Privacy Policy
MUSTANG FINANCIAL (PTY) LTD
MUSTANGPAY PRIVACY POLICY


Revision History:

Version Changes Date Modified Date Approval

1.0 First Version 17 October 2024



Approvals:

Document Owner: Mustang Financial (Pty) Ltd – Compliance Department
Approved By:



TABLE OF CONTENTS

1. INTRODUCTION 3
2. POLICY STATEMENT 3
3. DEFINITIONS 3
4. INFORMATION WE COLLECT 4
5. HOW WE USE YOUR INFORMATION 5
6. DATA SHARING AND DISCLOSURE 6
7. INTERNATIONAL TRANSFER OF DATA 6
8. DATA SECURITY 7
9. RETENTION OF INFORMATION 7
10. YOUR RIGHTS IN TERMS OF POPIA 7
11. CHANGES TO POLICY 7



1.INTRODUCTION

1.1This privacy policy (“Policy”) explains how MustangPay, as a third-party payment service provider (“We”, “Us”, or “Our”), collects, stores, uses, and discloses your personal and business information when you interact with our platform, including but not limited to our website, mobile applications, and associated payment services (collectively referred to as “Services”).
1.2We are committed to protecting your privacy and ensuring the security of your information. By accessing or using our Services, you agree to the collection and use of your information in accordance with this Policy. Should you sign up as a merchant, the collection, use, and disclosure of your customers' information (which you shall have sole responsibility for the accuracy, quality and legality of such customer information) will be governed by this Policy and the Master Terms of Service Agreement (“MSA”) you enter into with us.
1.3This Policy does not apply to third-party websites, products, or services that are not operated or controlled by MustangPay, even in the event that they link to our Services or vice versa. We advise you to review the privacy policies of any third parties involved.



2.POLICY STATEMENT

2.1This Privacy Policy is established to protect the privacy of users and to comply with relevant data protection laws, including but not limited to the Protection of Personal Information Act No. 4 of 2013 (“POPIA”) of South Africa, and any other applicable privacy laws. MustangPay recognizes the importance of the lawful processing of personal and business data, and this Policy sets out our commitment to ensure that all information collected is handled with the highest level of integrity, confidentiality, and security.
2.2In essence, this Privacy Policy outlines the practices and procedures MustangPay follows to protect data, ensuring that all information is collected, used, and disclosed in accordance with the legal rights of the users. By doing so, we seek to build trust with users, who can engage with our platform, services, and payment systems knowing that their data is managed responsibly.



3.DEFINITIONS

3.1For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them:
3.1.1Date Protection Laws and Regulation – means all data protection or data privacy laws and regulations, including the Protection of Personal Information Act (No. 4 of 2013) and any other data protection legislation and/or regulation applicable to the parties in respect of Personal Information as defined in the Protection of Personal Information Act (No. 4 of 2013) which may be processed;
3.1.2Personal Information – means any information relating to an identified or identifiable natural person or an identified or identifiable legal entity (where such information is protected similarly as personal data or personally identifiable information under applicable data protection laws and regulations). This can include names, addresses, email addresses, identification numbers, or other factors specific to the identity of that person;
3.1.3Business Information – refers to information related to businesses, including company names, business registration numbers, tax numbers, bank details, and any other relevant details for conducting business transactions;
3.1.4User – refers to any individual or entity that accesses, uses, or interacts with the MustangPay platform or services, including merchants, customers, and business partners;
3.1.5Processing – refers to any operation or set of operations performed on personal or business information, whether automated or manual. This includes collection, storage, use, disclosure, or deletion of such information;
3.1.6Third-Party Service Providers – means external companies or entities that provide services to MustangPay, such as cloud storage, payment processing, fraud prevention, or customer support;
3.1.7Cookies – refers to small data files that are stored on a user's device by the website or application to collect data on usage patterns, preferences, and device information; and
3.1.8Data Subject – refers to the individual or entity whose data is collected, used, or disclosed by MustangPay during the provision of services.



