Privacy Policy
01Who we are and what this policy covers
Settld (Pty) Ltd ("Settld", "we", "us") is the responsible party for the personal information described in this policy. Our Information Officer is Warren Ross, Chief Executive Officer, reachable at [email protected]. This policy covers visitors to settld.global, people who contact us, people who query a charge through our charge-query service, and, once our services are live, customers who buy through our checkout and the personnel and beneficial owners of merchants we onboard. It explains what we collect, why, who we share it with, how long we keep it, and your rights under the Protection of Personal Information Act 4 of 2013 ("POPIA").
02What we collect
We collect what you give us and a limited amount of technical information. If you contact us: your name, email address and the content of your message. If you query a charge: the email address you may have used for a purchase, the date, amount and currency of the charge, the payment method type, the last four digits of a card or the mobile money number charged, and your description of the issue. We never ask for, and you must never send, full card numbers, PINs, passwords or one-time passcodes. When you visit the site: standard technical logs such as IP address, device and browser type, and the pages requested, used for security and to keep the site working. When our services are live, we will also process purchase and subscription information for customers buying through our checkout, and identity, contact and beneficial-ownership information for merchant onboarding, including where the law obliges us to conduct due diligence.
03Why we process it, and on what basis
We process personal information under POPIA's conditions for lawful processing, principally: to respond when you contact us; to identify and resolve charges you query, including cancelling subscriptions and processing refunds where appropriate; to operate, secure and improve the site; to onboard, underwrite and monitor merchants; to detect and prevent fraud and misuse; and to comply with the laws that apply to us, including financial-sector record-keeping and due-diligence obligations. Where processing rests on our or a third party's legitimate interests, we weigh those interests against your rights. We use Google Analytics to measure aggregated site usage, as described in our Cookie Policy; we run no advertising tracking on this site, and we do not use your information for third-party marketing.
05Cross-border transfers
Some of our service providers process information outside South Africa. Where that happens, we rely on the safeguards POPIA section 72 allows, principally contractual protections that hold the recipient to substantially similar standards, and the Information Officer keeps a record of the transfer bases and locations.
06Security and breaches
We apply appropriate, reasonable technical and organisational measures to secure personal information, as POPIA section 19 requires, and we hold our operators to the same standard under section 21. If a security compromise affects your information, we will notify the Information Regulator and, where required, you, as soon as reasonably possible after establishing the extent of it, as section 22 requires.
07Your rights
Under POPIA you may: request confirmation of, and access to, the personal information we hold about you; request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date or unlawfully obtained; object to processing conducted on legitimate-interest or direct-marketing grounds; withdraw consent where processing relies on it; and complain to the Information Regulator. To exercise any of these rights, contact the Information Officer at [email protected]. We respond within the periods POPIA allows and may need to verify your identity first. Requests under the Promotion of Access to Information Act 2 of 2000 may also be directed to the Information Officer.
08Children
Our site and services are directed at adults and businesses. We do not knowingly process the personal information of children, and if we learn that we have, we will delete it.
09Retention
We keep personal information only as long as necessary for the purpose it was collected and to meet our legal obligations. Charge-query correspondence is kept for as long as needed to resolve the query and for a reasonable period afterwards to evidence the resolution. Once our services are live, consent, transaction, dispute and due-diligence records will be kept for the periods financial-sector law requires, which is at least five years. When information is no longer needed and no legal hold applies, it is securely deleted.
11Changes and complaints
We may update this policy and will post the current version here with its effective date; material changes will be flagged on the site. If you are unhappy with how we have handled your information, contact the Information Officer first and give us the chance to put it right. You may also complain to the Information Regulator (South Africa) at any time via inforegulator.org.za.