Zap Privacy Policy
Effective date: 12 August 2026 Last updated: 12 August 2026 Applies to: the Zap mobile application for iOS, and the websites and services operated by ZA Payments (Pty) Ltd.
Read this first
Zap is a payments app. To run it we have to collect more about you than most apps do, partly because the law requires it and partly because moving money safely is not possible anonymously. This policy tells you exactly what we collect, why, who else sees it, how long we keep it, and what you can make us do about it.
Three things are worth knowing up front:
- Your blockchain transactions are public and permanent. We cannot delete them, and neither can anyone else. See clause 8.
- We record how you use the app, including screen recordings with your typed input and images blanked out. You can turn this off. See clause 9.
- If you let Zap look at your phone contacts, your contacts' numbers travel to our servers. We convert them into one way codes within the same request and never store the numbers themselves. See clause 7.
This policy is written to meet section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). Where a clause exists because POPIA requires it, we say so.
1. Who we are
We are the responsible party for your personal information, which is POPIA's term for the organisation that decides why and how your information is used.
| Registered name | ZA Payments (Pty) Ltd |
| Trading as | Zap |
| Company registration number | 2025/911807/07 |
| Physical and registered address | 194 Bancor Avenue, Park Lane West Building, Waterkloof Glen, Pretoria, 0181, South Africa |
| ari@zapzar.co.za | |
| Website | https://zapzar.co.za |
| FIC registration | Accountable institution registered with the Financial Intelligence Centre on 12 August 2026, under reference SHREG-260812-0000141 |
| Information Officer | Arian Hobson, see clause 16 |
Throughout this policy, "Zap", "we", "us" and "our" mean ZA Payments (Pty) Ltd, and "you" means the person using the app.
What Zap is, and is not. Zap provides wallet and payments software. We are not a bank, we are not a registered credit provider, and we are not an authorised financial services provider. Your funds are held in blockchain wallets, not in an account with us. This matters for privacy because it shapes what we hold and what our partners hold: see clause 10.
2. What "personal information" means
POPIA defines personal information very broadly: it is information relating to an identifiable, living natural person (and, where applicable, an identifiable existing juristic person). It includes obvious things like your name, phone number and ID number, and less obvious things like your device identifier, your IP address, your transaction history, and opinions or inferences we form about you.
POPIA also singles out special personal information, which may not be processed at all unless a specific legal ground applies. Two categories of special personal information are relevant to Zap:
- Biometric information, which POPIA defines as a technique of personal identification based on physical, physiological or behavioural characterisation. A facial scan matched against your identity document falls squarely inside this definition.
- Information about criminal behaviour, which we encounter when we screen you against sanctions, politically exposed person and adverse media lists.
Clause 4 deals with both.
3. What we collect, and where it comes from
POPIA section 18(1)(a) requires us to tell you not just what we collect but, where information does not come from you, its source. We have split this section accordingly.
3.1 Information you give us directly
| Category | Specific items | Mandatory or voluntary |
|---|---|---|
| Account identity | First name, last name, email address, mobile phone number | Mandatory. You cannot open an account without them. |
| Public profile | Your ZapTag (username), profile photo, thumbnail, bio, QR code | ZapTag is mandatory. Photo and bio are voluntary. |
| Identity verification | Identity document type and number, date of birth, nationality, a photograph of your identity document, and a selfie or short video used for liveness and face matching | Mandatory before you can transact or use fiat services. See clause 4. |
| Banking details | Bank name, account number, branch code, account type, account holder name, and for international payouts the routing number, sort code, IBAN or BIC | Voluntary, but mandatory if you want to deposit or withdraw to a bank account. |
| Payment content | Amounts, currencies, recipients, payment references and any note or memo you attach to a payment | Mandatory for the transactions you choose to make. |
| Groups and pools | Pool names, descriptions, membership, contribution and withdrawal activity, and approvals you give or withhold | Voluntary. |
| Support correspondence | Anything you send us by email, in-app or on social channels | Voluntary. |
What happens if you do not provide mandatory information. POPIA section 18(1)(e) requires us to spell this out. If you decline to give us the account identity information, we cannot create your account. If you decline identity verification, we can create a limited account but you will not be able to send, receive, deposit or withdraw money. If you decline banking details, you can still use Zap for peer to peer payments but not for bank deposits or withdrawals.
