1. INTRODUCTION
SANDTONER (PTY) LTD ("we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data in compliance with the Protection of Personal Information Act (POPIA) of South Africa and other applicable laws.
By using our services, you consent to the practices described in this policy.
2. Scope of Application
This Privacy Policy applies to all personal information collected, processed, or stored by SANDTONER (PTY) LTD (Registration No. 2025/121656/07) through:
- Our website: www.sandtoner.com;
- Mobile applications: Sandtoner;
- Merchant platform services: Sandtoner;
- Customer support interactions (e.g., emails, phone calls);
- Offline activities (e.g., in-person meetings, events).
2.1 Who is covered
- Merchants using our payment and fintech services;
- Customers transacting through the Sandtoner platform;
- Website visitors and third-party partners.
2.2 Geographic Scope
1 | Primarily applies to operations within South Africa. |
2 | For cross-border data transfers, see Section 8. |
3. Types of Personal Information We Collect
SANDTONER (PTY) LTD collects personal information to provide and enhance our services, comply with legal obligations, and protect user interests. Below is a detailed breakdown of the categories of data we collect, their specific purposes, and legal bases under POPIA.
3.1 Identity & Contact Information
Category | Data Types |
---|---|
Individual Users |
|
Business Users |
|
Purpose:
- To create and manage user accounts;
- To verify identities for fraud prevention;
- To fulfill contractual obligations (e.g., payment settlements);
- To send service notifications or legal updates.
Legal Basis:
- Contractual necessity (POPIA Section 11(1)(b));
- Legal obligations (e.g., anti-money laundering laws).
3.2 Financial & Transactional Information
Data Types:
- Bank account details (account number, branch code);
- Credit/debit card details (card number, expiry date, CVV, encrypted storage);
- Transaction records (amount, timestamp, recipient, IP address);
- Invoices, payment status, refund or dispute records;
- Credit scores or risk assessment data (if applicable).
Purpose:
- To process payments and settlements;
- For fraud prevention and risk management;
- To generate financial reports (e.g., tax filings);
- To resolve transaction disputes.
Legal Basis:
Contractual necessity (POPIA Section 11(1)(b));
3.3 Technical Data
Category | Data Types |
---|---|
Device Information |
|
Usage Behavior |
|
Tracking Technologies |
|
Purpose:
- To optimize platform performance and compatibility;
- To analyze user behavior for service improvements;
- To prevent DDoS attacks or account breaches.
Legal Basis:
- Legitimate interests (service optimization and security);
- User consent (for non-essential cookies).
- Legitimate interests (e.g., fraud prevention).
3.4 Commercial & Preference Data
Data Types:
- Purchase history, order IDs, product preferences;
- Marketing interaction records (e.g., email open rates, ad clicks);
- Customer service records (call recordings, chat logs, complaints);
- Survey feedback or user ratings.
Purpose:
- To provide personalized recommendations (e.g., merchant promotions);
- To improve customer service quality;
- For market trend analysis and business decisions.
Legal Basis:
- User consent (POPIA Section 11(1)(a));
- Legitimate interests (service optimization).
- Call recordings will be notified in advance and require consent.
3.5 Special Category Data
Collected only when necessary.
Data Types:
- Race or ethnicity (for localized financial services);
- Religious beliefs (e.g., compliance for Halal-certified merchants);
- Health information (e.g., risk assessments for insurance products).
Purpose:
- To fulfill specific legal obligations (e.g., BEE policy compliance);
- To provide customized financial products (requires explicit consent).
Legal Basis:
- Explicit user consent (POPIA Section 27);
- Legal authorization (e.g., public health emergencies).
3.6 Data from Third Parties
Data Types:
- Credit scores from agencies (e.g., TransUnion);
- Public business records (e.g., CIPC registrations);
- Social media profiles (e.g., LinkedIn company verifications).
Purpose:
- To supplement merchant due diligence;
- For AML (Anti-Money Laundering) and KYC (Know Your Customer) checks.
Legal Basis:
- Legitimate interests (risk control);
- Legal obligations (e.g., Financial Intelligence Centre requirements).
3.7 User-Generated Content
Data Types:
- Product descriptions, images, or videos uploaded by merchants;
- Customer reviews, comments, or forum posts.
