Back to sign up

IOQ Privacy Policy

Last updated: 2 August 2026

1. Overview

This Privacy Policy explains how IOQ collects, uses, shares, and protects your personal information when you use IOQ.

When this Privacy Policy changes materially, IOQ may ask you to review and accept the latest version before continuing to use the platform.

Your acceptance applies to your account and to the active IOQ features you choose to use, including account access, public discovery, business profiles, business services, booking or enquiry actions, promotions, digital book and e-book hosting workflows, WhatsApp-related actions, QR/share links, notifications, reports, plan limits, uploads, and related support or security records.

2. What we collect

Depending on features you use, IOQ may collect:

  • Account data: name, email, phone (if used), profile photo/avatar, authentication identifiers (e.g., Google OAuth ID if you sign in with Google), hashed password (if password auth is enabled).
  • Session and device security data: session identifiers, device token/cookie identifiers, login timestamps, last-login metadata, last-seen timestamps, last activity timestamps, route/activity metadata, IP address, user agent, and session revocation status used to enforce account session controls and investigate suspicious use.
  • Usage & device data: app interactions (pages viewed, clicks, feature usage), device and browser info, IP address, log data, crash reports.
  • Location data, only when you allow it or a feature needs it: approximate or precise device location, selected places, place search inputs, autocomplete selections, map/place identifiers, reverse-geocode responses, route/navigation intents, and approximate IP-based location results.
  • User, author, and business content: public profile fields, author names, book titles, subtitles, descriptions, categories, language, ISBN, proposed selling details, business details, services, offers, images, listings, booking/contact requests, promotion drafts, published promotion fields, uploaded promotional media, and selected contact preferences such as WhatsApp, call, and phone visibility.
  • Digital book and e-book hosting submissions: intake form details, rights and review confirmations, WhatsApp contact consent, uploaded cover images, manuscript or PDF files, extracted page text, rendered page previews, generated EPUB or publisher-layout artifacts, validation reports, diagnostics, private storage paths, submission references, workflow status, attribution parameters, notification status, message identifiers, failure details, and timestamps.
  • Business linking and ownership context: place identifiers/details, link status, user-selected role metadata, and timestamped link history where business linking is used.
  • WhatsApp, campaign, author outreach, and customer-action data: recipient or contact inputs you provide, message/template status, campaign status, consent/status labels, delivery-related provider metadata where available, and contact-intent actions such as WhatsApp, call, public page, QR, and share clicks.
  • Plan and usage data: current plan, active allowances, media or promotion limits, credit usage, search/save/business/action counters, and enforcement records used to apply feature access rules.
  • Notification data: in-app notification records (type, status, timestamps, related entity references, and read state).
  • Report and branding data: report range selections, role scope, exported file metadata, branding fields such as display name, logo, colors, links, contact fields, and last-used business context.
  • Audit records: security and compliance event logs for sensitive actions such as business link/unlink, role changes, profile updates, campaign actions, and plan/access state actions where applicable.
  • Consent and settings: records of your acceptance of Terms/Privacy and your privacy-related preferences.

3. Why we collect it (purpose)

We use your information to:

  • Create and manage your account.
  • Authenticate you (including Google sign-in if enabled).
  • Enforce account session security rules (including active-device limits, session continuity checks, last-login tracking, app-activity alignment checks, and session revocation flows).
  • Provide explore, category, public page, save, share, contact, booking/enquiry, business profile, services, offers, digital book, e-book hosting, and promotion workflows.
  • Review author submissions, validate book files and cover assets, prepare author profiles, configure book pages, manage reader-access setup, and support operational follow-up for submitted e-book hosting requests.
  • Run e-book quality assurance workflows, including PDF extraction, metadata detection, page rendering, structure analysis, EPUB generation, EPUB standards validation, diagnostics, artifact promotion, and review gating before publication.
  • Enable business profile and promotion flows, including draft save/publish, uploaded media, public page display, QR/share links, WhatsApp/call contact-intent routing, and customer-action status tracking.
  • Enforce plan and usage limits and manage access states.
  • Measure feature performance, such as promotion creation counts, customer-action events, WhatsApp/call click interactions, page activity, and report activity, to improve product quality and reliability.
  • Drive notification and workflow continuity (for example unread counts, request review prompts, and status updates).
  • Improve performance, security, and user experience.
  • Prevent fraud/abuse and enforce our Terms.
  • Communicate service messages (security, important changes).
  • Troubleshoot location, mapping, WhatsApp, campaign, access, report, media upload, and integration failures, including maintaining logs and operational diagnostics.