3.2 Information collected automatically from your device
| Category | Specific items |
|---|---|
| Device | Device model, device name, operating system version, app version, a device identifier we generate, and whether you have marked the device as trusted |
| Session and network | IP address, user agent string, login method, session start and last activity times, and the reason a session was ended |
| Security keys | Passkey credential identifiers, public keys, authenticator identifiers (AAGUID), device type and signature counters. We never receive your Face ID or Touch ID data itself: Apple keeps that on your device and only tells the app whether the check passed. |
| Push tokens | Apple Push Notification service device tokens and OneSignal subscription identifiers |
| Approximate location | If you grant location permission during signup, we use your approximate location as a fraud signal. This is optional and the app works without it. We do not track your location in the background and we do not sell location data. |
| Product analytics and session replay | Screen views, feature usage, app launches, login and signup outcomes, wallet operation outcomes, transaction attempts and errors, and screen recordings. See clause 9, which explains this in full. |
| Crash and error data | Stack traces, device state at the time of a crash, and diagnostic breadcrumbs |
3.3 Information we obtain from other people and sources
This is the section POPIA section 18(1)(a) is really aimed at.
| Source | What we receive |
|---|---|
| Identity verification providers | The outcome of your verification, a result code and explanation, the fields extracted from your identity document, a match or mismatch decision, liveness and spoof detection results, and a flag if a duplicate identity was detected |
| Sanctions, PEP and adverse media screening | Whether you appear on any screened list, and the reason for any match |
| Bridge (our fiat partner) | Your verification status with Bridge, virtual account details, deposit and settlement events, and payout account status |
| Blockchain networks and indexers | Confirmed transactions involving your wallet address, balances, token transfers and network fees |
| Other Zap users | If another user has your phone number or email address saved in their phone and chooses to sync their contacts, we receive that number or email. See clause 7, including what this means if you are not a Zap user. |
| Apple | Whether an in-app purchase or subscription is valid, and anonymous install and crash statistics |
4. Special personal information: biometrics and screening
POPIA section 26 prohibits processing biometric information and information about criminal behaviour, unless a ground in section 27 applies. We rely on two grounds, and we want you to understand exactly which one covers what.
4.1 Biometric information
What we do. To verify that you are a real person and that you are the person on the identity document you upload, our verification partner captures a selfie or short video, performs a liveness check to confirm you are physically present and not a photograph or a deepfake, and compares your face against the photograph on your identity document. Our partner may also generate a mathematical representation of your face (a face template).
Our legal ground. We rely on your explicit consent under POPIA section 27(1)(a). We ask for that consent separately, on its own screen, before verification begins. It is not bundled into your acceptance of our Terms of Service, and ticking one does not tick the other. We also rely, as a secondary ground, on section 27(1)(b), because verifying your identity is necessary to comply with our obligations under the Financial Intelligence Centre Act 38 of 2001.
Withdrawing consent. You may withdraw your biometric consent at any time by writing to our Information Officer. Withdrawal is not retrospective: it does not undo verification that has already happened, and we may be legally required to keep the underlying verification record (see clause 13). Practically, withdrawing consent means we will delete or instruct our provider to delete the face template, and you will not be able to complete future verifications or re-verifications, which means most of the app will stop working for you.
How long the face template lives. We treat the biometric template differently from the verification record. We instruct our verification providers to delete face templates no later than twelve months after you stop being a Zap user, even though the underlying identity verification record must be kept for five years under the Financial Intelligence Centre Act. The law requires us to keep proof that we verified you. It does not require us to keep your face.
4.2 Screening against sanctions, PEP and adverse media lists
What we do. We check your name and identity details against sanctions lists, lists of politically exposed persons, and adverse media sources, both when you join and periodically afterwards. Where there is a match we record the flag and the reason.
Our legal ground. We rely on POPIA section 27(1)(b) (necessary for the establishment, exercise or defence of a right or obligation in law) and section 33(b) (information obtained in accordance with the law), because the Financial Intelligence Centre Act and the targeted financial sanctions provisions in sections 26A to 26C of that Act oblige us to screen and, in some cases, to freeze and report. This screening is not based on consent, and you cannot opt out of it while holding a Zap account.
If we have to report you. Where we file a report with the Financial Intelligence Centre, the law may prohibit us from telling you that we have done so. If we go quiet about a specific issue, that is why.