Purpose:
- To display merchant products or services;
- To maintain compliance of platform content.
Legal Basis:
- Contractual necessity (fulfillment of service terms).
3.8 Data Minimization Principle
We collect only the minimum necessary data to achieve specific purposes. Examples include:
- ID numbers are not mandatory unless for high-value transactions;
- Non-essential cookies are disabled by default and require user consent.
3.9 User Control & Transparency
- Real-Time Access: Users can view collected data via account settings.
- Dynamic Updates: Business users can update licenses in the backend.
- Withdraw Consent: Adjust cookie preferences or marketing subscriptions in the Privacy Center.
4. Legal Basis for Processing
Under the Protection of Personal Information Act (POPIA) of South Africa, SANDTONER (PTY) LTD processes personal information only when a valid legal basis exists. Below are the lawful grounds we rely on, along with specific examples and user rights.
4.1 Consent (Section 11(1)(a))
Definition
Processing is based on your explicit, voluntary, and informed consent.
Applicable Scenarios
- Sending marketing communications (e.g., promotional emails).
- Collecting sensitive data (e.g., biometric information).
- Using non-essential cookies or tracking technologies.
Examples
- A merchant opts in to receive newsletters about new platform features.
- A customer agrees to facial recognition for enhanced account security.
Your Rights
- Withdraw Consent
- Click "Unsubscribe" in emails or adjust preferences in the Privacy Center.
- Revoke Sensitive Data Use
- Contact info@sandtoner.com with a written request.
4.2 Contractual Necessity (Section 11(1)(b))
Definition
Processing is necessary to fulfill obligations under a contract with you.
Applicable Scenarios
- Account registration and identity verification.
- Payment processing and settlement.
- Providing customer support as per service terms.
Examples
- Collecting bank account details to process a merchant's payout.
- Verifying a user's ID to activate a payment gateway.
Your Rights
- Objection
- You may terminate the contract, but this may affect service availability.
4.3 Legal Obligations (Section 11(1)(c))
Definition
Processing is required to comply with South African laws or regulatory requirements.
Applicable Scenarios
- Tax reporting to SARS (South African Revenue Service).
- Anti-Money Laundering (AML) checks under FICA.
- Responding to court orders or government requests.
Examples
- Retaining transaction records for 7 years as per tax laws.
- Reporting suspicious transactions to the Financial Intelligence Centre (FIC).
Your Rights
- Access & Correction
- Request to review or update legally mandated data.
4.4 Legitimate Interests (Section 11(1)(f))
Definition
Processing is necessary for our legitimate business interests, provided they do not override your rights.
Applicable Scenarios
- Fraud prevention and cybersecurity measures.
- Service improvement through data analytics.
- Direct marketing to existing customers (soft opt-in).
Examples
- Analyzing transaction patterns to detect fraudulent activity.
- Using aggregated usage data to optimize platform performance.
Your Rights
- Object: Submit an objection request via feedback@sandtoner.com.
- Opt-Out of Marketing: Click "Unsubscribe" in marketing emails.
4.5 Public Interest or Historical Research (Section 11(1)(d)-(e))
Definition
Processing is necessary for public interest tasks or archival/research purposes.
Applicable Scenarios
- Public health data sharing during epidemics.
- Academic research on financial inclusion (anonymized data only).
Examples
- Providing anonymized transaction trends to the National Treasury for policy-making.
Your Rights
- Restrict Processing: Contact feedback@sandtoner.com if you believe public interest claims are unjustified.
4.6 Special Categories of Data (Section 27)
Definition
Processing of sensitive data (e.g., race, religion, health) requires explicit consent or legal authorization.
Applicable Scenarios
- Collecting race data for B-BBEE compliance.
- Health information for insurance underwriting.
Examples
- A user explicitly consents to provide religious affiliation for Halal payment services.
Your Rights
- Withdraw Consent: Immediate effect upon request.
- Complain: Lodge a complaint with the SA Information Regulator.
4.7 How We Balance Legitimate Interests
We conduct a Legitimate Interests Assessment (LIA) to ensure our interests do not infringe your rights. Factors considered include:
- Necessity: Fraud detection cannot be achieved without analyzing transaction IP addresses.
