POPIA & Data Protection Compliance

Privacy & POPIA Policy

How BluePay (Pty) Ltd collects, safeguards, processes, and respects personal information in strict compliance with South Africa's Protection of Personal Information Act (Act 4 of 2013).

Effective Date: August 2026 Version 2.0 Republic of South Africa
verified_user

POPIA Compliant

Strict adherence to South African privacy legislation & PAIA.

credit_card_off

No Card Storage

Payments processed via PCI-DSS Level 1 certified gateways.

lock

Zero Data Brokering

We never sell, rent, or trade your personal information.

1

Responsible Party & Overview

This Privacy and POPIA Policy explains how BluePay (Pty) Ltd ("BluePay", "we", "us", or "our"), registration number 2026/123456/07, acts as a "Responsible Party" under the Protection of Personal Information Act, No. 4 of 2013 (POPIA) and the Promotion of Access to Information Act, No. 2 of 2000 (PAIA).

BluePay operates a specialized technology platform and financial ledger engine that enables secure in-app digital tipping (gratuities) for car guards, security personnel, parking attendants, and service staff at partnered commercial venues, shopping centers, and retail districts across the Republic of South Africa.

Scope of this Policy

This policy governs all interactions across our platform, including drivers/payers initiating cashless tips via QR code lanyards and the BluePay mobile application, registered car guards receiving tip notifications, venue supervisors ("Bosses") managing daily cash-out bridge settlements, and visitors to our websites and mobile applications.

2

Categories of Personal Information Collected

Under POPIA Condition 2 (Processing Limitation), we collect and process only the minimal personal information necessary to fulfill our core tipping and ledger settlement functions:

directions_car A. Payers / Drivers (App Users)

  • Email Address: Captured during in-app registration and payment solely to dispatch electronic transaction receipts, confirm charge outcomes, resolve payment disputes, and enable retroactive account stitching when registering on the mobile app.
  • Name / Display Alias: Collected only if the payer voluntarily registers an account or updates their profile in the BluePay mobile app.
  • Transaction Metadata: Tip amount, currency (ZAR), transaction timestamp, location/venue ID, and assigned guard ID.
  • Gamification Data: Tipping streaks, community ranking scores, and empathy badges (e.g. "Rainmaker", "Night Owl").
  • Technical Telemetry: IP address, device user-agent string, and Cloudflare Turnstile anti-bot security tokens to prevent automated fraud and denial-of-service attacks.

badge B. Payees / Car Guards (Service Personnel)

  • Full Name & Display Nickname: Used on the public checkout screen and venue dashboard for identity verification and humanization.
  • Mobile Phone Number: Essential for transmitting real-time transactional SMS tip notifications and daily ledger balance summaries to the guard's phone.
  • Profile Photograph & Biographical Note: Provided with explicit consent to showcase personal aspirations (e.g., "Saving for school shoes") on the secure in-app payment screen.
  • Venue Location & QR Identity: Assigned QR lanyard code and venue affiliation.
  • Financial Ledger Records: Running cleared balances, daily tip tallies, cash advance settlement receipts, and optional bank details (if EFT backup is configured).

storefront C. Venue Supervisors & Parking Operators ("Bosses")

  • Manager / Representative Information: Full legal name, business email address, and direct telephone number.
  • Business & Venue Details: Registered company name, trading address, parking operational capacity, and venue ID.
  • Banking Details: Bank name, account number, branch code, and account type used strictly for automated bulk EFT reimbursements of daily cash-out balances.
3

Payment & Financial Security (PCI-DSS)

shield
BluePay Never Stores Debit or Credit Card Information

All secure in-app payments are processed exclusively through our registered payment service provider that maintains the highest level of PCI-DSS (Payment Card Industry Data Security Standard) Level 1 certification.

When you make a payment on BluePay:

  • Card numbers, CVV security codes, and bank login credentials never pass through or get stored on BluePay servers.
  • Payment data is encrypted and tokenized directly between your device and the payment gateway.
  • BluePay receives only an anonymized payment authorization token, a transaction reference string, and confirmation of success or failure.
4

Lawful Grounds for Processing (POPIA Section 11)

Under Section 11 of POPIA, personal information may only be processed if a specific lawful basis applies. BluePay relies on the following lawful justifications:

1. Performance of a Contract

Processing tips, generating digital receipts, sending instant SMS tip confirmations, reconciling ledger balances, and reimbursing venue supervisors.

2. Legitimate Interests

Preventing fraudulent transactions, ensuring network cybersecurity, resolving payment chargebacks, and maintaining audit logs.

3. Explicit Consent

Car guards consenting to the display of their first name, photograph, and biographical note on the public checkout screen to facilitate empathy tipping.

4. Legal & Statutory Compliance

Complying with South African tax laws (SARS), the Companies Act, FICA anti-money laundering statutes, and financial record-keeping mandates.

