Privacy Policy
TIPPED™
Privacy Policy
How Tipped™ collects, uses, protects and shares personal information
Entity: iThemba Voucher (Pty) Ltd t/a Tipped™ (Registration No. 2020/601718/07)
Effective date: 4 August 2026
Contact: support@tipped.biz |
This Privacy Policy applies to the Tipped™ mobile application, website, QR and payment journeys, wallet features, support channels and related services (together, the “Services”). It must be read with the Tipped™ User Terms and Conditions.
Tipped™ respects your privacy and processes personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable South African laws.
1. Who is responsible for your information
iThemba Voucher (Pty) Ltd t/a Tipped™ (“Tipped”, “we”, “us” or “our”) is the responsible party for personal information processed for the operation of the Tipped platform and Services, unless a third-party provider processes information for its own independently determined purposes.
Tipped owns and operates its core platform technology. Core Tippee profile, support and operational data is hosted and administered within systems controlled by Tipped. We do not outsource ownership or general control of the Tippee database. Certain providers must nevertheless receive and retain limited information to process payments, wallet functions, cash-outs, purchases, verification or compliance checks.
2. Who this policy applies to
This Policy applies to Tippees, tippers, corporate or merchant users, website visitors, prospective users and any person who contacts or interacts with Tipped. “Tippee” means a person registered to receive and use tips or rewards through Tipped.
3. Personal information we collect
The information collected depends on how you use the Services and your verification level. It may include:
- Profile and contact information: name, surname, cellphone number, email address, residential address, date of birth, gender, nationality, workplace or merchant association, profile image and unique Tipped account identifier.
- Identity and KYC information: identity number, identity document, passport, driver’s licence, permit or other supporting documents; selfie or face image; liveness, document-authenticity and face-match results; and information required to confirm that you are the person opening or using the account.
- AML and risk information: verification results, sanctions or politically exposed person screening, risk indicators, unusual-activity information, fraud indicators, source-of-funds or source-of-wealth information and supporting evidence where reasonably required.
- Financial and transaction information: bank account details and proof of account, wallet balance and ledger entries, tip and reward details, payment and cash-out references, amounts, dates, times, merchant or Tippee details, voucher and VAS purchases, refunds, reversals and transaction status.
- Device, usage and security information: IP address, device identifiers, operating system, app version, browser, session and log data, access times, activity records, authentication events, diagnostics and security alerts.
- Communications and support information: messages, calls, emails, support tickets, complaints, feedback and documents submitted to resolve a query.
- Optional permissions: camera access for identity checks and QR functions, location where a location-based feature is used, and contacts only where you choose a function that requires them. You can manage device permissions in your device settings, although some features may then not work.
- Tipper information: limited payment, device and transaction information supplied during a tip, including the amount, time, payment reference and intended Tippee. Tipped does not ordinarily receive or store a payer’s full card details.
4. Where information comes from
We collect information directly from you; from your device and use of the Services; from a participating employer, merchant or corporate partner that links you to a workplace or tipping programme; from payment, wallet, cash-out, voucher and compliance providers; from banks, card schemes and payment networks; and from lawful public, regulatory, sanctions or fraud-prevention sources.
If another person provides information about you, they must be authorised to do so and must ensure that the information is accurate.
5. Why we process personal information
We process personal information only where there is a lawful basis, including performance of our agreement with you, compliance with law, your consent, protection of legitimate interests, or another basis permitted by POPIA. We use information to:
- create, verify, maintain and secure your account;
- provide wallet functionality and record tips, rewards, purchases, transfers and balances;
- process incoming tips, spending, vouchers, VAS purchases and cash-outs;
- perform KYC, AML, sanctions, fraud and risk checks and meet applicable legal, regulatory and provider requirements;
- confirm bank details and prevent payments to an incorrect or unauthorised account;
- respond to support requests, complaints, disputes and transaction queries;
- send essential service, security, account and transaction communications;
- monitor, troubleshoot, audit and improve the Services and develop new features;
- produce de-identified or aggregated reporting and insights; and
- protect and enforce our rights, investigate misuse and comply with lawful requests.
Where information is mandatory for registration, verification or a transaction, failing to provide it may prevent us from opening an account, enabling a feature or completing a transaction.
6. AI-assisted KYC and automated processing
Tipped uses artificial intelligence and automated tools to assist with KYC. These tools may read identity documents, check image quality and authenticity, perform liveness or face-matching checks, detect duplicate or inconsistent information and assign a verification result or risk indicator.
An automated result may approve an account, request better information, pause onboarding or refer a case for review. Where a decision has legal or similarly significant effects, Tipped will not rely solely on automated processing unless permitted by law and appropriate safeguards are in place. You may request human review, provide additional information and challenge an adverse or inconclusive outcome by contacting support@tipped.biz.
AML screening is performed with the assistance of Ideco. Restricted AML, sanctions, criminal or suspicious-activity matters are reviewed through Tipped’s approved compliance process and may not be discussed where the law prohibits disclosure.
