Privacy Policy

Last updated: 29/07/2026

This Privacy Policy explains how PayZap (Pty) Ltd (“PayZap”, “we”, “us”) collects, uses, shares and protects personal information when you use the PayZap platform and websites (the “Service”). We handle personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

We act in two different capacities, and POPIA treats them differently. For your own account information — who you are, your organisation, your billing details — we are the responsible party and this Policy is our notice to you. For the data you upload about other people — your suppliers, your employees and your expense claimants — you are the responsible party and we are your operator, processing it on your behalf and on your instructions only. Sections 3 and 12 explain what that split means in practice.

This Policy should be read with our Terms of Service.

1. Who we are, and our Information Officer

The responsible party is PayZap (Pty) Ltd, a company incorporated in the Republic of South Africa.

  • Company registration number: 2022/308952/07
  • Registered address: Johannesburg, South Africa
  • Information Officer: [Information Officer name — to be completed]
  • Information Officer contact: hello@payzap.co.za

Address any privacy question, data subject request or complaint to the Information Officer at the address above.

2. Information we collect about you (where we are the responsible party)

Account and organisation details you give us:

  • Your name and email address, the role you hold in an organisation, and which organisations you belong to.
  • Your organisation’s name and type, and what brought you to PayZap if you answer that question during onboarding.
  • Billing details — billing name, VAT number, address, city, province, postal code and country — and the email addresses you nominate to receive billing mail.
  • Optionally, a WhatsApp number for your own account, which we store encrypted and verify by one-time code.
  • Support tickets, their attachments, feature requests, votes and any feedback you submit.

Information generated as you use the Service:

  • Activity and audit records — who changed what and when, including invoice history, supplier banking-detail changes, approval decisions and organisation-level activity logs.
  • The IP address of a person who approves or declines a payment approval, recorded on that decision as evidence of who authorised it.
  • Wallet and billing records — credit purchases, deductions, expiries and subscription payments.
  • Delivery records for the emails we send you, including whether a message was delivered, opened, clicked, bounced or reported as spam. We use this to tell whether important service mail is reaching you and to stop sending to dead addresses.
  • Technical log data needed to operate and secure the Service and to investigate faults and abuse.

Cookies and similar technologies:

  • Strictly necessary cookies that keep you signed in, remember which organisation you are working in, and protect forms against automated abuse.
  • Preference cookies and local browser storage that remember interface choices such as whether the sidebar is collapsed.
  • We do not use advertising cookies, and we run no analytics, behavioural-tracking or advertising scripts on the Service or our website.
What we never store. We do not store your password — authentication is handled by our authentication provider, and a password never reaches our database. We do not store your full card number — that is held by our payment processor, and we keep only a token, the card type and its last digits. We do not store South African ID or passport numbers: during employee identity verification the number submitted is compared in memory against the value already held in your payroll system, using a constant-time comparison, and is discarded immediately without ever being written to a database, a log or an error message. We do not store payslip PDFs anywhere — they are streamed from your payroll provider to the recipient and the buffer is released straight afterwards. For invoices that arrive by email, we record only the sender’s domain, not the full sender address.

3. Information you upload about other people (where we are your operator)

When you use PayZap you upload personal information about people who are not our customers. We process it only to provide the Service to you, only on your instructions, and never for our own purposes. You remain the responsible party for it.

  • Suppliers and beneficiaries — name, bank name, account number, branch code, account type, payment references, contact email or domain, and any proof-of-banking or supporting documents attached to them.
  • Invoices and documents — the invoices, receipts, statements and supporting files submitted through your account, whether you upload them, import them from a connected inbox, receive them through a supplier submission link, or an employee attaches one to an expense claim, together with the data extracted from them.
  • Employees, where you use WhatsApp payslip delivery — employee number, WhatsApp number, chosen language, and their consent and verification status.
  • Expense claimants — their banking details, the receipts they submit, and the approval trail for each claim.
  • Approvers — the email address, decision, any comment, and the IP address recorded against each approval decision.
Your obligations as the responsible party. You must have a lawful basis for giving us this information and must give those data subjects the notices POPIA requires — including that an operator and its sub-processors will process their information, and that some of that processing happens outside South Africa (section 8). We will give you reasonable assistance and reasonable information about our operators so you can meet those obligations.

