Privacy
What we know about your family
This portal holds information about your child. Here is exactly what, why we have it, and how to get rid of it.
Last updated: 11 August 2026
1. Who is responsible
The Kids Are Coding is operated by William du Plooy, based in Durban, KwaZulu-Natal, South Africa. Under the Protection of Personal Information Act (POPIA) that makes him the responsible party for the information described here — the person accountable for it.
Contact for anything on this page: WhatsApp 069 009 6569 or email william@thekidsarecoding.com.
2. What this portal collects
This page covers the portal specifically. Lessons and feedback also happen over WhatsApp, which has its own privacy terms we do not control.
About the parent or guardian
- Your name and email address (your email is your sign-in).
- Your phone number, if you gave one.
- A password, which is stored as a one-way hash. We cannot read it.
About the learner
- Their full name, and the name they prefer to be called.
- Their date of birth, if given — used only to pitch the material correctly.
- Which courses they are on and which weeks they have completed.
- The work they send in — photographs, screenshots, files — and any note they write with it.
- What the coach wrote back about that work.
About the account
- Your family name as we have it, your agreed monthly fee, and your billing day.
- A record of payments: amount, date due, date paid.
- A record of emails we sent you, so the same message is never sent twice.
What we do not collect
- No advertising or analytics trackers, and no third-party cookies.
- No card or banking details — payment happens by EFT, outside this portal.
- No location data, no contact lists, no access to your device.
The only cookies set are the ones that keep you signed in and remember your language. Without them the portal cannot work at all, so there is nothing to opt out of.
3. Why we hold it
Each item above exists for one of exactly four reasons:
- To deliver the lessons — releasing the right week to the right child, and getting their work to the coach.
- To give feedback — the coach cannot write about work they cannot see.
- To run the account — knowing who has paid, and telling you when something is due.
- To keep records we are legally required to keep, such as proof of payment.
We do not use any of it to build a profile, to score a child, or to sell anything to you beyond the programme you enrolled in.
4. Who can see it
The portal is built so that this list is enforced by the database itself:
- You see your own family — your children, their progress, their feedback, and your own account.
- Your child sees their own lessons and their own work. They cannot see anything about payments.
- Our staff (currently the founder) see the learners in the portal, their work, and account status.
- Nobody else. No other family can see your child, by any URL.
This is not only a policy — it is a set of rules inside the database, and there is an automated test suite that tries to break them from every angle before each release.
5. Your child’s work, and photographs
We are proud of what learners build and sometimes like to show examples on our website or social media.
We will never publish your child’s full name, face, contact details, or anything identifying, without asking you first and getting a clear yes. Where we show a project, we may credit it with a first name only, or anonymously, and only if you have agreed. You can withdraw that permission at any time and we will take it down.
Nothing you upload to this portal is published anywhere by the portal itself. Files are stored privately and served through short-lived links that stop working within the hour.
6. Children’s information
Most of our learners are under 18, and many are under 13. Under POPIA, information about a child is treated with extra care, and consent is given by the parent or guardian rather than by the child.
By enrolling and setting up a portal account you are giving that consent on your child’s behalf. You can withdraw it at any time, which means closing the account — see section 9.
We keep what we collect about a child to the minimum the programme actually needs. A child’s date of birth is optional. We never ask a child for anything about anyone else.
7. How long we keep it
- While you are enrolled — everything above, so the programme works.
- After you leave— we delete the account and the learner’s submitted work on request, and in any case within 12 months of the enrolment ending.
- Payment records are kept for five years, because South African tax law requires it. These are amounts and dates, not your child’s work.
8. Where it is kept, and the cross-border bit
We use three service providers to run this portal:
- Supabase — the database and file storage. Our data is hosted in their Ireland (eu-west-1) region.
- Vercel — serves the portal web pages.
- Resend — sends the notification emails.
This means your family’s information is stored outside South Africa. POPIA allows this where the receiving country has comparable protection — Ireland is in the European Union and subject to the GDPR, which meets that standard. We tell you plainly rather than burying it, because it is the kind of thing you have a right to know before you decide.
These providers process information on our instructions only. None of them are permitted to use it for their own purposes, and none of them are sent your child’s work except as needed to store it.
9. Your rights, and how to use them
Under POPIA you may, at any time:
- Ask what we hold about you or your child, and get a copy.
- Ask us to correct anything that is wrong.
- Ask us to delete it, subject to the payment records in section 7.
- Object to how we are using it.
- Withdraw the consent you gave on your child’s behalf.
Send one message on WhatsApp or by email and we will action it. There is no form and no fee. We will respond within 30 days, and usually the same week.
If you are not satisfied with how we handle it, you can complain to the Information Regulator of South Africa, at inforegulator.org.za.
10. Keeping it safe
- Everything travels over an encrypted connection (HTTPS).
- Passwords are stored as one-way hashes and cannot be read by us.
- Every table in the database has access rules attached to it, so a request for another family’s data returns nothing rather than relying on the app to remember to ask correctly.
- Uploaded work is private and reachable only through short-lived signed links.
- Access to the admin side is limited to our staff.
If information is ever exposed in a way that could harm you, we will tell you and the Information Regulator as soon as we reasonably can, as POPIA requires — and we will tell you what happened rather than a sentence of damage control.
11. Changes to this policy
If this changes we will update this page and the date at the top. If a change materially affects what we do with your family’s information, we will tell you directly rather than expecting you to notice.