Contents
1. Introduction2. Responsible Party3. What We Collect4. How We Collect It5. Why We Collect It6. Trust Score Data7. SMS Data8. Who We Share Data With9. Data Storage and Security10. Data Retention11. Your Rights Under POPIA12. Cookies13. Children14. Changes to This Policy15. Contact
Last updated
21 March 2026
Legal

Privacy Policy

How we collect, use, and protect your personal information. We believe in plain language and full transparency.

POPIA compliantNo data sellingSMS opt-out supported

1. Introduction

This Privacy Policy explains how EasyStokvel (Pty) Ltd ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our platform. We are committed to complying with the Protection of Personal Information Act, 2013 (POPIA) and all applicable South African data protection laws. By using EasyStokvel — whether through the website, dashboard, or SMS shortcode — you acknowledge that you have read and understood this Privacy Policy.

2. Responsible Party

EasyStokvel (Pty) Ltd is the responsible party as defined in POPIA. Email: support@easystokvel.co.za Website: easystokvel.co.za If you have any questions about how we handle your personal information, contact us at the email address above.

3. What We Collect

We collect the following personal information: — Phone number (required for registration and SMS service) — Name or display name (as provided by the treasurer) — Payment records (contribution amounts, dates, and statuses as entered on the platform) — Group membership data (which groups you belong to, your role) — Trust Score data (calculated from payment behaviour recorded on the platform) — Device and browser information (for security and platform improvement) — SMS interaction logs (messages sent to and received from our shortcode) We do not collect: — Banking details or bank account numbers — ID numbers (unless voluntarily provided) — Biometric data — Location data beyond what your browser provides by default

4. How We Collect It

We collect personal information in the following ways: — Directly from you when you register on the platform or text our shortcode — From your treasurer when they add you as a member of a group — Automatically through cookies and standard web analytics when you visit our website — Through our SMS service provider when you interact with our shortcode If a treasurer adds your phone number to a group, you will receive an SMS notification. You may opt out of the group by texting STOP to our shortcode.

5. Why We Collect It

We process your personal information for the following purposes: — To operate the platform and provide stokvel management tools — To send transactional SMS messages (payment confirmations, reminders, meeting notifications) — To calculate and maintain Trust Scores based on recorded payment behaviour — To authenticate your identity via OTP (one-time password) during login — To communicate service updates, billing notifications, and system alerts — To improve the platform based on usage patterns — To comply with legal obligations We will not use your personal information for any purpose other than those listed above without your consent.

6. Trust Score Data

Your Trust Score is calculated from payment behaviour recorded on the platform by your treasurer. It is a number between 0 and 100. Trust Scores are not credit scores. They are not shared with any credit bureau and are not regulated under the National Credit Act. Your Trust Score is visible to you and to the treasurer of any group you belong to. It is not publicly visible. We may in future offer anonymised, aggregated Trust Score data to financial partners for research and credit-risk modelling. If we do, no individual will be identifiable from this data. We will update this policy before any such sharing begins.

7. SMS Data

When you text our shortcode or receive an SMS from us, your phone number and message content are processed by these providers. We retain SMS interaction logs for 12 months for troubleshooting and compliance purposes. You may opt out of non-essential SMS messages at any time by texting STOP to our shortcode. You cannot opt out of essential transactional messages (such as OTP codes and payment confirmations) while your account is active. We do not send marketing SMS without your consent.

8. Who We Share Data With

We do not share your personal information with any third parties for their own marketing or data analysis purposes. We do not sell your personal information to any third party. We may disclose your information if required by law, court order, or regulatory authority.

9. Data Storage and Security

Your data is stored on servers that provide encryption at rest and in transit. We implement the following security measures: — Row-level security on all database tables — OTP-based authentication (no passwords stored) — HTTPS encryption on all web traffic — Access controls limiting who can view and modify data While we take reasonable steps to protect your information, no system is completely secure. We cannot guarantee absolute security of your data.

10. Data Retention

We retain your personal information for as long as your account is active. If you close your account, your data will be retained for 90 days to allow you to export records. After 90 days, personal data will be permanently deleted from active systems. We may retain anonymised data indefinitely for analytics and platform improvement. We retain records for a minimum of 5 years where required for legal or compliance purposes.

11. Your Rights Under POPIA

You have the following rights regarding your personal information: — Right to access: You may request a copy of the personal information we hold about you. — Right to correction: You may request that we correct inaccurate or incomplete information. — Right to deletion: You may request that we delete your personal information, subject to legal retention requirements. — Right to object: You may object to the processing of your personal information for specific purposes. — Right to withdraw consent: You may withdraw your consent to processing at any time, though this may affect your ability to use the platform. To exercise any of these rights, email support@easystokvel.co.za. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa at inforeg.org.za.

12. Cookies

We use essential cookies to keep you logged in and maintain your session. These are strictly necessary for the platform to function. We may use analytics cookies to understand how the platform is used. These do not identify you personally. We do not use advertising or tracking cookies.

13. Children

EasyStokvel is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it immediately.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via SMS or email at least 14 days before they take effect. The current version is always available at easystokvel.co.za/privacy.

15. Contact

EasyStokvel (Pty) Ltd Email: support@easystokvel.co.za Website: easystokvel.co.za Information Regulator (South Africa): inforeg.org.za
EasyStokvel (Pty) Ltd
Operating EasyStokvel · South Africa · 2026
TermsContactHome