Skip to content
Fundur

The fine print

Privacy

What is collected, why, who it reaches, and how to get rid of it.

Version 2.0In force from 05 August 2026FUNDUR (Pty) Ltd

In short

  • Your email, your purchases, and a download log. That is nearly all of it, and there is no advertising profile behind it.
  • No card details ever touch our systems. Payment is handled entirely by Whop.
  • You can take it or delete it yourself. Export or erase your data from settings — no email, no waiting on a reply.

The summary is here to be useful, not to be relied on — where it and the text below disagree, the text below is the agreement.

Who is responsible for this

The responsible party, as the Protection of Personal Information Act 4 of 2013 uses that term, is FUNDUR (Pty) Ltd, registration number 2023/644435/07, of Johannesburg, Gauteng, South Africa.

POPIA requires a private body to have an Information Officer. Ours is published as an office rather than a person, because the duty attaches to the office and outlives whoever holds it:

The Information Officer, FUNDUR (Pty) Ltd, at support@fundur.io.

For visitors in the EU and the UK, the GDPR gives you a materially similar set of rights and this notice is written to satisfy both. Where the two differ, whichever gives you more is what you get.

What is held

  • Your identity. Email address, and your name and picture if your sign-in provider supplied them.
  • Your purchases. Orders, what each one contained, what it cost, and the entitlements it created.
  • A download log. Timestamp, IP address and browser string for each download, kept as an anti-piracy measure and as the thing the download cap is counted from.
  • Your settings. Email preferences, and billing details if you chose to store them.
  • Anything you wrote to us. Enquiries, requests and support email.

No card details ever touch our infrastructure. Payment is handled entirely by Whop, which is also the merchant of record for the tax treatment of your purchase. We see that a payment succeeded, for how much, and in which country it was taxed. We never see the instrument.

No special personal information as POPIA defines it is collected, and nothing here is knowingly collected from a child.

Why, and on what ground

POPIA requires a lawful ground for each use rather than a general permission, so each is named:

  • To deliver what you bought, and let you re-download it. Necessary to perform the contract you entered into.
  • To keep the download log. Our legitimate interest in not having the catalogue redistributed, balanced against a log that holds no more than it needs to.
  • To send the weekly drop, or product email. Your consent, given by opting in, and withdrawable in one click.
  • To keep financial records. A legal obligation — the Companies Act and the Tax Administration Act both require it.

Nothing is sold, rented or shared with anyone for marketing, and no automated decision is made about you.

Direct marketing

Section 69 of POPIA permits direct marketing by electronic means only with consent, or to an existing customer about similar products where there was a chance to opt out at the point of sale. Both are honoured: the weekly drop is consent-only, and product email goes only to people who have bought something and can switch it off at any moment.

Receipts, download links and version notices are not marketing. They are the purchase itself, and there is no switch for them — turning them off would break the thing you paid for.

Manage what is sent to you.

Who else sees it

Five processors, named rather than gestured at, because “trusted third parties” tells a reader nothing they can check:

  • Whop — payment and checkout. Your payment details, which never reach us, and your billing country for tax. (United States)
  • Auth0 — sign-in. Your email address, name and picture — the identity you sign in with. (United States / European Union)
  • Vercel — hosting. Request logs, transiently, in the course of serving the site. (United States)
  • Cloudflare R2 — file storage. The design files themselves. No personal information. (Global, no fixed region)
  • Resend — email delivery. Your email address and the contents of what we send you. (United States)

Each is bound to use the information only to provide its service. None of them is permitted to use it for their own purposes, and none is paid in data.

Leaving South Africa

Every processor above is outside South Africa, so operating this site necessarily transfers personal information across the border. Section 72 of POPIA permits that where the recipient is subject to a law or binding agreement affording substantially similar protection, or where the transfer is necessary to perform the contract you asked for. Both apply here.

Stated plainly rather than buried: your email address is stored on infrastructure in the United States and the European Union. If that is not acceptable to you, the honest answer is not to buy — there is no version of this shop that runs without it.

Analytics and cookies

Privacy-respecting, aggregate analytics only: page views, referrers, and which items get looked at. No cross-site tracking, no advertising pixels, no profiles built about you, and nothing sold on. Analytics data is retained for 26 months.

The cookies this site sets are the ones it cannot work without: your session when signed in, your cart, and your theme and motion preferences — which are stored in your own browser and never reach us at all. There are no advertising or tracking cookies here, which is why there is no banner asking you to accept any.

How long it is kept

  • Account and entitlements. For as long as the account exists — an entitlement is a permanent right to re-download, and deleting it would delete what you bought.
  • Orders and invoices. Five years after the transaction, because the Companies Act and the Tax Administration Act require it. This one survives a deletion request; see below.
  • Download log. 24 months, then deleted.
  • Analytics. 26 months, aggregate throughout.
  • Email you sent us. 24 months after the conversation ends.

Security, and what happens if it fails

Everything is served over TLS. Files are held in private object storage and reached only through signed links that expire in fifteen minutes. API keys are stored hashed and can be revoked instantly. Access to the production database is limited to one person.

Section 22 of POPIA requires that a compromise of personal information be reported to the Information Regulator and to you as soon as reasonably possible after it is discovered. That is what would happen, and it would say what was taken rather than that “an incident occurred”.

Your rights, and how to use them now

Under POPIA — and, for EU and UK visitors, the GDPR — you may ask what is held about you, ask for it to be corrected, ask for it to be deleted, object to a use, and withdraw a consent you gave. Two of those are buttons rather than requests:

  • Access. Download everything held about you as a file, immediately, without asking anyone.
  • Erasure. Request deletion from settings. It is acknowledged on the spot and completed within 30 days.
  • Correction. Your name and email live with your sign-in provider and change there; everything else is editable in settings or by email.
  • Objection and withdrawal of consent. The email switches in settings, effective immediately.

One caveat, stated honestly rather than discovered later: orders and invoices are retained even after a deletion request, because the law requires financial records to be kept for five years. Your identity is dissociated from them — the record of the transaction survives, the record of who you are does not.

Anything not covered by a button: support@fundur.io, done within 30 days.

If you are not satisfied

Write to the Information Officer first — it is faster, and most of what arrives is a question rather than a complaint.

If that does not resolve it, you have the right to complain to The Information Regulator (South Africa), which regulates POPIA and is independent of us: POPIAComplaints@inforegulator.org.za or inforegulator.org.za. EU and UK visitors may complain to their own supervisory authority instead.

Who you are dealing with

Published under section 43 of the Electronic Communications and Transactions Act 25 of 2002, which requires a supplier selling through a website to say plainly who it is.

Registered name
FUNDUR (Pty) Ltd
Registration number
2023/644435/07
Legal status
A private company registered in the Republic of South Africa
Place of business
Johannesburg, Gauteng, South Africa
Website
design.fundur.io — the only address this catalogue is sold from

Version history

  1. v2.0 · 05 August 2026

    Named every processor and where it sits, published the Information Officer and the Regulator, and made access and deletion self-service.

  2. v1.0 · 29 July 2026

    First published.

Questions about any of this: support@fundur.io, answered within two working days.