← Swim Pursuit SA

Privacy Policy

Version 2.0.0 — Effective 10 July 2026

Swim Pursuit SA was built by Ronald Vleggaar and his son Daniel, a competitive swimmer, as an independent, family-made project. This policy describes exactly what the app does with data today — nothing more, nothing generic. It intentionally collects the minimum information needed to provide its functionality, and it will always tell you plainly when that changes.

Who we are

Swim Pursuit SA is operated by Ronald Vleggaar, based in Cape Town, South Africa. For the personal information processed through the app, Ronald Vleggaar is the Responsible Party as defined in South Africa's Protection of Personal Information Act, 2013 (POPIA).

Contact: Ronald Vleggaar, Cape Town, South Africa — ronaldv.apps@gmail.com

Information we collect

Account holder (the adult who registers): email address, date of birth.

Each swimmer profile: name, date of birth, gender, club, province, area, swimming stroke/event preferences, logged swim times and results, and an optional profile photo.

We intentionally minimise what we collect. Swim Pursuit SA does not collect home addresses, phone numbers, payment information, or precise device location. There is no public leaderboard — swimmer data is only ever visible to the people described below.

How we use this information, and why we're allowed to

We use this information solely to provide the app's functionality: tracking times, calculating qualification status against published standards, goal tracking, and showing progress over time.

We process this information because doing so is necessary to provide the service you've asked to use. Where information relates to a child under 18, processing is based on the consent of that child's parent or legal guardian, as described below.

We do not use your data for advertising, do not run analytics or tracking software of any kind, do not build behavioural profiles, and will never sell your personal information.

Diagnostic and crash data

We don't embed any separate analytics or crash-reporting software in the app ourselves. That said, some diagnostic data is collected outside our control, as a normal part of how phones and app stores work:

Apple and Google each automatically collect basic crash and performance diagnostics as part of running any app on their platform. If you have diagnostic sharing enabled on your device, we may see an aggregated, anonymised version of this through App Store Connect or the Google Play Console — never data tied to your account or identity.

Expo/EAS, the tooling used to build and deliver the app, does not add its own crash-reporting or analytics code to the app you install.

Supabase, our backend provider, keeps the routine server logs any backend keeps (request timestamps, IP address, endpoint called) for security and reliability. This is infrastructure logging, not analytics.

None of this is used for advertising or profiling.

Who can see this data, and linked accounts

The account holder who owns a swimmer profile; anyone that account holder has granted access to via a linked account, using a one-time invite code — typically a second parent, or the swimmer themselves once they're 13 or older with their own login; and us, only as needed to operate the app or respond to a support request — never to unrelated third parties, never for marketing.

What a linked account can do: the same day-to-day access as the owner — viewing the profile and full history; adding, editing and deleting logged times and goals; uploading or replacing the profile photo; updating club/province/area/swimming type; exporting the swimmer's data; and seeing everyone else who has access.

What only the original account owner can do: permanently delete the swimmer's profile and history; revoke someone else's access (a linked account can only remove its own — "leave"); and create new invite codes.

Access can be reviewed and managed at any time from Settings → Linked accounts.

Children's privacy and guardian consent

Only individuals aged 13 or older may create their own Swim Pursuit SA account. Swimmers younger than 18 may only be added to the app by their parent or legal guardian, who creates and holds the account on the swimmer's behalf.

When a guardian adds a swimmer, they confirm — from their own logged-in account — that they are that swimmer's parent or legal guardian and consent to their data being processed as described here. When an invited co-parent or guardian accepts access to a swimmer under 18, they separately attest that they are the swimmer's parent or legal guardian (or otherwise legally authorised to access that swimmer's information), and consent independently rather than inheriting the original owner's consent.

This is an attestation, not an identity-verification process — we have no way to independently confirm a family relationship, and we say so plainly rather than imply a verification we don't perform.

We keep an audit record of each consent (method, policy version, and timestamp) for accountability. If a swimmer or account is later deleted, this record is retained but stripped of anything that could identify a person.

Data retention

We retain your information for as long as your account remains active. When you delete a swimmer profile or your whole account, that personal information is permanently removed from our live systems — except that anonymised consent audit records are kept for accountability, as described above, and deleted information may remain in encrypted backups for a limited period before those backups are automatically overwritten.

How we store and protect data

Data is stored using Supabase, a hosted Postgres database and file-storage provider. Access between users is enforced by database-level security rules (Row Level Security), so one family cannot access another family's information through the app. Access to production data by us is strictly limited and controlled. Profile photos are kept in a private storage bucket and are only ever served via short-lived, expiring links.

Data in transit is encrypted (HTTPS/TLS). No password is ever visible to us in plain text.

International transfers

Where personal information is processed outside South Africa — which may happen given Supabase's hosting infrastructure — we take reasonable steps to ensure appropriate contractual and technical safeguards are in place.

Your rights

Under POPIA, you can: export a swimmer's data at any time from Settings; delete a single swimmer's profile and history, or your entire account, at any time — this is immediate, permanent, and cannot be undone; correct inaccurate data, or make any request you can't complete in-app, by contacting us; withdraw consent at any time where processing is based on consent, though doing so may limit your ability to use certain features; and lodge a complaint with the Information Regulator (South Africa) if you believe your information has been mishandled.

If you only hold a linked login to a swimmer you don't own, deleting your account removes your own access but leaves the swimmer's data with its owner.

Third parties we rely on

Supabase (database, authentication, and file storage) and Expo/EAS (the platform used to build and deliver the app itself). These providers process information only on our behalf, under their own data-processing terms, and do not acquire any right to use your personal information for their own advertising or marketing purposes.

Cookies

Swim Pursuit SA does not use cookies. If a web version is released in future, this policy will be updated to reflect that.

Changes to this policy

If this policy changes in a way that affects what we collect or how we use it, we will update the version number shown in-app and, where the change is material, ask existing users to acknowledge it.

Contact us

Ronald Vleggaar, Cape Town, South Africa — ronaldv.apps@gmail.com