Privacy Commitment
Effective Date: 3 September 2026
Your privacy is fundamental to the trust you place in OSQR. OSQR Technologies (Pty) Ltd ("OSQR", "we", "our" or "us") is committed to protecting the privacy, confidentiality and security of the Personal Information entrusted to us by our customers, merchants, business partners and other users of the OSQR Pay Platform.
This Privacy Policy explains how we collect, use, store, disclose, protect and otherwise process Personal Information when you use OSQR Pay and related products or services. Our processing is guided by accountability, lawfulness, transparency, purpose limitation, data minimisation, information quality, security safeguards, openness and responsible innovation.
Where applicable, OSQR processes Personal Information in accordance with the Protection of Personal Information Act, 2013 ("POPIA"), the Electronic Communications and Transactions Act, 2002 ("ECTA"), the Consumer Protection Act, 2008, the Financial Intelligence Centre Act, 2001 ("FICA"), and other applicable South African legislation. By using the OSQR Pay Platform, you acknowledge that you have read and understood this Privacy Policy.
Scope of this Privacy Policy
This Privacy Policy applies to Personal Information processed by OSQR through the OSQR Pay mobile application, website, merchant portals, customer support services, digital wallet services, QR code payment services, transport payment services, loyalty and rewards programmes, merchant services, APIs, integrations and future digital products forming part of the OSQR Ecosystem.
It applies to registered and prospective Users, Merchants, Business Partners, Mobility Partners, corporate clients, suppliers where applicable, and visitors to OSQR digital platforms. Certain products or services may have additional privacy notices that supplement this Privacy Policy. This Privacy Policy should be read together with the OSQR Pay Platform Terms and Conditions.
Information We Collect
Depending on the Services you use, OSQR may collect identity information such as full names, South African ID or passport number, date of birth, nationality, photograph and biometric verification data where permitted by law; contact information such as mobile number, email address, residential address and postal address; and financial information such as bank account details, payment card information, digital wallet identifiers, transaction history and merchant payment information.
We may also collect technical information including device identifiers, device model, operating system, IP address, mobile network information, browser information and application version; usage information including login activity, payment history, QR code usage, loyalty activity, merchant interactions, transport payment activity and customer support interactions; and communication information including emails, chat messages, support recordings, survey responses and feedback.
Where enabled or necessary for specific Services, OSQR may collect approximate or precise location information for fraud prevention, locating nearby merchants, transport services, improving customer experience and regulatory compliance. OSQR will only collect Personal Information that is reasonably necessary to provide the Services, comply with legal obligations or improve the OSQR Ecosystem.
How We Collect Personal Information
OSQR collects Personal Information directly from you, automatically through your use of the Platform, and, where permitted by law, from trusted third parties. We collect information you provide when you register for an OSQR Pay Account, verify your identity, link payment cards or bank accounts, complete Merchant registration, contact Customer Support, participate in surveys or promotions, enter competitions or campaigns, join loyalty or rewards programmes, use Group Banking services, or communicate with OSQR through an approved channel.
When you use the Platform, we may automatically collect device information, application usage data, operating system details, network information, login history, transaction activity, QR code interactions, session information, diagnostic and performance data, and security logs. Where permitted by law, OSQR may obtain Personal Information from participating banks, payment service providers, card schemes, Merchants, Business Partners, Mobility Partners, identity verification providers, credit bureaux, fraud prevention service providers, public registers and government authorities. You are responsible for ensuring that information you provide is accurate, complete and up to date.
Why We Process Personal Information
OSQR processes Personal Information only for legitimate, lawful and clearly defined purposes, including creating and managing Accounts, verifying Users, maintaining account security, providing customer support, processing and settling Transactions, enabling QR code and merchant payments, and supporting transport fare payments.
We also process Personal Information to comply with FICA, anti-money laundering, tax and financial reporting obligations; respond to lawful requests; prevent fraud; detect suspicious activity; monitor cybersecurity threats; protect Users and Business Partners; improve Platform functionality; develop Services; personalise the User experience; administer rewards; improve accessibility; provide service updates and security notifications; respond to enquiries; and notify Users of changes to our Services or legal documents. OSQR will not process Personal Information for purposes incompatible with the purposes for which it was originally collected unless permitted or required by applicable law.
