Privacy Policy
This policy explains how Subtle Estimates handles personal information, payment references, and project documents.
Last updated: 12 May 2026
1. Scope of this policy
This Privacy Policy explains how Subtle Estimates collects, uses, stores, shares, and protects personal information and project documents when you use our website, contact us, upload information, request an estimate, make a payment, or use a client portal.
Subtle Estimates is based in South Africa and aims to handle personal information in a practical, purpose-limited way consistent with POPIA principles.
2. Information we collect
We collect information that you provide directly, information generated through your use of the website or portal, and limited information from service providers needed to operate the service.
- Identity and contact details, such as name, email address, WhatsApp number, phone number, company, and billing details.
- Project details, such as location, property type, project stage, floor area, scope notes, finishes, budget range, and preferred service.
- Project documents, such as drawings, specifications, schedules, photographs, bills, notes, and related files you upload or send to us.
- Transaction information, such as package selected, payment status, Paystack payment references, invoice details, and order history.
- Technical information, such as device, browser, IP address, logs, security events, and website usage information.
3. Special or sensitive information
Please do not send unnecessary identity documents, banking documents, medical information, children information, access credentials, or other sensitive personal information unless we specifically request it for a legitimate purpose.
If sensitive information is included in project documents by mistake, we will handle it only as needed for the service, support, security, legal compliance, or deletion where practical.
4. How we use information
We use personal information and project documents for specific service, communication, payment, security, compliance, and business administration purposes.
- Responding to enquiries and support requests.
- Recommending suitable estimate packages and clarifying scope.
- Preparing estimates, schedules, reports, and related cost planning outputs.
- Creating and managing client accounts, project records, uploads, and dashboards.
- Processing payments, reconciling orders, issuing invoices, and managing refunds or disputes.
- Maintaining security, preventing abuse, diagnosing faults, and protecting the website and client portal.
- Meeting legal, tax, accounting, audit, and record-keeping obligations.
- Improving templates, workflows, service quality, and internal operating processes.
5. Legal basis and POPIA context
Depending on the context, we process personal information because you have consented, because processing is necessary to respond to your request or perform a service, because we have a legitimate business interest, because we must comply with a legal obligation, or because processing is needed to protect a lawful interest.
We aim to collect only information that is relevant to the purpose, use it in a reasonable way, keep it reasonably accurate, protect it with appropriate safeguards, and retain it only for as long as reasonably needed.
6. Project document confidentiality
Drawings, specifications, schedules, photographs, and related project documents are treated as confidential business information. We use them for the requested estimate, support, quality review, record keeping, and lawful administration unless you instruct us otherwise or disclosure is required by law.
We do not sell project documents or client personal information.
7. Payment information
Online payments are processed through Paystack. We may receive payment references, payment status, transaction amount, payer contact details, and related reconciliation information.
We do not store your full card number or card security code. Paystack processes payment information under its own terms, privacy notices, and security controls.
8. Service providers and sharing
We may share limited information with trusted service providers where needed to operate the website, client portal, storage, email, payment, security, analytics, support, accounting, or document handling workflows.
Service providers are expected to process information only for the authorised purpose and to apply appropriate confidentiality and security measures.
- Hosting and application infrastructure providers.
- Payment and payment-status providers.
- Email, messaging, and support tools.
- Document storage, backup, and processing services.
- Professional advisers, auditors, accountants, or authorities where legally required.
9. International processing
Some service providers may store or process information outside South Africa. Where this happens, we aim to use providers and arrangements that support appropriate privacy and security safeguards for the type of information involved.
10. Security
We use reasonable technical and organisational steps to protect information against unauthorised access, loss, misuse, alteration, or disclosure. These steps may include access controls, protected routes, encrypted transport, role-based administration, logging, and separation of public and internal evidence.
No internet service, email system, or storage platform can be completely risk-free. If you believe your information or project documents have been exposed, please contact us promptly.
11. Retention
We retain personal information, project documents, estimate outputs, payment records, and communications for as long as reasonably needed for service delivery, client support, operational records, tax and accounting obligations, dispute handling, audit, security, or lawful business administration.
Where information is no longer reasonably needed, we may delete, archive, anonymise, or aggregate it, depending on the record type and operational requirements.
12. Cookies and analytics
The website may use cookies or similar technologies for basic site operation, security, session handling, preference storage, analytics, and performance monitoring.
You can manage cookies through your browser settings. Some website or portal features may not work correctly if required cookies are disabled.
13. Your rights and choices
Subject to applicable law and practical verification, you may ask us to confirm whether we hold your personal information, request access to it, request correction, request deletion where appropriate, object to certain processing, or withdraw consent where processing is based on consent.
Some records may need to be retained where required for payment records, accounting, security, legal compliance, dispute handling, or legitimate business administration.
14. Direct marketing and service messages
We may send service messages related to enquiries, orders, payments, reports, support, policy updates, or security. Where we send optional marketing messages, you may opt out using the available unsubscribe or contact method.
Opting out of optional marketing does not stop necessary service, payment, legal, or security messages.
15. Children
Subtle Estimates is intended for adults and businesses planning residential building work. We do not knowingly request personal information from children. If a child has supplied personal information without appropriate consent, please contact us so that we can review and delete it where appropriate.
16. Security incidents
If we become aware of a security compromise affecting personal information, we will assess the incident and take reasonable steps required by applicable law, which may include notifying affected persons and the Information Regulator where required.
17. Contact
Privacy questions, correction requests, access requests, or deletion requests can be sent to estimates@subtleconsulting.co.za or raised through our official WhatsApp contact channel.
We may need to verify your identity before acting on a privacy request.
18. Updates to this policy
We may update this Privacy Policy from time to time. The latest version displayed on this page applies from the last updated date below.
South African privacy context
POPIA provides conditions for lawful processing of personal information and rights for data subjects. This policy is intended to support transparent, purpose-limited handling of client and project information.