Privacy Policy
Last updated: 29/07/2026
This Privacy Policy explains how PayZap (Pty) Ltd (“PayZap”, “we”, “us”) collects, uses, shares and protects personal information when you use the PayZap platform and websites (the “Service”). We handle personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).
This Policy should be read with our Terms of Service.
1. Who we are, and our Information Officer
The responsible party is PayZap (Pty) Ltd, a company incorporated in the Republic of South Africa.
- Company registration number: 2022/308952/07
- Registered address: Johannesburg, South Africa
- Information Officer: [Information Officer name — to be completed]
- Information Officer contact: hello@payzap.co.za
Address any privacy question, data subject request or complaint to the Information Officer at the address above.
2. Information we collect about you (where we are the responsible party)
Account and organisation details you give us:
- Your name and email address, the role you hold in an organisation, and which organisations you belong to.
- Your organisation’s name and type, and what brought you to PayZap if you answer that question during onboarding.
- Billing details — billing name, VAT number, address, city, province, postal code and country — and the email addresses you nominate to receive billing mail.
- Optionally, a WhatsApp number for your own account, which we store encrypted and verify by one-time code.
- Support tickets, their attachments, feature requests, votes and any feedback you submit.
Information generated as you use the Service:
- Activity and audit records — who changed what and when, including invoice history, supplier banking-detail changes, approval decisions and organisation-level activity logs.
- The IP address of a person who approves or declines a payment approval, recorded on that decision as evidence of who authorised it.
- Wallet and billing records — credit purchases, deductions, expiries and subscription payments.
- Delivery records for the emails we send you, including whether a message was delivered, opened, clicked, bounced or reported as spam. We use this to tell whether important service mail is reaching you and to stop sending to dead addresses.
- Technical log data needed to operate and secure the Service and to investigate faults and abuse.
Cookies and similar technologies:
- Strictly necessary cookies that keep you signed in, remember which organisation you are working in, and protect forms against automated abuse.
- Preference cookies and local browser storage that remember interface choices such as whether the sidebar is collapsed.
- We do not use advertising cookies, and we run no analytics, behavioural-tracking or advertising scripts on the Service or our website.
3. Information you upload about other people (where we are your operator)
When you use PayZap you upload personal information about people who are not our customers. We process it only to provide the Service to you, only on your instructions, and never for our own purposes. You remain the responsible party for it.
- Suppliers and beneficiaries — name, bank name, account number, branch code, account type, payment references, contact email or domain, and any proof-of-banking or supporting documents attached to them.
- Invoices and documents — the invoices, receipts, statements and supporting files submitted through your account, whether you upload them, import them from a connected inbox, receive them through a supplier submission link, or an employee attaches one to an expense claim, together with the data extracted from them.
- Employees, where you use WhatsApp payslip delivery — employee number, WhatsApp number, chosen language, and their consent and verification status.
- Expense claimants — their banking details, the receipts they submit, and the approval trail for each claim.
- Approvers — the email address, decision, any comment, and the IP address recorded against each approval decision.
4. Why we process personal information, and our lawful basis
| Purpose | Lawful basis under POPIA |
|---|---|
| Providing the Service — scanning invoices, capturing and verifying beneficiary details, generating payment files, running approval workflows and delivering payslips. | Necessary to perform our contract with you (section 11(2)(b)); for data you upload about others, processing on your instruction as your operator. |
| Detecting and warning about changed banking details and potential payment fraud. | Our legitimate interests and yours in preventing fraud (section 11(1)(f)). |
| Taking payment for subscriptions and Credits, and issuing tax invoices. | Necessary to perform our contract, and to comply with tax and accounting law (section 11(1)(c)). |
| Sending service, billing, security and approval communications. | Necessary to perform our contract with you. |
| Securing, monitoring and troubleshooting the Service, and keeping audit logs. | Our legitimate interests in operating a secure service, and compliance with our security obligations under section 19. |
| Employee WhatsApp payslip delivery. | Consent — the employee must actively accept before any payslip is sent, and can decline or stop at any time (section 11(1)(a)). |
| Re-engagement email to an existing customer’s own administrators. | Our legitimate interests, subject to the opt-out described in section 10. |
| Complying with legal obligations and establishing or defending legal claims. | Sections 11(1)(c) and 11(1)(d). |
We do not sell personal information, we do not share it for third-party advertising, and we do not profile data subjects.
