This Privacy Policy explains how Rooikat Systems (“we”, “us”, “our”) collects, uses, stores and protects personal information when you use Mamba (the “Service”). We are the responsible party for this information under the Protection of Personal Information Act 4 of 2013 (“POPIA”).
1.1 Product accounts. When you create an account we collect your name, email address and account credentials (your password is stored hashed), and generate records needed to operate your account.
1.2 Billing information. When you subscribe or pay for work we process billing records: your billing contact details, VAT number (if provided), and the amount, date, payment status and a payment reference. Your card details are captured and stored by Payfast, our payment processor — we receive only a secure payment token and transaction confirmations, never your card number.
1.3 Content you submit. To provide the Service we process the images you upload for conversion, the prompts and reference images you provide for AI generation, and the vector files, mockups and other outputs we generate for you.
1.4 Consent records. When you accept our Terms & Conditions in the Service we record your user ID, the date and time, and the version of the Terms you accepted, so the agreement can be verified later.
1.5 Technical data. Our servers keep standard technical logs (IP address, request time, user agent) and audit records for security, rate limiting and troubleshooting.
We do not send marketing communications without your consent, and we do not sell or rent personal information to third parties.
We share personal information only with service providers who need it to perform functions on our behalf, under appropriate safeguards:
We will disclose information where the law requires it — for example to a regulator, court or law enforcement acting within their powers.
The Service uses only the cookies or tokens strictly necessary to keep you signed in and keep your session secure. We do not use advertising or analytics trackers. Fonts on these pages are loaded from Google Fonts, which may log the request as described in Google's privacy policy.
We apply appropriate technical and organisational measures: encrypted connections (HTTPS/TLS), hashed passwords, secrets kept out of source code, access limited to those who need it, audit logging, and payment card handling delegated entirely to a PCI DSS compliant processor. No system is perfectly secure, but if a breach occurs that affects your personal information we will notify you and the Information Regulator as POPIA requires.
Under POPIA you may, at any time:
To exercise any of these rights, email info@rooikatsystems.com from the address linked to your account. We respond within 24 hours and resolve requests as quickly as the law allows.
The Service is intended for adults and businesses. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
We may update this policy from time to time. Each revision carries a new version number and effective date at the top of this page. Material changes will be communicated to active customers before they take effect.
Privacy questions and information requests: info@rooikatsystems.com.