Crossa Logo crossa
POPIA & Regulatory Compliant

Privacy Policy

Last Updated: August 27, 2026 • Version 2.4

This Privacy Policy describes how Crossa (Pty) Ltd (Reg: 2025/689735/07) t/a Crossa South Africa and its operating affiliate Crossa Eswatini (Pty) Ltd (“Crossa,” “we,” “us,” or “our”) collect, use, process, and safeguard your personal information across our website (crossa.africa) and mobile applications. As a registered entity with South Africa’s Information Regulator (Reg: 2025-061657), we adhere strictly to the Protection of Personal Information Act (POPIA) and international data privacy benchmarks.

1. Information We Collect

To deliver cross-border shopping and logistics services, we collect the following categories of data:

  • Personal Identification: Full name, verified mobile phone number, email address, and physical delivery address in Eswatini or South Africa.
  • Account Authentication: Firebase Authentication tokens, Google / Apple sign-in metadata, and encrypted session credentials.
  • Cross-Border Customs & Procurement: Retailer package tracking IDs, uploaded merchant invoice PDFs/images, declared commodity classifications, and customs item descriptions required by SARS and Eswatini Revenue Service (ERS).
  • Payment Identifiers: Transaction reference numbers for MTN MoMo Eswatini, Standard Bank EFT transfers, and secure iKhokha gateway confirmations. (Note: We do not store raw credit card numbers or banking PINs on our servers).
  • Technical & Diagnostics: Device model, OS version, app version, IP address, and anonymized Firebase Crashlytics reports to troubleshoot performance.

2. How We Use Your Information

We process your personal information strictly for legitimate operational purposes, including:

  • Generating and assigning your dedicated South African warehouse transit address.
  • Receiving, sorting, inspecting, and cataloging incoming retailer packages in our Johannesburg and regional transit hubs.
  • Automated customs clearance declaration generation and compliance clearance.
  • Dispatching real-time shipment status notifications via SMS, WhatsApp, and in-app push alerts.
  • Generating secure QR code passes for hub collection and verifying authorized pick-up agents.

3. Information Sharing & Third Parties

We do not sell, rent, or trade your personal data. We only share necessary data with authorized service providers under strict data-processing agreements:

  • Customs & Border Authorities: SARS and ERS as legally required for cross-border import declarations.
  • Payment Service Gateways: MTN Eswatini (MoMo OpenAPI), Standard Bank Eswatini, and iKhokha South Africa.
  • Cloud Infrastructure: Google Cloud Platform (GCP) and Firebase under enterprise-grade encryption at rest and in transit.

4. Data Retention and Security

We implement administrative, technical, and physical security measures, including 256-bit TLS encryption, strict role-based access control, and tokenized authorization. Transactional customs records are retained for the minimum statutory period required by revenue authorities, after which data is purged or permanently anonymized.

5. Your Data Rights & Deletion

Under POPIA and data protection laws, you maintain full control over your information:

  • Access & Rectification: You can review or edit your personal profile and phone numbers directly in the app or portal settings.
  • Instant Account & Data Deletion: You can permanently delete your account, login credentials, and personal records directly in the app or via our Data Deletion Portal.

6. Contact Our Information Officer

If you have questions, regulatory inquiries, or wish to submit a POPIA data request, contact our Information Officer:

• Email: compliance@crossa.africa / sawubona@crossa.africa

• Tel / WhatsApp: +27 60 017 9999

πŸ‡ΈπŸ‡Ώ Eswatini Office:

Crossa Eswatini
Plot 70 A, Office No. 201
Independent Centre Building
Dzeliwe Street, Mbabane

πŸ‡ΏπŸ‡¦ South Africa Office:

Crossa (Pty) Ltd.
13 Kwartel Street
Halfway House
Midrand, 1686, South Africa

Canonical Clean URL: https://crossa.africa/privacy-policy Legacy Reference: #privacy-policy