5. Automated processing and AI
Parts of the Service work by sending content to a third-party AI provider that processes it on our behalf and returns structured data to us. This is how document scanning works, and the feature cannot be provided without it. This AI provider is engaged as an operator under written terms.
What is sent, and when:
- Invoices and receipts submitted for scanning. Where a PDF has a readable text layer we send only the text we extract from it locally; otherwise, and for scanned documents and photographs, we send the document file itself. Either way we send at most the first five pages.
- Supplier statements uploaded for reconciliation — the statement file itself, up to the first eight pages, so the transaction lines can be read.
- Proof-of-banking documents, such as bank confirmation letters, that a supplier attaches when responding to a bank-detail verification request.
- For the AI assistant — your questions and the conversation, together with a summary of your workspace figures: your organisation name, wallet balance, invoice and supplier counts, and batch and payment totals. Your stored supplier records and bank account numbers are not included in that summary.
- Text you submit in a support ticket or feature request, where we use AI to help triage and respond.
How we use this content. Content is sent to the AI provider to return a result to you, such as extracted fields, a reconciliation match, or an answer in the assistant. We may also use Customer Data — including content processed by the AI provider — to improve the Service and to train and refine our own extraction and processing models, for example to make document scanning more accurate over time. It is not used for profiling, marketing or advertising, and we do not sell it. We contract with our AI provider on terms that do not permit it to use your Customer Data to train its own underlying models.
Human review. Automated outputs are suggestions that you review and correct. We do not make decisions with legal or similarly significant effects about a data subject based solely on automated processing, and no payment leaves your bank without a person in your organisation reviewing and authorising it.
This AI processing takes place outside South Africa — see Cross-border transfers in section 8.
6. Google user data (Gmail integration)
Connecting your Gmail account to PayZap is optional. If you connect it, PayZap requests read-only access to your Gmail messages and their attachments via Google’s OAuth 2.0 authorisation, for a single purpose: to detect supplier invoice attachments in your inbox and import them into your PayZap invoice queue for review.
- Read-only access to Gmail messages and attachments (the googleapis.com/auth/gmail.readonly scope), used only to identify and retrieve invoice attachments.
- We never send email on your behalf, and never modify or delete anything in your mailbox.
- Your Google OAuth access and refresh tokens are encrypted at rest and used only to perform the invoice scans you have enabled.
- Only the invoice documents we detect are imported into your account; we do not retain the content of emails that are not invoices.
- We do not sell Google user data, do not use it for advertising, and do not use it to develop, improve or train generalised AI or machine-learning models.
- We do not allow humans to read your Google user data except with your explicit consent, where necessary for security or to investigate abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
- You can disconnect Gmail at any time from Settings, which revokes PayZap’s access and stops all further scanning.
Separately, you may choose to sign in with Google, in which case Google confirms your identity and gives us your email address and basic profile details. We also use Google’s address-lookup service to offer suggestions when you type a billing address.
7. Who we share information with (operators and recipients)
We share personal information only as needed to run the Service, with operators bound by written confidentiality, security and data-protection terms. They are:
| Operator | What it does for us | Where it processes |
|---|---|---|
| Supabase | Database, authentication and file storage — the primary store for your account, supplier, invoice and document data. | South Africa (Cape Town region) |
| Vercel | Hosts and runs the web application and its scheduled jobs. All server-side processing of your data happens here. | European Union (Frankfurt region) |
| Railway | Runs the background worker that delivers payslips and synchronises payroll data. | Outside South Africa |
| AI provider | AI reading of invoices, receipts, statements and proof-of-banking documents, and the AI assistant. See section 5. | Outside South Africa |
| Meta Platforms (WhatsApp Business Platform) | Delivers payslips and consent messages to employee WhatsApp numbers, where you use that feature. | Outside South Africa |
| Resend | Sends our outbound email and receives invoices sent to your PayZap inbox address. | Outside South Africa |
| Postmark | Receives inbound payslip email for organisations still using the legacy email-ingestion mode. | Outside South Africa |
| Upstash | Redis caching, rate limiting and background job queueing. | Outside South Africa |
| Paystack | Processes subscription and Credit payments. Receives your billing email and the amount; we never send it supplier or employee data. | Outside South Africa |
| Optional Gmail invoice import, optional Google sign-in, and billing-address lookup. See section 6. | Outside South Africa | |
| Cloudflare | Bot and abuse protection on public forms, password reset and support requests. Receives the visitor’s IP address. | Outside South Africa |
| goQR.me | Renders the QR code shown when you set up two-factor authentication. | Outside South Africa |
| SimplePay | Your own payroll provider, where you connect it — we read employee and pay-run data and fetch payslips to deliver. | Outside South Africa |
Where you connect a further integration yourself, such as accounting software, data flows to it only because you chose to connect it, and its own terms govern what it then does.
