Privacy Policy
Last updated: 23 August 2026
This policy explains what personal information Foundly collects, why, and the rights you have over it — in line with South Africa's Protection of Personal Information Act (POPIA) and, for members in the UK/EU, the GDPR.
1. What we collect
| Data | Why we collect it |
|---|---|
| Name, email, password (hashed) | Your account and login. Passwords are stored only as bcrypt hashes — we cannot read them. |
| Profile details (company, role, industry, city, about, needs/offers, links, photo) | Shown to other members so the network can work — this is the product. |
| Approximate location (only if you tap “detect my location”) | To place you in the nearest city. Never collected in the background. |
| Activity (connections, RSVPs, messages, posts, favourites, profile views) | To run the features you use and recommend relevant founders. |
| Payment records (amount, reference, status) | PRO purchases. Card details go directly to Paystack — we never see or store them. |
| Technical basics (session cookie) | Keeping you logged in securely. We don't run third-party ad trackers. |
2. What other members see
Your profile (name, photo, company, role, city, about, needs/offers, links) is visible to logged-in members. Your email address is never shown to other members. Messages are visible only to you and the recipient.
3. Who we share data with
- Paystack — payment processing when you buy PRO.
- Our hosting provider — the servers and email delivery that run Foundly.
- Nobody else. We do not sell or rent personal information. We disclose data only if the law requires it.
4. Email
We send transactional email: account verification, password resets, meetup changes/cancellations, waitlist promotions and payment confirmations. Platform announcements are kept to a minimum.
5. Your rights (POPIA & GDPR)
- Access & correction — view and edit your information any time in My Profile.
- Deletion — My Profile → Danger zone → Delete my account permanently removes your profile, photo, messages, posts, RSVPs, connections and tokens. This is immediate and irreversible.
- Objection & complaints — contact the platform administrator; you may also lodge a complaint with the Information Regulator (South Africa) or your local authority.
6. Safety controls
You can block any member (you disappear from each other completely) and report members or posts for review. Blocking is silent — the other person is not notified.
7. Security
Passwords are bcrypt-hashed, sessions use secure HttpOnly cookies, reset/verification links are single-use and hashed at rest, and payment card data never touches our servers. No internet service can promise perfect security, but we design conservatively.
8. Retention
We keep your data while your account exists. When you delete your account, your personal data is removed immediately; anonymised payment records may be retained where financial law requires it.
9. Children
Foundly is for adults (18+). We do not knowingly collect information about children.
10. Changes & contact
If this policy changes materially we'll announce it in-app. Questions or requests: contact the platform administrator via the app or the contact email published on the site.