Korvani logo Korvani
ProductPricingPilot AccessAboutContact
Sign In Get Started
ProductPricingPilot AccessAboutContact Sign In Get Started

Privacy Policy

How Korvani handles personal and business information

This policy explains how Korvani collects, uses, shares, protects, retains, and responds to requests about information across the public website, pilot access process, account flows, onboarding, and private business workspaces.

Effective date
18 July 2026
Last updated
18 July 2026

Contents

  1. Responsible party and privacy contact
  2. Information we collect
  3. How we collect information
  4. Why we process information
  5. Required and optional information
  6. Pilot access and account approval
  7. Accounts, authentication, and onboarding prefill
  8. Workspace, customer, and business data
  9. Billing, payments, refunds, and disputes
  10. Service providers and other recipients
  11. International processing
  12. Security safeguards
  13. Retention
  14. Your privacy rights
  15. Marketing choices
  16. Website technology and analytics
  17. Children’s information
  18. Changes to this policy
  19. Contact and complaints

1. Responsible party and privacy contact

Korvani is a South African technology business. Korvani determines how personal information is collected, used, stored, and otherwise processed for the purposes described in this Privacy Policy.

Privacy enquiries and requests

hello@korvanihq.com

You may contact Korvani to request access to personal information, request corrections, object to certain processing, ask questions about this policy, or raise a privacy concern.

Requests will be considered in accordance with applicable law, legitimate business requirements, security obligations, and record-retention duties.

For personal information that a business enters about its customers or staff in a workspace, that business generally decides why the information is used. Korvani processes it to provide the workspace service, subject to applicable law and the business’s instructions.

2. Information we collect

Depending on how you interact with Korvani, we may collect:

  • Pilot and contact details: owner name, business name, email address, WhatsApp number, and a business website or page where provided.
  • Business profile and location: business type, selling channels, estimated monthly order range, team size, country, province/state/region, city, and area.
  • Business needs: current tools or methods, setup priorities, plan direction, and the written business problem or operational challenge you submit.
  • Application context: application source, landing page, UTM campaign values, referring page, browser locale, browser timezone, application status, review activity, approval status, and approval-email delivery records.
  • Account and authentication information: email, user and account identifiers, authentication and session records, confirmation or password-reset events, and records of accepting active legal terms and privacy-policy versions.
  • Onboarding and workspace information: business profile, workspace settings, selected customer channels, setup progress, and related workspace configuration.
  • Business operational data: customers, products or services, orders, stock or inventory records, payment-request or payment-status information, reports, and operational workflow.
  • Billing and payment information: billing contact, selected plan and billing interval, amount and currency, payment status, provider and transaction references, limited payer or payment-method details returned by a processor, invoices or receipts, and refund, reversal, chargeback, fraud-review, and dispute records. Where card payments are offered, full card details should ordinarily be entered directly with the payment processor rather than stored by Korvani.
  • Staff and support information: workspace-owner and staff details, roles or access records where applicable, messages sent to Korvani, support history, security events, and technical logs needed to operate and protect the service.

3. How we collect information

We collect information:

  • directly from you when you complete forms, apply for pilot access, create an account, complete onboarding, use a workspace, or contact us;
  • from a workspace owner or authorised user who enters customer, staff, product, order, stock, or payment-status records;
  • automatically from the website, browser, authentication service, and platform when needed for source attribution, session operation, security, reliability, and technical diagnosis; and
  • from connected service providers when they return authentication, email-delivery, database, payment, refund, dispute, fraud-screening, or operational events; and
  • from banks, payment networks, customers, workspace users, or authorities when a transaction, refund, chargeback, fraud concern, or complaint needs to be investigated.

4. Why we process information

Korvani processes information to:

  • receive, assess, administer, approve, decline, or follow up on pilot applications;
  • send approval, confirmation, password-reset, support, security, and other service-related messages;
  • create accounts, authenticate users, record legal acceptance, and control access to private workspaces;
  • prefill onboarding for an approved applicant and establish, operate, support, and improve a business workspace;
  • provide customer, product or service, order, stock, payment-status, staff-access, reporting, and workflow features;
  • administer plans and subscriptions, process or reconcile payments, issue invoices or receipts, handle cancellations and refunds, investigate chargebacks or billing disputes, and prevent payment fraud;
  • respond to enquiries, provide support, maintain service continuity, diagnose faults, and improve reliability;
  • protect accounts and workspaces, detect or prevent misuse, fraud, abuse, and security incidents; and
  • meet applicable legal duties, resolve disputes, enforce agreements, and maintain appropriate operational or audit records.

