Security & Data Protection
Last updated: 21 July 2026
This page summarises the security and data-protection measures Raved (operated by The Web Group (Pty) Ltd) applies to personal information, and our procedure for responding to security incidents. It supports our commitments under POPIA and to the platforms we integrate with.
1. Data minimisation
We collect the minimum personal data required to provide the service: a customer's mobile number and optional first name. We do not collect or store order contents, email addresses, or physical addresses, and we use the data solely to send a single review request on the merchant's behalf.
2. Encryption
All data is encrypted in transit using TLS. Data at rest, including database backups, is encrypted by our managed infrastructure providers. Passwords are hashed with bcrypt and are never stored in plain text.
3. Retention and deletion
Customer mobile numbers are automatically deleted after twelve months. A customer may opt out at any time by replying STOP, which is honoured permanently. On request from an integrated platform, or from a merchant on a customer's behalf, we erase the relevant personal data promptly through automated deletion endpoints.
4. Access control and logging
Access to personal data is restricted to authenticated administrators. Administrative access to customer data is recorded in an audit log. Staff accounts use strong, hashed passwords, and access is limited to what is necessary to operate and support the service.
5. Separation of environments
Testing and development are carried out against a separate database environment, isolated from production data, so that live customer information is never used for testing.
6. Security incident response
Should a security incident affecting personal data occur, we follow this procedure:
- Identify and contain. The incident is investigated immediately, affected systems or credentials are isolated, and access is revoked or rotated as needed.
- Assess. We determine what data was affected, the cause, and the scope of any exposure.
- Remediate. We fix the underlying cause and verify that the vulnerability is closed.
- Notify. Where required by POPIA or by our platform agreements, we notify the Information Regulator, affected merchants and, where applicable, affected individuals, without undue delay.
- Review. We record the incident and update our controls to prevent recurrence.
To report a suspected security issue, contact us at support@raved.co.za and we will respond promptly.
Questions about this document? See the FAQ or contact us on the details above.
