Privacy policy
The short version. You can check any reference number on this site without an account. We do not store your reference. There are four exceptions: if the application turns out to be approved, we add a masked entry to our approval history list, which signed-in users can view; every check anyone runs, approved or not, sends the site operator a short Telegram notification with the masked reference, the application type and the outcome; we add one to a count of how many searches the site answered that day; and every check adds to the anonymous counts on our Analytics page. None of the four identifies you. If you tell us which police station took an application, we keep that station against a keyed fingerprint of the reference, never against you, and anyone who checks that reference sees it. If you create an account, we keep only what is needed to save the applications you choose to save. If you use our metered API, a reference or serial you submit through it is kept only long enough to produce your result, then erased within 24 hours; what we keep permanently is a record that a call was made against your plan, not what you searched for. If you buy a motivation letter or a renewal motivation, we also collect your identity number, to print in its letterhead and to see whether you hold permanent residence, so that your document lists your permit; we encrypt it and it is never sent to the AI provider that writes the document. A renewal motivation also asks you the two questions SAPS asks about convictions and about being unfit to possess a firearm, because the document has to answer them; section 3.12 says what that means and what we do about it. We never look up a reference nobody asked us to, and we never sell or share your information.
1. Who we are
Is It Approved? (isitapproved.co.za) is an independent service that helps a person in South Africa check the status of their own SAPS firearm licence, renewal or competency application. We are not affiliated with the South African Police Service or the Central Firearms Register.
For the purposes of the Protection of Personal Information Act 4 of 2013 (POPIA), isitapproved.co.za is the responsible party for the personal information described below, and you are the data subject. We operate from South Africa.
Contact us at info@isitapproved.co.za for anything in this policy, including to exercise any of your rights.
2. Using the site without an account
The status checker requires no account and no sign-in, wherever you use it. When you use it:
- Your reference number is sent to SAPS to perform the lookup, and the result is shown to you.
- Your reference number is not stored in our own database. Neither is your serial number, nor any firearm detail SAPS returns.
- There are four exceptions. The first: if the application turns out to be approved, we add an entry to our approval history list, which signed-in users can view, so that other people waiting can see roughly how far SAPS has progressed. The entry holds four things: the reference with its last two digits replaced by asterisks, the application type, the date SAPS recorded the approval, and a keyed fingerprint of the full reference, used only so that two approvals in the same batch are not counted as one. It holds nothing else. It is not linked to you, to an account, or to an IP address, and we do not link an entry to a visitor.
- The second: every check anyone runs on this site, including an anonymous one, a refusal, or a reference SAPS has no record of, sends the site operator a short Telegram message with the application type, the same masked reference used in the approval history entry, and the outcome. We do not add that message to our own database, but Telegram keeps its own copy of every message it delivers, and it lands on the operator's phone, so it is a real record of the fact that a check happened, held both by Telegram and by us: the operator is us, as section 1 says, not a separate third party. Section 8 says more about what Telegram receives.
- The third: we add one to a count of how many searches this site answered on that calendar day, so we can tell how much the service is being used. The count is a number and a date, and nothing else. It holds no reference number, no serial number, no account, no IP address and no browser details, and it records searches one at a time only as a total, so nothing in it can be traced back to you or used to tell one search apart from another.
- The fourth: every check anyone runs, approved or not, adds to the counts on our Analytics page, which shows where the applications checked here are sitting in SAPS's process. For that we record the application type, the status and status date SAPS returned, the batch (the first four digits of the reference, after the C or R that begins a competency or renewal reference), and a keyed fingerprint of the full reference. The fingerprint cannot be turned back into the reference without a secret key that only this site holds, and we never use the key to do so. It is used only so that checking the same application twice is not counted twice. None of this is linked to you, to an account or to an IP address. The Analytics page shows only counts and the range of dates behind them, per stage and per batch, including a batch that holds a single application. We have recorded these since September 2026.
- If you choose to tell us which police station you handed an application in at, we keep that station, the application type, the same keyed fingerprint of the reference, when you answered and when you last changed it, and nothing else: not your name, your account or your IP address. Anyone who checks the same reference on this site sees the station you chose. Choosing again replaces it. The Analytics page counts applications per province and per police station, including a station with a single application.
