ABOUT DING
DING is a food delivery marketplace operating in South Africa. Our platform connects three groups of people: customers who order food, merchants who prepare it, and delivery drivers who bring it to you.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.
DING is operated by JUST IDENTIFICATION SYSTEMS (registration number 2000/063841/23). JUST IDENTIFICATION SYSTEMS is the legal entity responsible for your personal information, and it is the same entity that contracts with customers, drivers and merchants.
Legal entity: JUST IDENTIFICATION SYSTEMS
Registration number: 2000/063841/23
Registered address: 7 Sugnet Lane, Lonehill, Sandton, Gauteng, 2191
Information Officer: Adam Ismail
Deputy Information Officer: Scott Kilmister
Privacy email: dingappsupport@gmail.com
In this policy, “DING”, “we”, “us” and “our” refer to the legal entity above.
This policy is written to give effect to the Protection of Personal Information Act 4 of 2013 (“POPIA”) and should be read alongside other South African laws that apply to us, including the Promotion of Access to Information Act 2 of 2000 (“PAIA”), the Electronic Communications and Transactions Act 25 of 2002, the Consumer Protection Act 68 of 2008, the Companies Act 71 of 2008, the Tax Administration Act 28 of 2011, the Basic Conditions of Employment Act 75 of 1997 and, in relation to our drivers and vehicles, the National Road Traffic Act 93 of 1996 and Regulation R638 of 2018 under the Foodstuffs, Cosmetics and Disinfectants Act 54 of 1972.
PART A — GENERAL
A1. Who this policy applies to
Customers — people who browse the platform, create an account, place orders, make payments, save addresses, communicate with merchants or drivers, receive deliveries, give feedback, contact support, or receive communications from us.
Delivery drivers — people who apply, register or work as delivery drivers, including applicants being verified and former drivers whose information we still hold. Drivers are DING employees. They are employed directly, not engaged as independent contractors or through any broker or fleet operator, and they operate DING-owned vehicles.
Merchants — restaurant owners and franchise owners who use DING to list food, receive orders and receive payment, together with the individuals who act for them: owners, directors, partners, managers, authorised representatives, staff and account administrators. We contract with each franchise outlet individually rather than with a franchisor centrally, so each outlet owner is a separate merchant.
Where we operate. DING currently operates only in South Africa. All customers, drivers and merchants are located here.
What we sell. DING lists food only. We do not sell liquor, tobacco, medicines or any other age-restricted product.
A2. How to read this policy
- Part A — general matters and the POPIA terms used
- Part B — customers
- Part C — delivery drivers
- Part D — merchants
- Part E — provisions that apply to everyone
If you are a customer, read Parts A, B and E. If you are a driver, read A, C and E. If you are a merchant, read A, D and E.
A3. Platforms covered
This policy applies to personal information processed through the DING Delivery mobile application (iOS and Android) and the DING web portal used by merchants. Ordering happens only through the app. There is no web ordering, telephone ordering, or ordering through any messaging channel. You must create an account to order — there is no guest checkout.
How we make you aware of this policy. Section 18 of POPIA requires us to take reasonably practicable steps to make you aware of what we collect and why. During onboarding, we show you a short summary of the key points of this policy together with a link to the full text, and ask you to confirm that you have seen it before you continue.
A4. POPIA roles and key terms
Personal information — information relating to an identifiable living person and, where applicable, an identifiable juristic person.
Special personal information — a narrower category given extra protection under section 26, including information about health, religious beliefs, race, biometrics and criminal behaviour.
Processing — almost anything done with personal information: collecting, storing, using, sharing, changing or deleting it.
Responsible party — the person or organisation that decides what is collected and why. Where DING decides why and how your personal information is processed, DING is the responsible party.
Operator — an organisation that processes personal information for a responsible party, under contract.
Information Officer — Adam Ismail, supported by Scott Kilmister as Deputy Information Officer under section 56 of POPIA.
A5. Why we may process your information
Section 11 of POPIA sets out the lawful grounds for processing. Depending on the activity, we rely on performance of a contract (section 11(1)(b)), legal obligation (section 11(1)(c)), protecting a legitimate interest of the data subject (section 11(1)(d)), legitimate interests of DING or a third party (section 11(1)(f)), or consent (section 11(1)(a)). Special personal information is processed only where one of the grounds in sections 27 to 33 applies.
PART B — CUSTOMERS
B1. What we collect from customers
We collect a deliberately limited set of information: first name and surname; email address; mobile number; date of birth; delivery address; account ID; order history (including special requests); and support correspondence. Customers cannot upload a profile photograph. We do not collect your identity document.
One-time passcodes: When you sign up, we send a one-time passcode to your mobile number by SMS, through Twilio, to confirm the number belongs to you.
Delivery information: Your delivery address may include apartment, unit, building or complex details, and any delivery instructions you give.
Information we receive from others: We may receive information about you from merchants and drivers, from our payment provider, and from law enforcement or regulators where lawfully required.
B2. Location information
We distinguish the delivery address you provide, optional device location permission, approximate location used to show available restaurants, and live location during a delivery (which is the driver’s location, not yours). We do not continuously track customers.
B3. Order information
We collect and store information about your orders to fulfil and route them, take and reconcile payment, complete delivery, provide support, handle refunds, resolve disputes, prevent fraud, and meet accounting and tax obligations. The platform does not currently support customer tipping.