5. Why we use your information, and on what legal basis
| Purpose | What this covers | Lawful basis under POPIA |
|---|---|---|
| Creating and running your account | Registration, authentication, wallet creation, ZapTag allocation, profile, device and session management | Section 11(1)(b): necessary to perform our contract with you |
| Making payments work | Resolving a recipient, building and submitting transactions, tracking confirmations, keeping your ledger, handling payment requests, running pools | Section 11(1)(b): performance of our contract |
| Verifying your identity | Document and biometric verification, duplicate detection, re-verification | Section 27(1)(a) consent for biometrics; section 11(1)(c) legal obligation under FICA for the rest |
| Preventing fraud and abuse | Device and session anomaly detection, velocity and threshold checks, approximate location signals, multi factor prompts on higher value payments, investigating reported scams | Section 11(1)(d): our legitimate interests and yours in not being defrauded |
| Complying with the law | FICA customer due diligence and record keeping, Travel Rule submissions, sanctions screening and freezing, responding to court orders, subpoenas and regulator requests, tax reporting | Section 11(1)(c): compliance with a legal obligation |
| Keeping the service running and improving it | Crash reporting, performance monitoring, product analytics, session replay, deciding what to build next | Section 11(1)(d): legitimate interests. Session replay and analytics can be switched off: see clause 9 |
| Talking to you | Transaction notifications, security alerts, service and policy updates, support replies | Section 11(1)(b) for service messages; these are not marketing and continue even if you opt out of marketing |
| Marketing | Product announcements, offers and newsletters | Section 11(1)(a) consent, and section 69 for electronic marketing. See clause 19 |
Laws that require us to collect your information
POPIA section 18(1)(f) requires us to name them:
- Financial Intelligence Centre Act 38 of 2001, sections 21 to 21H (customer due diligence), 22 to 24 (record keeping), 26A to 26C (targeted financial sanctions) and 28 to 29 (reporting).
- Financial Intelligence Centre Directive 9 of 2023 (the Travel Rule), which requires originator and beneficiary information to accompany crypto asset transfers.
- Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011, where reporting is required.
- Protection of Personal Information Act 4 of 2013 itself, which obliges us to keep records of our processing.
6. Automated decisions
POPIA section 71 gives you the right not to be subject to a decision based solely on automated processing that has legal consequences for you or affects you substantially. Zap makes several such decisions:
| Automated decision | What can happen | Your route to a human |
|---|---|---|
| Identity verification result | Your verification is approved, rejected or flagged for manual review. Rejection blocks most of the app | Every rejection can be appealed. Contact support and a person will review it |
| Sanctions or PEP match | Your account can be restricted or frozen | Contact support. Note that where the law prohibits us from disclosing the reason, we will tell you that a restriction exists but not necessarily why |
| Fraud and risk scoring | A specific transaction can be blocked or delayed, or an additional authentication step required | Contact support to have the transaction reviewed |
| Multi factor thresholds | Payments above a value threshold require additional authentication | This is a security control rather than a judgement about you, and the threshold is adjustable in your settings |
In each case you may ask us to explain the decision, give us your point of view, and ask a person to reconsider it. Write to our Information Officer at ari@zapzar.co.za.
7. Your phone contacts, and finding friends on Zap
This clause deserves your attention because it involves other people's information as well as your own.
It is optional. Zap works without contact access. iOS will ask your permission and you can decline or revoke it at any time in Settings.
What happens if you allow it. The app reads the phone numbers and email addresses in your address book and sends them to our servers over an encrypted connection so we can work out which of your contacts are already on Zap.
What we store. In the same request, before anything is written to our database, each number and email address is converted into a one way code using HMAC-SHA256 with a secret key. We store only the codes. We do not store your contacts' phone numbers or email addresses. The codes cannot be reversed back into a phone number without the secret key, and they are useless to anyone who obtains them without it. When you sync again, codes for contacts you have deleted are removed.
What we do with the codes. We compare them against the equivalent codes for existing Zap users, and show you which of your contacts are on Zap. We also use the fact that a code exists on both sides to decide whether a phone number or email search is allowed: searching for someone by number or email only works if you and they have each other saved.
