Privacy Policy & Data Protection Notice
Statutory Compliance Notice under Protection of Personal Information Act (POPIA Act 4 of 2013), EU General Data Protection Regulation (GDPR 2016/679), and Electronic Communications and Transactions Act (ECTA 25 of 2002).
Statutory Disclosure Index
1. Responsible Party Identity & Scope
This Privacy Policy applies to all applications, websites, and APIs operated under Zash Holdings Pty Ltd t/a Kustomcode and related operational portfolio, including but not limited to kustomcode.xyz, fleet.kustomcode.xyz, zbot.kustomcode.xyz, Relay Ingress gateways, and OEM diagnostics software.
Under Section 1 of the Protection of Personal Information Act (POPIA Act 4 of 2013), Zash Holdings Pty Ltd t/a Kustomcode acts as the designated Responsible Party determining the purpose and means of processing Personal Identifiable Information (PII).
2. POPIA Section 18 Explicit PII Notice
Pursuant to POPIA Section 18, we provide explicit notice regarding the precise categories of data collected directly from data subjects during platform onboarding and interaction:
Legal full name, verified email address, phone number for OTP authentication, hashed credentials, and device identifiers.
Coarse and fine PostGIS spatial coordinates used exclusively for localized parcel tracking and fleet dispatching.
Stripe and PayFast transaction IDs. Raw credit card numbers are processed directly via PCI-DSS Level 1 compliant gateways and are never stored on Kustomcode servers.
3. POPIA Section 57 Biometric Consent & Zero-Knowledge Burn
POPIA Section 57 requires prior authorization and explicit data subject consent for processing special personal information, specifically biometric data.
When undergoing verification (e.g. driver badge verification or selfie liveness checks), our client-side MediaPipe engine extracts facial geometry landmarks in client memory. Once verification is calculated:
- Raw camera frames are immediately destroyed in memory (Zero-Knowledge Burn).
- Only a boolean verification status flag (`isVerified: true`) and cryptographically signed verification token are stored in PostgreSQL.
- No raw biometric imagery, facial depth maps, or facial feature templates are retained or shared with third parties.
4. ECTA Section 43 Disclosures & Section 44 Digital Waiver
In compliance with Section 43 of the Electronic Communications and Transactions Act (ECTA 25 of 2002), merchant details are disclosed below:
- Merchant / Company Name: Zash Holdings Pty Ltd t/a Kustomcode
- Website: https://kustomcode.xyz
- Primary & Legal Email: contact@kustomcode.xyz
- Physical Jurisdiction: Polokwane, Limpopo / Gauteng, Republic of South Africa
By purchasing digital API keys, software licenses, or digital PDF publications, users acknowledge that digital content is delivered immediately upon transaction confirmation. Pursuant to ECTA Section 44(2), the standard 7-day cooling-off period does not apply to un-downloadable digital services or delivered digital assets once performance has commenced.
5. Right to Erasure & Tombstone Ledger Policy
Under POPIA Section 24 and GDPR Article 17, users possess the absolute statutory right to request erasure of their personal identifiable information.
Upon submitting an Account Deletion request via settings or by emailing contact@kustomcode.xyz:
- All profile PII, telemetry records, and chat histories are permanently hard-deleted from live production databases within 72 hours.
- Financial transaction records mandated by South African Revenue Service (SARS) tax laws are anonymized into non-identifiable tombstone ledgers.
6. Contact Information Officer
For statutory privacy inquiries, POPIA Form 2 objection requests, or data protection officer communications, contact: