1. Introduction
GetQubic (Pty) Ltd, enterprise number 2026/301994/07, operates Qubic ("Qubic", "we", "us" or "our"). We respect privacy and are committed to protecting personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA").
This Policy explains how we collect, use, store and protect personal information when you use the Qubic website and web application (the "Service").
2. Roles under POPIA
For purposes of POPIA:
- You, the business user, are the Responsible Party for customer data you upload or process using Qubic.
- Qubic acts as an Operator, processing personal information on your behalf.
- We may also act as a Responsible Party for your account-related data.
3. Accounts and authentication
Qubic uses passwordless email authentication provided through Supabase Auth. We process your email address, profile information and browser authentication session to create and secure your account. Profile information may include your name and phone number where provided.
Normal registration creates an owner business for the new user. Registration through a team invitation can skip that normal owner-business creation so the user can review and join an existing business. If a signed-in user does not have an available business, Qubic can ask the user to create one explicitly.
A user may own or belong to more than one business. Qubic processes the user's business memberships and selected business so the application can present the relevant business data and settings.
4. Business, customer and document information
Business information may include business and company names, registration and VAT details entered by users, contact and address details, banking information displayed on documents, logos, branding and document-display settings, separate quote and invoice numbering, optional prefixes, and subscription or plan state.
Customer and workflow information may include customer names, addresses and contact details; selected browser-contact details; job and Start Quote information; quotes and invoices; descriptions, notes and line items; VAT, discounts, deposits and markup; document lifecycle events; revisions and version history; public-document links and customer responses; approval, decline and rejection-note records; payment and payment-status information; PDFs and printing data; client history and suggestions; and activity and actor attribution.
If you choose to open a supported browser contact picker, Qubic receives only the contact information you actively select. Qubic does not automatically read or upload your complete address book. Manual entry remains available and device or browser support varies.
5. Referral information
The public website may receive a business-scoped referral code in a refquery parameter and store a valid-format code in browser local or session storage so it can be included with a later signup request. If browser storage is unavailable, the code may be held only in memory for the current loaded website session and may be lost on refresh. Signup remains available without referral attribution.
Qubic may process new-account and first-business attribution; the relationship between referring and referred businesses; subscription-payment state used for qualification; referral statuses; R50 referred-business discount events; referrer credit events; and additional-month reward events. Each business has its own code, progress and reward records.
Authorised platform administrators may review referral records and record supported corrections. Participant-facing referral views use generic progress summaries and do not disclose another participant's private business or account identity.
6. Team invitations
When an authorised business user creates an invitation, Qubic processes the invited email address, the inviting business name, the offered role, and records relating to creation, expiry, delivery, resend, replacement, cancellation, decline and acceptance. These records may include the users who create, accept, decline or cancel an invitation and the outcome of delivery attempts.
The invitation recipient is shown the inviting business name and offered role. Invitation links expire after seven days and may be resent, replaced or cancelled. Acceptance requires the authenticated account email to match the invited email. Matching authenticated users may also be shown that a pending invitation exists.
Resend currently provides transactional invitation-email delivery. Authorised Qubic personnel may use invitation and delivery-status information to investigate delivery or status questions. Qubic does not publish or expose the sensitive internal handling used to protect invitation links.
7. Public quote and invoice links
Customers do not need a Qubic account to use a valid and currently available public quote or invoice link. Anyone who receives such a link may be able to view the document information and customer actions needed for the available workflow, such as downloading a PDF, accepting or declining a quote, adding a rejection note or proceeding to an eligible payment action.
Public document links are not authenticated customer portals and should be shared carefully. A link may stop working when a document is recalled, replaced, expired, closed or otherwise restricted by its lifecycle rules.
9. PayFast and payment information
A Qubic business may connect its own PayFast merchant account for eligible customer payments on accepted quotes or invoices. PayFast processes the payment. Qubic records available payment-attempt, status and confirmation information and does not receive or store the customer's full card details or hold the business's customer funds. Some payment states may require review where an automatic confirmation is not received.
