Privacy policy

Draft — pending legal review. Last updated 2026/10/05.

This platform processes personal information on behalf of the businesses that use it (our merchants), which makes SubCharge an Operator under the Protection of Personal Information Act (POPIA). Merchants remain the Responsible Party for their own customers' data. A qualified attorney must review this policy, our terms and our Data Processing Agreement before this platform processes any live customer's personal information.

What we process, and on whose instruction

Two categories of personal information pass through SubCharge. Our own account data — the staff who sign in to a merchant's dashboard — is processed on the basis of the contract between us and that merchant. A merchant's customer data — names, emails, phone numbers and billing history — is processed only on that merchant's instructions, as set out in our Data Processing Agreement (see /legal/dpa). We never sell personal information, and we never use a merchant's customer data for our own marketing.

Special personal data

We do not collect government ID numbers, health data or other special personal information. Membership businesses such as schools may submit details of minors as part of billing a parent or guardian's subscription — merchants using SubCharge for this must have the lawful right to process that data themselves.

Cross-border transfers

Our infrastructure runs on Neon (hosted on AWS, us-east-1) and Vercel, which means personal information is transferred and stored outside South Africa. Each payment add-on's provider — PayFast, Paystack or Peach Payments — separately processes payment data as the merchant's own processor, under that provider's own terms.

Retention

Financial records (invoices, payments and the consent records behind them) are retained for 5 years to meet SARS requirements. Audit logs are retained for 1 year. When a customer is deleted, their personal fields are anonymised rather than removed outright, with financial records kept intact for the retention period above.

Your rights, and how to exercise them

If you are a merchant's customer, requests to access, correct or delete your personal information should go to that merchant directly — they are the Responsible Party and hold the context to action your request. If you are a merchant, or need to reach us directly about our own processing of your staff accounts, use the contact details below.

Data breaches

If a breach affects your personal information, we notify affected merchants without delay, and follow the Information Regulator's process where required. See our security practices at /security.

Information Officer

Contact details for our Information Officer will be published here before this platform processes any live customer's data.