Where you choose to use a specific feature, we may process the information reasonably necessary for that feature’s setup, permissions, discovery logic, workflow state, visibility controls, moderation, audit trail, quota enforcement, report generation, fraud prevention, and support.

4. Legal basis (South Africa / POPIA-friendly wording)

We process information based on:

  • Your consent (e.g., location permission, marketing if applicable).
  • Performance of a contract (providing IOQ service).
  • Legitimate interests (security, fraud prevention, product improvement).
  • Legal obligations (where applicable).

5. How we share information

We may share data:

  • With service providers (hosting, analytics, messaging, email delivery, error monitoring) who process data under contract.
  • With infrastructure providers needed for core feature delivery, including hosting, media storage, maps/place lookup, messaging/WhatsApp, email delivery, and analytics/error monitoring.
  • With other users or the public when you choose to publish a public profile, business page, promotion, service, offer, contact route, QR/share link, or other customer-facing content.
  • For legal and safety reasons, if required by law, court order, or to protect users, IOQ, and the public.

We do not sell your personal information.

Where a feature relies on an external provider, relevant data may be processed by that provider according to its own terms and privacy practices. Examples can include authentication providers, mapping/place data services, WhatsApp or messaging providers, media storage, and communication channels initiated at your request.

5A. Feature and integration consent

When you intentionally use a feature, submit content into a workflow, connect an external account, enable a permission, or trigger a third-party dependent action, you consent to the processing and data movement reasonably necessary to provide that feature.

  • Google and similar sign-in/integration flows may require us to receive account identifiers, profile details, and authorization tokens permitted by the provider.
  • Location, maps, nearby search, and venue suggestion features may require device location, destination inputs, coordinates, and provider lookup data.
  • Place, business, booking/enquiry, service, offer, save, share, promotion, digital book, e-book hosting, and contact-action features may require us to store requests, linked entity references, uploaded assets, submission state, and activity history.
  • Business, promotion, plan/access, and report features may require us to process quota events, linked business context, branding details, campaign status, and contact-intent actions.

If you do not want that feature-specific processing to occur, do not use that feature or disable the relevant permission where available.

6. Business contact, campaign, and WhatsApp controls

When you publish business content or run campaign-style actions, you control the information you provide and the contact routes you enable, such as WhatsApp, call, public links, QR links, or other customer-action paths.

If you submit customer, recipient, or buyer contact details, you confirm you have permission to share that information for the intended contact, campaign, or enquiry purpose.

WhatsApp, template-message, campaign, and delivery-related metadata may be processed by IOQ and relevant providers to operate the action, record status, prevent abuse, troubleshoot failures, and support compliance.

Where business linking is available, a linked business marked Unverified indicates user-asserted association only and does not represent confirmed ownership authority until official verification requirements are completed.

6A. Author submissions and digital book files

When you submit e-book hosting details, IOQ may process the author information, book details, uploaded files, consent confirmations, attribution data, and communication metadata needed to review, prepare, support, and manage the hosting workflow.

Book files and cover images may be stored in private or restricted storage and surfaced to authorised operational users through controlled review and temporary-download workflows. Public pages should not expose private manuscript storage paths.

For quality assurance, IOQ may generate derived files such as extracted text, rendered page images, EPUB packages, validation summaries, diagnostics, and processing reports. These artifacts are used for review, troubleshooting, approval decisions, support, and service integrity.