- Outside those four exceptions and a police station you choose to tell us about, nothing is written to our own database for a search.
- This is enforced in the software, not merely as a policy: the lookup code has no access to our database, the reference is masked or turned into a keyed fingerprint before anything is written, and masked before anything is sent to Telegram, and automated tests fail the build if any of that changes.
We keep short-lived technical logs of requests for security and fault-finding. Those logs never contain reference numbers, email addresses, or the contents of any lookup.
3. What we collect if you create an account
An account exists so you can save applications and be told when their status changes. We collect only the following.
3.1 Your account
- Your email address.
- A cryptographic hash of your password, produced with Argon2id. We never store your actual password and cannot recover it.
- The dates your account was created, verified, and last signed in.
- How many searches you have run while signed in, and the date and time of your most recent one. This is a running count and a single timestamp: we do not keep a list of your searches, and we never record which reference numbers you searched for. It lets us see how much the service is actually used by the people who have signed up for it. It is included in your data export, and it is deleted with your account.
3.2 Your sessions
- A hash of your session token, its expiry, and whether it has been revoked.
- The IP address and browser user-agent recorded when the session was created, so you can recognise unfamiliar sign-ins and so we can investigate abuse.
3.3 Applications you choose to save
- The label you give the application, its reference number, an optional serial number, and the application type.
- The status information SAPS returns for it over time: status, status description, next step, status date, and the make, calibre and serial number as SAPS displays them.
- If you choose to tell us the date you handed the application in, we store it. This is optional, and you can change or remove it at any time.
- A record of your consent to store it, described in section 4.
3.4 Telegram, if you connect it
- Your Telegram chat_id, recorded once you link your account by messaging our bot. This is the only Telegram identity we store: no username, no phone number, no display name.
- The date you linked it, and a record of your consent to receive alerts there, described in section 4.
3.5 Google, if you sign in with it
- A permanent identifier for your Google account, which Google calls your sub, recorded the first time you sign in with Google. This is the only Google identity we store: no name, no profile picture, no contacts.
- The date you linked it.
3.6 Firearms you add to your register
The register is optional. Nothing in it is collected unless you add a firearm yourself.
- What you tell us about the firearm: make, model, type and calibre.
- Its serial number, if you give us one. This is the most sensitive thing on the site and we treat it that way: it is shown to you masked, it is never included in an email, a Telegram message or a shared card, and it appears in full only in the data export you ask for about yourself.
- Its licence section, licence number, and the dates the licence was issued and expires. The expiry date is the one your reminders are worked out from.
- Any note you choose to add.
We do not ask where a firearm is kept and there is no field for it anywhere on this site. A record of who owns what, stored beside where it is kept, is a thing we have chosen not to build.
3.7 Activities you log
Also optional, and also only what you enter yourself: the date, the kind of activity, the place, the association if you name one, the firearm from your register if you link one, the number of rounds if you record it, and any note. You can add the result (a score, the event and your placing), the game taken on a hunt, the name of the person who can confirm the activity, the kinds of proof you hold, and proof files such as a photo of your targets or the farmer's letter. This exists so you can show your association the activity that keeps your dedicated status.
3.8 Your reporting details
If you use the printable activity record, you may give us your name so the document is headed with it, along with the date your association wants activities reported by and how many it asks for. All of it is optional and you can clear it at any time.
3.9 Reminders we have sent you
When we send you a licence renewal reminder we record that we sent it: which firearm, which reminder, which channel, and when. We keep that so we never send you the same reminder twice, and so there is a record of whether you were warned.
3.10 If you use our API
We also offer a paid, subscription-metered API for checking references by machine instead of by hand. It is off by default, keys are self-issued at /account/api by any signed-in, verified account, and none of this applies to you unless you have one.
- Your API keys: a label you give each one, the first part of the key so you can recognise it in a list, and when it was created, last used and revoked. Like your session token, we store only a cryptographic hash of the key itself, and cannot recover it.
- A reference or serial number you submit, and the result SAPS returns for it, are stored from the moment you submit them until 24 hours after your result is ready, so you or your own system can retrieve it if you missed it the first time, and are then permanently erased. What is left afterwards is the bare fact that a request was made and its outcome, with no reference or serial in it, the same "count it, not log it" principle behind the daily search count in section 2.
