1. Introduction
Welcome to Proximate. Proximate is a location-aware platform for discovering nearby venues, events, communities and live experiences. Depending on the features available, people may scan venue QR codes, check in, join time-limited Live Hubs, participate in conversations, request venue service, make reservations, leave reviews, receive relevant offers, earn rewards and use premium discovery tools.
This Privacy Policy describes how we process personal information and should be read together with our Terms of Service, Community Guidelines, Cookie Notice and any feature-specific notice presented at the time information is collected.
Under the Protection of Personal Information Act 4 of 2013 ("POPIA"), simply using a service is not treated as blanket consent for every type of processing. We therefore identify the applicable lawful ground for each processing activity and request consent where consent is legally required or is the appropriate basis.
2. Who we are
Proximate is operated by Proximate Applications (Pty) Ltd, referred to in this policy as "Proximate", "we", "us" or "our".
For the personal information for which we determine the purpose and means of processing, Proximate is the responsible party under POPIA. A participating venue may also act as a separate responsible party for information it collects for its own reservations, customer service, loyalty, safety, legal or operational purposes.
Where Proximate processes information only on documented instructions from a venue, Proximate may act as that venue's operator. The applicable venue notice or agreement should explain that relationship where relevant.
3. Scope of this policy
This policy applies to personal information processed through:
- the Proximate website, Progressive Web App and mobile experiences;
- account registration, authentication and profile features;
- nearby venue, event and Live Hub discovery;
- venue QR codes, check-ins, check-outs and table sessions;
- reservations, menus, reviews and venue service requests;
- Live Hubs, conversations, reactions and moderation tools;
- premium subscriptions, rewards, referrals and PRXM records;
- push notifications, email, SMS or other communications;
- venue dashboards and analytics generated through Proximate; and
- support, safety, fraud prevention and legal compliance.
This policy does not control a third party's independent processing. This includes a venue's own point-of-sale system, booking platform, Wi-Fi service, CCTV, payment system, website or loyalty database. Those parties must provide their own privacy information.
4. Our privacy principles
Purpose limitation
We collect information for identified, lawful and reasonably necessary purposes.
Data minimisation
We aim not to collect more information than a feature reasonably needs.
Location protection
Precise coordinates are not intended to be publicly displayed to other users.
User control
Users can manage permissions, visibility, communications and account choices.
Venue separation
Venues should receive aggregate insights by default unless identity is needed.
No sale of data
We do not sell personal information to data brokers or advertisers.
5. Information we collect
5.1 Account and authentication information
When a user creates or accesses an account, we may collect:
- display name, full name or username;
- email address and, where enabled, mobile number;
- date of birth or age confirmation;
- authentication identifiers and login records;
- password credentials in hashed or provider-managed form;
- account status, verification status and subscription tier; and
- records of acceptance of terms, privacy notices and consent choices.
5.2 Profile information
Depending on the profile features a user chooses, we may collect:
- profile photograph or selected avatar;
- biography, occupation, languages and interests;
- favourite venues, preferred activities or discovery preferences;
- city, general area or voluntarily supplied profile details; and
- privacy, visibility and notification settings.
Optional fields are marked or presented as optional. Users should not place sensitive personal information in public biographies, hub names, messages or reviews unless it is genuinely necessary and they are comfortable sharing it with the intended audience.
5.3 Avatar and identity-protection features
A user may be allowed to display an avatar instead of a personal photograph. An avatar reduces public exposure but does not make an account anonymous to Proximate. We may retain the account identifier and verification information needed for safety, abuse prevention, support and legal compliance.
5.4 Device, network and technical information
We may automatically receive:
- IP address, browser, operating system and app version;
- device type, language, time zone and approximate network location;
- cookie, local-storage, session and push-notification identifiers;
- referring pages, feature interactions and timestamps;
- crash information, diagnostics, logs and performance data; and
- signals used to identify abuse, duplicate accounts or automated activity.
5.5 Content and communications
We may process content that users submit, including:
- Live Hub messages, direct messages, reactions and attachments;
- reviews, ratings, reports, feedback and survey responses;
- support correspondence and evidence supplied with a complaint;
- venue announcements or campaign content created by authorised venue staff; and
- message metadata such as sender, recipient, delivery status and timestamp.
5.6 Information from other sources
We may receive information from:
- authentication providers where a user selects social sign-in;
- participating venues when they manage bookings or respond to service requests;
- payment processors confirming payment or subscription status;
- referral links or promotional partners;
- fraud, safety or security service providers; and
- public sources where lawful and reasonably necessary.
We will not assume that third-party information is accurate. Users may request correction where information is inaccurate, incomplete, excessive, outdated or misleading.
