SoftPOS Privacy Policy

Introduction

TravelBuy SoftPOS is a secure Software Point-of-Sale (SoftPOS) solution that enables authorised merchants to initiate and accept digital payment transactions using supported payment methods.

Legal basis for the TravelBuy SoftPOS Privacy policy

This Privacy Policy explains how TravelBuy SoftPOS (“the App”, “TravelBuy”, “we”, “our”, or “us”) collects, uses, processes, stores and protects personal and transactional information when users access or use the TravelBuy SoftPOS Android application.

The policy is issued in accordance with:

  • The Protection of Personal Information Act, 4 of 2013 (POPIA)
  • Applicable banking, payment scheme (Visa/Mastercard), and regulatory requirements
  • Google Play Developer Program Policies

By using the App, users acknowledge and consent to the processing of information as described in this Policy.

The following abbreviations, acronyms and specialised terms are used in this document:

Term

Definition

App

Application programme

CVV

Card verification value

NFC

Near field communication

PCI-DSS

Payment Card Industry Data Security Standard

PIN

Personal identification number

POPIA

Protection of Personal Information Act

QR code

Quick response code

SoftPOS

Software Point-of-sale

SMS

Short message service

TLS

Transport layer security

VAS

Value Added Services

TravelBuy SoftPOS provides the following payment and financial service functionalities:

  • Tap to Pay near field communication (NFC)
  • Pay by Code
  • Scan to Pay QR codes
  • Request to Pay
  • Value-Added Services (VAS)
  • Send Money (where enabled)

The App is intended solely for authorised merchants and approved users who have completed the required onboarding, verification and contractual processes.

TravelBuy applies data minimisation principles and only collects information necessary to provide secure, compliant financial services. This includes information that is collected automatically and Information provided by the user.

TravelBuy will collect the following information automatically:

  • Transaction identifiers and references
  • Transaction status and timestamps, as well as transaction amounts
  • Device security and non-personal integrity indicators
  • Application logs related to errors, diagnostics and security events

TravelBuy will collect the following information from SoftPOS users:

  • Merchant identifiers and credentials
  • Payment-related inputs initiated by the user
  • Information required to process transactions or support services

 

The TravelBuy SoftPOS does not access or collect:

  • Personal contacts or address books
  • SMS messages or call logs
  • Personal photos, videos or files
  • Real-time or background location data
  • Microphone recordings
  • Personal emails or private communications

Information collected through the App is processed strictly for the following lawful purposes:

  • Execution and processing of payment transactions
  • Fraud prevention, risk monitoring and security controls
  • Compliance with legal, regulatory and payment scheme obligations
  • System integrity, performance monitoring and service improvement
  • Customer support, where initiated by the user

The TravelBuy SoftPOS does not sell, rent or use personal data for advertising or marketing purposes.

The SoftPOS App requests the following Android permissions, only where essential for core functionality:

Permission

Purpose

Camera

Scanning QR codes for Scan to Pay and Pay by Code

Internet

Secure communication with backend payment services

Phone state

Device integrity checks and fraud prevention

Wake lock

Prevents interruption during active transactions

Receive_Boot_ Completed

Restores essential services after device restart

Notifications

Transaction confirmations and security alerts

 

All permissions are used only during relevant user-initiated actions and are not abused or used for tracking purposes.

TravelBuy SoftPOS implements appropriate technical and organisational safeguards, including:

  • Encryption of data in transit using transport layer security (TLS)
  • Encryption of sensitive data at rest, where applicable
  • Role-based access controls
  • Secure backend environments aligned with financial industry standards
  • No storage of full card numbers, CVV values, or PIN data on the device

Where required, payment data handling aligns with PCI-DSS principles through approved service providers.

Personal and transactional information is retained only for as long as necessary to:

  • Process transactions and settlements
  • Meet legal, regulatory and reporting obligations
  • Resolve disputes, chargebacks or investigations

Once data is no longer required, it is securely deleted or anonymised in accordance with applicable laws.

TravelBuy SoftPOS integrates with regulated banks, payment processors and financial service providers, strictly for payment execution and compliance purposes.

All third parties are:

  • Contractually bound to confidentiality and data protection obligations
  • Required to comply with POPIA and applicable financial regulations

No data is shared beyond what is necessary for lawful processing.

Under POPIA, users have the right to:

  • Request access to personal information held about them
  • Request correction of inaccurate or incomplete information
  • Request deletion of personal data, where legally permissible
  • Object to unlawful processing of their personal information

Users may submit requests for information through official TravelBuy support channels. Requests will be handled in accordance with POPIA timelines.

TravelBuy SoftPOS is not intended for individuals under the age of 18, defined as minors under POPIA. TravelBuy does not knowingly collect or process personal information of minors.

The TravelBuy SoftPOS Privacy Policy may be updated periodically to reflect legal, regulatory or operational changes.
Material updates will be published within the App or via official communication channels, together with a revised effective date.

Contact and complaints

For privacy-related queries, requests or complaints, users may contact TravelBuy via official support channels.

Email: support@travelbuy.co.za

 

Where unresolved, users may lodge a complaint with the Information Regulator of South Africa in accordance with POPIA.

Email: enquiries@inforegulator.org.za

 

Scroll to Top