Skip to content

POPIA notice

Effective from · Version 1.0

This is the notification required by section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). It tells you, before or as soon as reasonably practicable after we collect your personal information, what we are collecting and why.

1. Responsible party

WynkPay (Pty) Ltd, registration number 2016/409836/07, PO Box 0000, Johannesburg, 2000, South Africa. Our Information Officer is registered with the Information Regulator in terms of section 55 and can be contacted at privacy@wynk.cash, or in writing addressed to "The Information Officer, WynkPay (Pty) Ltd" at the address above.

2. Information collected and its source

We collect personal information directly from you when you apply, verify your identity, transact or contact support. We also collect it from third parties where the law allows or requires: identity verification and sanctions screening providers, credit bureaux where you have consented to an enquiry, our sponsor bank in respect of settlement, and your device in respect of security attestation.

3. Purposes of processing

  • Opening and operating a wallet or merchant account, including authenticating you.
  • Executing, settling and reconciling payment transactions, and providing statements.
  • Meeting our obligations under FICA, including customer due diligence, screening and record-keeping.
  • Assessing affordability and managing credit risk under the National Credit Act, where you apply for a credit product.
  • Detecting, investigating and preventing fraud, money laundering and terrorist financing.
  • Providing support, handling disputes and chargebacks, and complying with regulatory reporting.
  • Direct marketing, only where you have consented or where section 69 of POPIA otherwise permits it.

4. Whether supply is voluntary or mandatory

Identity, contact and verification information is mandatory: FICA does not allow us to open an account without it, and we cannot proceed if you decline. Credit bureau consent is voluntary — decline it and we simply cannot offer you a credit product, but your wallet or merchant account is unaffected. Marketing consent is voluntary and has no effect on any product.

5. Consequences of not supplying information

If mandatory information is not supplied we cannot open or continue to operate an account, and where an account is already open we may be obliged to restrict it until the information is provided.

6. Recipients

Personal information is shared with our sponsor bank, payment schemes and the national payment system operator, credit bureaux where applicable, value-added service aggregators for the specific product purchased, operators processing on our behalf under written contract, and regulators, law enforcement or the courts where the law requires. Each operator is bound by a written contract that requires it to process only on our instruction and to maintain appropriate security safeguards.

7. Cross-border transfers

Where an operator processes personal information outside the Republic, we permit it only on the basis set out in section 72 of POPIA — where the recipient is subject to binding contractual terms that uphold principles of reasonable processing substantially similar to POPIA and include onward-transfer restrictions.

8. Retention

Records are retained for the periods set out in our privacy policy: five years for financial transaction and identity verification records as required by FICA and tax legislation, the statutory period for credit agreement records, three years for support and marketing preference records, and twelve months for device and security logs. Automated purge jobs enforce these periods.

9. Security safeguards

We apply appropriate, reasonable technical and organisational measures as required by section 19: encryption in transit and at rest, database-enforced tenant isolation, role-based access control with multi-factor authentication for administrative access, full audit logging, annual external penetration testing and quarterly vulnerability scanning. We will notify you and the Information Regulator of a compromise of your personal information as required by section 22.

10. Your rights and how to exercise them

  • Section 23 — request confirmation of what we hold and a record of it. Use the data request function in the app or email us.
  • Section 24 — request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully.
  • Section 11(3) — object, on reasonable grounds, to processing based on legitimate interests.
  • Section 69(3)(c) — object to direct marketing at any time, at no cost.
  • Section 71 — request that a decision affecting you is not based solely on automated processing, and ask us to explain the basis of an automated credit decision.
  • Sections 74 and 5(h) — complain to the Information Regulator.

Requests are handled within 30 days. A request for access may attract the prescribed fee under the Promotion of Access to Information Act 2 of 2000; we will tell you the amount before we process the request. Our PAIA manual is available on request from privacy@wynk.cash.

11. Complaints to the Information Regulator

The Information Regulator (South Africa) can be contacted at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, or by email at the complaints address published on the Regulator's website. You may complain to the Regulator whether or not you have complained to us first, although we would prefer the chance to fix it.

12. Consent records

Each consent you give is recorded with the purpose it relates to, the version of the notice you were shown, and the date and time. Consent is captured explicitly — no box on this site or in our apps is pre-ticked — and each purpose is consented to separately. Withdrawing consent for one purpose does not withdraw it for another.

13. This website specifically

If you submit the sign-up form on this site, we process the cellphone number and shop name you give us in order to send you a one-time PIN and start your application. We record a hashed form of your IP address for rate limiting and abuse prevention, retained for seven days. The number you enter is never written to our application logs in full — only in a masked form that cannot be used to identify you.