
, trading as AutoSourceSA, is the responsible party for personal information processed through this portal unless another party is expressly identified for a specific processing activity.
Privacy contact: . Information Officer contact: — .
We process personal information to create and secure accounts; source vehicle parts; prepare offers and documents; manage orders, payments and deliveries; communicate transaction updates; onboard and manage suppliers; prevent fraud and misuse; maintain records; respond to support, privacy and legal requests; and comply with applicable law.
Some information is mandatory to create an account or process a sourcing/order request. If required vehicle, contact, payment or delivery information is not provided, AutoSourceSA may be unable to provide the requested service. Optional information, such as certain photos or preferences, is identified by the portal where practical.
We may share information with approved parts suppliers, delivery/courier providers, authentication providers, hosting/database providers, communication providers and payment providers where this is necessary to operate the service. Current technology providers may include Supabase, Cloudflare, Google and Resend; payment and WhatsApp providers may be added when those services are activated.
We do not sell personal information to data brokers or advertisers.
Where necessary to identify a vehicle or confirm part fitment, AutoSourceSA may use specialist vehicle and parts catalogues. This may involve submitting the VIN or vehicle details to a catalogue provider for identification. AutoSourceSA limits this activity to vehicle/parts information needed for the sourcing purpose and does not provide customer payment information or unrelated customer contact information for a fitment lookup.
Some technology or vehicle/parts catalogue providers may process or store information outside South Africa. AutoSourceSA will use providers and contractual/technical safeguards intended to support the transborder transfer requirements of POPIA.
When a secure external payment gateway is activated, payment-card or bank credentials will be entered with that payment provider. AutoSourceSA should retain transaction references, status and amounts needed for the order and reconciliation rather than full card credentials.
AutoSourceSA uses access controls, role separation, private storage, authenticated sessions and server-side functions for sensitive operations. No system can guarantee absolute security. Where POPIA requires notification of a security compromise, AutoSourceSA will notify the Information Regulator and affected data subjects as required.
Personal information is retained only for as long as reasonably necessary for the purpose collected, transaction/audit evidence, legal obligations, disputes, fraud prevention and legitimate business records, after which it should be deleted, de-identified or restricted where appropriate.
Subject to POPIA and other applicable law, you may request confirmation of whether AutoSourceSA holds your information, request access, correction or deletion where applicable, object to certain processing, or lodge a complaint. Contact .
You may also complain to the Information Regulator (South Africa). Current regulator contact channels include POPIAComplaints@inforegulator.org.za and telephone 010 023 5200.
Emails or WhatsApp messages needed to administer a request, quote, payment, order, delivery, supplier onboarding or account security are transactional communications. Any future direct marketing programme should use a separate lawful opt-in/opt-out process and should not be bundled into this legal acknowledgement.
Material changes will be versioned. The portal may require users to acknowledge a new version before continuing where appropriate.