- Your subscription: the plan you are on, its term, and the dates your access runs between. And, for each billing cycle, a record of how many calls your plan's allowance held and how many you used. This is a financial record, and unlike everything else on this page we keep it indefinitely, for the same reason we keep the approval history list in section 2, because it is the record itself.
3.11 If you buy a motivation letter or a renewal motivation
Both are paid, optional features: R250 for one motivation letter for a new licence application, and R180 for one renewal motivation for one firearm. Each is generated from your own answers and addressed to your Designated Firearms Officer and the Registrar of Firearms. A SAPS motivation is a formal submission, and it has to carry the applicant's own identity number in its letterhead, so generating one asks for details the rest of this site does not.
A renewal motivation is different from a motivation letter in one way that matters here: it is written as the additional motivation to field D6 of the Annexure to SAPS 518(a), which you swear to in front of your Designated Firearms Officer. Fields D2 and D3 of that Annexure ask you about convictions and about being unfit to possess a firearm, and we ask you the same two questions so that the document can answer them. That makes them special personal information, and section 3.12 below says what we do about it.
- Your full name, identity number, street address, postal code, phone number, email address and, where your application needs it, your employer's name. These exist to be printed in the letterhead and sign-off, and are printed nowhere else. We store them encrypted at rest, in a database column kept separate from your other answers, and they are never sent to the AI provider that writes the letter's body: the letterhead and sign-off are assembled mechanically from what you typed, not by the model, so these details are never in a prompt at all. We also read one fact from your identity number, whether you hold permanent residence, which a bullet below explains.
- A motivation letter only: your suburb, city, province and police precinct are a different part of the same address, and unlike the fields above, these are sent to the AI provider: the letter's argument needs to say where you live and where you travel, and the crime figures it argues from are looked up by that precinct. Your street address and postal code stay withheld regardless of that: only the area around you is sent, never what would find your door. A renewal motivation sends no part of your address at all, not even the area: it argues what has happened since your licence was issued, not where you live, so there is nothing there for it to use.
- The circumstances you describe answering the wizard's questions, which is what the argument is actually built from: why you need the firearm, what you will use it for or the dedicated status you apply under, and for vermin control the infestation and what it costs you, your existing security measures, your training, and similar. These are sent to the AI provider, because the document is written from them.
- Whether you hold permanent residence rather than South African citizenship, which we read from your identity number when you save it. If you do, the documents we list for you to attach, and the ones your document names, include a certified copy of your permanent residence permit. The AI provider is given that list to cite from, so it can tell that you are a permanent resident, but your identity number itself is never sent.
- Which AI provider and model produced each generation, so we can always say which one saw a particular applicant's circumstances.
What a renewal motivation asks for on top of that, all of which is sent to the AI provider, because the document is written from it:
- The licence you are renewing: the date it was issued and the date it expires, and the timing we work out from that expiry date, which decides which deadline in the Firearms Control Act the document argues under. If that timing makes your application a late one, we also ask for, and send, the reason you give for it being late.
- The firearm itself: its type, make, model and calibre. Not its serial number and not the licence number, which we never ask for at all, because those belong on the SAPS forms rather than in a motivation.
- Your competency certificate: which category it covers, the date it is valid until, and whether its own renewal is lodged with this application. Not the certificate number.
- Your answers to Annexure fields D2 and D3: whether you have been convicted of an offence under the Firearms Control Act and sentenced to imprisonment without the option of a fine, and whether you have become or been declared unfit to possess a firearm. If the first step of the wizard asked you the same question about unfitness, we keep that answer too. This is the special personal information section 3.12 deals with.
- Your safe: a description of it, the SABS standard it meets, whether and to what it is mounted, the room it is kept in, and when it was last inspected.
- Your answer to Annexure field D5: either your confirmation that you will carry the firearm as prescribed, or that the firearm is not carried and is kept in the safe except when it is in use.
- What has changed since the licence was issued, and any incidents, thefts or losses since then.
- Why you still need the firearm, under whichever section of the Act it is licensed: what the firearm was licensed for, or the dedicated status the licence was issued on and whether it has lapsed, your hunting or sport shooting record, your association and membership, your dedicated status, farm owners' declarations, competition results, a collection's theme, and similar. These are the same kinds of answer a motivation letter's argument is built from.