Qubic separately uses PayFast for eligible Qubic subscription checkout. Subscription payment state may be used to manage access and to process referral qualification, discounts, credits and additional-month rewards.
10. How we use information
We use information to provide and operate Qubic; authenticate accounts; create, store and share quotes and invoices; maintain document and activity history; support client suggestions; manage businesses, teams, invitations, subscriptions and referrals; facilitate payment requests; provide support; protect the Service; improve functionality; and comply with legal obligations.
We do not sell personal information.
11. Lawful basis for processing
We process personal information based on consent, performance of a contract, compliance with legal obligations and legitimate business interests such as platform security and improvement.
You are responsible for ensuring you have a lawful basis to process your customers' data.
12. Service providers and external destinations
Qubic uses service providers that currently include Vercel for website and application hosting; Supabase for authentication, database and file-storage services; PayFast for the payment-processing contexts described above; and Resend for team-invitation transactional email.
WhatsApp, Google Maps and the email application selected by a user are external destinations. Opening one of these destinations may cause that provider to process information under its own terms and privacy practices. They are not described here as providers processing data for Qubic merely because a user chooses to open them.
13. Business, team and support access
Current business roles are owner, admin, member and viewer. Access is scoped to a business and depends on the controls implemented for the relevant operation. Authorised users of a business may share access to that business's settings, documents and customer information. A user's separate businesses retain their own data, settings, subscription state and membership records.
Authorised support or platform personnel may access restricted account, business, team, client-name and diagnostic information where needed for customer support, payment-readiness or document diagnostics, referral administration, invitation delivery and status investigation, or security and abuse investigation. This access is purpose based and is not unrestricted employee access.
14. Application analytics and browser storage
The authenticated application currently records first-party screen and workflow events, a session identifier and restricted event metadata to understand feature use and diagnose the Service. Qubic does not currently use third-party advertising pixels or third-party analytics tags on the public website or authenticated application.
Qubic uses browser local or session storage for functions such as authentication state, the selected business, referral attribution, invitation flow, analytics session state, checklist state, temporary workflow hand-offs and the public website's storage notice. Browser controls may block or clear this information. Doing so can affect attribution and other functionality but does not prevent ordinary website signup.
15. Legal disclosure
We may disclose information if required by law or to comply with legal processes, protect rights, safety or property, or prevent fraud or abuse.
16. International data transfers
Your data may be processed or stored outside South Africa. Where this occurs, we take reasonable steps to ensure that the recipient is subject to laws or agreements that provide adequate protection and that appropriate safeguards are in place.
17. Data security
We implement reasonable technical and organizational measures, including authentication, access controls, business-scoped database policies, public-link controls and protected server-side payment handling. No system is completely secure, and we cannot guarantee absolute security.
See the Security page for implementation-based detail without certification, backup, uptime or absolute-access claims.
18. Data retention
We retain personal information for as long as your account is active, as necessary to provide the Service, and as required by law, including applicable financial record-keeping obligations. Referral attribution, qualification, credit and reward records may be retained as service and subscription-accounting records even after a particular reward has been applied or a referral no longer progresses. You may request deletion of your data, subject to legal and operational record-keeping requirements.
19. Your rights under POPIA
You may have the right to access personal information held about you; request correction or deletion; object to processing in certain circumstances; withdraw consent where applicable; and lodge a complaint with the Information Regulator.
20. Business-user responsibilities
Business users are responsible for obtaining necessary consent, using personal information lawfully, avoiding spam or unlawful messaging, maintaining accurate documents, and complying with POPIA and other applicable laws.
21. Changes to this Policy
We may update this Privacy Policy from time to time. Updated versions will be posted with a revised "Last updated" date.
22. Contact and regulator
General privacy questions or requests may be sent to info@getqubic.co.za. This contact does not identify a formally appointed Information Officer.
If you believe your rights have been violated, you may contact the Information Regulator (South Africa).