4. Why we process personal information, and our lawful basis

PurposeLawful basis under POPIA
Providing the Service — scanning invoices, capturing and verifying beneficiary details, generating payment files, running approval workflows and delivering payslips.Necessary to perform our contract with you (section 11(2)(b)); for data you upload about others, processing on your instruction as your operator.
Detecting and warning about changed banking details and potential payment fraud.Our legitimate interests and yours in preventing fraud (section 11(1)(f)).
Taking payment for subscriptions and Credits, and issuing tax invoices.Necessary to perform our contract, and to comply with tax and accounting law (section 11(1)(c)).
Sending service, billing, security and approval communications.Necessary to perform our contract with you.
Securing, monitoring and troubleshooting the Service, and keeping audit logs.Our legitimate interests in operating a secure service, and compliance with our security obligations under section 19.
Employee WhatsApp payslip delivery.Consent — the employee must actively accept before any payslip is sent, and can decline or stop at any time (section 11(1)(a)).
Re-engagement email to an existing customer’s own administrators.Our legitimate interests, subject to the opt-out described in section 10.
Complying with legal obligations and establishing or defending legal claims.Sections 11(1)(c) and 11(1)(d).

We do not sell personal information, we do not share it for third-party advertising, and we do not profile data subjects.

5. Automated processing and AI

Parts of the Service work by sending content to a third-party AI provider that processes it on our behalf and returns structured data to us. This is how document scanning works, and the feature cannot be provided without it. This AI provider is engaged as an operator under written terms.

What is sent, and when:

  • Invoices and receipts submitted for scanning. Where a PDF has a readable text layer we send only the text we extract from it locally; otherwise, and for scanned documents and photographs, we send the document file itself. Either way we send at most the first five pages.
  • Supplier statements uploaded for reconciliation — the statement file itself, up to the first eight pages, so the transaction lines can be read.
  • Proof-of-banking documents, such as bank confirmation letters, that a supplier attaches when responding to a bank-detail verification request.
  • For the AI assistant — your questions and the conversation, together with a summary of your workspace figures: your organisation name, wallet balance, invoice and supplier counts, and batch and payment totals. Your stored supplier records and bank account numbers are not included in that summary.
  • Text you submit in a support ticket or feature request, where we use AI to help triage and respond.
This content includes banking details. A supplier invoice or bank confirmation letter normally carries the supplier’s name, bank name, account number, branch code, amounts and references, and an expense receipt may carry an employee’s name. Whatever appears on the document forms part of what is sent to be read. Where the document is sent as a file rather than as text, the whole page image is sent, including anything else printed on it.

How we use this content. Content is sent to the AI provider to return a result to you, such as extracted fields, a reconciliation match, or an answer in the assistant. We may also use Customer Data — including content processed by the AI provider — to improve the Service and to train and refine our own extraction and processing models, for example to make document scanning more accurate over time. It is not used for profiling, marketing or advertising, and we do not sell it. We contract with our AI provider on terms that do not permit it to use your Customer Data to train its own underlying models.

Human review. Automated outputs are suggestions that you review and correct. We do not make decisions with legal or similarly significant effects about a data subject based solely on automated processing, and no payment leaves your bank without a person in your organisation reviewing and authorising it.

This AI processing takes place outside South Africa — see Cross-border transfers in section 8.

6. Google user data (Gmail integration)

Connecting your Gmail account to PayZap is optional. If you connect it, PayZap requests read-only access to your Gmail messages and their attachments via Google’s OAuth 2.0 authorisation, for a single purpose: to detect supplier invoice attachments in your inbox and import them into your PayZap invoice queue for review.

  • Read-only access to Gmail messages and attachments (the googleapis.com/auth/gmail.readonly scope), used only to identify and retrieve invoice attachments.
  • We never send email on your behalf, and never modify or delete anything in your mailbox.
  • Your Google OAuth access and refresh tokens are encrypted at rest and used only to perform the invoice scans you have enabled.
  • Only the invoice documents we detect are imported into your account; we do not retain the content of emails that are not invoices.
  • We do not sell Google user data, do not use it for advertising, and do not use it to develop, improve or train generalised AI or machine-learning models.
  • We do not allow humans to read your Google user data except with your explicit consent, where necessary for security or to investigate abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
  • You can disconnect Gmail at any time from Settings, which revokes PayZap’s access and stops all further scanning.

Separately, you may choose to sign in with Google, in which case Google confirms your identity and gives us your email address and basic profile details. We also use Google’s address-lookup service to offer suggestions when you type a billing address.

