Move Payroll Move Physio & Pilates Kimberley

Privacy notice

Effective 27 September 2026. Applies to the Move payroll app at payroll.movephysioandpilates.co.za, and to the employee take-on form it sends to new staff.

In short: Move Physio & Pilates Kimberley uses this app to pay its staff. It holds the personal, contact, bank and tax details that employment and South African tax law require, and nothing is sold, shared for marketing or used for advertising.

If you are a new employee filling in the take-on form: your form is held on the server only until Anna de Beer adds you to payroll, and is then deleted. Forms that are never added are deleted after 30 days.

1. Who is responsible

The responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA) is Move Physio & Pilates Kimberley, 8 At v Niekerk Street, Kimberley, 8301, South Africa. The Information Officer is Anna de Beer, reachable at movepilatessa@gmail.com or 079 150 7603.

The software is built and maintained by JL Reynders, trading as JLR Dev, Bloemfontein, South Africa (jan-louis@jlrdev.co.za). JLR Dev is an operator: it processes information only on the practice's instructions, to keep the software working, and not for any purpose of its own.

2. Whose information, and what

Employees

Name and preferred name, South African ID number or passport details, date of birth, contact numbers and email, home and postal address, bank account details, income tax reference number, emergency contact, and the employment and pay information the practice records (job title, pay rates, hours, leave, deductions, payslips and tax certificates).

People who sign in

The email address and password of each person given access to the payroll, managed by Supabase Auth. Supabase stores passwords only in scrambled (hashed) form.

Emergency contacts

An employee's emergency contact is recorded so the practice can reach someone if the employee is hurt or ill at work. The take-on form asks the employee to tell that person.

3. Why it is used

The lawful bases are the employment contract, the practice's legal obligations, and, for the emergency contact, the employee's legitimate interest. The information is not used for marketing, profiling or automated decisions about anyone.

4. Where it is kept, and who can see it

WhereWhatWho
The practice's own device The payroll itself: employees, pay runs, payslips and leave, stored in the browser on the computer or phone the payroll is used on. People the practice has given a payroll sign-in.
Supabase (Supabase Inc., supabase.co), servers in Stockholm, Sweden Sign-in accounts; the optional cloud backup of the payroll, linked to the account that made it; and take-on forms waiting to be added. The practice. JLR Dev can reach it only to maintain the service.
Cloudflare (Cloudflare Inc.) Hosts the app and the take-on form, and sees the network details of each visit (IP address, browser) as any web host does. Cloudflare, as a hosting provider.
Resend (Resend Inc., api.resend.com) Delivers a payslip by email when the practice chooses to email one: the employee's email address and the payslip. Resend, as an email provider.

Transfer outside South Africa. Supabase stores data in the European Union and Cloudflare and Resend operate internationally. POPIA section 72 allows this because these providers are bound by laws and agreements that give protection substantially similar to POPIA, including the EU General Data Protection Regulation.

Tax tables. When it is online, the app checks wagewise.jlrdev.co.za, a JLR Dev site, for updated SARS tax tables. That request carries no personal information, but like any web request it reveals the device's IP address to that site.

Visit statistics. Cloudflare Web Analytics is enabled on this domain and counts visits to the payroll app without cookies. The take-on form blocks it, so no statistics are collected from employees filling it in.

Links out. The tax screen links to the SARS tax rates page on www.sars.gov.za; opening it takes you to the SARS site, under SARS's own terms. The WhatsApp button for sharing a take-on link opens WhatsApp (wa.me) with the link ready to send; WhatsApp's own terms and privacy policy apply to that message.

5. The take-on form

The practice can send a new employee a personal link to fill in their own details. The link carries a random single-use code. Only a scrambled (hashed) copy of that code is stored, so the link cannot be rebuilt from the server. The link stops working when the form is sent, after 14 days, or when the practice cancels it.

The form sends information and can never read anything back: nobody who has the link can see what was sent, or anything else in the payroll. The form is held on Supabase until Anna de Beer adds the employee to payroll, and is then deleted from the server. A form that is never added is deleted after 30 days. The form page is not indexed by search engines and sets no cookies of its own.

6. What is stored in the browser

StoredWhyHow to remove it
wagewise (IndexedDB) and wagewise.state.v1 The payroll data on the practice's device, and a safety copy. Reset in the app, or clear the site's data in the browser.
wagewise.auth.session Keeps the payroll user signed in. Sign out.
wagewise.device A random name for this device, used by the cloud backup. Clear the site's data.
ww-theme Remembers light or dark mode. Clear the site's data.
takeon.t (session storage, take-on form only) Holds the link's code while the form is open, so it can be removed from the address bar. Removed when the form is sent or the tab is closed.

No advertising, tracking cookies or fingerprinting are used.

7. How long it is kept

Take-on forms: until the employee is added to payroll, and at most 30 days. Payroll records: for as long as South African tax and labour law require the practice to keep them (tax records at least five years), then deleted. A cloud backup is replaced each time a new one is made and can be removed by the practice at any time.

8. Security

Connections are encrypted (HTTPS). Every server table has row-level security switched on, and the public take-on form has no access to any table: it can only hand a form to one checked function. No system is perfectly secure; if a breach that affects you occurs, the practice will tell you and the Information Regulator as POPIA section 22 requires.

9. Your rights

Under POPIA sections 23 to 25 you may ask what information the practice holds about you, ask for it to be corrected or deleted where the law allows, and object to its use. Where the GDPR applies, you have the equivalent rights under its articles 15 to 21. Ask Anna de Beer at movepilatessa@gmail.com. Some payroll records cannot be deleted before the law allows, because the practice is required to keep them.

If you are not satisfied, you may complain to the Information Regulator of South Africa: inforegulator.org.za.

10. Children

This app is for employment records and is not intended for anyone under 18. It knowingly holds information about a child only where the law requires it for an employee.

11. Changes

If this notice changes, the new version is published here with a new effective date.