6. Location information
Proximate is location-aware, but location access should be limited to the feature being used and the permissions granted by the user.
6.1 Types of location information
Depending on the feature and device permission, we may process:
- approximate location derived from the device or IP address;
- precise GPS coordinates for a nearby search or location-dependent feature;
- distance between the user and a venue or hub;
- location accuracy, timestamp and permission state;
- a check-in or check-out event associated with a venue; and
- limited movement signals needed to determine whether a session should end.
6.2 What other users see
Users should nevertheless understand that joining a venue-specific hub, checking in, posting a message, uploading media or identifying a table can reveal that they are at, or were recently associated with, that place.
6.3 Background location
Proximate should not collect continuous background location unless a clearly identified feature genuinely requires it, the operating system allows it, and the user has granted the relevant permission. Where an exit-detection feature is enabled, location may be checked for the limited purpose of determining whether a venue session should be ended.
6.4 Location controls
A user can generally:
- deny or withdraw device location permission;
- use manual venue discovery where that option is available;
- leave a hub or manually check out;
- adjust visibility and radius settings; and
- disable background permissions in device settings.
Some features may not function, or may be less accurate, when location access is disabled.
7. QR codes, venue sessions and check-ins
7.1 Scanning a venue QR code
A Proximate QR code may identify a venue, table, event, campaign or session. When scanned, it may open a venue page and create a session record. Depending on whether the visitor is logged in, this record may be linked to an account or to a temporary pseudonymous session identifier stored on the device.
7.2 Guest and anonymous-style sessions
A person may be permitted to browse or use limited venue functions without creating an account. "Guest" does not necessarily mean that no information is collected. We may still process a session identifier, venue and table identifier, timestamps, device information, network information and interactions needed to operate and secure the session.
Guest sessions do not qualify for account-linked rewards, persistent loyalty history or some community features unless the person signs in or creates an account.
7.3 Check-in and check-out events
A venue session may include:
- venue and table identifiers;
- check-in and check-out timestamps;
- session duration;
- service requests, reservations or reviews;
- Live Hub participation;
- reward eligibility and redemption records; and
- a reason for session closure, such as manual checkout, expiry or detected exit.
7.4 Automatic checkout
Where enabled, Proximate may use a limited location comparison, session timeout or user confirmation prompt to determine whether the visitor has left a venue. If the visitor does not respond, the session may end automatically according to the disclosed feature rules. Automatic checkout should not be represented as continuous public tracking.
8. Participating venues and venue analytics
8.1 What a venue may receive
A participating venue may receive information necessary to deliver the selected experience. This may include a reservation name, table number, service request, review, loyalty status, campaign response or message sent directly to the venue.
8.2 Aggregate and de-identified analytics
Where individual identity is not necessary, Proximate aims to provide venues with aggregated, statistical or de-identified insights, such as:
- visitor counts and live occupancy estimates;
- new-versus-returning visitor trends;
- average session duration;
- busy periods and engagement trends;
- reservation, check-in and campaign conversion rates;
- service-request volumes and response times; and
- combined rating or review trends.
8.3 When identity may be visible to a venue
A venue may receive identifiable information where:
- the user makes a reservation or asks the venue to contact them;
- the user joins an identified loyalty or rewards programme;
- the user submits a service request linked to a table or account;
- the user sends a direct message, review or profile swap request;
- identity is reasonably necessary to investigate fraud, safety or misconduct; or
- the user is clearly informed and has an appropriate choice.
8.4 Venue responsibilities
A venue must use Proximate information only for authorised purposes, protect account access, limit staff permissions and comply with POPIA and its agreement with Proximate. A venue may not use dashboard information to harass, discriminate against, secretly track or improperly profile visitors.
9. Live Hubs, messaging and community features
Live Hubs are temporary or ongoing digital spaces associated with a venue, event, topic or broad area. The audience for a Hub depends on its settings.
9.1 Visibility
A display name, avatar, message, reaction and time of posting may be visible to other Hub participants. A venue-specific Hub can reveal the user's association with that venue. Users should check the Hub's visibility before posting.
9.2 Content moderation
Proximate may use automated signals and human review to detect spam, harassment, threats, fraud, impersonation and violations of the Community Guidelines. Reports may include the reported content, account identifiers, surrounding context, device or session signals and moderator actions.
9.3 Message privacy
Messages are not guaranteed to be confidential from recipients. A recipient may save, forward or capture content. Proximate personnel or authorised service providers may access messages where reasonably necessary for support, security, moderation, legal compliance or investigation of a reported violation.