Limited Use. PayZap’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

7. Who we share information with (operators and recipients)

We share personal information only as needed to run the Service, with operators bound by written confidentiality, security and data-protection terms. They are:

OperatorWhat it does for usWhere it processes
SupabaseDatabase, authentication and file storage — the primary store for your account, supplier, invoice and document data.South Africa (Cape Town region)
VercelHosts and runs the web application and its scheduled jobs. All server-side processing of your data happens here.European Union (Frankfurt region)
RailwayRuns the background worker that delivers payslips and synchronises payroll data.Outside South Africa
AI providerAI reading of invoices, receipts, statements and proof-of-banking documents, and the AI assistant. See section 5.Outside South Africa
Meta Platforms (WhatsApp Business Platform)Delivers payslips and consent messages to employee WhatsApp numbers, where you use that feature.Outside South Africa
ResendSends our outbound email and receives invoices sent to your PayZap inbox address.Outside South Africa
PostmarkReceives inbound payslip email for organisations still using the legacy email-ingestion mode.Outside South Africa
UpstashRedis caching, rate limiting and background job queueing.Outside South Africa
PaystackProcesses subscription and Credit payments. Receives your billing email and the amount; we never send it supplier or employee data.Outside South Africa
GoogleOptional Gmail invoice import, optional Google sign-in, and billing-address lookup. See section 6.Outside South Africa
CloudflareBot and abuse protection on public forms, password reset and support requests. Receives the visitor’s IP address.Outside South Africa
goQR.meRenders the QR code shown when you set up two-factor authentication.Outside South Africa
SimplePayYour own payroll provider, where you connect it — we read employee and pay-run data and fetch payslips to deliver.Outside South Africa

Where you connect a further integration yourself, such as accounting software, data flows to it only because you chose to connect it, and its own terms govern what it then does.

Each operator is engaged under written terms requiring it to process personal information only on our instructions, keep it confidential and apply appropriate security measures. We remain accountable to you for their processing. Where we add or replace an operator in a way that materially changes how personal information is processed, we will update this Policy and take reasonable steps to notify you.

We may also disclose information where required by law, to protect our rights or safety or those of others, or in connection with a corporate transaction such as a merger or sale of assets, subject to this Policy.

8. Cross-border transfers (POPIA section 72)

As the table in section 7 shows, most of our operators process personal information outside South Africa. In particular, the application itself runs in the European Union, and the AI provider that reads your documents, our email infrastructure, our messaging provider, our payment processor and our background worker all operate outside the country.

This means content from the invoices, receipts, statements and proof-of-banking documents submitted through your account — including supplier and employee names and banking details — is transmitted outside South Africa to be processed. Employee WhatsApp numbers and payslip documents are transmitted outside South Africa in order to be delivered.

Section 72 of POPIA permits a transfer of this kind on several grounds. We rely principally on written agreements binding each recipient to uphold principles of lawful processing substantially similar to those in POPIA, and on the transfer being necessary to perform the contract between us and to deliver the Service you have asked for. Where the transfer is for the benefit of a data subject who is not a party to that contract — a supplier or an employee — it is made at your instruction as the responsible party, and on terms that are for their benefit and which they would be reasonably likely to consent to. We transfer only what is needed for the purpose, and we do not authorise onward transfer except on equivalent terms.

You can ask us at any time for reasonable information about our operators and where they process data.

9. Security safeguards (POPIA section 19)

We maintain appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unlawful access and unlawful processing. These include:

  • Encryption in transit using TLS, and AES-256-GCM encryption at rest for the most sensitive fields — bank account numbers, employee numbers, WhatsApp and phone numbers, payroll API keys, and the access tokens for any inbox or accounting integration you connect.
  • Encrypting those values everywhere they land, including inside extracted-data records and audit tables, so that column-level encryption is not defeated by a database dump.
  • Masking account numbers to their last digits wherever they are displayed, except on a payment review screen, where the reviewer must be able to check the full number they are about to pay.
  • Authentication managed by a dedicated provider, with optional two-factor authentication, single-use hashed backup codes, and a server-side check on every request that a two-factor account has actually satisfied its second factor.
  • Role-based access control, so a user only reaches the parts of the Service their role allows, enforced in the interface and independently on every API route.
  • Time-limited signed links for document access, which expire by default one hour after they are issued.
  • Cryptographic signature verification with constant-time comparison on every inbound webhook, and rate limiting and bot protection on public and authentication endpoints.
  • Audit logging of sensitive changes — supplier banking-detail changes, approval decisions, invoice history and organisation activity.
  • Masking of phone numbers and employee numbers in application logs, so sensitive values are never written to a log.

We do not currently hold a formal information-security certification such as ISO/IEC 27001 or a SOC 2 report, and this Policy should not be read as claiming one.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.

10. Direct marketing and electronic communications (POPIA section 69)

Almost everything PayZap sends is service or transactional communication — approval requests, delivery results, security notices, tax invoices, billing reminders and account notifications. We do not send unsolicited electronic marketing. We do not buy, rent or use third-party marketing lists, and we do not market to people who are not already our customers.

The only promotional message we send is an occasional re-engagement email to the administrators of an existing customer organisation that has stopped using the Service. It goes to their own registered account address, is sent at most once per organisation, and is switched off the moment it is opted out of.

