Privacy notice
What LotSpot knows about you, why it knows it, where it is kept, and what you can make it do about that.
Version of 14 August 2026
1.Who is responsible
LotSpot, operating at lotspot.co.za, is the responsible party for the personal information described here — the term the Protection of Personal Information Act (POPIA) uses for whoever decides why and how information is processed. You are the data subject.
The responsible party is Proper Stake Holdings SA (Pty) Ltd, trading as LotSpot.
- Information Officer:
- Mr JP Janse van Vuuren
- Registration number:
- 2025/560156/07
- Address:
- 82 Marais Street, Heidelberg, Gauteng, South Africa
- Email:
- mylotspot@gmail.com
- Telephone:
- 067 947 9757
2.What is collected, and why
Nothing below is optional decoration — each one exists for a stated reason.
Given at signup. The name appears on your lots and to the person on the other side of an escrow, because a stranger is about to hand you either money or goods. The email address is how LotSpot reaches you about a lot you have won or sold, and how a password reset works.
Stored as a scrypt hash with a per-account salt. LotSpot cannot read your password, cannot email it to you, and cannot tell you what it was. That is why the only recovery route is to set a new one.
One row per browser you are signed in on, so you can see where your account is signed in and end a session you do not recognise. What is stored is a hash of the session cookie, never the cookie itself, so a stolen copy of the database cannot be replayed as a live login.
Two timestamps. The second one exists so LotSpot can show when you agreed rather than merely assert that you did.
Listings, photographs, bids, watchlist entries, escrow records and ledger entries. This is the marketplace itself. Bids and listings are visible to other users; your bid amounts are visible against a lot, your maximum bid is not.
Account holder, bank, account number and branch code. The account number and branch code are encrypted with AES-256-GCM before they are written, so they are not readable in the database itself. Only the last four digits are kept in plain text, so the site can show you which account it holds without decrypting anything. They are decrypted in exactly two situations: when you ask to see your own number, and when a payout is being sent.
Stored as a hash of the emailed token, with an expiry, and marked used the moment they are spent. The link itself exists only in your inbox.
LotSpot does not run advertising trackers, does not use analytics that profile you across other sites, and does not sell personal information to anybody.
3.On what basis
Most of it is necessary to perform the contract you enter into by using the marketplace — you cannot be paid without bank details, and an escrow cannot be settled without knowing who the two parties are. Session records and rate-limiting exist for the legitimate interest of keeping accounts from being broken into. Records of completed sales are kept because a marketplace that holds money has to be able to evidence what it did with it.
4.Who else sees it
The other party to your sale — but not before the money is in. While a sale is unpaid, neither of you is given anything about the other beyond a trading name, and LotSpot will not carry a phone number, an email address or a link between you in the message thread.
When an administrator confirms the payment, and only then, LotSpot gives each of you what the collection needs and nothing further:
- The buyer receives the seller’s name, phone number and the address the lot is collected from.
- The seller receives the buyer’s name and phone number. Not their address — every sale is collected from the seller, so nothing about the exchange uses it, and LotSpot does not store one.
Both of you are told, on the screen where the details appear, what the other has been given. LotSpot records that the disclosure happened and when, so if you ever ask who was given your number, the answer is a fact rather than a rule. A sale that is never paid for discloses nothing, however it ends.
Operators who process it for LotSpot and may not use it for anything else:
- Render — hosting and the managed PostgreSQL database. The database is in Frankfurt, Germany, and is not reachable from the public internet.
- Cloudflare R2 — storage for lot photographs.
- Resend — delivery of the transactional emails described above. If email is not configured on a deployment, no message is sent and the site says so rather than pretending one went out.
And whoever the law requires: a court order, a regulator, or a legitimate law-enforcement request.
5.It leaves South Africa
The database and the servers are in the European Union, not in South Africa. POPIA permits this where the destination has comparable protection; the EU’s GDPR is generally accepted as comparable or stronger. Saying so plainly matters more than burying it: your information is stored abroad.
Needs a decision before launch: Section 72 of POPIA sets the conditions for a cross-border transfer. Which of them LotSpot is relying on, and whether the processor agreements with Render, Cloudflare and Resend actually satisfy it, is a question for the legal review.
6.How long it is kept
Your account and its details are kept while the account exists. Sessions expire after thirty days and can be ended by you at any time. Reset and confirmation links expire in an hour and a day respectively.
Records of completed sales — bids, escrows, ledger entries — are not deleted. They are the evidence of what happened to money that LotSpot held on behalf of two other people, and a suspended account keeps its history for the same reason.
Needs a decision before launch: The retention period for financial records, and what exactly is erased when somebody asks for their account to be deleted, has to be settled against POPIA’s deletion right and the retention obligations that come with holding money for others. These pull in opposite directions and the answer is not obvious.
7.How it is protected
Passwords are hashed with scrypt. Session cookies, password reset links and email confirmation links are stored as SHA-256 hashes, so what is in the database cannot be replayed. Bank account and branch numbers are encrypted with AES-256-GCM, bound to the account they belong to, so a ciphertext moved to another row fails to decrypt rather than revealing somebody else’s account. Traffic to the site is over HTTPS, and the session cookie is HTTP-only, so a script running on the page cannot read it.
No system is perfect. If personal information here is ever compromised in a way that creates a real risk to you, POPIA requires that you and the Information Regulator are told, and you will be.
8.Cookies
One cookie: lotspot_session, which says who you are signed in as. It is HTTP-only, restricted to this site, and lasts thirty days or until you sign out. There are no advertising cookies and no third-party analytics cookies.
9.Your rights
Under POPIA you may:
- ask what personal information LotSpot holds about you;
- have information that is wrong corrected — your name, your email address and your bank details are all editable on your account page;
- ask for information to be deleted, subject to the retention point above;
- object to processing that relies on legitimate interest;
- complain to the Information Regulator of South Africa, which you may do without going through LotSpot first.
10.Children
LotSpot is for people aged 18 and over. It does not knowingly collect information about children, and an account found to belong to one will be closed.
11.Contact
The terms of use describe the service this notice relates to.
Privacy requests — to see what is held about you, to correct it, or to have it deleted — go to the Information Officer, Mr JP Janse van Vuuren, at mylotspot@gmail.com or 067 947 9757.
If you are not satisfied with the response, POPIA gives you the right to complain to the Information Regulator directly. That right does not depend on raising it here first, and nothing on this page asks you to waive it.
Terms of use · Privacy notice · Version of 14 August 2026