If you are not a Zap user and you are reading this because a friend told you. If someone who has your number in their phone syncs their contacts, a one way code derived from your number will exist on our servers. We do not have your number, we cannot contact you from it, and we do not build a profile of you. If you would rather that code did not exist, email our Information Officer and we will remove any code matching a number or address you give us, and block it from being stored again.
Being found on Zap. Separately from contacts, your ZapTag is publicly searchable by default, and your name and profile photo are shown to people who find you. You can turn off discoverability in Settings, which removes you from search results.
8. The blockchain: what is public, and what we cannot delete
Zap moves money on public blockchain networks (currently Solana and Base). This has privacy consequences that no policy and no company can undo.
- Your wallet address, its full balance history and every transaction it has ever made are public. Anyone in the world can look them up, at any time, without asking you or us.
- Blockchain records are permanent and cannot be changed or deleted. Not by you, not by us, not by any regulator or court. When clause 15 gives you a right to have information deleted, that right cannot extend to on chain data, because there is no mechanism by which anyone could comply.
- Wallet addresses can be linked to people. Blockchain analytics firms, exchanges and law enforcement routinely connect addresses to identities using patterns of activity. If you tell anyone your Zap wallet address, or if the person you pay knows who you are, your other activity on that address may become linkable to you.
- What Zap contributes. We store your wallet address next to your account, which means we know which address is yours. We share it with the parties in clause 10 where they need it.
If a payment must not be traceable to you, a public blockchain is the wrong tool, and Zap is the wrong app.
9. Analytics, session replay and crash reporting
We are being specific here because we think you should know the extent of it.
9.1 Product analytics
We use PostHog to understand how the app is used. We record events such as screen views, app launches and backgrounding, login and signup attempts and their outcomes, wallet creation and operation outcomes, transaction attempts, successes and failures with the amount and type, and feature usage. Events are linked to your user identifier so we can understand a journey rather than isolated taps.
9.2 Session replay
PostHog session replay is enabled in the Zap app. It periodically captures screenshots of your screen while you use the app and stitches them into a replayable recording, so we can see where people get stuck or where the app misbehaves.
We have configured it as follows:
- All text you type is masked. Amounts you enter, search terms, ZapTags, notes and any other text input are blanked out before the screenshot leaves your device.
- All images are masked. Profile photos, QR codes and identity documents are blanked out.
- Console logs are not captured.
- Network telemetry is captured, meaning the timing and outcome of requests the app makes, not their contents.
Masking is applied on your device, before anything is transmitted. It is a strong control but it is not a guarantee: a masking rule can miss a newly built screen. We review this, and if you would rather not be recorded at all, you can turn session replay and analytics off in Settings → Privacy, or write to us and we will do it for you.
9.3 Where the analytics data goes
PostHog data is sent to PostHog's European Union infrastructure (eu.i.posthog.com), not to the United States.
9.4 Crash reporting
We use Sentry, including its crash reporter, to capture crashes and errors. Crash reports contain the technical state of the app when it failed and may incidentally include an identifier for your account. They are not used for any purpose other than fixing the app.
10. Who we share your information with
We do not sell your personal information, and we never have. We share it with the following categories of recipient, which POPIA section 18(1)(h)(i) requires us to identify.
10.1 Service providers who process on our behalf
Each of these acts as an operator under POPIA, which means they may only process your information on our written instructions and must secure it. We have or will put a written operator agreement in place with each of them.
| Provider | What they do | What they receive | Where they process |
|---|---|---|---|
| Privy | Creates and secures your wallet, handles login and transaction signing | Account identifier, email or phone, wallet identifiers and addresses | United States |
| Bridge (Bridge Building Sp. Inc.) | Fiat deposits and withdrawals, virtual accounts, identity verification for those services, Travel Rule submissions | Name, date of birth, address, identity document details, verification status, bank account details, transaction amounts and counterparties | United States |
| Persona (via Bridge) | Identity document capture, liveness and face matching for the Bridge flow | Identity document images, selfie or video, biometric template, extracted document fields | United States |
| Smile Identity | Identity verification against the Department of Home Affairs database for local rand services. Being retired, see clause 10.4 | Identity number, names, date of birth, selfie, biometric template | South Africa and Kenya |
| Neon | Hosts our PostgreSQL database | All information described in clause 3, in encrypted form where clause 14 says so | European Union |
| Fly.io | Hosts our backend servers (Johannesburg region) | All information passing through the API in transit | South Africa |
| Amazon Web Services (S3) | Stores uploaded files including profile photos and verification documents | Profile images, identity documents | European Union (eu-central-1) |
| PostHog | Product analytics and session replay | Events in clause 9, user identifier, device and app version, masked screen recordings | European Union |
| Sentry | Crash and error reporting | Stack traces, device state, account identifier | United States |
| OneSignal | Push notification delivery | Device push token, subscription identifier, notification content | United States |
| Apple Push Notification service | Push notification delivery on iOS | Device token, notification content | United States |
| Resend | Transactional email delivery | Email address, message content | United States |
| Helius and Alchemy | Blockchain indexing and transaction notifications | Wallet addresses and on chain transactions, which are already public | United States |
10.2 Other Zap users
When you pay someone, request money from someone, or join a pool, the other people involved see your name, ZapTag, profile photo, the amount and any note you attach. Do not put anything in a payment note you would not want the recipient to keep a copy of forever.