9.4 Deleted and expired content
Removing content from user-facing screens may not immediately remove every copy from backups, security logs, moderation records or a recipient's device. Content may be retained where required for dispute resolution, abuse prevention or law.
10. Reservations, reviews and venue service requests
10.1 Reservations
For reservations we may process a name, contact details, date, time, party size, venue, special request, attendance status and communications. Dietary or accessibility information should be provided only when needed and may constitute sensitive information.
10.2 Service requests
Requests such as "call waiter", "request bill" or similar operational actions may be linked to a venue, table, session, time and user account or guest identifier. Relevant venue staff may see the request.
10.3 Reviews and ratings
Reviews may be public or shared with the venue depending on the product design. We may analyse reviews to produce combined insights, detect manipulation and enforce review standards. Users must not publish another person's private information in a review.
11. Rewards, referrals, premium features and PRXM
11.1 Rewards and loyalty records
We may process:
- points, PRXM or rewards earned and redeemed;
- eligible check-ins, referrals, promotions or campaign actions;
- participating venue, date, reward status and expiry;
- fraud-prevention signals; and
- account tier and premium feature entitlements.
11.2 Referrals
A referral link may identify the referring account and record whether a referred person completed the disclosed qualifying action. We should not reveal the referred person's unrelated account activity to the referrer.
11.3 PRXM
Unless expressly stated otherwise in separate legally reviewed terms, PRXM is an in-platform rewards or utility mechanism. Records may include allocations, transfers, redemptions, balances and anti-abuse checks. This policy does not promise that PRXM has cash value, investment value, withdrawal rights or legal status as a regulated financial product.
11.4 Payments and subscriptions
Payments may be handled by an authorised payment provider. Proximate may receive a transaction reference, amount, currency, status, subscription period and limited billing information. Full card details should be collected and stored by the payment provider, not by Proximate, unless a compliant payment arrangement expressly requires otherwise.
12. How we use personal information
We may process personal information to:
- create, authenticate and manage accounts;
- provide venue, map, discovery, check-in and Live Hub features;
- process reservations, service requests, reviews and rewards;
- personalise recommendations and rank relevant nearby content;
- calculate distances without publicly exposing exact coordinates;
- operate customer support and communicate service information;
- protect users, venues, Proximate and the public;
- detect fraud, spam, fake activity, scraping and security attacks;
- moderate content and enforce agreements and guidelines;
- measure performance and improve the product;
- produce aggregate venue and platform insights;
- administer subscriptions, rewards and promotional campaigns;
- comply with tax, accounting, legal and regulatory obligations; and
- establish, exercise or defend legal claims.
If we want to use personal information for a materially different and incompatible purpose, we will provide an appropriate notice and obtain consent where required.
13. Lawful grounds for processing
POPIA requires personal information to be processed lawfully and reasonably. Depending on the activity, we rely on one or more of the following grounds recognised by POPIA:
| Ground | Typical Proximate examples |
|---|---|
| Consent | Optional precise-location access, certain marketing, optional profile fields, or another feature where consent is the appropriate basis. |
| Contract or steps requested before contract | Creating an account, providing a selected service, processing a reservation, subscription or reward. |
| Legal obligation | Accounting, lawful requests, regulatory duties, security-compromise reporting and record preservation. |
| Protecting a legitimate interest of the user | Responding to an urgent safety report or protecting an account from suspected compromise. |
| Public-law duty | Only where a public-law obligation lawfully applies. |
| Legitimate interests of Proximate or a third party | Service security, fraud prevention, limited analytics, enforcing rules and improving the platform, provided the user's rights do not unjustifiably override those interests. |
13.1 Withdrawal of consent
Where processing is based on consent, consent may be withdrawn prospectively. Withdrawal does not invalidate lawful processing already performed and may make a dependent feature unavailable.
13.2 Special personal information
Proximate does not seek to infer or use special personal information unless a lawful basis and any required authorisation exist. Users should avoid sharing health, biometric, religious, political, trade-union, sexual-life or similar sensitive information in public spaces. Where information such as dietary or accessibility needs is necessary, it should be limited to the purpose for which it was supplied.
14. When we share personal information
We may share limited information with:
14.1 Other users
Other users may see information made visible by the user or required by a social feature, such as display name, avatar, public profile, Hub content, reactions, reviews or broad distance information.
14.2 Participating venues
Venues may receive operational information, identified interactions and aggregate analytics as described in section 8. Venue access should be role-based and limited to authorised staff.
14.3 Operators and service providers
We may appoint providers for cloud hosting, database services, authentication, maps, email, messaging, push notifications, analytics, error monitoring, support, payment processing and security. They may process information only for authorised services, subject to appropriate contractual and security obligations.