WhatsApp confirmations, template messages, and author-invitation campaigns may be processed through messaging providers. Delivery status, message identifiers, provider errors, and timestamps may be retained for support, compliance, duplicate-prevention, and troubleshooting.

7. Location sharing and safety features

If you enable location-based features:

  • We may process location to provide the feature, such as nearby discovery, place lookup, public pages, booking context, and map/navigation actions.
  • For nearby discovery features, distance values and suggested places depend on location permissions, provider data quality, and device/network conditions.
  • Location accuracy depends on device and permissions.
  • You can disable location permissions in your device settings (some features may stop working).
  • If precise device location is unavailable, IOQ may use approximate fallbacks such as selected place data or IP-based location estimates, which can be less accurate.

IOQ (I Own Quarters / IOQs) acts as a discovery and exposure tool. Public pages, contact actions, bookings, and any resulting real-world interactions are controlled by users and businesses, not IOQ. IOQ does not supervise, manage, or guarantee outcomes of user-arranged or business-arranged interactions.

8. Quota, feature gating, and upgrade prompts

To enforce plan rules and system fairness, IOQ may process action counters such as searches, saves, booking/enquiry actions, business actions, promotion actions, media uploads, campaign status changes, and related active feature events.

These enforcement records are used for entitlement checks, abuse prevention, and service reliability, and are retained in line with our retention section.

8A. Report generation and branded export processing

When you generate a report, IOQ processes data needed to build the selected report scope (Explorer or Business), date range, and output format.

  • for business exports, IOQ may use your active or last-selected linked business context to align report content,
  • if branding is enabled, uploaded logo/contact details are used in generated report headers/footers,
  • export activity may be logged as audit metadata (for example role, format, range, branded state),
  • generated exports may be downloaded to your device, and handling/storage after download is your responsibility.

9. Data retention

We keep personal data only as long as needed for:

  • Providing the service.
  • Legitimate business needs (security logs, dispute handling).
  • Compliance with law.

We may retain limited data after account deletion where required or justified (e.g., fraud prevention, legal obligations).

Operational records related to consent, request state transitions, campaign status, contact actions, and notification delivery/read state may be retained for compliance, fraud prevention, and platform reliability analysis.

Session and device-security records may be retained for account protection, abuse detection, auditability, and support review, including revoked/expired session history, last-login metadata, and app-activity-aligned session history where reasonably necessary.

Feature-level operational records may remain in backups, audit trails, or reconciliation systems for a reasonable period where required for security, fraud prevention, dispute handling, financial reporting, service integrity, or legal compliance.

9A. Cross-border processing

Some IOQ providers or infrastructure may process or store information outside South Africa. Where this occurs, IOQ takes reasonable steps to require appropriate safeguards consistent with applicable law and the provider relationship.

10. Security

We use reasonable technical and organizational measures to protect data (access controls, encryption where appropriate, secure authentication practices). No system is perfectly secure; you use IOQ at your own risk.

For clarity, data/privacy controls and account-level approvals do not eliminate real-world risk. After users choose to communicate, visit, book, or transact outside IOQ, users remain responsible for their own safety and decisions.

11. Your rights

Subject to applicable law, you may request to:

  • Access, correct, or delete your personal data.
  • Object to certain processing.
  • Withdraw consent (where processing is based on consent).

To make a privacy request, email office@ioqs.co.za.

12. Children

IOQ is not intended for children who are not legally allowed to consent to data processing in their jurisdiction. If you believe a child provided data, contact us.

13. Changes

We may update this policy. We’ll post the updated version and change the “Last updated” date. Material changes may be notified in-app or via email.

14. Contact

Privacy requests: office@ioqs.co.za.

I Own Quarters (IOQs), entertainment division of Reify Maxim Group (registration number 2025/223053/07).

Registered office: 2 Roos Street, Aquila Estate, Witkoppen Fourways, Johannesburg, Gauteng, 2068.

Parent company: Reify Maxim Group (Pty) Ltd.