7. Service providers and information sharing
We share only the information reasonably necessary for the relevant service. Our current service chain includes:
- VALR – wallet-related infrastructure and processing;
- Paysoft – cash-out and bank payout processing;
- Stitch and Yoco – incoming tip and payment processing;
- Scan to Pay – payment and spending functionality;
- 1Voucher – value-added services, airtime, data and voucher products; and
- Ideco – AML screening and related compliance checks.
We may also share information with banks, card schemes, payment networks, merchants, participating employers or corporate partners, telecommunications and messaging providers, hosting and cybersecurity providers, auditors, insurers, professional advisers, regulators, law-enforcement bodies and courts where necessary and lawful.
A provider may act as Tipped’s operator, as a joint responsible party, or as an independent responsible party depending on the service and contract. Providers may have their own privacy terms. Tipped remains responsible for its own processing and requires operators acting for Tipped to protect information through appropriate contractual and security measures.
We do not sell personal information. We do not disclose identifiable Tippee information to advertisers for their independent direct marketing without a lawful basis and any required consent.
8. Corporate and employer reporting
If your account is linked to a participating employer, merchant or corporate programme, Tipped may provide that organisation with information reasonably required to administer the programme, such as your name, account identifier, workplace link, onboarding or verification status, tip or reward totals, allocation records and de-identified or aggregated performance reporting.
We do not provide unnecessary identity documents, biometric material, full bank details or unrestricted wallet activity to an employer or corporate partner. Any wider sharing must have a lawful purpose and appropriate notice or consent.
9. Storage and security
Tipped applies appropriate, reasonable technical and organisational safeguards designed to protect information against loss, damage, unauthorised destruction, access, use, alteration or disclosure. Measures include role-based access, authentication controls, encryption where appropriate, logging, monitoring, backups, staff confidentiality duties, provider due diligence and incident-response procedures.
No internet or electronic system is completely secure. You must protect your PIN, password, OTP and device, use current software, and notify Tipped promptly if you suspect unauthorised access.
10. Cross-border processing
Core Tippee data is controlled by Tipped, but a service provider or its infrastructure may process or back up limited information outside South Africa. Where a cross-border transfer occurs, Tipped will apply section 72 of POPIA and use an appropriate lawful basis and safeguards, such as binding contractual protections or a recipient subject to substantially similar data-protection requirements.
11. Retention and deletion
We retain information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, resolve disputes, prevent fraud and comply with legal, tax, financial intelligence, audit and recordkeeping duties. KYC, AML and transaction records may need to be retained for at least five years or for a longer period where required by law, a regulator, litigation hold or an active dispute.
When retention is no longer required, information is securely deleted, destroyed or de-identified. Closing your profile does not require Tipped or a provider to delete records that must lawfully be retained.
12. Your rights
Subject to POPIA, PAIA and other applicable law, you may:
- ask whether Tipped holds personal information about you;
- request access to your personal information and information about relevant recipients;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing based on legitimate interests in the prescribed manner;
- withdraw consent where processing relies on consent, without affecting prior lawful processing;
- request human review of a qualifying automated decision;
- opt out of direct marketing; and
- lodge a complaint with the Information Regulator.
Send a request to support@tipped.biz. We may ask for adequate proof of identity before providing or changing information. A request may be limited or refused where the law permits or requires this, and we will explain the applicable reason where allowed.
13. Marketing, service messages and cookies
We may send essential service, security and transaction messages without treating them as marketing. We send electronic direct marketing only where permitted by law and will provide a simple way to opt out. Opting out of marketing does not stop essential account or transaction communications.
Our website and app may use necessary, functional, analytics and security cookies or similar technologies. You may manage optional cookies through available consent tools or browser settings, although disabling some technologies may affect functionality.
14. Security compromises
If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Tipped will investigate and notify the Information Regulator and affected persons as required by POPIA, subject to any lawful delay requested by law enforcement.
15. Children
The Services are intended for persons aged 18 or older unless Tipped has expressly approved a lawful guardian-consent arrangement. If we learn that a child’s information was processed without proper authority, we will take appropriate steps to restrict or delete it, subject to legal retention duties.
16. Third-party links and services
The Services may link to third-party sites, applications or checkout pages. Their terms and privacy notices apply to processing they control. Tipped is not responsible for an independent third party’s content or privacy practices, but will assist with a service-related query where reasonably possible.
17. Changes to this Policy
We may update this Policy when our Services, providers or legal duties change. The latest version and effective date will be published through the app or website. We will give reasonable notice of material changes where required.
18. Contact and complaints
Information Officer: Chief Executive Officer of iThemba Voucher (Pty) Ltd (contact via support@tipped.biz)
Business address: 166 Main Street, Nieuw Muckleneuk, Pretoria, 0181, South Africa
Customer care: +27 65 708 7076 | Monday to Friday, 08:00-17:00
For privacy requests or complaints: support@tipped.biz
Information Regulator (South Africa): POPIAComplaints@inforegulator.org.za | 010 023 5200 | www.inforegulator.org.za