B4. Special requests, allergies and what your orders may reveal
The special requests field is passed unchanged to the merchant. Allergy and medical information is special personal information under POPIA section 26. Where you choose to type such information, we process it on the basis that you have deliberately provided it for the specific purpose of having your food prepared safely (sections 27(1)(a) and 27(1)(e)). We do not build a profile of your health from it. We do not draw inferences about religious or philosophical belief from order history.
B5. Payment information
Payments are processed by Stitch, a South African payment provider. DING does not store your full card number or banking credentials.
B6. Delivery PIN
DING uses a temporary delivery verification PIN. PIN verification is the only proof of delivery we use. We do not photograph deliveries.
B7. What merchants see about you
Merchants receive your first name and surname and telephone number, together with order details and any special requests. They do not receive your delivery address, email, date of birth or payment details. Merchants may use your information only to prepare and fulfil your order.
B8. What drivers see about you
Drivers receive your first name and surname, telephone number, delivery address, delivery instructions, order number and status. Once a delivery is completed, the driver no longer has access to your details through the app.
B9. Communications
Operational communications form part of the service and cannot be switched off entirely while you have an active account and live orders. We do not currently send marketing communications. If we do in future, we will only do so where section 69 of POPIA permits it, and every marketing message will include a way to opt out.
B10–B13. Support, feedback, device information and sharing
Support is handled in-house by DING staff. No chatbot or AI assistant is used. We do not operate a public ratings or reviews system. Data minimisation is the governing principle under POPIA section 10. Merchants and drivers receive only what they need.
PART C — DELIVERY DRIVERS
C1–C2. Information collected and identity verification
We collect identity, contact, account, verification, payment, employment, delivery and device information from drivers. Facial comparison produces biometric information processed under POPIA sections 27(1)(a), 27(1)(b) and 33. No facial template is stored. Identity document images are retained for as long as the driver works for DING and deleted when they leave.
C3. Location data
Location tracking is workplace monitoring. We rely on the employment relationship as our legal basis. Monitoring is proportionate and occurs only while you are on shift. Customers and merchants see your live location only while you are carrying out a delivery for them.
C4–C8. Pay, customer information obligations, PIN, communications and performance
Drivers may use customer information only to complete the delivery. Misuse may breach POPIA and result in disciplinary and legal action. PIN verification is the only proof of delivery. Decisions about employment are made by people, not by the system.
PART D — MERCHANTS
D1–D11. Information collected, obligations and POPIA duties
We process business and individual information about merchants and the people acting for them. Merchants must use customer information only to prepare and fulfil the DING order. Printed order tickets must be kept secure and disposed of securely. Merchants have their own obligations under POPIA as responsible parties for information they process in their own businesses.
PART E — PROVISIONS THAT APPLY TO EVERYONE
E1. Third-party service providers
Our operators include AWS (Africa Cape Town region), Amazon CloudFront, Twilio, Firebase, Mapbox and Stitch. We have written contracts with each operator under POPIA sections 20 and 21. We do not sell personal information.
E2. Automated processing
DING does not use artificial intelligence or machine learning that produces legal consequences or substantially affects individuals. Delivery dispatch is automated on the basis of proximity and availability only. Employment, merchant account and customer access decisions are made by people.
E3. Fraud, security and platform integrity
We process personal information to detect fraud, protect accounts, prevent abuse and maintain platform integrity.
E4. International data transfers
Our database and backups are held in South Africa. Transfers involving Twilio, Firebase, Mapbox and CloudFront rely on POPIA section 72(1)(a) (binding contractual terms) and section 72(1)(c) (necessary for performance of the contract).
E5. Data retention
Our general retention period is three years from the date a record is created or an account is closed, whichever is later. This period is enforced by an automated deletion process. Financial and tax records are retained for five years; company records for seven years; employment records for three years from the end of employment (or longer where required).
E6. Security
We implement encryption in transit and at rest, rate limiting, access logging, local data residency, and contractual security requirements on vendors. We never receive or store card or banking credentials.
E7. Data breaches
If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects in accordance with POPIA section 22.
E8. Your rights
You have the rights of access, correction, deletion, objection, withdrawal of consent, objection to direct marketing, and complaint under POPIA. Exercising these rights will not affect your account status, employment or standing on the platform.
E9. Deactivation, closure and deletion
The DING platform is for adults. You must be 18 or older. We do not knowingly collect or process the personal information of children. Where we establish that an account holder is under 18, we will close the account and delete the associated personal information, other than anything we are legally required to retain.
E10. How to contact us
DING, operated by JUST IDENTIFICATION SYSTEMS (registration number 2000/063841/23)
Information Officer: Adam Ismail
Deputy Information Officer: Scott Kilmister
Email: dingappsupport@gmail.com
Physical address: 7 Sugnet Lane, Lonehill, Sandton, Gauteng, 2191
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints email: POPIAComplaints@inforegulator.org.za
Telephone: 010 023 5200
Website: www.inforegulator.org.za
E11. Changes to this policy
We may update this policy when our services, technology, data practices, service providers or legal obligations change. Where a change is significant, we will take reasonable steps to bring it to your attention before it takes effect.
Version: 1.0
Effective date: 23 September 2026
Last updated: 23 September 2026