SENTRY

Privacy

Privacy notice

Version 2026-09-10 · effective 10 September 2026

A record of who owns which firearm, where, and with what serial number is a burglary shopping list. That is the reason for most of the choices below.

Draft — not yet in force

This document is incomplete and has not been reviewed by an attorney. It is published here so it can be reviewed, and it does not bind anyone.

  • · Still needed: the supplier's full name (ECTA s 43(1)(a))
  • · Still needed: the supplier's legal status (ECTA s 43(1)(b))
  • · Still needed: the registration number (ECTA s 43(1)(i))
  • · Still needed: a physical address (ECTA s 43(1)(c))
  • · Still needed: a telephone number (ECTA s 43(1)(c))
  • · Still needed: an email address (ECTA s 43(1)(d))
  • · Still needed: the Information Officer (POPIA s 55)
  • · Still needed: contact details for the Information Officer
  • · Still needed: confirmation that the Information Officer is registered with the Information Regulator (POPIA s 56)

The liability, indemnity and dispute-resolution clauses are marked below and have not been settled. Under the Consumer Protection Act both their wording and how prominently they are shown are legal questions.

What Sentry collects

  • · Your name, email address and a hashed password.
  • · The SAPS reference number of each application you choose to track, and for firearm applications the serial number of the firearm.
  • · Your licences: the section they were issued under, licence numbers, and the expiry dates you enter.
  • · Your firearms: make, model and serial number.
  • · Any documents you upload — licence cards, competency certificates, proof of posting.
  • · Optional notes, nicknames and station names you add to your own records.
  • · A push notification token for each device you sign in on, if you allow notifications.

Sentry never asks for your identity number. The SAPS status form does not need one, so it is not collected and not stored.

There is no third-party analytics or advertising code anywhere near this data, and the web fonts are served from our own domain so that loading a page does not tell a font provider you were here.

Whether you have to provide it

All of it is voluntary, and most of it is what the product is for. Without a reference number Sentry cannot check an application; without an expiry date it cannot work out a renewal deadline. Nothing happens if you decline except that the corresponding feature has nothing to work with.

Who else sees it

  • SAPS. To check an application, Sentry submits its reference number — and, for a firearm application, the serial number — to a public South African Police Service status page on your behalf. That is the purpose of the feature and it cannot work without it. Nothing else about you is sent.
  • Google, for push notifications. If you allow notifications, a device token and the text of the notification pass through Firebase Cloud Messaging, which processes data outside South Africa. This is a transborder flow under POPIA section 72. You can decline notifications and still receive reminders, because Sentry also schedules them on your device.
  • Our email provider, for verification, password resets and renewal reminders — your address and the content of the email.

Your records are never sold, and never shared for advertising.

How it is protected

  • · Serial numbers, licence numbers and reference numbers are encrypted by the application before they reach the database, so a copy of the database alone does not read them. Searching still works, through a keyed one-way index.
  • · Uploaded documents sit on a private disk with no public path, reachable only through short-lived links tied to your session.
  • · The portal authenticates with a session cookie rather than a token that browser JavaScript could read.
  • · The mobile app pins our TLS certificate, so it will not talk to an intercepting proxy.
  • · Sign-in and status checks are rate limited, and asking about a reference number that belongs to someone else returns the same answer as one that does not exist.

How long it is kept

  • · Your records stay while your account exists.
  • · A completed application is archived rather than deleted, so its history stays with you.
  • · When a SAPS response cannot be understood, the raw page is kept for seven days so the fault can be diagnosed, then deleted automatically.
  • · Deleting your account is a hard delete, carried out immediately: your records and your uploaded files are erased rather than flagged.

Your rights

Under POPIA you may ask what is held about you, have it corrected, and have it deleted. Two of those are buttons rather than a support request:

  • · Export. Settings gives you a machine-readable copy of everything on your account.
  • · Delete. Settings deletes the account and its contents outright.
  • · Correct. Every record is editable in the app.

Who is responsible

POPIA sections 55 and 56 require a named Information Officer, registered with the Information Regulator before processing begins. That appointment has not been published here yet.

If you think we have got it wrong

Tell us first if you can. You may also complain to the Information Regulator (South Africa) at PAIAComplaints@inforegulator.org.za.