Each operator is engaged under written terms requiring it to process personal information only on our instructions, keep it confidential and apply appropriate security measures. We remain accountable to you for their processing. Where we add or replace an operator in a way that materially changes how personal information is processed, we will update this Policy and take reasonable steps to notify you.
We may also disclose information where required by law, to protect our rights or safety or those of others, or in connection with a corporate transaction such as a merger or sale of assets, subject to this Policy.
8. Cross-border transfers (POPIA section 72)
As the table in section 7 shows, most of our operators process personal information outside South Africa. In particular, the application itself runs in the European Union, and the AI provider that reads your documents, our email infrastructure, our messaging provider, our payment processor and our background worker all operate outside the country.
This means content from the invoices, receipts, statements and proof-of-banking documents submitted through your account — including supplier and employee names and banking details — is transmitted outside South Africa to be processed. Employee WhatsApp numbers and payslip documents are transmitted outside South Africa in order to be delivered.
Section 72 of POPIA permits a transfer of this kind on several grounds. We rely principally on written agreements binding each recipient to uphold principles of lawful processing substantially similar to those in POPIA, and on the transfer being necessary to perform the contract between us and to deliver the Service you have asked for. Where the transfer is for the benefit of a data subject who is not a party to that contract — a supplier or an employee — it is made at your instruction as the responsible party, and on terms that are for their benefit and which they would be reasonably likely to consent to. We transfer only what is needed for the purpose, and we do not authorise onward transfer except on equivalent terms.
You can ask us at any time for reasonable information about our operators and where they process data.
9. Security safeguards (POPIA section 19)
We maintain appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unlawful access and unlawful processing. These include:
- Encryption in transit using TLS, and AES-256-GCM encryption at rest for the most sensitive fields — bank account numbers, employee numbers, WhatsApp and phone numbers, payroll API keys, and the access tokens for any inbox or accounting integration you connect.
- Encrypting those values everywhere they land, including inside extracted-data records and audit tables, so that column-level encryption is not defeated by a database dump.
- Masking account numbers to their last digits wherever they are displayed, except on a payment review screen, where the reviewer must be able to check the full number they are about to pay.
- Authentication managed by a dedicated provider, with optional two-factor authentication, single-use hashed backup codes, and a server-side check on every request that a two-factor account has actually satisfied its second factor.
- Role-based access control, so a user only reaches the parts of the Service their role allows, enforced in the interface and independently on every API route.
- Time-limited signed links for document access, which expire by default one hour after they are issued.
- Cryptographic signature verification with constant-time comparison on every inbound webhook, and rate limiting and bot protection on public and authentication endpoints.
- Audit logging of sensitive changes — supplier banking-detail changes, approval decisions, invoice history and organisation activity.
- Masking of phone numbers and employee numbers in application logs, so sensitive values are never written to a log.
We do not currently hold a formal information-security certification such as ISO/IEC 27001 or a SOC 2 report, and this Policy should not be read as claiming one.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.
10. Direct marketing and electronic communications (POPIA section 69)
Almost everything PayZap sends is service or transactional communication — approval requests, delivery results, security notices, tax invoices, billing reminders and account notifications. We do not send unsolicited electronic marketing. We do not buy, rent or use third-party marketing lists, and we do not market to people who are not already our customers.
The only promotional message we send is an occasional re-engagement email to the administrators of an existing customer organisation that has stopped using the Service. It goes to their own registered account address, is sent at most once per organisation, and is switched off the moment it is opted out of.
