy@myda.co.za
- Website: myda.co.za