- Proportionality: Using anonymized data for analytics instead of raw personal information.
- Impact on Users: Minimal privacy impact when using aggregated statistics for service improvement.
4.8 Exercising Your Rights
Submit requests to our Data Protection Officer:
- Email: feedback@sandtoner.com
- Postal Address: Rivonia Boulevard and 9th Avenue Johannesburg Sandton Gauteng 2128
- Response Time: Within 15 business days (extendable to 30 days for complex cases).
5. How We Share Information
SANDTONER (PTY) LTD shares personal information only for legitimate purposes and in compliance with POPIA. Below is a detailed breakdown of the categories of recipients, purposes, data types, legal bases, and safeguards.
5.1 Third-Party Service Providers
Purpose:
To support core business operations, including payment processing, cloud storage, customer support, and analytics.
Data Types Shared:
- Payment Processors (e.g., PayGate, Peach Payments):
- Transaction details (amount, timestamp, merchant ID);
- Card tokenization data (encrypted).
- Cloud Service Providers (e.g., AWS, Microsoft Azure):
- User account information;
- Technical logs and backups.
- Customer Support Platforms (e.g., Zendesk):
- Communication records (emails, chat logs);
- Case resolution notes.
Legal Basis:
- Contractual necessity (POPIA Section 11(1)(b));
- Legitimate interests (service efficiency).
Safeguards:
- Data Processing Agreements (DPAs) requiring POPIA compliance;
- Encryption during transmission and storage;
- Annual audits of third-party security practices.
5.2 Financial Institutions & Regulators
Purpose:
To comply with legal obligations and prevent financial crimes.
Data Types Shared:
- Banks & Payment Networks (e.g., Visa, Mastercard):
- Settlement records;
- Fraud alerts.
- Regulatory Bodies (e.g., FIC, SARS):
- KYC documents (ID copies, business licenses);
- Transaction reports for AML/CTF compliance.
Legal Basis:
- Legal obligations (POPIA Section 11(1)(c));
- Public interest (fraud prevention).
Safeguards:
- Data minimization (only necessary fields shared);
- Secure portals for regulatory submissions;
- Anonymization where possible (e.g., aggregated tax reports).
5.3 Affiliated Companies
Purpose:
To enable group-wide services (e.g., cross-border payments, shared loyalty programs).
Data Types Shared:
- Shared Customer Profiles:
- Name, contact details, transaction history;
- Risk assessment scores (for fraud prevention).
Legal Basis:
- Legitimate interests (POPIA Section 11(1)(f));
- User consent (for marketing across affiliates).
Safeguards:
- Binding Corporate Rules (BCRs) for intra-group data transfers;
5.4 Business Transfers
Purpose:
To facilitate mergers, acquisitions, or asset sales.
Data Types Shared:
- Due Diligence Packages:
- Merchant portfolios;
- Financial performance metrics.
- Post-Transition Data:
- Customer databases;
- Contractual records.
Legal Basis:
- Legitimate interests (corporate restructuring);
- Legal obligations (disclosure to auditors).
Safeguards:
- Confidentiality Agreements with acquiring parties;
- Data Erasure clauses if the transfer fails.
5.5 Marketing & Advertising Partners
Purpose:
To deliver targeted ads or measure campaign effectiveness.
Data Types Shared:
- Advertising Networks (e.g., Google Ads):
- Cookie IDs, device identifiers;
- Aggregated demographic segments (no direct identifiers).
- Analytics Providers (e.g., Mixpanel):
- Anonymized usage patterns;
- Conversion rates.
Legal Basis:
- User consent (POPIA Section 11(1)(a));
- Legitimate interests (marketing ROI analysis).
Safeguards:
- Pseudonymization (e.g., hashed email addresses);
- Opt-Out Mechanisms:
- AdChoices for interest-based ads;
- Cookie preference centers.
- User Controls Over Data Sharing
- Granular Consent: Enable/disable sharing for specific purposes (e.g., marketing) in the Privacy Center.
- Access Reports: Request a list of third parties with whom your data has been shared via feedback@sandtoner.com.