- The entries from your own activity log, if you keep one here, for the period since the licence was issued. Each entry gives the date, the type of activity and the place. Where you recorded them, it also gives the association, your score and what it was out of, the event, your placing and the number of competitors, and the game taken on a hunt, or that nothing was taken. If this renewal is for a firearm in your register, an entry logged with that firearm also says it used the firearm being renewed. The wizard offers them as a starting point and you can edit or delete any of them before you generate, but whatever is in that box when you do is sent. This is the one place where something you recorded under section 3.7 above reaches the AI provider.
- Your original motivation, if you choose to paste in a copy of it. Anything shaped like an identity number is removed from it automatically before it is stored or sent, and it is used only to keep the renewal consistent with what you argued the first time.
An identity number is collected for either document, and this is the only place on this site that collects one. The status checker, your firearm register and your activity log, described above, still collect none.
3.12 Special personal information, and what we deliberately do not collect
We do process one kind of special personal information, and only in a renewal motivation. POPIA section 26 treats information about a person's criminal behaviour as special personal information, and that is what Annexure fields D2 and D3 ask about: whether you have been convicted of an offence under the Firearms Control Act, and whether you have become or been declared unfit to possess a firearm. We ask because SAPS asks, on a form you swear to, and because a renewal motivation that argued continued compliance while stepping around those two questions would be arguing around the form itself.
The basis we rely on is your own consent, given when you answer those questions in the wizard. It is asked in exactly two places, both of them inside the renewal wizard, and nowhere else on this site. Nothing else we offer needs it: if you never buy a renewal motivation, you are never asked. Your answer is stored with the rest of that draft's answers and is deleted with the draft, and it is sent to the AI provider as part of what the document is written from, described in section 3.11 above. We do not process special personal information of any other kind: not your religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, and no biometric information.
Outside the two paid documents described in section 3.11 above, we do not ask for your identity or passport number, and a proof file you choose to upload may show one (below). We do not ask for and do not store your physical address, telephone number, date of birth, or any payment details. The one kind of upload we accept is a proof file for an activity you log (section 3.7): photos are shrunk to print size and stripped of their location data, and every file is stored encrypted. A target card you upload may show your identity number; it is stored encrypted with the file, and we never read it out or use it. If you connect Telegram, we store only your chat_id: not your Telegram username, not your phone number, and not your display name or profile photo.
Your name is the one exception, and it is optional: we ask for it in a single place, to head the printable activity record described in section 3.8. Leave it blank and the record prints a blank line instead.
On identity numbers outside those two documents: associations ask for one on the confirmation documents that keep your dedicated status, and no form on this site asks you for it. The printable activity record leaves a labelled blank line for you to complete by hand on the copy you submit. No field on the activity log or the firearm register asks for an identity number; the two documents described in section 3.11 above are the one exception, and a test asserts that no other file in this codebase adds one. A proof file you upload may carry one, such as a target card or a hunt confirmation: it is stored encrypted with the file, as described above.
4. Consent, and how saving works
Saving an application is the act of consent. When you save one, we record a consent entry alongside it: what it authorises, the date and time, the version of these terms in force, and the IP address the consent was given from. Nothing about an application is stored before that moment.
That consent authorises two things: storing the application you saved, and checking its status with SAPS on your behalf.
You can switch auto-refresh off for any saved application at any time. We then stop checking its status with SAPS, and the history already collected stays visible to you. You can switch it back on later, which records a fresh consent entry. We never erase the record that consent was previously withdrawn.
To stop us storing an application altogether, delete it. That removes the application and its entire status history.
Licence renewal reminders are a separate consent of their own, recorded the same way and switched on and off from your account page. Turning them off revokes that consent and stops the reminders; it does not touch your status alerts, and it does not remove anything from your register.
Your firearm register and your activity log need no consent switch. You put something there by adding it and you take it away by deleting it, and nothing is stored in either until you do.
5. Lawful basis for processing
- Consent (POPIA section 11(1)(a)) for storing your saved applications and checking their status.
- Necessary to perform a contract with you (section 11(1)(b)) for operating your account, signing you in, sending the transactional email described in section 7, and generating a motivation letter or a renewal motivation you have paid for, including the identity details it must carry.
