POPIA-aligned consent tracking

Consent your customers can actually see.

A customer scans your branch's QR code, chooses exactly what they're happy to share, and it's logged - visible to them in their app and to your staff in the dashboard, the instant it happens. No paper forms, no opt-in lists your store has to maintain alone.

01
Customer scans the branch QR Or types a short code your till texted or emailed them.
02
They choose, purpose by purpose Nothing is pre-selected - marketing email, SMS, and analytics are each a separate, explicit choice.
03
Your dashboard reflects it instantly Same database the app writes to - a staff lookup shows the grant the moment it's made, not after a nightly sync.
Real-time, not batched
What you get

Everything a branch needs to capture and prove consent

Built for the pilot stage of a real South African retail rollout - not a speculative feature list.

QR & POS codes

Every branch gets its own rotating QR code, plus a POS-issued short code fallback for a till without a scannable screen.

Consent activity feeds

Filterable grants and withdrawals, by branch, purpose, date range, or customer - org-scoped, so one business never sees another's.

Role-scoped staff accounts

Admins manage branches and staff; every account is confined to its own organization's data.

A point-of-sale API

Your till can check whether a customer has already consented, or request a review code - authenticated per branch.

How it works

Live in a branch in three steps

Display your QR code

Generated per branch from the dashboard, and rotated whenever you need to invalidate an old one.

Customers grant on their own phone

The Vumela app is the record of truth - customers can review or withdraw any consent later, from any store, without contacting you.

Your team tracks it as it happens

Filter granted and withdrawn consent by branch or purpose, or look up a single customer's full history.

Built for POPIA

Consent that holds up under South African law, not just good intentions

Vumela is built around the Protection of Personal Information Act from the data model up - purpose-bound consent, not a blanket opt-in, is the only kind of consent the platform can capture.

Protection of Personal Information Act, 2013 (POPIA)
  • Every consent is tied to one specific purpose, captured at the point of interaction - never a bundled opt-in.
  • Withdrawal is a single action in the customer's app - never harder than granting was.
  • Every branch and staff account is scoped to its own organization - no cross-business visibility, ever.
  • Customer data is hosted in South Africa (AWS af-south-1, Cape Town) - a hard requirement, not a preference.

See it running in your stores

We're onboarding pilot organizations directly - tell us about your stores and we'll get back to you.