SoftPOS Privacy Policy
Introduction
TravelBuy SoftPOS is a secure Software Point-of-Sale (SoftPOS) solution that enables authorised merchants to initiate and accept digital payment transactions using supported payment methods.
Legal basis for the TravelBuy SoftPOS Privacy policy
This Privacy Policy explains how TravelBuy SoftPOS (“the App”, “TravelBuy”, “we”, “our”, or “us”) collects, uses, processes, stores and protects personal and transactional information when users access or use the TravelBuy SoftPOS Android application.
The policy is issued in accordance with:
- The Protection of Personal Information Act, 4 of 2013 (POPIA)
- Applicable banking, payment scheme (Visa/Mastercard), and regulatory requirements
- Google Play Developer Program Policies
By using the App, users acknowledge and consent to the processing of information as described in this Policy.
Terminology
The following abbreviations, acronyms and specialised terms are used in this document:
Term | Definition |
App | Application programme |
CVV | Card verification value |
NFC | Near field communication |
PCI-DSS | Payment Card Industry Data Security Standard |
PIN | Personal identification number |
POPIA | Protection of Personal Information Act |
QR code | Quick response code |
SoftPOS | Software Point-of-sale |
SMS | Short message service |
TLS | Transport layer security |
VAS | Value Added Services |
Application scope and intended use
TravelBuy SoftPOS provides the following payment and financial service functionalities:
- Tap to Pay near field communication (NFC)
- Pay by Code
- Scan to Pay QR codes
- Request to Pay
- Value-Added Services (VAS)
- Send Money (where enabled)
The App is intended solely for authorised merchants and approved users who have completed the required onboarding, verification and contractual processes.
Collection and processing of information
TravelBuy applies data minimisation principles and only collects information necessary to provide secure, compliant financial services. This includes information that is collected automatically and Information provided by the user.
Information collected automatically
TravelBuy will collect the following information automatically:
- Transaction identifiers and references
- Transaction status and timestamps, as well as transaction amounts
- Device security and non-personal integrity indicators
- Application logs related to errors, diagnostics and security events
Information provided by the user
TravelBuy will collect the following information from SoftPOS users:
- Merchant identifiers and credentials
- Payment-related inputs initiated by the user
- Information required to process transactions or support services
The TravelBuy SoftPOS does not access or collect:
- Personal contacts or address books
- SMS messages or call logs
- Personal photos, videos or files
- Real-time or background location data
- Microphone recordings
- Personal emails or private communications
Purpose of processing information
Information collected through the App is processed strictly for the following lawful purposes:
- Execution and processing of payment transactions
- Fraud prevention, risk monitoring and security controls
- Compliance with legal, regulatory and payment scheme obligations
- System integrity, performance monitoring and service improvement
- Customer support, where initiated by the user
The TravelBuy SoftPOS does not sell, rent or use personal data for advertising or marketing purposes.
Permissions and functional justification
The SoftPOS App requests the following Android permissions, only where essential for core functionality:
Permission | Purpose |
Camera | Scanning QR codes for Scan to Pay and Pay by Code |
Internet | Secure communication with backend payment services |
Phone state | Device integrity checks and fraud prevention |
Wake lock | Prevents interruption during active transactions |
Receive_Boot_ Completed | Restores essential services after device restart |
Notifications | Transaction confirmations and security alerts |
All permissions are used only during relevant user-initiated actions and are not abused or used for tracking purposes.
Data storage and security measures
TravelBuy SoftPOS implements appropriate technical and organisational safeguards, including:
- Encryption of data in transit using transport layer security (TLS)
- Encryption of sensitive data at rest, where applicable
- Role-based access controls
- Secure backend environments aligned with financial industry standards
- No storage of full card numbers, CVV values, or PIN data on the device
Where required, payment data handling aligns with PCI-DSS principles through approved service providers.
Data retention
Personal and transactional information is retained only for as long as necessary to:
- Process transactions and settlements
- Meet legal, regulatory and reporting obligations
- Resolve disputes, chargebacks or investigations
Once data is no longer required, it is securely deleted or anonymised in accordance with applicable laws.
Third-party and payment partners
TravelBuy SoftPOS integrates with regulated banks, payment processors and financial service providers, strictly for payment execution and compliance purposes.
All third parties are:
- Contractually bound to confidentiality and data protection obligations
- Required to comply with POPIA and applicable financial regulations
No data is shared beyond what is necessary for lawful processing.
User rights under POPIA
Under POPIA, users have the right to:
- Request access to personal information held about them
- Request correction of inaccurate or incomplete information
- Request deletion of personal data, where legally permissible
- Object to unlawful processing of their personal information
Users may submit requests for information through official TravelBuy support channels. Requests will be handled in accordance with POPIA timelines.
Protection of personal information of minors under POPIA
TravelBuy SoftPOS is not intended for individuals under the age of 18, defined as minors under POPIA. TravelBuy does not knowingly collect or process personal information of minors.
Policy updates
The TravelBuy SoftPOS Privacy Policy may be updated periodically to reflect legal, regulatory or operational changes.
Material updates will be published within the App or via official communication channels, together with a revised effective date.
Contact and complaints
For privacy-related queries, requests or complaints, users may contact TravelBuy via official support channels.
Email: support@travelbuy.co.za
Where unresolved, users may lodge a complaint with the Information Regulator of South Africa in accordance with POPIA.
Email: enquiries@inforegulator.org.za