Browns Digital

Privacy Policy

Last updated: 23 July 2026

1. Introduction

This Privacy Policy explains how Robert Brown trading as Browns Digital ("Browns Digital", "we", "us", or "our") collects, uses, shares, and protects personal information when you use brownsdigital.org, Studio, My Account, Help, Status, Roadmap, and related services.

We process personal information in line with South Africa's Protection of Personal Information Act, 2013 (POPIA) and, where relevant, other applicable law. Related documents:

2. Who is the responsible party

For personal information about Browns Digital accounts, billing, support, and use of our own platform surfaces, the responsible party (POPIA equivalent of a controller) is:

  • Robert Brown trading as Browns Digital
  • Email: legal@brownsdigital.org (subject line "POPIA request" for data-subject requests)

We aim to acknowledge POPIA requests within five business days and resolve them within 30 days where reasonably practicable.

3. Controller vs operator roles for hosted sites

  • Your account with us: we are the responsible party for account, authentication, billing, and support data.
  • Visitors to sites you publish: you are typically the responsible party for personal information collected through forms, analytics, cookies, or other tooling on your site. We act as an operator when we host or transmit that information as part of Studio hosting. Those obligations are set out in the Data Processing Addendum.
  • You must provide an appropriate privacy notice to your site visitors and ensure you have a lawful basis under POPIA (or other applicable law) for your processing.

4. Key definitions

  • Personal information — information relating to an identifiable, living natural person (and, where applicable, an identifiable juristic person), as defined in POPIA.
  • Responsible party — the person who determines the purpose of and means for processing personal information.
  • Operator — a person who processes personal information for a responsible party under contract or mandate, without coming under the direct authority of that party.
  • Processing — any operation concerning personal information, including collection, storage, use, disclosure, and deletion.

5. Information we collect

5.1 Information you provide

  • Account details (name or display name, email address, password or authentication credentials).
  • Billing contact details and payment-related metadata (card numbers stay with Paystack).
  • Support messages, feedback, and correspondence.
  • Content you create or upload in Studio (Your Content), which may include personal information if you choose to include it.

5.2 Information collected automatically

  • Device, browser, and approximate location signals derived from IP address.
  • Log data (for example timestamps, request paths, error codes, and security events).
  • Cookies and similar storage needed for sessions and security (see section 12).

5.3 Information from third parties

  • Optional OAuth providers (for example Google or GitHub) may provide email, name, and avatar.
  • Payment processors provide transaction status and limited card metadata.

6. How we use personal information

We use personal information to:

  • Provide, operate, and improve the services.
  • Authenticate you and maintain sessions across our subdomains.
  • Host and serve sites you publish.
  • Process payments, send receipts, and manage subscriptions.
  • Answer support requests and notify you of incidents affecting you.
  • Detect, prevent, and respond to abuse, fraud, and security incidents.
  • Comply with law and enforce our Terms and Acceptable Use Policy.

We do not sell personal information. We do not use Your Content or personal information to train general-purpose machine-learning models for third parties. See the AI Policy for how AI features are handled when offered.

7. Lawful bases under POPIA

Processing Typical POPIA justification
Account creation and service delivery Contract / necessary for performance of the agreement
Billing and tax records Contract and legal obligation
Security, abuse prevention, and fraud controls Legitimate interest / legal obligation where applicable
Optional marketing emails (if ever offered) Consent (you may withdraw)
Operator hosting of your site visitors' data Processing on your mandate under the DPA

8. Sharing and subprocessors

We share personal information with operators who process it on our instructions to deliver the services. Material subprocessors include:

Provider Purpose Data involved Region (typical)
Supabase Authentication and application database Account details, sessions, content metadata EU / US
Paystack Payment processing Billing contact, transaction data (cards stay with Paystack) ZA / NG
Resend / Brevo (or successor transactional email providers) Transactional email delivery Email address, message content US / EU
Google / GitHub Optional OAuth sign-in Email, name, avatar (from the provider to us) US
Hosting provider (cPanel / LiteSpeed or equivalent web hosting) Web hosting and server logs Traffic data, hosted content As shown on Status / hosting notices
Discord Optional community / support community Discord profile and messages you choose to share there Per Discord's policies

Beyond subprocessors, we disclose personal information only: (a) when the law compels it; (b) to protect the rights, safety, or property of Browns Digital, our users, or the public; or (c) in a business transfer, in which case this policy continues to apply and you will be notified where required. We will update this table when we add a subprocessor that handles personal information in a material way.

9. International transfers

Some subprocessors store or process data outside South Africa. POPIA section 72 permits cross-border transfers where, among other grounds, the recipient is subject to a law, binding corporate rules, or agreement providing an adequate level of protection, where the transfer is necessary for the performance of a contract, or with your consent.

Our arrangements with subprocessors are intended to incorporate appropriate protections. By using services that rely on these providers, you acknowledge these transfers.

10. Retention

  • Account data: kept while your account is active. After deletion, we remove or de-identify personal information within a reasonable period, subject to residual backups that roll off automatically.
  • Billing and tax records: retained for as long as tax and accounting law requires.
  • Security and server logs: retained for a limited period needed for security, troubleshooting, and abuse investigation.
  • Hosted site content: kept while you maintain the site or account, then deleted or de-identified per the DPA and backup schedule.
  • Support correspondence: retained as needed to handle your request and for a reasonable follow-up period.

11. Security

POPIA section 19 requires appropriate, reasonable technical and organisational measures. Ours include access controls, transport encryption where supported, isolation of customer sites where architecture permits, credential hashing, and logging of administrative access. No method of transmission or storage is perfectly secure; we work to reduce risk and respond to incidents.

If personal information is accessed or acquired by an unauthorised person, POPIA section 22 requires notification to the Information Regulator and affected data subjects as soon as reasonably possible. We will tell you what happened, what data was involved, what we have done, and what you can do — typically by email to your account address and, where appropriate, via status.brownsdigital.org.

12. Cookies and similar technologies

We use cookies and local storage primarily for authentication, session continuity, security, and essential preferences. We do not run third-party advertising cookies on the core platform.

Category Purpose Typical lifetime
Session / auth Keep you signed in and enforce security controls Session or until logout / expiry
Preferences Remember UI settings you choose Until cleared or updated
Security CSRF protection, rate limiting, abuse detection Short-lived as needed

You can control cookies through your browser. Blocking essential cookies may prevent sign-in or core features from working.

13. Your POPIA rights

Under POPIA you may, subject to lawful exceptions:

  • Access — confirm whether we hold your personal information and request a copy.
  • Correction — request correction of inaccurate, incomplete, or outdated information.
  • Deletion / destruction — request deletion where information is no longer needed, consent is withdrawn (where consent is the basis), or processing is unlawful.
  • Objection — object to certain processing on reasonable grounds.
  • Complaints — lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za).

Send requests to legal@brownsdigital.org. We may need to verify your identity before acting.

14. Automated processing

We use automated systems for rate limiting and abuse detection (for example blocking rapid repeated sign-in failures). These are not intended to produce legal effects of the kind restricted by POPIA without human review. Account suspension based on automated signals can be appealed to a human via support.

15. Children's privacy

Our services are not directed at children under 18. POPIA restricts processing of children's personal information. Accounts require you to be 18+, or 13+ with the consent and supervision of a parent or guardian who accepts the Terms on your behalf.

If we learn we hold a child's information without proper consent, we will delete it. Parents or guardians may contact us at any time.

16. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email and/or via the status page where practical. The version shown on the policy page identifies the current revision. Continued use after the effective date constitutes acceptance of the updated policy.

17. Contact