Midgard
Terms

Privacy policy & POPIA notice

Last updated 28 August 2026. This notice explains how Midgard processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA). It applies to merchants who use Midgard and to the subscribers whose numbers merchants send messages to.

1. Who is responsible for your information

When you sign up as a merchant, Midgard is the responsible party for your account information.

When you upload or collect subscriber data and send campaigns, you are the responsible party for that data and Midgard acts as your operator — we process subscriber information only on your instruction and only to deliver the service.

2. What personal information we collect

  • Merchant account data: your name, email address, password (hashed), store name, store URL and ecommerce platform.
  • Subscriber data: mobile numbers (South African +27 format), first and last name, email address where supplied, and language preference.
  • Consent records: opt-in source, opt-in and opt-out timestamps, and the wording shown at the point of consent. These are kept as proof of consent under POPIA and the Consumer Protection Act.
  • Order and cart data from Shopify or WooCommerce: order number, order value in Rand, cart contents and cart recovery links, order and cart timestamps.
  • Messaging data: message content you send, delivery receipts, failures and click events used for revenue attribution.
  • Billing data: plan, invoices, SMS top-ups and credits. Card details are handled by PayFast — Midgard never receives or stores them.
  • Technical data: log records, IP address and browser information used for security and debugging.

3. How we use it and our lawful basis

We process personal information to perform the contract with you, to comply with legal obligations, and for the legitimate interests of running the platform securely. Uses are:

  • Creating and operating your Midgard account.
  • Sending the SMS campaigns and automations you configure, through our licensed SMS suppliers.
  • Recording and honouring opt-outs, quiet hours and consent proof.
  • Attributing recovered revenue and producing analytics in your dashboard.
  • Billing your subscription and SMS credit top-ups, and issuing invoices.
  • Support, fraud prevention, security monitoring and legal compliance.

Subscribers only receive marketing messages where the merchant has recorded a valid opt-in. Every message includes an opt-out instruction, and opt-outs are applied immediately across the merchant's list.

4. Who we share it with

We do not sell personal information, and we never rent or trade subscriber lists. We share only what is necessary with:

  • SMS network suppliers (SMS Messenger and Africa's Talking) to deliver messages.
  • PayFast, for subscription and top-up payments.
  • Our hosting and database provider, for storage of the platform data.
  • Email delivery providers, for invoices and service notifications.
  • Law enforcement or regulators, where we are legally required to do so.

Some of these providers process data outside South Africa. Where that happens we rely on the transfer conditions in section 72 of POPIA and require comparable protection.

5. How long we keep it

  • Merchant account data: for as long as your account is active, then 12 months after closure.
  • Subscriber records and consent proof: until the merchant deletes them or the account closes, then 12 months — consent proof may be kept longer where needed to defend a complaint.
  • Message and delivery logs: 24 months, for attribution, billing disputes and network queries.
  • Order and cart events: 24 months.
  • Invoices and billing records: 5 years, as required by South African tax law.

After these periods data is deleted or irreversibly anonymised.

6. How we protect it

Data is encrypted in transit, access is restricted per merchant by database-level row security, and staff access is limited to what support requires. Passwords are stored hashed. We will notify you and the Information Regulator of a compromise as required by section 22 of POPIA.

7. Your rights — access, correction and deletion

Under POPIA you may:

  • Ask what personal information we hold about you and request a copy.
  • Ask us to correct or delete information that is inaccurate, irrelevant or out of date.
  • Object to processing, or withdraw consent at any time.
  • Lodge a complaint with the Information Regulator of South Africa.

Merchants can export or delete subscriber data directly from the Subscribers page. Subscribers can opt out at any time by replying STOP to any message, at no cost, or by emailing us. To make an access or deletion request, email support@sendmidgard.com with the phone number or email address concerned. We respond within 30 days. Where you are a subscriber of a merchant's list, we will pass the request on to that merchant as the responsible party.

8. POPIA Information Officer

Midgard's designated Information Officer handles all privacy queries, access requests and complaints:

If you are not satisfied with our response, you may complain to the Information Regulator (South Africa) at inforegulator.org.za.

9. Changes to this notice

We may update this notice as the product or the law changes. Material changes will be communicated by email or in the dashboard before they take effect. Continued use of Midgard after that date means you accept the updated notice.