The legal basis depends on the activity and applicable law. It may include your consent, steps requested before entering an agreement, performance of an agreement, compliance with a legal obligation, protection of legitimate interests, or another basis permitted by law. Korvani does not sell personal information to advertisers.

5. Required and optional information

Fields marked as required must be provided so Korvani can receive and assess a pilot application, identify the applicant, communicate the outcome, create or secure an account, or provide a requested workspace function. If required information is missing or inaccurate, Korvani may be unable to submit or review the application, approve access, create or recover the account, complete onboarding, or provide the relevant service.

Fields not marked as required are optional. Optional context may help Korvani understand the business and prepare a more relevant setup, but choosing not to provide it will not by itself prevent the form or feature from working unless the interface explains otherwise.

6. Pilot access and account approval

Pilot applications are reviewed to assess product fit, operating needs, plan direction, setup priorities, and whether access should be approved. Review records may include status, reviewer activity, approval time, and email-delivery status. Approval is not the same as email confirmation and does not automatically create an authenticated account.

If an application is approved, Korvani may activate approved access for the application email address and use Resend to deliver a signup link. Access may still depend on completing signup, confirming the email address, accepting applicable terms, and satisfying security or account requirements.

7. Accounts, authentication, and onboarding prefill

Korvani uses account and authentication information to register and sign in users, maintain sessions, confirm email addresses, reset passwords, protect routes, and associate activity with the correct workspace.

After an approved applicant authenticates, Korvani may retrieve that same user’s latest approved application and use available business, location, and channel details to prefill empty onboarding fields. Saved onboarding information is not automatically overwritten by application information, and users can review or edit prefilled details before continuing.

8. Workspace, customer, and business data

Workspace owners and authorised users decide what customer, staff, catalog, order, stock, payment-status, and operational information to enter into Korvani. They are responsible for collecting and using that information lawfully, providing their own notices where needed, keeping access accurate, and removing staff access when it is no longer required.

Korvani processes workspace information to store and organise records, support customer and order workflows, maintain stock and payment-status visibility, manage authorised access, generate reports, support users, maintain backups, and secure the service.

Where a business uses Korvani to record, request, or monitor its own customer payments, the business generally determines why customer and transaction information is processed. Korvani processes that information to provide the requested workspace features and does not become the seller of the business's goods or services merely by providing software or a payment-status workflow.

9. Billing, payments, refunds, and disputes

If Korvani introduces paid plans or payment features, it may use Paystack or another processor identified at or before checkout. Payment details entered into a processor-hosted form are handled by that processor under its own terms and privacy notice. Korvani does not claim in this policy that Paystack is currently active. Full card numbers, card security codes, and online banking credentials are not represented as being stored by Korvani.

Korvani may receive and retain the information reasonably needed to administer billing and payments, such as a customer or merchant identifier, payer name or contact, masked payment-method details, transaction reference, amount, currency, time, status, processor response, and fraud or verification signals. Korvani may also keep invoices, receipts, cancellation requests, refund records, chargeback evidence, correspondence, and dispute outcomes.

Billing and transaction information may be shared with the relevant workspace business, processor, bank, payment network, fraud-prevention provider, adviser, insurer, regulator, court, or authority where reasonably necessary to complete a transaction, protect an account, handle a refund or dispute, comply with law, or establish, exercise, or defend legal rights. The related commercial rules are in the Terms of Service.

10. Service providers and other recipients

Services currently confirmed in the Korvani codebase include:

  • Supabase for authentication, database, backend, and related workspace infrastructure. Depending on the feature, this may involve account identifiers, authentication events, pilot applications, onboarding data, workspace records, customer and operational records, and technical metadata.
  • Google when a user chooses Google sign-in. Google may provide account identifiers and profile information needed to authenticate the user, subject to Google's own terms and privacy notice. Email and password sign-in remains available; Microsoft and Apple sign-in are presented as coming soon and are not represented here as active authentication providers.
  • Resend for pilot-approval email delivery. This may involve the recipient email address, email content, delivery status, provider message identifier, and error or delivery metadata.

Korvani may add a payment processor such as Paystack if paid plans or payment features are launched. The selected processor and its terms should be disclosed before a user submits payment information. Payment processors, banks, card or payment networks, and fraud or verification providers may receive billing and transaction data needed to provide their services, comply with law, and resolve refunds, reversals, chargebacks, or disputes.

