Legal
Your data belongs to you. Talo Pay acts as a secure custodian โ retaining only what is necessary, for only as long as required, and deleting everything else.
Talo Pay collects and stores personal and transactional data as part of providing its scan-to-pay and tap-to-pay tipping service. This policy explains what data we hold, how long we keep it, and how we protect it.
All data handling is conducted in compliance with the Protection of Personal Information Act (POPIA), the Financial Intelligence Centre Act (FICA), and applicable South African financial regulations.
| Data Category | What It Includes | Retention Period | Reason |
|---|---|---|---|
| Worker Identity Data | Name, ID number, selfie / liveness check | 5 years from account closure | FICA / AML legal requirement |
| Bank Account Details | Account number, bank name, PayShap proxy | Duration of account + 5 years | Settlement records and audit |
| Transaction Records | Tip amounts, timestamps, payment references | 5 years from transaction date | FICA / NPS Act requirements |
| Contact Information | Email address, mobile number | Duration of account + 1 year | Account management and support |
| Technical Logs | IP addresses, session data, device info | 90 days | Security and fraud monitoring |
| Support Communications | Emails and messages sent to Talo Pay | 3 years | Dispute resolution and compliance |
| Analytics Data | Anonymised usage statistics | 24 months | Platform improvement (anonymised) |
After the applicable retention period, data is securely deleted or anonymised so it can no longer be linked to an individual.
All personal and transactional data is stored in encrypted cloud environments hosted within or with appropriate protections for transfers outside South Africa. Access is restricted to authorised Talo Pay personnel and contracted service providers who are bound by data processing agreements.
Talo Pay does not store payment card numbers or full bank account credentials in a retrievable format. Banking details are used solely for initiating PayShap settlement and are stored with encryption at rest.
All stored personal and financial data is encrypted using industry-standard algorithms.
All data transmitted between your device and Talo Pay uses TLS/HTTPS encryption.
Strict role-based access limits which personnel can view personal information.
Automated monitoring flags unusual patterns to protect Workers and Customers.
All access to personal data is logged and reviewed regularly.
All service providers handling personal data are assessed for security compliance.
In line with POPIA, you may at any time:
Please note that financial transaction records, identity verification data, and records required by FICA cannot be deleted before the legally mandated retention period expires, regardless of a deletion request.
To exercise any of these rights, email info@talopay.co.za. We will acknowledge your request within 3 business days and respond fully within 30 days.
When a Worker closes their Talo Pay account, non-essential data (profile photo, preferences, marketing data) is deleted within 30 days. Financial and identity records are retained for the applicable statutory periods set out in the table above, after which they are securely and permanently deleted.
For data access requests, deletion requests, or questions about this policy:
Information Officer โ Talo Pay (Pty) Ltd
info@talopay.co.za
If you are unsatisfied with our response, you may lodge a complaint with the Information Regulator of South Africa at www.justice.gov.za/inforeg/.