- Your consent for the special personal information described in section 3.12: the Annexure field D2 and D3 answers a renewal motivation asks for. That is a separate question from the contract above, and we treat it as one: it is asked of nobody who does not buy a renewal motivation, and answering it is how the consent is given.
- Our legitimate interests (section 11(1)(f)) for keeping the service secure and available, which covers rate limiting and short-lived technical logs.
6. What we will never do
These are design commitments, not just promises, and each is enforced in the software:
- We never look up a reference number nobody gave us. We query SAPS only for references you personally submitted or personally saved. We do not crawl, guess, or enumerate reference numbers, and we do not build a picture of people who never asked us to.
- We never sell, rent or trade your information, and we do not use it for advertising.
- We do not use advertising trackers or social media pixels. We do use Google Analytics, to see how many people visit and which pages they read -- section 8 says exactly what that sends to Google.
- We do not put tracking images in our email. Our messages carry no remote images and no read receipts, so opening one tells us nothing.
To keep the first commitment enforceable, an account may save at most 15 applications at a time. That limit exists as a safeguard, not as an upsell.
7. Email and Telegram messages we send you
All email we send is transactional, meaning it results from something you did. We send you a message to confirm your email address, to reset your password if you ask, and, if you have email alerts turned on, to tell you when a saved application's status changes. We do not send newsletters or marketing, and we do not share your address with anyone for marketing purposes.
If you connect Telegram to your account, we send that same kind of status-change alert there too, or instead, depending on which channels you turn on. A Telegram alert only ever reaches you after you have linked your account yourself by messaging our bot, and you can disconnect it or turn the alerts off at any time from your account page.
If you add a firearm to your register with a licence expiry date and turn renewal reminders on, we also write to you as that date approaches: about six months out, about four months out, and on the last day the Firearms Control Act allows you to lodge the renewal. A reminder names the firearm by make, model and calibre so you know which one it means, and never by its serial number. Reminders go to whichever of the channels above you already have turned on, so with both off there is nowhere for them to go and none are sent.
8. Who else is involved
- SAPS. When you check a reference, we send it to the official SAPS Firearms Online Enquiry service on your behalf, in the same way your own browser would. SAPS is not our processor and handles that request under its own terms.
- Our email provider, which delivers the messages described in section 7 and sees the recipient address and message content in order to do so.
- Google Sign-In, but only if you choose to sign in with Google. When you press Continue with Google, Google learns that you signed in to this site and when. We ask Google for two things only: a permanent identifier for your Google account, and your email address. We do not ask for, and never receive, your name, your profile picture, your contacts, or any other information about you. If you create your account with an email address and a password instead, this exchange never happens and none of your account information reaches Google this way. Google Analytics, described next, still sees your visit either way.
- Google Analytics, on every page, for every visitor, whether or not you have an account or ever sign in with Google. It receives your IP address, the pages you view, and an approximate location derived from that IP, and it sets its own cookies to tell one visit from the next: see section 14. We use it to see how many people use this site and which pages they read; we do not use it to build advertising profiles, and we have no separate advertising or marketing relationship with Google. This is a different flow from Google Sign-In above and applies to every visitor, signed in or not, however they signed in.
- Telegram, if you connect it, and for our own operational notifications regardless of whether you do. Telegram receives: every new account's email address, sent to the site operator as an operational message when someone registers; if you link Telegram to your account, your chat_id and the full content of every status alert we send you there, the same label, status, queue position and plain-language text an email alert would carry; and, for every check anyone runs on this site, the masked reference, application type and outcome described in section 2. Telegram Messenger Inc. stores this content on its own servers under its own terms, in the same way SAPS handles a lookup request under its own terms.