Korvani may also disclose information to authorised workspace users; professional advisers; regulators, courts, law-enforcement bodies, or other authorities where lawfully required; and parties involved in a genuine business reorganisation or transaction, subject to appropriate confidentiality and legal safeguards. Providers should receive only information reasonably needed for their function.

No active third-party analytics service, payment processor, or named hosting provider was confirmed in the current repository, so none is represented here as currently processing information for those purposes. This policy should be updated before a new provider begins processing personal information where notice is required.

11. International processing

Some service providers may store, route, support, or otherwise process information outside South Africa. Where personal information is transferred across borders, Korvani should use providers and arrangements intended to provide an appropriate level of protection and handle transfers as required by applicable data-protection law. Provider locations and infrastructure may change over time.

12. Security safeguards

Korvani uses reasonable technical and organisational safeguards appropriate to the information and service, which may include authenticated access, workspace permissions, database access policies, controlled administrative access, transport encryption where supported, logging, backups, and security monitoring.

No system or transmission method is completely secure. Korvani does not guarantee that incidents or unauthorised access can never occur. If a security issue is identified, Korvani should investigate, contain or reduce harm, improve controls, and provide notifications where required by law.

13. Retention

Korvani retains information only for as long as reasonably needed for the purposes described in this policy or as required or permitted by law. Relevant considerations include whether an application is still under review, whether an account or workspace remains active, the nature and sensitivity of the information, service continuity, backups, invoicing, payment, refund, chargeback, transaction and tax records, security and fraud prevention, legal obligations, disputes, audit needs, and deletion or objection requests.

Different records may therefore be kept for different periods. Some information may remain in protected backups or be retained where deletion is not legally or technically immediate, and will be handled subject to the applicable safeguards and retention purpose.

14. Your privacy rights

Subject to applicable law and relevant exceptions, you may ask Korvani to confirm whether it holds personal information about you, request access to it, ask for inaccurate or incomplete information to be corrected, object to certain processing, withdraw consent where processing depends on consent, or request deletion, destruction, or restriction where appropriate.

Korvani may need to verify your identity and authority before acting on a request. A request may be limited where another person’s rights, legal duties, security, fraud prevention, backups, billing, disputes, audit requirements, or other lawful grounds require information to be protected or retained. Workspace customer or staff requests may need to be directed first to the business that controls that workspace.

15. Marketing choices

Service messages about an application, approval, account, security, support request, or workspace are not promotional marketing. If Korvani sends optional marketing messages, recipients may use the unsubscribe method in the message or contact Korvani to object or opt out. Opting out of marketing does not prevent necessary service, security, or legal communications.

16. Website technology and analytics

Korvani may use essential browser storage, cookies, session technology, and technical request data where needed for account sessions, security, form operation, source attribution, and reliable delivery of the website or app. Browser settings may allow you to control some storage, but blocking essential technology can prevent authentication or core features from working.

The current marketing code does not include an active third-party analytics integration. Korvani will update its public notice before introducing analytics or tracking where applicable law requires it.

17. Children’s information

Korvani is a business operations service and is not directed to children. Do not submit a child’s personal information unless you have lawful authority and it is genuinely necessary for an authorised business purpose. If you believe a child’s information was submitted inappropriately, contact Korvani so the circumstances can be reviewed.

18. Changes to this policy

Korvani may update this policy when products, processing activities, providers, laws, or operational practices change. The effective and last-updated dates will be revised when a new version is published. Where a material change requires additional notice or consent, Korvani will take reasonable steps to provide it.

19. Contact and complaints

For privacy questions or requests, email hello@korvanihq.com or use the Korvani contact page. Account and product support is also available at hello@korvanihq.com. Please describe your request clearly and avoid emailing passwords or unnecessary sensitive information.

If you are not satisfied with Korvani’s response, you may complain to the Information Regulator (South Africa) through its official complaints page, the eServices portal, or by emailing POPIAComplaints@inforegulator.org.za. General enquiries may be sent to enquiries@inforegulator.org.za.

Also read Korvani’s Terms, Acceptable Use terms, or contact Korvani.

Korvani logo Korvani

Korvani is a Commerce Operating System for customer conversations, orders, products, payments, stock, staff, and daily operations.

hello@korvanihq.com

Product

ProductPricingPilot Access

Company

AboutContactSign In

Legal

Privacy PolicyTerms

© 2026 Korvani. One business system for every customer conversation.