Privacy policy
This policy explains, in plain language, what we do with personal information. The formal processing notice required by section 18 of the Protection of Personal Information Act 4 of 2013 is published separately as our POPIA notice, and the two documents describe the same processing.
Who is responsible for your information
WynkPay (Pty) Ltd is the responsible party. Our Information Officer is registered with the Information Regulator and can be reached at privacy@wynk.cash or by post at PO Box 0000, Johannesburg, 2000, South Africa.
What we collect
- Identity and contact information: your name, identity or passport number, date of birth, cellphone number, email address and physical address.
- Verification information: images of your identity document, a selfie used for a liveness check, and the result of the sanctions and politically-exposed-person screening that FICA requires.
- Business information, for merchants: trading name, category, trading address, business registration and VAT number where you have them, and your settlement bank account details.
- Transaction information: what you paid or were paid, when, at which shop or till, on which rail, and the fee that applied.
- Device and technical information: device model, operating system version, the attestation result for card-accepting devices, IP address and app version.
- Credit information, only if you apply for a credit product: your credit bureau record, affordability inputs, and repayment history.
- Support information: the content of tickets, calls and chats with our support team.
We never store your PIN, and we never store a card number. Your PIN is hashed on your device before it leaves it. Card numbers are tokenised by our sponsor bank and no card number is written to a WynkPay system.
Why we are allowed to process it
- To perform our contract with you — running your wallet or merchant account, moving money, settling your takings and supporting you when something breaks.
- To comply with a legal obligation — FICA identity verification and record-keeping, National Credit Act affordability assessment and reporting, tax record-keeping, and reporting obligations to the Financial Intelligence Centre.
- For our legitimate interests, balanced against yours — fraud detection, security monitoring, credit risk management, and improving the platform.
- With your consent — marketing communications, and any credit bureau enquiry. Consent given for marketing can be withdrawn at any time without affecting your account.
Who we share it with
- Our sponsor bank, which holds wallet funds in trust and executes settlement instructions.
- Payment schemes and the national payment system operator, to the extent a transaction has to travel over their rails.
- Credit bureaux, where you have applied for a credit product and consented to an enquiry. We are also obliged to report the conduct of a credit agreement to them.
- Value-added service aggregators, which receive only the information needed to fulfil a specific purchase — for example a meter number for a prepaid electricity token.
- Service providers who process on our behalf under written contract: cloud hosting, communications gateways, crash reporting and analytics, and courier partners for wholesale deliveries.
- Regulators, law enforcement and the courts, where the law requires it.
We do not sell personal information, and we do not share it with third parties for their own marketing.
Where it is processed
Personal information is processed in South Africa wherever we can. Where a service provider processes it outside South Africa, we only permit that where section 72 of POPIA is satisfied — that is, where the recipient is bound by binding contractual terms providing an adequate level of protection.
How long we keep it
- Financial transaction records: five years from the date of the transaction, as required by FICA and tax legislation.
- Identity verification records: five years from the end of the relationship, as required by FICA.
- Credit agreement records: as required by the National Credit Act and its regulations.
- Marketing preferences and support history: three years, or until you ask us to delete them, whichever is sooner.
- Device and security logs: twelve months.
When a retention period ends the records are deleted or de-identified by an automated purge. Where you ask us to delete information we are legally required to keep, we will tell you which records we must retain and why.
Your rights
- Ask what we hold about you, and get a copy of it.
- Ask us to correct anything that is wrong, or delete anything we are not required to keep.
- Object to processing based on our legitimate interests.
- Withdraw marketing consent, or opt out of direct marketing entirely.
- Complain to the Information Regulator if you think we have got it wrong.
You can exercise all of these from inside the app, or by emailing privacy@wynk.cash. We respond within 30 days. The full procedure, including the Regulator's contact details, is in our POPIA notice.
Security
Personal information is encrypted in transit using TLS 1.3 and at rest using AES-256. Access is controlled at the database level so that one merchant's data cannot be read from another merchant's session, administrative access requires multi-factor authentication, and every access is written to an audit log. We test the platform with an annual external penetration test and quarterly vulnerability scanning.
Cookies
This website sets no advertising or tracking cookies and loads no third-party script. Nothing on this site profiles you across other websites.
Children
The platform is not offered to people under 18 and we do not knowingly process the personal information of a child. If you believe we have, tell us and we will delete it.
Changes
We version this policy and record the version you were shown when you consented. Material changes are notified in the app before they take effect.