1. Who we are
SWIPE.co.za is a trading identity operated by Hippo Bay in South Africa. In this notice, “SWIPE”, “we”, “us” and “our” refer to that operator.
Contact our privacy function at privacy@swipe.co.za. General support requests should go to support@swipe.co.za.
2. When SWIPE is responsible
SWIPE acts as a responsible party for personal information used for this public website, sales, customer administration, security, communications, support, billing and our own legal obligations.
For merchant staff, customer and transaction information processed through the retail product, the merchant may determine why and how that information is processed. In that situation, SWIPE generally acts as the merchant's operator under the applicable service agreement. Requests about a merchant's customer or staff record may need to be directed to that merchant.
3. Information we process
Depending on how you interact with us, this may include:
- identity and contact details, including name, telephone number, email address and organization;
- tenant, company, store, role, user and device-assignment information;
- authentication, device-enrollment and security event information;
- support cases, fault reports, messages, notes and attachments you choose to provide;
- commercial, billing, payment and account-administration records;
- website and service technical records such as IP address, browser, request time, correlation reference and security logs;
- retail records processed for a merchant, which may include customer, sale, account, receipt and approval information;
- communications preferences and proof of consent or opt-out.
Do not send passwords, manager PINs, API tokens, unnecessary identity documents or full payment-card details through public contact channels.
4. Where it comes from
We collect information directly from you, from the merchant or organization that assigned your account, from the SWIPE applications and devices you use, from authorized integration providers, and from public or lawful business records when needed for onboarding, security or compliance.
5. Why we process it
- to provide, secure, support and improve the SWIPE service;
- to create and administer tenants, companies, stores, Tills, users, roles and trusted devices;
- to process retail instructions and keep operational and audit evidence;
- to respond to sales, support, privacy and security requests;
- to deliver requested transactional, security and operational communications;
- to bill, reconcile, prevent fraud, investigate incidents and enforce agreements;
- to comply with legal, regulatory, tax, accounting and recordkeeping duties;
- to perform limited analytics needed to understand reliability and service use.
6. Lawful processing
We process information where it is necessary to perform or prepare a contract, comply with law, protect a legitimate interest that does not override your rights, protect a legitimate interest of a merchant or another person, or where you have given consent. We keep direct marketing separate from necessary security, service and transaction messages.
7. Who receives information
We may share information with the merchant or organization responsible for your account, authorized SWIPE staff, vetted hosting and technology operators, communications providers, professional advisers, payment or service providers involved in the requested workflow, and authorities where disclosure is lawful and necessary. We do not sell personal information.
Operators may process only the information required for their service and must be subject to appropriate confidentiality, security and data-protection terms.
8. Processing outside South Africa
Some technology or communications providers may process information in other countries. Before relying on such processing, SWIPE must assess the destination and provider and use the safeguards required by POPIA, including an adequate legal basis, contract or consent where applicable.
9. How long we keep it
We retain information only for as long as the operating purpose, contract, security requirement or applicable law requires. Retention differs by record type. Financial, tax, transaction, security and audit records may be kept after account closure where law, dispute handling, fraud prevention or ledger integrity requires it. When retention ends, we delete, destroy or de-identify the information through a controlled process.
10. Security
We use layered administrative and technical controls appropriate to the information and risk. These include scoped access, authentication, secret separation, event logging, encrypted transport, service boundaries, backups and incident procedures. No connected service can promise absolute security. Report a suspected vulnerability through our security page.
11. Your choices and rights
Subject to POPIA and other applicable law, you may ask whether we hold your personal information; request access, correction or deletion; object to certain processing; withdraw consent; ask us to restrict direct marketing; or complain about our handling of your information. We may need to verify your identity and authority before acting.
Use the data deletion and privacy request process. We will explain when a request must be handled by the relevant merchant or when a lawful retention duty prevents immediate deletion.
12. Automation and AI assistance
SWIPE may use rules and AI-assisted tools to normalize supplier information, suggest mappings, classify requests or support an operator. Important actions remain subject to validation and the permissions of an authorized user. We do not describe an assistive suggestion as a final legal or financial decision.
13. Children
The public website and business service are not directed at children. Merchants must not use SWIPE to process children's personal information unless they have a lawful purpose, the required authority and suitable controls.
14. Changes to this notice
We will publish material changes on this page, update the effective date and use an appropriate communication where the change significantly affects existing users.
15. Complaints
Please contact us first so we can investigate. You may also contact South Africa's Information Regulator through its official website. The Regulator currently publishes contact and complaint channels for POPIA and PAIA matters.