5

SMS & Email Communications

BluePay strictly restricts electronic communications to essential, service-related transactional notices:

sms Guard Offline SMS Alerts

Guards receive automated SMS notifications immediately upon successful tip payments (e.g. "🔥 R20 tip received! Today's total: R150."). Phone numbers are used solely for ledger notifications and never for unsolicited commercial promotions.

mark_email_read Payer Digital Receipts

Payers receive an itemized transaction receipt via email containing the date, tip amount, guard name, and venue name. We do not send marketing newsletters without explicit prior opt-in consent.

6

Third-Party Operators & Gateways

Under POPIA Sections 20 and 21, third parties who process personal information on our behalf are classified as "Operators". All BluePay Operators are bound by strict written data processing agreements requiring robust security standards and confidentiality.

Operator Category Purpose Compliance & Safeguards
Payment Gateways (our registered payment service provider) Processing secure in-app payments PCI-DSS Level 1 certified, SARB & PASA regulated
Telecommunications & SMS Services Dispatching carrier SMS alerts to car guard phones Encrypted API transmissions, ephemeral SMS dispatch
Cloud Infrastructure (Cloudflare) Database hosting, WAF, bot detection, edge security ISO 27001, SOC 2 Type II, TLS 1.3 encryption at rest
Transactional Email Service Delivering transaction receipts to payers DKIM/SPF authenticated, TLS in transit
7

Trans-Border Data Transfers (POPIA Section 72)

BluePay utilizes secure distributed cloud edge infrastructure to ensure ultra-low latency checkouts (sub-10 second loading). Consequently, encrypted personal information may be transmitted or temporarily cached across international data centers.

In strict compliance with Section 72 of POPIA, all trans-border data transfers occur only to jurisdictions that maintain adequate legal data protection standards substantially similar to POPIA (such as GDPR-compliant countries), or where robust contractual clauses bind the foreign service provider to equivalent data privacy obligations.

8

Security Safeguards & Encryption (POPIA Section 19)

We take comprehensive technical, organizational, and physical security measures to protect personal data against loss, damage, unauthorized access, or unlawful processing:

End-to-End Encryption All web and API traffic is strictly enforced over TLS 1.3 encryption. At-rest databases are encrypted using AES-256 standards.
Least Privilege & Access Controls Internal platform access is restricted strictly on a need-to-know basis protected by Multi-Factor Authentication (MFA).
Prepared SQL Statements All database queries strictly use parameterized SQL bindings to completely prevent SQL injection vulnerabilities.
Automated Threat Mitigation Cloudflare Turnstile bot detection and DDoS mitigation shield checkout endpoints from credential stuffing and scraping.
9

Security Breach Notification Protocol (POPIA Section 22)

warning Mandatory Incident Notification Protocol

In the unlikely event that personal information is accessed or acquired by an unauthorized person, BluePay will immediately notify both the South African Information Regulator and all affected data subjects in writing as soon as reasonably possible, detailing the nature of the breach, potential consequences, and remediation measures implemented.

10

Data Retention & Auto-Purge Standards (POPIA Section 14)

In adherence to POPIA Section 14, personal information is retained only for as long as necessary to achieve the purpose for which it was collected, or as required by statutory law:

  • Financial & Ledger Records: Retained for a mandatory period of 5 years in accordance with the South African Companies Act, Tax Administration Act, and FICA guidelines.
  • Temporary Security Tokens & Action Records: Automated background cleanup tasks purge completed transient records and temporary tokens older than 24 hours.
  • Inactive Guard / Supervisor Profiles: Securely archived and de-identified upon termination of service, subject to required accounting audit retention.
11

Your Data Subject Rights Under POPIA

As a Data Subject under the Protection of Personal Information Act, you hold the following explicit statutory rights:

Right of Access (Section 23)

Request confirmation of whether we hold personal information about you and obtain a copy of that record.

Right to Correction / Deletion (Section 24)

Request the correction, updating, or deletion of inaccurate, irrelevant, excessive, or unlawfully retained data.

Right to Object (Section 11(3))

Object on reasonable grounds to the processing of your personal information where processing is based on legitimate interest.

Right to Withdraw Consent

Withdraw your consent at any time where processing was originally based on voluntary consent.

To exercise any of these rights, please submit a written request to our Information Officer at [email protected] using the prescribed PAIA Form 2. We will respond within thirty (30) calendar days without undue delay.

12

Information Officer & Complaints Procedure

BluePay (Pty) Ltd — Information Officer
Physical Address: Gauteng, Republic of South Africa
Official Website: https://bluepay.co.za
Response SLA: Within 30 Calendar Days
South African Information Regulator

If you are dissatisfied with our response to your inquiry, you have the right to lodge a formal complaint with the South African Information Regulator:

Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints Email: [email protected]
General Enquiries: [email protected]
Official Website: https://inforegulator.org.za