- Object to Sharing: Submit objections for non-essential sharing (response within 15 days).
- Cross-Border Data Transfers
- If data is transferred outside South Africa, we ensure:
- Adequacy Decisions: Recipient countries have POPIA-recognized data protection laws (e.g., EU GDPR).
6. Your Rights Under POPIA
The Protection of Personal Information Act (POPIA) grants you specific rights over your personal data. Below is a clear, simplified explanation of these rights, how to exercise them, and our commitments.
6.1 Right to Access (Section 23)
What It Means:
You can request a copy of the personal data we hold about you, including how it is used and shared.
How to Exercise:
- Email feedback@sandtoner.com with your full name and proof of identity (e.g., ID copy).
Response Time:
- Within 15 business days (free for first request; fees may apply for subsequent requests).
6.2 Right to Correction (Section 24)
What It Means:
- Request correction of inaccurate, incomplete, or outdated data (e.g., wrong phone number).
How to Exercise:
- Update directly in your account settings or contact customer support.
Our Commitment:
- Correct within 7 business days and notify third parties if applicable.
6.3 Right to Deletion (Section 25)
What It Means:
- Request deletion of data that is no longer necessary or unlawfully processed.
Exceptions:
- Data required by law (e.g., tax records) or for ongoing disputes.
How to Exercise:
- Submit a written request to feedback@sandtoner.com with reasons.
6.4 Right to Object (Section 11(3))
What It Means:
- Object to processing based on legitimate interests (e.g., direct marketing).
How to Exercise:
- Click "Unsubscribe" in emails or disable marketing preferences in your account.
Our Commitment:
- Stop processing within 5 business days unless overriding legal grounds exist.
6.5 Right to Data Portability (Section 22)
What It Means:
- Request your data in a structured, machine-readable format to transfer to another service.
Applicable Data:
- Only data processed by automated means with your consent or under contract.
How to Exercise:
- Email feedback@sandtoner.com specifying the desired format (e.g., CSV, JSON).
6.6 Right to Complain (Section 74)
What It Means:
Lodge a complaint with the South African Information Regulator if unsatisfied with our response.
Steps:
- Contact us first to resolve the issue internally.
- If unresolved, submit a complaint via:
- Website: https://www.sandtoner.com/feedback/
- Tel: +27 829076662
6.7 Summary of Your Rights
Right | Action | Response Time |
---|---|---|
Access | Email request with ID proof. | 15 business days. |
Correction | Update in account or contact support. | 7 business days. |
Deletion | Submit written requests with reasons. | 15 business days. |
Object | Click "Unsubscribe" or adjust preferences. | 5 business days. |
Data Portability | Request specific data format via email. | 15 business days. |
6.8 How We Protect Your Rights
- Dedicated Team: A Data Protection Officer (DPO) oversees all requests.
- No Discrimination: Exercising rights will not affect service quality.
- Transparency: Track request status via your account dashboard.
7. Data Security Measures
SANDTONER (PTY) LTD implements a multi-layered security framework to protect your personal information against unauthorized access, disclosure, alteration, or destruction. Below are our technical, administrative, and physical safeguards:
7.1 Technical Measures
Measure | Description | Example |
---|---|---|
Encryption | All sensitive data is encrypted during transmission and storage. | AES-256 encryption for databases and SSL/TLS 1.3 for web traffic. |
Access Controls | Role-based access permissions ensure only authorized personnel handle specific data. | Merchants can only view their own transaction history. |
Intrusion Detection | Real-time monitoring for suspicious activities using AI-driven tools. | Alerts for multiple failed login attempts. |
Penetration Testing | Regular third-party security audits to identify vulnerabilities. | Annual penetration tests by certified cybersecurity firms. |
7.2 Administrative Measures
Measure | Description | Example |
---|---|---|
Data Minimization | Collect only necessary data and delete outdated information. | Automatically purge inactive accounts after 2 years. |
Employee Training | Mandatory annual POPIA and cybersecurity training for all staff. | Phishing simulation exercises and GDPR/POPIA certification. |
Incident Response Plan | A documented process for handling data breaches. | 72-hour breach notification to SA Information Regulator. |
7.3 Physical Measures
Measure | Description | Example |
---|---|---|
Data Center Security | Tier-IV certified data centers with 24/7 surveillance and biometric access. | AWS data centers with redundant power and fire suppression. |
Document Shredding | Secure disposal of physical records containing personal data. | Cross-cut shredders for confidential paperwork. |
Device Management | Encryption and remote wipe capabilities for company-issued devices. | Mobile Device Management (MDM) software for laptops. |
7.4 Additional Safeguards
Third-Party Audits:
- Annual ISO 27001 and POPIA compliance audits by independent auditors.