10.3 Authorities and legal recipients
We disclose personal information where we are legally required or permitted to: to the Financial Intelligence Centre in regulatory reports, to the South African Revenue Service, to the South African Police Service and other law enforcement bodies acting under lawful process, to courts under subpoena or court order, to the Information Regulator, and to our professional advisers, auditors and insurers under duties of confidence.
Under the Travel Rule (FIC Directive 9), identifying information about you may accompany a crypto asset transfer to the receiving institution. For inbound deposits handled by Bridge, that identifying information is a self reference, because Bridge already holds your verified identity.
10.4 Changes to this list
Providers change. We will keep this table current, and where we add a provider that receives a materially new category of information, or that processes in a new country, we will tell you before the change takes effect. Didit is a verification provider we intend to introduce, and Smile Identity is being retired: when that changes we will update this clause and notify you.
10.5 Business transfers
If Zap is acquired, merged, or sells part of its business, your personal information may transfer to the acquirer. We will notify you and the acquirer will be bound by this policy until it gives you notice of its own.
11. Sending your information outside South Africa
Several of the providers in clause 10 are outside South Africa, mainly in the United States and the European Union. POPIA section 72 restricts this, and section 18(1)(g) requires us to tell you about it and about the level of protection in the destination.
The protection in those countries. The European Union has a comprehensive data protection regime (the GDPR) that is broadly comparable to POPIA. The United States has no comprehensive federal data protection law, so we do not rely on the destination country's law there.
What we rely on instead. Our primary mechanism is section 72(1)(a): a binding written agreement with each recipient that requires it to uphold principles substantially similar to POPIA's conditions for lawful processing, and that restricts the recipient from onward transferring your information to anyone else in another country except on the same terms. We rely, additionally and in the alternative, on section 72(1)(c), because the transfer is necessary to perform our contract with you (we cannot create your wallet without Privy or move money to your bank without Bridge), and on section 72(1)(b), your consent, which you give by accepting this policy.
You may request a copy of the safeguards we rely on for a specific provider by writing to our Information Officer. We will provide it, redacted for commercial terms.
12. Keeping your information secure
POPIA section 19 requires appropriate technical and organisational measures. Ours include:
- Encryption at rest of directly identifying information using AES-256-GCM. Your phone number, email address, first and last name, date of birth, bank name, bank account number, branch code, account holder name, routing numbers, IBANs and BICs are all stored encrypted, not in plain text.
- Blind indexes. Where we need to look someone up without storing the underlying value, we store an HMAC-SHA256 code instead of the value. Your identity number is never stored in plain text anywhere in our systems, only as a blind index.
- Encryption in transit. All communication between the app and our servers uses TLS.
- Access control. Administrative access is role based, limited to staff who need it, and logged.
- Authentication. Passkeys (WebAuthn), device biometrics through Apple's secure enclave, session and device tracking, the ability to see and revoke your active sessions, and additional authentication above a value threshold you control.
- Rate limiting and abuse controls on sensitive endpoints, including contact sync.
- Monitoring through error tracking and alerting.
No system is perfectly secure, and we do not claim otherwise. What you can do: keep your device passcode and biometrics enabled, register a passkey, keep your recovery method safe, do not share verification codes with anyone (including anyone claiming to be from Zap, because we will never ask), and review your active devices and sessions in Settings.
