1. Start the request
Email privacy@swipe.co.za with the subject “SWIPE privacy request”. State whether you want access, correction, objection, restriction, consent withdrawal, communication opt-out or deletion.
Include your name, the contact details we may use to respond, the merchant or organization involved, and enough information to identify the account or interaction. Do not email passwords, manager PINs, API tokens or full payment-card details.
2. Identity and authority
We must avoid disclosing or deleting information for the wrong person. We may ask for proportionate proof of identity, account control or legal authority. We will not request more identification than the risk requires, and verification material will receive restricted handling and retention.
3. Merchant-controlled information
If the request concerns staff, customer, sale, account or receipt information processed for a SWIPE merchant, that merchant may be the responsible party. We may direct the request to the merchant or assist the merchant as its operator. We will not independently change a merchant record when the merchant is legally responsible for the decision.
4. What deletion means
Where deletion is appropriate, we identify the relevant live systems, communication records and controlled copies; block further ordinary use where necessary; propagate the approved deletion through the responsible services; and record enough evidence to show the request was completed.
Backup copies may age out through the protected backup lifecycle rather than being altered immediately. They remain restricted and must not be restored into ordinary use without the deletion being reapplied.
5. Records we may retain
We may retain information where applicable law, tax and accounting duties, fraud prevention, dispute resolution, security investigations, contractual claims or ledger integrity require it. Where possible, we restrict or de-identify retained information and explain the reason and expected retention basis.
6. Response and outcome
We will acknowledge the request, identify the responsible party, ask for any necessary verification, communicate the decision and provide an outcome reference. Complex or multi-party requests may take longer; we will explain material delays.
7. Meta and social sign-in data
If a Meta or other external account was used only to initiate an integration, include that provider and the relevant account identifier in the request. Deleting data held by SWIPE does not automatically delete data held independently by the external provider; use that provider's own privacy controls as well.
8. Escalation
If you are not satisfied, reply to the outcome so we can review it. You may also use the complaint channels published by South Africa's Information Regulator.