14.4 Business restructuring
Information may be disclosed in connection with a genuine investment, financing, merger, acquisition, reorganisation or sale, subject to confidentiality, due diligence controls and applicable law. Users will be notified if a new responsible party materially changes the processing purposes.
14.5 Legal, safety and enforcement disclosures
We may disclose information where reasonably necessary to:
- comply with a valid legal obligation, court order or lawful process;
- respond to an authorised regulator or law-enforcement request;
- protect the rights, safety or property of users, venues or Proximate;
- investigate fraud, abuse, security incidents or contractual violations; or
- establish, exercise or defend a legal claim.
14.6 Aggregate information
We may use and share information that has been aggregated or de-identified so that it no longer identifies a person, provided we do not deliberately attempt to re-identify it.
15. Direct marketing, venue promotions and notifications
15.1 Service communications
We may send necessary account, transaction, reservation, safety, security, policy and service messages. These are not promotional communications and may continue while an account or active transaction exists.
15.2 Electronic direct marketing
We will request consent before sending unsolicited electronic direct marketing where required by section 69 of POPIA. Where contact details were obtained in the context of a customer relationship, we may market our own similar products or services only where the legal requirements are met and a free, uncomplicated opportunity to object is provided.
Marketing messages must identify the sender and provide a functional way to stop future marketing. An opt-out is not treated as consent. Consent records may be retained to prove the user's choice.
15.3 Venue promotions
A venue promotion may be based on broad criteria such as selected area, venue interest, visit history or account preferences. A venue should not receive a user's contact details merely because the user fits a campaign audience. Where Proximate sends the message on the venue's behalf, appropriate roles and instructions must be contractually defined.
15.4 Push notifications
Push notifications require a device permission and may use a device token supplied by a notification provider. Users can adjust notification settings in Proximate or the device. Disabling push notifications does not necessarily disable essential email or in-app service notices.
16. Cookies, local storage and similar technologies
Proximate may use cookies, browser storage, service workers, cache storage and similar technologies to:
- keep a user signed in and maintain session security;
- remember preferences and consent choices;
- support PWA installation and offline functionality;
- associate a guest scan with a temporary venue session;
- measure product performance and diagnose faults;
- prevent fraud and abuse; and
- deliver notifications where permission has been granted.
Essential technologies are required for the service to function. Non-essential analytics or advertising technologies should be activated only in accordance with applicable law and the choices presented in the Cookie Notice or consent interface.
Clearing browser storage may sign the user out, reset preferences, end a guest session or prevent rewards from being associated with that device.
17. Data retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, an authorised compatible purpose, or a legal requirement. Retention depends on the category, sensitivity, operational need, risk, user expectations and applicable limitation periods.
| Category | General retention approach |
|---|---|
| Account and profile | While the account is active, then deleted or de-identified following closure, subject to legal, fraud, dispute and backup requirements. |
| Precise location samples | Kept only as briefly as reasonably necessary for the enabled location feature, security or dispute purpose. Venue check-in events may be kept longer than raw coordinate samples. |
| Venue sessions and check-ins | Retained for account history, rewards, analytics, fraud prevention, venue reporting and legal needs, then aggregated, de-identified or deleted under the retention schedule. |
| Messages and Hub content | While available in the relevant feature and for a limited period afterwards where needed for moderation, reports, disputes, safety or backups. |
| Reservations and transactions | For fulfilment, accounting, dispute resolution, fraud prevention and legally required recordkeeping periods. |
| Security and audit logs | For a proportionate period based on security risk, investigation needs and legal requirements. |
| Marketing preferences | For as long as needed to honour and demonstrate consent or an objection, including suppression records. |
| Backups | Removed through normal secure backup rotation unless preservation is required by law or an active incident. |
17.1 Account deletion
A user may request account deletion through an available account tool or by contacting us. We will verify the request and remove, de-identify or restrict personal information in accordance with POPIA and our retention schedule.
Deletion is not always immediate or absolute. We may retain limited information where required for legal compliance, accounting, fraud prevention, enforcement, safety, suppression of unwanted marketing, disputes, legal claims or secure backup rotation.
17.2 Anonymisation and aggregation
Information that has been irreversibly de-identified so that it no longer relates to an identifiable person may be retained for statistical, research and service-improvement purposes.
18. Security safeguards and compromises
We use reasonable technical and organisational safeguards appropriate to the nature of the information and foreseeable risks. Measures may include:
- encrypted transport connections;
- authentication and password-hashing controls;
- role-based access and least-privilege permissions;
- database and storage access policies;
- logging, monitoring and incident-response procedures;
- secure development, update and vulnerability-management practices;
- operator contracts and confidentiality obligations;
- backups and availability controls; and
- staff awareness and access review.
