1. Introduction
The Common Sense ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (thecommonsense.co.za), use our mobile applications, or engage with our services.
This policy complies with the Protection of Personal Information Act (POPIA) in South Africa and applies to all users of our services.
2. Information We Collect
2.1 Information You Provide Directly
When you create an account, subscribe, or interact with our services, we may collect:
- Account Information: Name, email address
- Profile Information: Username, profile picture, preferences
- Subscription Information: Payment details, subscription tier
- Communications: Messages you send us, comments, feedback, and survey responses
2.2 Information Collected Automatically
When you use our services, we automatically collect:
- Usage Data: Articles read, time spent, interactions, search queries
- Device Information: IP address, browser type, operating system, device identifiers
- Location Data: General location based on IP address (not precise geolocation)
- Analytics Data: Cookieless page view analytics via Fathom Analytics (no personal data collected)
- Essential Cookies: Session data and user preferences only
2.3 Information from Third Parties
- Authentication Providers: When you sign in with Google SSO or other OAuth providers, we receive your name, email address, and profile picture from those services
- Social Media: If you share our content or interact with us on social platforms, we may receive limited information based on your privacy settings
- Analytics Services: Aggregated usage data from third-party analytics tools
3. How We Use Your Information
3.1 Provide and Improve Services
- Create and manage your account
- Process subscriptions and payments
- Deliver personalized content recommendations
- Improve our content, website, and mobile applications
- Analyze usage patterns and trends
3.2 Communication
- Send you newsletters and content updates (with your consent)
- Respond to your inquiries and support requests
- Notify you about account activity and subscription status
- Send important service announcements
3.3 Legal and Security
- Comply with legal obligations under POPIA and other applicable laws
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service
- Resolve disputes
3.4 Marketing (With Consent)
- Send promotional materials about our services
- Conduct surveys and research
- Provide personalized advertising (you can opt out)
4. Third-Party Services We Use
4.1 Authentication and User Management
Clerk.com - Securely manages user authentication, accounts, and sessions
Google OAuth - Optional sign-in method using your Google account
4.2 Content Management
Sanity.io - Content management system for our articles and media
4.3 Analytics and Performance
Fathom Analytics - Privacy-first website analytics
- Data collected: Page views, referrers, device type, general location (country-level only)
- No cookies or personal data collection
- No cross-site tracking or data sharing with third parties
- Fully GDPR, POPIA, and CCPA compliant
- Privacy Policy: https://usefathom.com/privacy
We may also use Vercel Analytics for performance monitoring of our application.
4.4 Payment Processing
Payment information is processed by secure third-party payment processors. We do not store your full credit card details.
4.5 Hosting and Infrastructure
Our services are hosted on secure cloud infrastructure providers who may process data on our behalf.
5. Legal Basis for Processing (POPIA Compliance)
Under POPIA, we process your personal information based on:
- Consent: When you agree to receive marketing communications or use optional features
- Contract Performance: To provide services you've subscribed to
- Legal Obligation: To comply with South African and applicable laws
- Legitimate Interests: To improve our services, prevent fraud, and ensure security
6. Data Sharing and Disclosure
6.1 We Share Information With:
- Service Providers: Third-party vendors who help us operate our services (as listed in Section 4)
- Business Transfers: In case of merger, acquisition, or sale of assets
- Legal Requirements: When required by law or to protect rights and safety
- With Your Consent: When you explicitly authorize us to share information
6.2 We Do NOT:
- Sell your personal information to third parties
- Share your data with advertisers (except aggregated, anonymized data)
- Use your data for purposes beyond what's described in this policy
7. Your Rights Under POPIA
As a South African user, you have the right to:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your data (subject to legal obligations)
- Objection: Object to processing for marketing purposes
- Restriction: Request limitation of processing in certain circumstances
- Data Portability: Receive your data in a portable format
- Withdraw Consent: Opt out of marketing communications at any time
To exercise these rights, contact us at: info@thecs.org
8. Data Security
We implement industry-standard security measures:
- Encryption of data in transit (SSL/TLS)
- Secure authentication through Clerk and OAuth providers
- Regular security audits and updates
- Access controls and authentication requirements
- Secure backup procedures
However, no internet transmission is 100% secure. We cannot guarantee absolute security.
9. Data Retention
We retain your information for as long as:
- Your account is active
- Necessary to provide our services
- Required by law or for legitimate business purposes
- You request deletion (subject to legal retention requirements)
Typical retention periods:
- Active accounts: Retained while account is active
- Inactive accounts: Deleted after 3 years of inactivity (after notification)
- Marketing data: Retained until you unsubscribe
- Transaction records: 5-7 years for tax and legal compliance
10. Children's Privacy
Our services are not directed to children under 18. We do not knowingly collect information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries outside South Africa where our service providers operate. We ensure appropriate safeguards are in place to protect your data in accordance with POPIA.
12. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and preferences
- Analyze site usage and performance
- Provide personalized content recommendations
- Remember your settings
Cookie Types:
- Essential: Required for site functionality (cannot be disabled)
- Analytics: Help us understand how you use our site
- Functional: Remember your preferences
- Marketing: Track engagement with promotional content (opt-out available)
You can manage cookie preferences through your browser settings. Note that disabling cookies may limit functionality.
13. Links to Other Websites
Our service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies.
14. Changes to This Privacy Policy
We may update this policy periodically. We will notify you of significant changes by:
- Email notification to registered users
- Prominent notice on our website
- Updated "Last Updated" date at the top of this policy
Continued use of our services after changes constitutes acceptance of the updated policy.
16. Consent
By using The Common Sense services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
For marketing communications, we will obtain your explicit consent through:
- Opt-in checkboxes during registration
- Separate email consent requests
- Preference center in your account settings
You may withdraw consent at any time by:
- Clicking "unsubscribe" in our emails
- Updating preferences in your account settings
- Contacting info@thecs.org
This Privacy Policy is designed to comply with the Protection of Personal Information Act (POPIA) and other applicable South African laws. For questions or concerns about your privacy, please contact our Data Protection Officer at info@thecs.org.