Lawful Basis for Processing
OSQR processes Personal Information only where there is a lawful basis to do so. Depending on the circumstances, processing may be based on your consent, the performance of a contract with you, compliance with legal or regulatory obligations, protection of your legitimate interests or those of another person, OSQR's legitimate business interests where those interests do not override your rights and freedoms, or another authorisation under applicable South African law.
Where OSQR relies on your consent, you may withdraw that consent at any time, subject to legal or contractual limitations. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. Certain Services may no longer be available where the processing is necessary to provide them.
Identity Verification and Regulatory Compliance
As a financial technology platform operating within the South African financial services sector, OSQR may be required to verify your identity before providing certain Services. To comply with applicable legislation, including FICA, we may collect and verify identity documents, passports, visas or residence permits, proof of address, business registration documents, tax information, biometric verification, photographs and other supporting documentation required by law.
OSQR may verify this information using authorised verification providers, participating financial institutions or government databases where legally permitted. Where required by law, OSQR may retain verification records for the applicable retention period, even after your Account has been closed. Failure to provide required verification information may result in delayed activation, restricted functionality or refusal of certain Services.
Payment and Transaction Information
To provide secure payment services, OSQR processes payment card identifiers, tokenised payment credentials, linked bank account information, merchant identifiers, QR Code transaction data, transaction amounts, payment references, settlement information, loyalty and rewards information, transport payment records, timestamps and transaction locations where required.
We use this information to process and authorise Transactions, detect and prevent fraud, comply with legal and regulatory obligations, resolve payment disputes, administer loyalty and rewards programmes, and improve payment performance and reliability. Sensitive payment credentials are protected using encryption, tokenisation and secure authentication technologies where applicable. OSQR does not intentionally retain CVV or CVC data except where expressly permitted by law and applicable payment scheme rules.
Artificial Intelligence and Automated Processing
OSQR may use Artificial Intelligence ("AI"), machine learning and other automated technologies for fraud detection, identity verification, cybersecurity monitoring, transaction risk analysis, customer support assistance, service personalisation, loyalty optimisation, accessibility improvements, operational efficiency and product development.
Where AI is used, OSQR will seek to ensure that Personal Information is processed lawfully, appropriate safeguards are implemented, automated systems are monitored, significant decisions are subject to human oversight where required by law, and unfair discrimination is minimised. OSQR will not use AI in a manner inconsistent with applicable law or this Privacy Policy.
Sharing Personal Information
OSQR treats Personal Information as confidential and will not sell your Personal Information to third parties. Where reasonably necessary, it may be shared with participating financial institutions, payment service providers, payment networks and card schemes, Merchants, Mobility Partners, Business Partners, identity verification providers, fraud prevention agencies, cloud hosting providers, technology service providers, auditors, legal advisers, regulators, law enforcement agencies, courts and competent authorities.
Third parties receiving Personal Information are required, where applicable, to protect it using appropriate contractual, technical and organisational safeguards. Service providers processing Personal Information on OSQR's behalf may only process it in accordance with OSQR's instructions and applicable law. OSQR may disclose Personal Information where necessary to comply with legal obligations, enforce the Terms, protect Users, investigate fraud, protect the integrity of the Platform or respond to lawful requests.
Information Security
OSQR implements administrative, technical and physical safeguards designed to protect Personal Information against accidental loss, unauthorised access, misuse, alteration, disclosure or destruction. Measures may include encryption of data in transit and at rest where appropriate, tokenisation of payment credentials, multi-factor authentication, secure software development, continuous security monitoring, vulnerability assessments, penetration testing, fraud detection, business-need access controls and security awareness training.
No electronic system can be guaranteed to be completely secure. Users also play an important role by safeguarding passwords, devices and authentication credentials. Where required by applicable law, OSQR will notify affected individuals and relevant authorities of eligible Personal Information security compromises within the prescribed timeframes.
International Transfers
OSQR primarily stores and processes Personal Information within the Republic of South Africa. In certain circumstances, Personal Information may be transferred to or processed in another country where necessary to provide the Services, use reputable cloud hosting providers, support international payment processing, comply with legal obligations or use trusted technology service providers.
Before transferring Personal Information outside South Africa, OSQR will take reasonable steps to ensure appropriate safeguards are in place in accordance with POPIA. These may include contractual protections, transfers to countries with substantially similar data protection laws, consent where required, or another lawful transfer mechanism recognised under POPIA.
