Security help
Keep your information safe.
This guide explains how Fundaripay protects palm biometrics and how you can make POPIA requests in South Africa.
Biometrics stay tokenised. Merchants stay in control. Customers stay confident at the till.
For customers
What to do if something feels wrong
- Use your device security and keep access protected.
- Do not share your login details or enrolment access.
- If you suspect misuse, contact support right away so we can review your account.
- To delete your account and personal information, use delete account in the Fundaripay app or email support@fundaripay.com.
- To request access, correction, or deletion of specific personal information, make a POPIA request through support.
- If you are not satisfied with our response, you can lodge a complaint with the Information Regulator.
For merchants
Keep staff access and terminals secure
- Give staff access only when needed and remove access when roles change.
- Keep terminals physically secured before, during, and after trading.
- Train staff to follow customer consent expectations and privacy basics.
- If you receive a customer POPIA request, contact our privacy team so we can help you respond lawfully.
- Report lost devices, tampering, or suspected fraud immediately.
How your data is protected
Encryption, limited visibility, and lawful sharing
Personal information is encrypted in transit and at rest. Within Fundaripay operational systems, the only customer information visible for identity and support purposes is your South African identity number, first name and surname, email address, and mobile phone number.
Full card numbers, CVV codes, and PINs are never visible to Fundaripay. Card and payment credential data is encrypted and processed by our licensed payment facilitator. Palm images are never stored. When a palm is scanned at the terminal, the capture is encrypted and deleted immediately after processing.
Personal information is shared with our payment facilitator only where necessary to process payments lawfully under POPIA. Read our Privacy Policy and POPIA Act page for full details.
POPIA in plain language
Your rights as a data subject
Fundaripay supports privacy rights under POPIA in South Africa. We collect and process personal information only as needed for our services, and we secure it with appropriate technical and organisational measures.
- Request access to your personal information that we hold.
- Request correction of inaccurate personal information.
- Delete your account at any time in the app or by contacting support.
- Request deletion of personal information where applicable under POPIA.
- Object to processing that is not required under applicable law or contract.
- Withdraw consent where processing relies on consent, and where POPIA allows it.
- Ask us to explain our processing and the purposes for which we use your information.
How to submit a POPIA request
- Choose the request type you need.
- Include enough information for identity verification.
- Send it to support at the email address below.
- We will respond within the timelines required under POPIA and where we can, we will explain the outcome clearly.
Delete your account
Your right to account deletion under POPIA
You may delete your Fundaripay account at any time. Use delete account in the Fundaripay app settings, or email support@fundaripay.com from your registered email address and request account deletion.
When your account is deleted, we delete personal information linked to your account, including identity details, contact information, and biometric enrolment records, except where limited retention is required by South African law. We confirm once deletion is complete.
Report security issues responsibly
If you discover a security vulnerability, please do not publish details publicly. Send a report to us so we can investigate and remediate quickly.
- Send your report to security@fundaripay.com.
- Include a clear description, expected impact, and safe reproduction steps.
- Avoid testing on real customer accounts.
This page provides security guidance and POPIA information. It is not legal advice.
- 01
Tokenised biometrics
Palm data becomes a protected template, not a reusable photo of your hand.
- 02
Encrypted in transit
Every authorisation travels over TLS with modern cipher suites and strict transport security.
- 03
Merchant isolation
Access is scoped per business. Staff never see raw biometric material on the till.
- 04
Privacy by design
We collect only what settlement needs. You can review our Privacy Policy any time.
Stack
Four layers between the palm and the payout.
Layer 01
Capture
The sensor reads a live palm presentation at the till. No card number enters this step.
Layer 02
Tokenise
A template is derived and stored as a protected token, not a reusable photograph.
Layer 03
Authorise
The payment travels over TLS. Staff screens never show raw biometric material.
Layer 04
Settle
Funds move in rand. Access stays scoped per merchant so one business cannot see another.
Questions
Straight answers.
Palm images are never stored. Captures at the terminal are encrypted, processed, and deleted immediately. Fundaripay does not keep raw scan files or photographs on the till.
Read how we handle data.
Our Privacy Policy covers enrolment, immediate deletion of palm captures, retention, and your rights under POPIA.
