Privacy & Data Protection Policy
Last updated: June 2026
Your trust and privacy are important to us. This policy explains how Swiffy (Pty) Ltd ("Swiffy", "we", "us") collects, uses, stores and protects your personal information when you use our services. We are committed to full compliance with the Protection of Personal Information Act (POPIA) and applicable GDPR obligations.
1. Information We Collect
1.1 Information You Provide
When you create an account or use Swiffy's services, we collect personal information including:
- Full name and identity documentation
- Email address and contact details
- Banking details and payment information
- Business registration information (for merchant accounts)
- Source of funds and financial information required for KYC/AML compliance
1.2 Information Collected Automatically
When you interact with our platform, we automatically collect:
- Device information (hardware model, operating system version, device identifiers)
- Usage data including access logs, IP addresses, browser type and session activity
- Transaction data including amounts, timestamps, payment methods and outcomes
- Location information as permitted by your device settings
2. How We Use Your Information
Swiffy uses collected information to:
- Provide, maintain and improve our payment processing services
- Verify your identity and comply with KYC/AML obligations under FICA
- Process transactions and prevent fraud
- Communicate with you regarding your account and our services
- Meet our legal and regulatory reporting obligations
- Analyse platform usage to develop new features and improve performance
- Detect and investigate security incidents or suspicious activity
3. Legal Basis for Processing
We process your personal information on the following legal bases:
- Contract performance — processing necessary to provide the services you have requested
- Legal obligation — processing required to comply with FICA, POPIA, and other applicable law
- Legitimate interest — fraud prevention, security monitoring, and platform improvement
- Consent — where you have given us explicit consent for specific processing activities
4. Data Sharing
Swiffy does not sell your personal information. We share your data only in the following circumstances:
- With your explicit consent
- With acquiring banks, payment processors and financial institutions necessary to complete your transactions
- With regulatory authorities, law enforcement or the Financial Intelligence Centre (FIC) as required by law
- With service providers under contractual confidentiality obligations who assist in operating our platform
- In aggregated, non-identifiable form for research or reporting purposes
All third parties with whom we share data are required to maintain appropriate security standards and to use your information only for the purposes for which it was shared.
5. International Transfers
Swiffy may process and store personal information on servers located outside South Africa. Where this occurs, we ensure appropriate safeguards are in place, including contractual protections equivalent to those required by POPIA.
6. Data Retention
We retain personal information for as long as necessary to provide our services and meet our legal obligations. Transaction records are retained for a minimum of five years in accordance with FICA requirements. When data is deleted, it may persist in encrypted backups for a limited period before permanent deletion.
7. Your Rights
Under POPIA and applicable law, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your data, subject to our legal retention obligations
- Object to processing based on legitimate interests
- Lodge a complaint with the Information Regulator (South Africa)
To exercise any of these rights, contact us at privacy@swiffy.co.za. We will respond within the timeframes required by applicable law. We may decline requests that are unreasonably repetitive, impractical, or that would compromise the rights of others.
8. Security
Swiffy implements industry-standard security measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Access controls restricting employee access to personal data on a need-to-know basis
- Regular penetration testing and security audits
- Automated monitoring for unauthorised access or anomalous activity
- Contractual confidentiality obligations for all staff and service providers
9. Cookies
Our website uses cookies and similar technologies to maintain session state, analyse usage and improve the user experience. You can control cookie settings through your browser, though disabling certain cookies may affect platform functionality.
10. Changes to This Policy
We may update this policy from time to time. For significant changes, we will provide advance notice via email or a prominent notice on our platform. Continued use of our services after the effective date constitutes acceptance of the updated policy.
11. Contact Us
For questions or concerns about this policy or your personal information, please contact our Privacy Officer at privacy@swiffy.co.za or at our registered address in South Africa.