Retention of Personal Information
OSQR retains Personal Information for three years, unless a longer period is required or permitted by law. This period may be extended where necessary for legal and regulatory obligations, financial reporting, tax legislation, FICA record-keeping, fraud prevention investigations, dispute resolution or contractual requirements.
Once Personal Information is no longer required, OSQR will securely delete, destroy or anonymise it in accordance with applicable law and internal retention policies. Information may continue to be retained after an Account is closed where required by law or necessary to establish, exercise or defend legal claims.
Your Privacy Rights Under POPIA
Subject to applicable law, you may have the right to request confirmation that OSQR holds your Personal Information; request access to it; request correction of inaccurate or incomplete information; request deletion where appropriate; object to certain processing; withdraw consent; request restrictions on processing where permitted; and lodge a complaint with the Information Regulator.
OSQR may require reasonable proof of identity before responding to a request. Where permitted by law, requests may be declined if manifestly unfounded, excessive, or where another lawful basis exists for refusing the request. OSQR will provide reasons where required.
Marketing Communications
OSQR may send communications relating to service updates, security notifications, product announcements, loyalty and rewards programmes, educational content and promotional offers where permitted by law. Where required, OSQR will obtain consent before sending direct marketing communications.
You may withdraw marketing preferences by updating communication preferences within the Platform, selecting the unsubscribe option in electronic communications or contacting OSQR Customer Support. Essential operational and security communications will continue where necessary to provide the Services.
Cookies and Similar Technologies
OSQR may use cookies, software development kits, pixels and similar technologies on its website and digital platforms to improve functionality, security and user experience. These technologies may remember preferences, maintain secure sessions, analyse performance, detect fraud, improve functionality and measure communications.
Where required by law, Users will be provided with choices regarding non-essential cookies and similar technologies. Browser or device settings may be used to manage certain cookies, but disabling them may affect Platform or website functionality.
Children's Privacy
The OSQR Pay Platform is intended for persons legally capable of entering into binding agreements under applicable South African law. OSQR does not knowingly collect Personal Information directly from children except where permitted or required by law, parental or legal guardian consent has been obtained where required, or processing is necessary for a lawful purpose authorised under applicable legislation.
Where OSQR becomes aware that Personal Information has been collected from a child in a manner that does not comply with applicable law, OSQR will take reasonable steps to delete or otherwise lawfully process it. Parents or legal guardians may contact OSQR regarding inappropriate collection of a child's Personal Information.
Changes to this Privacy Policy
OSQR may amend this Privacy Policy from time to time to comply with changes in law, reflect new products or services, improve transparency, address security or operational requirements, reflect developments in technology or improve the protection of Personal Information.
Where required by applicable law, OSQR will provide reasonable notice of material changes before they become effective. The latest version will be published through the OSQR Pay Platform, the official OSQR website and other appropriate communication channels. Continued use after the effective date constitutes acknowledgement of the revised Policy where permitted by law.
Information Officer and Contact Details
OSQR has appointed, or will appoint, an Information Officer in accordance with POPIA. The Information Officer oversees POPIA compliance, responsible information governance, Personal Information requests and complaints, security incident responses, and liaison with the Information Regulator where required.
Privacy-related requests or enquiries may be submitted through the official OSQR Pay Platform or official OSQR website. Users should provide sufficient information to enable OSQR to verify their identity and respond appropriately.
Complaints to the Information Regulator
If you believe OSQR has processed your Personal Information inconsistently with applicable law, you are encouraged to contact OSQR first so that we can investigate and resolve your concern. If it is not resolved to your satisfaction, or if you believe your POPIA rights have been infringed, you may lodge a complaint with the Information Regulator of South Africa.
Nothing in this Privacy Policy limits rights or remedies available under applicable South African law. OSQR is committed to cooperating with the Information Regulator and other competent authorities in accordance with applicable legislation.
Our Privacy Promise
At OSQR, privacy is more than a legal requirement. We are committed to collecting only Personal Information reasonably necessary to provide our Services; using it lawfully, fairly and transparently; protecting it through appropriate technical and organisational safeguards; giving Users clear information; respecting rights under POPIA and other applicable laws; and continuously improving our privacy and security practices.
As the OSQR Ecosystem grows, our commitment to protecting your Personal Information will remain at the centre of every product, service and innovation we develop.
