Your data belongs to you. Talo Pay acts as a secure custodian โ€” retaining only what is necessary, for only as long as required, and deleting everything else.

1. Overview

Talo Pay collects and stores personal and transactional data as part of providing its scan-to-pay and tap-to-pay tipping service. This policy explains what data we hold, how long we keep it, and how we protect it.

All data handling is conducted in compliance with the Protection of Personal Information Act (POPIA), the Financial Intelligence Centre Act (FICA), and applicable South African financial regulations.

2. Data We Hold & Retention Periods

Data Category What It Includes Retention Period Reason
Worker Identity Data Name, ID number, selfie / liveness check 5 years from account closure FICA / AML legal requirement
Bank Account Details Account number, bank name, PayShap proxy Duration of account + 5 years Settlement records and audit
Transaction Records Tip amounts, timestamps, payment references 5 years from transaction date FICA / NPS Act requirements
Contact Information Email address, mobile number Duration of account + 1 year Account management and support
Technical Logs IP addresses, session data, device info 90 days Security and fraud monitoring
Support Communications Emails and messages sent to Talo Pay 3 years Dispute resolution and compliance
Analytics Data Anonymised usage statistics 24 months Platform improvement (anonymised)

After the applicable retention period, data is securely deleted or anonymised so it can no longer be linked to an individual.

3. How Your Data Is Stored

All personal and transactional data is stored in encrypted cloud environments hosted within or with appropriate protections for transfers outside South Africa. Access is restricted to authorised Talo Pay personnel and contracted service providers who are bound by data processing agreements.

Talo Pay does not store payment card numbers or full bank account credentials in a retrievable format. Banking details are used solely for initiating PayShap settlement and are stored with encryption at rest.

4. Data Protection Measures

Encryption at Rest

All stored personal and financial data is encrypted using industry-standard algorithms.

Encryption in Transit

All data transmitted between your device and Talo Pay uses TLS/HTTPS encryption.

Access Controls

Strict role-based access limits which personnel can view personal information.

Fraud Detection

Automated monitoring flags unusual patterns to protect Workers and Customers.

Audit Logging

All access to personal data is logged and reviewed regularly.

Third-Party Vetting

All service providers handling personal data are assessed for security compliance.

5. Your Rights Over Your Data

In line with POPIA, you may at any time:

Please note that financial transaction records, identity verification data, and records required by FICA cannot be deleted before the legally mandated retention period expires, regardless of a deletion request.

To exercise any of these rights, email info@talopay.co.za. We will acknowledge your request within 3 business days and respond fully within 30 days.

6. Account Closure

When a Worker closes their Talo Pay account, non-essential data (profile photo, preferences, marketing data) is deleted within 30 days. Financial and identity records are retained for the applicable statutory periods set out in the table above, after which they are securely and permanently deleted.

7. Contact

For data access requests, deletion requests, or questions about this policy:
Information Officer โ€” Talo Pay (Pty) Ltd
info@talopay.co.za

If you are unsatisfied with our response, you may lodge a complaint with the Information Regulator of South Africa at www.justice.gov.za/inforeg/.