13. How long we keep your information
POPIA section 14 says we may not keep records longer than necessary, unless the law requires us to keep them.
| Category | Retention period | Why |
|---|---|---|
| Identity verification records (verification result, document type, identity number blind index, encrypted names and date of birth, nationality, screening flags) | Five years from the date your relationship with us ends, or from the date of any report we file with the Financial Intelligence Centre, whichever is later | Financial Intelligence Centre Act sections 22 to 24. We cannot delete these on request |
| Biometric templates (face templates held by our verification providers) | No more than twelve months after you stop being a Zap user | Not required by FICA. We cap this deliberately |
| Identity document images | Five years, in encrypted storage with access restricted to compliance staff | FICA record keeping |
| Transaction records (ledger entries, payment requests, fiat requests, swaps, Travel Rule submissions) | Five years from the date the transaction was concluded | FICA sections 22A and 23 |
| Bank account details | For as long as the account is linked, then five years as part of the transaction record | FICA, and dispute resolution |
| Account profile (name, email, phone, ZapTag, photo, bio) | For as long as your account is open, then deleted or de-identified once the FICA period above has run | Contract performance |
| ZapTag history | For as long as your account is open, plus five years | Fraud investigation, because tag changes are a common scam pattern |
| Contact codes | Until you sync again without that contact, revoke contact permission, or close your account | Consent based, and no longer needed once withdrawn |
| Device and session records | Twenty four months from last activity | Fraud investigation and security incident reconstruction |
| Push tokens | Until the token is deactivated or your account closes | Notification delivery |
| Analytics events and session replays | Twelve months | Product improvement, after which their value falls away |
| Crash and error reports | Ninety days | Debugging |
| Support correspondence | Three years from the last message | Dispute resolution |
| Marketing consents and opt outs | Indefinitely, in a suppression list | So that an opt out actually stays honoured |
| On chain transactions | Permanent and outside our control | See clause 8 |
When you close your account. We disable your account and stop using your information to provide services or to market to you. Information we are legally required to keep is moved into restricted processing, which means it is retained for the legal purpose only and is not used for anything else. Once every applicable retention period has run, we delete, destroy or de-identify the information in a way that prevents it being reconstructed.
14. Children
Zap is for people 18 years and older. We do not knowingly collect information about anyone under 18. POPIA section 34 prohibits processing a child's personal information without the prior consent of a competent person, and our identity verification step is designed to catch under 18s at signup.
If you believe a person under 18 has an account, tell our Information Officer and we will investigate, close the account and delete the information, except where the law requires us to keep a record of the verification itself.
15. Your rights
POPIA section 5 gives you the following rights. Clause 16 explains how to use them.
| Right | What it means | Limits |
|---|---|---|
| To be told we are collecting your information | This policy is that notice | |
| To be told if your information is accessed by an unauthorised person | See clause 17 | |
| To ask what we hold and to get a copy | Free confirmation that we hold information about you, and a copy of the record or a description of it, including who has had access to it | A fee may be payable for the copy itself, and we will give you a written estimate first. Some grounds in PAIA allow us to refuse part of a request, in which case we release everything else |
| To correct or delete | We must correct information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, and delete information we are no longer entitled to keep | We cannot delete records FICA requires us to keep (clause 13), and nobody can delete blockchain records (clause 8) |
| To object to processing | On reasonable grounds relating to your situation, you can object to processing we base on legitimate interests or public interest | We cannot stop processing that a law requires |
| To refuse direct marketing | Absolutely, at any time, for free | See clause 19 |
| Not to be subject to a decision based solely on automated processing | See clause 6 | |
| To withdraw consent | Where we rely on your consent (biometrics, contacts, analytics, marketing), you can withdraw it at any time | Withdrawal is not retrospective, and withdrawing biometric consent means you cannot re-verify |
| To complain to the Information Regulator | See clause 18 | |
| To go to court | You may institute civil proceedings for interference with the protection of your personal information |
16. How to exercise your rights, and who to contact
Information Officer
| Name | Arian Hobson |
| Designation | Information Officer, ZA Payments (Pty) Ltd |
| ari@zapzar.co.za | |
| Telephone | 072 432 1456 |
| Address for delivery of requests | 194 Bancor Avenue, Park Lane West Building, Waterkloof Glen, Pretoria, 0181, South Africa |
The forms to use
South African law prescribes specific forms. We will accept a plain email too, but using the right form makes it faster.
| What you want | Form | Where to send it |
|---|---|---|
| Access to your information | PAIA Form 2 (Request for Access to Record of Private Body) | Our Information Officer |
| Correction or deletion | POPIA Form 2 (Regulation 3) | Our Information Officer. Free of charge. We will tell you the outcome within 30 days |
| Objection to processing | POPIA Form 1 (Regulation 2) | Our Information Officer. Free of charge |
| Complaint about how we handled it | POPIA Form 5 (Regulation 7) | The Information Regulator, see clause 18 |
All forms are at https://inforegulator.org.za/popia-forms/. You may send them by email, by hand, by post, or by any other reasonable means.