Data Breach Response:
- Step 1: Isolate affected systems and conduct forensic analysis.
- Step 2: Notify regulators and affected users within 72 hours.
- Step 3: Provide free credit monitoring services if sensitive data is exposed.
User Controls:
- Enable two-factor authentication (2FA) for account logins.
- Review active sessions and connected devices in account settings.
Contact for Security Concerns
Report security vulnerabilities or suspicious activities to:
- Email: security@sandtoner.com
- Phone: +27 829076662
8. Data Retention & Deletion
SANDTONER (PTY) LTD retains personal information only as long as necessary to fulfill the purposes outlined in this policy or as required by law. Below is our detailed data retention schedule, deletion processes, and exceptions.
8.1 Data Retention Schedule
Data Category | Retention Period | Legal Basis | Deletion Method | Exceptions |
---|---|---|---|---|
Account Information | 5 years after account closure. | Tax compliance (SARS requirements). | Secure erasure from databases and backups. | Ongoing disputes or legal holds. |
Transaction Records | 7 years from transaction date. | Financial Intelligence Centre Act (FICA). | Anonymization for analytics; physical records shredded. | Regulatory investigations. |
Customer Support Logs | 3 years from case resolution. | Legitimate interests (service improvement). | Automated deletion from CRM systems. | Litigation or audit requirements. |
Marketing Data | Until consent is withdrawn. | POPIA Section 11(1)(a) (consent). | Removal from marketing databases; opt-out lists maintained. | Aggregated analytics (no personal identifiers). |
Technical Logs | 1 year from collection. | Cybersecurity incident response. | Automated purging of server logs. | Forensic investigations (extended retention). |
8.2 Deletion Process
- Identification:
- Locate data across all systems (databases, backups, third-party platforms).
- Verification:
- Confirm user identity and legal authority for deletion requests.
- Execution:
- Electronic Data: Overwrite or cryptographically erase to prevent recovery.
- Physical Records: Cross-cut shredding or incineration.
- Confirmation:
- Notify the user and update audit logs.
8.3 User Rights & Requests
- How to Request Deletion:
- Submit a request via https://www.sandtoner.com/privacy or email feedback@sandtoner.com.
- Response Timeline:
- Standard Requests: Processed within 15 business days.
- Complex Cases (e.g., data across multiple systems): Up to 30 business days.
8.4 Exceptions to Deletion
We may retain data longer in specific circumstances, including:
- Legal Obligations:
- Tax audits, AML investigations, or court orders.
- Public Interest:
- Health or safety emergencies (e.g., pandemic contact tracing).
- Technical Constraints:
- Backup systems with immutable storage (data will be deleted upon backup rotation).
8.5 Our Commitments
- Transparency: Provide a detailed retention schedule upon request.
- Security: Use certified data erasure tools (e.g., Blancco).
- Proactive Review: Bi-annual audits to ensure compliance with retention policies.
9. Cookies & Tracking Technologies
SANDTONER (PTY) LTD uses cookies and similar tracking technologies to enhance user experience, analyze service usage, and deliver targeted advertising. This section explains how these technologies work, their purposes, and your control options under POPIA.
9.1 Types of Cookies & Tracking Tools
Category | Purpose | Examples | Storage Duration |
---|---|---|---|
Essential Cookies | Required for core website functionality (e.g., login, payment processing). | Session cookies for shopping carts. | Until browser closure. |
Analytics Cookies | Collect anonymized data to understand user behavior and improve services. | Google Analytics, Mixpanel. | Up to 2 years. |
Advertising Cookies | Deliver personalized ads based on browsing history and interests. | Facebook Pixel, Google Ads. | Up to 1 year (reset with consent). |
Social Media Cookies | Enable content sharing on social platforms and track social media campaigns. | LinkedIn Share button, Twitter widgets. | Varies by platform. |
9.2 How We Use Tracking Technologies
- Heatmaps & Session Recordings:
- Tools like Hotjar visualize user interactions to identify usability issues.