How to control what you receive:
- Every email that belongs to an opt-out category carries a one-click unsubscribe that your email client can action directly, without you signing in.
- You can also switch categories on or off at any time in Settings → Account → Email notifications. The categories are Product updates, Billing and payments, Account security, Tips and best practices, Marketing, Approval notifications, and the daily invoice summary.
- Opting out is recorded against your email address and applies to every organisation you belong to.
Employees receiving payslips by WhatsApp. No payslip is ever sent to an unverified number. Before anything is delivered, the employee is asked to accept, in a language they choose, and they can decline. An employee who declines or stops is blocked from further messages immediately. These messages are transactional and are never used to market anything.
11. Retention
We keep personal information for as long as the account is active and as needed to provide the Service, and thereafter only as long as necessary for legal, accounting, tax or audit obligations, to resolve disputes, and to enforce our agreements. The specific periods we apply are:
| Data | What happens |
|---|---|
| Invoices, receipts and supporting documents you upload | Kept until you delete them or the account is closed. We do not automatically delete stored documents to free up space. |
| Items you dismiss from an invoice inbox or submission feed | Permanently deleted, together with the stored file, 30 days after you dismiss them. |
| Incomplete or abandoned uploads | Temporary files are deleted 24 hours after upload. |
| Demo data | Deleted automatically about two hours after the demo. |
| Prepaid, add-on and signup Credits | Expire 12 months after they are granted. Subscription Credit allowances expire at the end of each billing period. |
| Invitations, approval links and supplier verification links | Stop working on expiry — 7 days for an organisation invitation and a supplier bank-verification link, 14 days for an approval link, 30 days for a claimant banking-change request, and 90 days for a shared batch audit link. |
| Inactive organisations | After 120 days without activity we send a warning, then a final notice, and then begin closing the account and deleting its stored documents. |
| Financial and audit records | Kept for as long as the law requires us to keep accounting records, and generally not deleted. This includes the wallet and payment ledger, organisation activity logs, supplier banking-change audit trails, approval decisions and invoice history. |
| Suppliers with payment history | Archived rather than deleted, so the payment record they belong to stays intact and auditable. |
We have not yet defined a fixed purge period for employee records held for WhatsApp payslip delivery. Until we do, that data stays for as long as the employer keeps the employee on their PayZap account, and the employer can delete it.
12. Your rights as a data subject
Subject to applicable law, you have the right to:
- ask whether we hold personal information about you, and request access to it;
- request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- object, on reasonable grounds, to processing based on our legitimate interests;
- object at any time to the use of your information for direct marketing, and to withdraw consent where processing is based on consent, without affecting processing already carried out;
- not have a decision with legal or similarly significant consequences made about you based solely on automated processing;
- complain to the Information Regulator, as described in section 13.
To exercise any of these rights, contact our Information Officer at hello@payzap.co.za. We will ask you for enough information to verify your identity, and we will respond within the period POPIA requires. POPIA allows the Regulator to prescribe a fee for an access request, and we will tell you before any fee applies.
Requests are handled by our team, not by a self-service button. There is currently no button in the Service that deletes an account, so please send deletion requests to the address above. Where a record must be kept for the reasons in section 11, we will tell you what we are retaining and why, and we will restrict its use rather than keep it in active service.
13. Complaints — Information Regulator of South Africa
You have the right to complain to the Information Regulator (South Africa).
- Post: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
- Complaints: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Website: inforegulator.org.za
We would appreciate the chance to address your concern first, so please consider contacting our Information Officer before lodging a complaint.
14. Children
The Service is intended for use by businesses and is not directed at children. We do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact us so we can remove it.
15. Security compromises (POPIA section 22)
If a security compromise affecting personal information occurs, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after establishing the extent of the compromise, as section 22 requires. Where we are your operator, we will notify you without undue delay so you can meet your own notification obligations.
16. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you. The “Last updated” date above shows when this Policy was last revised. Continued use of the Service after changes take effect means you accept the updated Policy.
17. Contact us
For any privacy question, data subject request or complaint, contact our Information Officer at hello@payzap.co.za.
PayZap (Pty) Ltd, Johannesburg, South Africa, South Africa.