Our PAIA manual
Our manual under section 51 of the Promotion of Access to Information Act 2 of 2000 is available on request. Ask our Information Officer using any of the contact details above and we will send you a copy. It sets out the categories of records we hold and how to request them.
Timing
We acknowledge requests within five business days and aim to resolve them within thirty days. If a request is complex and we need longer, we will tell you why and give you a new date.
17. If there is a security breach
If we have reasonable grounds to believe that your personal information has been accessed or acquired by someone unauthorised, POPIA section 22 requires us to notify both the Information Regulator and you, as soon as reasonably possible after discovering it. We may only delay telling you if the Regulator or a law enforcement body determines that notification would impede a criminal investigation.
We will notify you in writing, by email to your registered address, by in-app message, and by a prominent notice on our website. The notification will tell you:
- what happened and what information was involved,
- what the possible consequences are,
- what we have done and are doing about it,
- what we recommend you do to protect yourself, and
- who was responsible, if we know.
18. Complaining to the Information Regulator
If you are unhappy with how we have handled your personal information or your request, you may complain to the Information Regulator. You do not have to come to us first, though we would like the chance to fix it.
The Information Regulator (South Africa) Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Telephone: 010 023 5200 Toll free: 0800 017 160 POPIA complaints: POPIAComplaints@inforegulator.org.za PAIA complaints: PAIAComplaints@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Website: https://inforegulator.org.za
Use POPIA Form 5. The Regulator will acknowledge your complaint with a reference number within 14 days.
19. Marketing
We only send electronic marketing (email, SMS, WhatsApp or push) to people who have opted in. POPIA section 69 prohibits unsolicited electronic direct marketing without consent, and since the amended regulations of April 2025 it is explicit that failing to opt out does not count as consent. We do not pre-tick boxes.
- You can opt in or out at any time in Settings → Notifications, or by using the unsubscribe link in any marketing message, at no cost.
- If you are already a Zap user, we may send you information about our own similar products under section 69(3), and every such message will carry a clear and free way to stop them.
- Service messages are not marketing. Transaction notifications, security alerts, verification requests, and changes to these terms will continue regardless, because they are part of providing the service. If you do not want them you must close your account.
- Every marketing message will identify us and give you a contact address to stop them.
20. Cookies and our website
Our website uses cookies that are strictly necessary for it to work, and analytics cookies that we only set with your consent. You can manage your preference through the banner on the site or through your browser settings. Blocking necessary cookies will break parts of the site. The mobile app does not use cookies; it uses the analytics described in clause 9.
21. Electronic Communications and Transactions Act
We collect personal information electronically, and we comply with the data protection principles in sections 50 and 51 of the Electronic Communications and Transactions Act 25 of 2002 in addition to POPIA. We will not disclose your information to a third party except as described in clause 10 or as required by law, and we keep a record of the personal information we hold and the specific purpose for which it was collected.
22. Changes to this policy
We will update this policy when what we do changes. When a change is material (a new category of information, a new purpose, a new country, or a new class of recipient) we will give you at least 30 days' notice by email and in the app before it takes effect, and we will summarise what changed at the top of the policy. Minor changes take effect when posted.
Every version is dated. Previous versions are available on request from our Information Officer.
23. Contact us
| General privacy questions | ari@zapzar.co.za |
| Support | support@zapzar.co.za |
| Exercising your rights, and formal requests | ari@zapzar.co.za |
| Post | ZA Payments (Pty) Ltd, 194 Bancor Avenue, Park Lane West Building, Waterkloof Glen, Pretoria, 0181, South Africa |
ZA Payments (Pty) Ltd, registration number 2025/911807/07. This policy is governed by the laws of the Republic of South Africa.