- Cross-Device Tracking:
- Link user activity across devices (e.g., mobile app and website) using encrypted identifiers.
- Retargeting Pixels:
- Display ads to users who visited specific pages (e.g., abandoned cart reminders).
9.3 Your Control Options
Action | Steps | Impact |
---|---|---|
Browser Settings | Disable all cookies via browser preferences (e.g., Chrome: Settings > Privacy). | May break essential functions (e.g., login). |
Opt-Out of Analytics | Use tools like the Google Analytics Opt-Out Browser Add-on. | Stops data collection for analytics. |
Adjust Ad Preferences | Visit the Digital Advertising Alliance (DAA) or Your Online Choices (EU). | Limits personalized ads across platforms. |
Privacy Center Controls | Customize cookie categories (essential, analytics, advertising) via our Privacy Center. | Granular control without affecting core services. |
9.4 Third-Party Data Sharing
We share cookie data with the following third parties under strict safeguards:
Third Party | Purpose | Safeguards |
---|---|---|
Google Analytics | Traffic analysis and user behavior insights. | Anonymized IP addresses; data retention set to 14 months. |
Facebook Pixel | Ad performance measurement and retargeting. | Limited data sharing via Advanced Matching (hashed emails). |
Hotjar | Usability testing and heatmaps. | GDPR/POPIA-compliant data processing agreements. |
9.5 Our Commitments
- Transparency: Provide a real-time cookie consent banner on first visit.
- No Sneaky Tracking: We do not use fingerprinting or supercookies.
- Regular Audits: Review tracking tools quarterly for POPIA compliance.
10. Children's Privacy
SANDTONER (PTY) LTD is committed to protecting the privacy of minors. Our services are not directed to individuals under the age of 18 (“Children"), and we do not knowingly collect personal information from Children without verified parental or guardian consent.
10.1 Our Stance on Children's Data
- Service Restrictions:
- Our platform is designed for merchants and adult users. We do not offer products or features targeting Children.
- Age Verification:
- During account registration, users must confirm they are at least 18 years old.
10.2 If We Accidentally Collect Children's Data
If we discover that personal information of a Child has been collected without valid consent, we will:
Action | Description |
---|---|
Immediate Deletion | Delete the Child's data from our active systems within 72 hours. |
Notification | Inform the parent/guardian via email or phone (if contact details are available). |
Audit & Prevention | Investigate the cause and update safeguards to prevent recurrence. |
10.3 Parental Rights
- Parents or guardians of Children may:
- Request Access:
- Obtain a copy of the Child's data we hold.
- Request Deletion:
- Demand erasure of the Child's data.
- Withdraw Consent:
- Revoke any previously granted consent.
- Request Access:
How to Exercise Rights:
- Submit a request to feedback@sandtoner.com with:
- Proof of parental/guardianship status (e.g., birth certificate, court order).
- Child's identifying information (e.g., name, registered email).
10.4 Educational Resources
We support digital literacy for Children and recommend the following resources:
- South African Resources:
- Childline South Africa: Online safety guides for parents.
- Film and Publication Board: Tools to report inappropriate content.
10.5 Our Commitments
- No Marketing to Children: We do not use Children's data for advertising.
- Data Minimization: If parental consent is obtained, we collect only essential data.
- Regular Training: Staff receive annual training on handling minors' data.
11. Updates & Notification
We will notify users of material changes via email or platform announcements 30 days in advance.
Historical versions of this policy are archived at www.sandtoner.com/privacy-archive (Please update this link to your actual archive page) for review.
12. Contact Information
Designated Information Officer (POPIA Compliance)
- Name: Feedback
- Email: feedback@sandtoner.com
- Address: Rivonia Boulevard and 9th Avenue Johannesburg Sandton Gauteng 2128
- Phone: +27 829076662
Complaints: If dissatisfied with our response, you may lodge a complaint with the South African Information Regulator.