- Our AI provider, if you generate a motivation letter or a renewal motivation. Generating either makes exactly one call to it, carrying only what section 3.11 describes as sent. For a motivation letter that is the circumstances you answer in the wizard plus the area-level part of your address (your suburb, city, province and police precinct). For a renewal motivation it is the list section 3.11 sets out in full: the licence's issue and expiry dates and the timing worked out from them, your reason for a late application if yours is one, the firearm's type, make, model and calibre, your competency certificate's category and expiry, your Annexure field D2 and D3 answers, your safe's description, standard, mounting and room, your carrying confirmation, what has changed and what has happened since the licence was issued, the continued-purpose answers your section turns on, the activity-log entries the wizard offered you and you kept, and any original motivation you paste in. For either document, if you hold permanent residence rather than South African citizenship, the call also names your permanent residence permit among the documents to cite, as section 3.11 explains. A renewal motivation sends no part of your address, not even the area. Neither ever receives your name, identity number, street address, postal code, phone number, email address or employer's name, and neither receives a licence number, a firearm's serial number or a competency certificate number, because we do not ask for those at all. We do not name a single provider here because the operator can change which one is selected; what we do instead is record the provider and model against each individual letter, so we can always say exactly which one processed a particular applicant's circumstances, whatever is selected today.
- Our hosting provider, which runs the servers this service operates on. Those servers are in Manchester, United Kingdom.
Your information is processed outside South Africa. Because our servers are in the United Kingdom, everything described in this policy other than what we send to Telegram, to Google Analytics and to our AI provider is stored and processed there rather than locally. POPIA Chapter 9 governs sending personal information out of the country, and section 72 permits it where the destination is subject to a law providing protection substantially similar to POPIA's own principles. The United Kingdom is: its data protection regime, the UK GDPR together with the Data Protection Act 2018, imposes materially the same duties on us and gives you materially the same rights over your information as POPIA does. Our hosting provider processes this information only in order to run the servers, and does not use it for its own purposes. It is our operator in POPIA's sense, and POPIA section 21 requires that relationship to rest on a written contract: it does, through the data processing terms that form part of our agreement with them, which bind them to process this information only on our instructions and to keep it secure.
Telegram is a separate transfer. Telegram Messenger Inc. runs its own infrastructure, and it is not in the United Kingdom, so this is a different cross-border transfer from the UK hosting described above. For the status alerts you choose to receive there, the transfer rests on your own consent: you are the one who connects Telegram and sends the first message to our bot, and POPIA section 72 recognises the data subject's own consent as a basis for a transfer like this. The admin-notification pings described in section 2 and above are different: they happen whether or not you have an account or use Telegram yourself, so they are not something you consented to, and we are not claiming a Chapter 9 basis for them in the way we do for the two transfers above. We are telling you about them here plainly rather than papering over the gap.
Our AI provider is a separate transfer, in the same way. This call leaves South Africa whichever provider is currently selected, and it is a distinct cross-border transfer from the UK hosting described above: our hosting provider does not see or forward it. It rests on the contract you enter into by paying for a motivation letter or a renewal motivation: sending what section 3.11 lists is necessary to produce the document you asked for, which POPIA section 72 recognises as a basis for a transfer like this. Only what section 3.11 names is ever sent, and that section now lists both documents in full; your name, identity number, street address, postal code, phone number, email address and employer's name are never part of it. The special personal information a renewal motivation carries (section 3.12) travels on this call too, and it travels on your own consent, given by answering the two questions that produce it.
Google Analytics is a separate transfer, in the same way. Google processes this data on servers in the United States, which is a different cross-border transfer from the UK hosting above and from the Telegram transfers. Like the admin-notification pings, this one does not rest on your consent: Google Analytics runs for every visitor automatically, the moment a page loads, whether or not you have an account or have ever agreed to anything on this site. We are not claiming a Chapter 9 basis for it. We are telling you about it here plainly rather than papering over the gap.
We use no advertising networks and no data brokers, and Google Analytics is the only third-party analytics service we use. We may disclose information where the law requires it, for example in response to a valid court order.
9. Security
- The whole site is served over HTTPS, and connections to SAPS and to our email provider are made over verified TLS. We never disable certificate verification.
- Passwords are hashed with Argon2id. Session, verification and password-reset tokens are stored only as hashes, so a copy of our database does not let anyone sign in as you.
- Verification and password-reset links are single-use and expire (24 hours and 1 hour respectively), and are excluded from our access logs so they cannot leak through them.
- Our logs never record personal information. When a failure involves your email address, we log the type of failure and nothing else.
- The application runs as an unprivileged user in a container with a read-only file system, and the database is not reachable from the internet.
10. How long we keep things
- The reference number of a lookup, and the firearm details SAPS returns: not stored, so there is nothing to keep.