How to control what you receive:

  • Every email that belongs to an opt-out category carries a one-click unsubscribe that your email client can action directly, without you signing in.
  • You can also switch categories on or off at any time in Settings → Account → Email notifications. The categories are Product updates, Billing and payments, Account security, Tips and best practices, Marketing, Approval notifications, and the daily invoice summary.
  • Opting out is recorded against your email address and applies to every organisation you belong to.
Some messages cannot be switched off. Essential communications are not marketing and have no opt-out: tax invoices and payment receipts, password resets and account-security mail, organisation invitations, notices that your own access or permissions have changed, supplier bank-verification requests, and subscription lifecycle notices. If you no longer want these, close your account.

Employees receiving payslips by WhatsApp. No payslip is ever sent to an unverified number. Before anything is delivered, the employee is asked to accept, in a language they choose, and they can decline. An employee who declines or stops is blocked from further messages immediately. These messages are transactional and are never used to market anything.

11. Retention

We keep personal information for as long as the account is active and as needed to provide the Service, and thereafter only as long as necessary for legal, accounting, tax or audit obligations, to resolve disputes, and to enforce our agreements. The specific periods we apply are:

DataWhat happens
Invoices, receipts and supporting documents you uploadKept until you delete them or the account is closed. We do not automatically delete stored documents to free up space.
Items you dismiss from an invoice inbox or submission feedPermanently deleted, together with the stored file, 30 days after you dismiss them.
Incomplete or abandoned uploadsTemporary files are deleted 24 hours after upload.
Demo dataDeleted automatically about two hours after the demo.
Prepaid, add-on and signup CreditsExpire 12 months after they are granted. Subscription Credit allowances expire at the end of each billing period.
Invitations, approval links and supplier verification linksStop working on expiry — 7 days for an organisation invitation and a supplier bank-verification link, 14 days for an approval link, 30 days for a claimant banking-change request, and 90 days for a shared batch audit link.
Inactive organisationsAfter 120 days without activity we send a warning, then a final notice, and then begin closing the account and deleting its stored documents.
Financial and audit recordsKept for as long as the law requires us to keep accounting records, and generally not deleted. This includes the wallet and payment ledger, organisation activity logs, supplier banking-change audit trails, approval decisions and invoice history.
Suppliers with payment historyArchived rather than deleted, so the payment record they belong to stays intact and auditable.
Some records deliberately survive a deletion request. Financial and audit records are how a payment can later be proved, reconciled or investigated, so an account that has approved payments, exported a payment file or changed supplier banking details cannot simply be erased. In that case we revoke access instead, and we retain the audit trail. Section 12 explains how this affects a deletion request.

We have not yet defined a fixed purge period for employee records held for WhatsApp payslip delivery. Until we do, that data stays for as long as the employer keeps the employee on their PayZap account, and the employer can delete it.

12. Your rights as a data subject

Subject to applicable law, you have the right to:

  • ask whether we hold personal information about you, and request access to it;
  • request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
  • object, on reasonable grounds, to processing based on our legitimate interests;
  • object at any time to the use of your information for direct marketing, and to withdraw consent where processing is based on consent, without affecting processing already carried out;
  • not have a decision with legal or similarly significant consequences made about you based solely on automated processing;
  • complain to the Information Regulator, as described in section 13.

To exercise any of these rights, contact our Information Officer at hello@payzap.co.za. We will ask you for enough information to verify your identity, and we will respond within the period POPIA requires. POPIA allows the Regulator to prescribe a fee for an access request, and we will tell you before any fee applies.

Requests are handled by our team, not by a self-service button. There is currently no button in the Service that deletes an account, so please send deletion requests to the address above. Where a record must be kept for the reasons in section 11, we will tell you what we are retaining and why, and we will restrict its use rather than keep it in active service.

If you are a supplier, employee or expense claimant. Your information is in PayZap because a business you deal with put it there, and that business — not PayZap — is the responsible party for it. Please direct your request to them first. If you contact us instead, we will pass it to them and assist them in responding, as their operator.

13. Complaints — Information Regulator of South Africa

You have the right to complain to the Information Regulator (South Africa).

We would appreciate the chance to address your concern first, so please consider contacting our Information Officer before lodging a complaint.

14. Children

The Service is intended for use by businesses and is not directed at children. We do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact us so we can remove it.

15. Security compromises (POPIA section 22)

If a security compromise affecting personal information occurs, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after establishing the extent of the compromise, as section 22 requires. Where we are your operator, we will notify you without undue delay so you can meet your own notification obligations.

16. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you. The “Last updated” date above shows when this Policy was last revised. Continued use of the Service after changes take effect means you accept the updated Policy.

17. Contact us

For any privacy question, data subject request or complaint, contact our Information Officer at hello@payzap.co.za.

PayZap (Pty) Ltd, Johannesburg, South Africa, South Africa.