No system is perfectly secure. Users should protect their devices, keep login details confidential, use strong unique passwords and report suspected account compromise.
18.1 Security compromises
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and make the notifications required by section 22 of POPIA. This may include notifying the Information Regulator and affected data subjects as soon as reasonably possible, subject to lawful restrictions.
19. Cross-border processing
Some service providers may process or store information outside South Africa. We will transfer personal information to a foreign country only where permitted by section 72 of POPIA, such as where:
- the recipient is subject to a law, binding corporate rules or agreement providing an adequate level of protection;
- the user consents to the transfer after being informed of relevant considerations;
- the transfer is necessary for performance of a contract or pre-contractual steps requested by the user;
- the transfer is necessary for a contract concluded in the user's interest; or
- another lawful section 72 condition applies.
Safeguards may include data-processing agreements, confidentiality, security requirements, access controls and assessment of the recipient's legal environment.
19.1 European and United Kingdom users
Where the EU General Data Protection Regulation or United Kingdom data-protection law applies to Proximate's processing, affected users may have additional rights, including restriction, objection, portability and rights concerning certain automated decisions. These rights apply only where the relevant law has territorial application and may be subject to legal exceptions.
20. Your rights under POPIA
Subject to POPIA and lawful limitations, a data subject may:
- be notified that personal information is being collected;
- be notified of a security compromise where required;
- request confirmation of whether we hold personal information about them;
- request access to personal information and information about relevant third parties;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- request destruction or deletion of a record we are no longer authorised to retain;
- object, on reasonable grounds, to certain processing;
- withdraw consent where processing depends on consent;
- object to direct marketing;
- not be subject to certain decisions based solely on automated processing where section 71 applies;
- submit a complaint to the Information Regulator; and
- institute civil proceedings where permitted by law.
20.1 Exercising a right
Requests may be sent to legal@proximate.co.za. Please state the right being exercised and provide enough information for us to locate the relevant record. We may request reasonable identity verification before disclosing, changing or deleting information.
We will respond within the period required by applicable law. Access may be subject to lawful refusal grounds and a prescribed fee where permitted. We will explain a refusal where the law requires us to do so.
20.2 Correction and objection forms
The Information Regulator publishes forms for objections, correction or deletion and complaints. A request does not have to use legal jargon, but using the applicable form may help identify the requested action.
21. Children's personal information
Proximate is intended for persons aged 18 years or older. A person under 18 may not create or use a standard Proximate account.
We do not knowingly seek to process children's personal information through the standard service. If we learn that a child has created an account contrary to this rule, we may suspend the account and take reasonable steps to delete or restrict the information, subject to safety, evidence-preservation and legal requirements.
A parent, guardian or competent person who believes a child's information has been processed may contact us at legal@proximate.co.za.
22. Personalisation, profiling and automated processing
Proximate may use automated rules or models to rank nearby venues, recommend Live Hubs, detect suspicious activity, identify spam, estimate campaign relevance or prioritise moderation review.
These systems may use factors such as general location, stated interests, past feature interactions, venue engagement, account status, device signals and report history.
We do not intend to make a decision based solely on automated processing that produces legal consequences or similarly significant effects unless the decision is permitted by section 71 of POPIA and appropriate safeguards are provided. Users may contact us to ask about a significant automated decision affecting them.
23. Third-party services and links
Proximate may contain links to venue websites, maps, social networks, menus, ticketing, delivery, payment or booking services. When a user leaves Proximate or intentionally interacts with a third-party service, that party's terms and privacy policy apply.
We are not responsible for an independent third party's privacy practices merely because its link or integration appears in Proximate. Users should review the relevant notice before providing personal information.
24. Changes to this policy
We may update this policy to reflect new features, legal developments, security practices or operational changes. The current version and effective date will be published on this page.
Where a change is material, we will provide a prominent in-app, website or direct notice where reasonably practicable. If consent is required for a new purpose, we will request it rather than treating continued use as consent.
25. Contact, Information Officer and complaints
25.1 Proximate contact details
Sandton, Johannesburg,
Gauteng, 2090, South Africa
legal@proximate.co.za
25.2 Complaints to the Information Regulator
We encourage users to contact us first so we can try to resolve a privacy concern. A data subject also has the right to complain to the Information Regulator (South Africa).
25.3 Governing legal framework
This policy is primarily designed around the Protection of Personal Information Act 4 of 2013 and applicable South African regulations. It does not waive any right a data subject has under applicable law.
Back to top ↑