- A reference or serial you submit through the API: kept until 24 hours after your result is ready, then permanently erased, as section 3.10 describes.
- Entries on the approval history list: kept indefinitely, because the list is a history and old entries are the point of it. An entry is a masked reference, an application type, a date and a keyed fingerprint. It carries no identifier, so there is nothing in it to erase on request.
- The stage records behind the Analytics page: kept indefinitely, for the same reason as the approval history list: how long applications wait only shows over time. A record is an application type, a status, a date, a batch and a keyed fingerprint. It carries no identifier, so there is nothing in it to erase on request.
- The police station you told us about: kept indefinitely, like the stage records it sits beside. It is a station, the application type, a keyed fingerprint, when you answered and when you last changed it, with no identifier, so there is nothing in it to erase on request; choosing a different station replaces it.
- Your subscription and billing-cycle history: kept indefinitely, for the same reason the approval history list is, because it is a financial record, and it is the point of it.
- Your account and saved applications: for as long as your account exists.
- A motivation letter or renewal motivation application, once you start one: for as long as your account exists. Its identity details are held encrypted at rest for that whole time, as section 3.11 describes, and a renewal's Annexure field D2 and D3 answers are held with the rest of that draft's answers for the same period.
- Your firearm register, your activity log, your reporting details and the record of reminders sent to you: for as long as your account exists, or until you remove them yourself.
- A firearm you remove from your register: it stops appearing and stops generating reminders immediately, and the row itself is removed when your account is. An activity you logged against it keeps the activity and forgets the firearm, because selling a firearm should not erase the proof that you shot it.
- An activity you delete: removed immediately and completely.
- A deleted application: its status history is removed immediately.
- A deleted account: your account, sessions, tokens, saved applications, status history, consent records, your firearm register, your activity log, your reporting details, the record of reminders sent to you, your Telegram link if you connected one, your Google identifier if you signed in with Google, and, if you used our API, your keys, your subscription and billing-cycle history, and every request you made through it, and, if you generated a motivation letter or a renewal motivation, your application, its encrypted identity details, the special personal information described in section 3.12, and every document you generated, are all removed immediately and permanently. There is no recovery period, because we do not keep a copy.
- Technical logs: a short period for security and fault-finding.
11. Your rights under POPIA
You may exercise any of these at info@isitapproved.co.za, and we will respond within 30 days. Two of them you can exercise yourself, immediately, without asking us:
- Access and portability (section 23). Your account page has an export button that gives you everything we hold about you as a JSON file, straight away.
- Deletion (section 24). Your account page can delete your account and everything attached to it, straight away.
- Correction (section 24). Ask us to correct anything inaccurate.
- Objection (section 11(3)). Object to our processing of your information.
- Withdrawing consent. Switch auto-refresh off, or delete the application, as described in section 4.
Status information originates from SAPS. If it is wrong at the source we cannot correct it, and you would need to take that up with SAPS or your DFO.
12. Complaints
Please raise anything with us first at info@isitapproved.co.za. If you are not satisfied, you may complain to the Information Regulator of South Africa:
- Website: inforegulator.org.za
- Email: enquiries@inforegulator.org.za
- Complaints: POPIAComplaints@inforegulator.org.za
13. Security breaches
If personal information is accessed or acquired by an unauthorised person, we will notify the Information Regulator and every affected person as soon as reasonably possible, as POPIA section 22 requires. We will tell you what happened, what information was involved, and what you can do about it.
14. Cookies
We set one cookie ourselves, which holds your sign-in session and only once you sign in, plus a short-lived cookie during a Google sign-in, which holds only the security values that tie the sign-in to your browser and is deleted when the flow ends. Your light or dark theme preference is kept in your browser's local storage and never sent to us.
Google Analytics sets its own cookies, on every page, to tell one visitor from another and one visit from the next. We do not set those cookies ourselves and do not control what Google keeps in them or for how long. We set no advertising cookie of our own, and no cookie we set is used for advertising.
15. Children
This service is intended for adults applying for firearm licences and is not directed at children. We do not knowingly create accounts for anyone under 18.
16. Changes
If we change this policy we will publish the new version here with a new version number. Because your consent record stores the version in force when you gave it, you can always tell which version you agreed to. If a change materially affects how we handle your information, we will tell you by email before it takes effect.