4.INFORMATION WE COLLECT

4.1MustangPay collects both personal and business information directly from users when they engage with our services. This includes information voluntarily provided when creating accounts, communicating with our customer service team, or submitting feedback. The information collected includes but is not limited to full names, title, position, employer, contact information (company contact information, email addresses, contact numbers, physical addresses), identification details, business registration information, financial records, account numbers and transactional data. Additionally, users may provide us with information when participating in surveys, promotions, or by submitting requests through the platform.
4.2We also automatically gather certain data through the use of cookies, tracking pixels, and server logs. This includes information such as IP addresses, device information, browser types, operating system details, geographic location, and user behaviour on the platform. This data is critical for maintaining the platform’s security and improving user experience. If users prefer to restrict the use of cookies, they may modify their browser settings; however, doing so may affect their ability to fully utilize our services.
4.3We process customers personal information on explicit written instructions by the merchant in terms of applicable Data Protection Laws and Regulations. To the extent legally permitted, the merchant shall be responsible for any costs arising from provision of any assistance by us under this clause.



5.HOW WE USE YOUR INFORMATION

5.1The information collected is utilized for a range of legitimate business purposes. Primarily, we use personal and business data to deliver, manage, and improve the services we offer. This includes processing payments, facilitating transactions, managing user accounts, and offering customer support.
5.2Compliance with legal and regulatory requirements is another key use of the information we collect. MustangPay is obligated to adhere to the National Payment System Act (“NPSA”) and other financial regulations. Information is collected for purposes such as anti-money laundering compliance, fraud detection and prevention, and ensuring transparency in our operations.
5.3We also use data to customize user experiences, providing personalized content and targeted marketing where applicable, and ensuring that users receive relevant offers. Users can opt out of receiving marketing communications at any time by following the unsubscribe instructions in any such communication or by contacting us directly.
5.4Additionally, MustangPay employs data analytics to monitor platform usage, conduct research, and develop new products or services that enhance user experience. Information collected through analytics is anonymized or aggregated to protect user privacy.
5.5Security is a priority, and we use collected data to identify and prevent potential risks such as fraud, unauthorized access, and illegal activities. We also use information to maintain the integrity and security of the platform, employing technologies like encryption and access control measures.
5.6Finally, in certain instances, we may need to disclose your information to comply with legal obligations or regulatory requests, respond to governmental inquiries, or in the course of legal proceedings. In such cases, only the information required to fulfil these legal obligations will be shared.



6.DATA SHARING AND DISCLOSURE

6.1MustangPay does not sell your personal information. However, to provide certain services, we may need to share your data with trusted third-party service providers. These providers may offer cloud hosting services, payment processing solutions, or verification tools that are necessary for the operation of the platform. All third-party service providers are vetted to ensure they comply with relevant data protection laws and maintain the security of your information.
6.2We may also share information with our corporate affiliates, including subsidiaries or partners, for purposes aligned with those outlined in this Policy. In the event of corporate mergers, acquisitions, or other business transactions, your information may be transferred as part of the company's assets. Should this occur, the new entity will be required to uphold the same commitments to privacy.
6.3Where mandated by law or necessary to protect our rights, we may disclose user information in response to court orders, subpoenas, or legal investigations. This can also apply if we detect fraudulent or suspicious activity, in which case we may share information with relevant financial institutions or law enforcement agencies.



7.INTERNATIONAL TRANSFER OF DATA

7.1Given the global nature of our operations, your data may be transferred to and stored in countries outside your own jurisdiction. This may include transfers to regions such as the Peoples Republic of China, the European Union, the United States, or wherever MustangPay and its partners operate. We take the necessary steps to ensure that such transfers comply with applicable data protection laws, utilizing mechanisms such as standard contractual clauses or similar legal safeguard.



8.DATA SECURITY

8.1MustangPay employs a variety of security measures designed to protect your personal and business information from unauthorized access, alteration, disclosure, or destruction. These measures include encryption technologies, secure server infrastructure, and restricted access to sensitive data. Employees and service providers who have access to personal data are required to adhere to strict confidentiality obligations.
8.2While we take every precaution to safeguard your data, no system is entirely infallible. Users are encouraged to protect their account credentials and exercise caution when sharing sensitive information. Should you suspect any breach of security involving your account, we urge you to report it immediately to our support team.
9.RETENTION OF INFORMATION
9.1We retain personal and business information for as long as is necessary to fulfil the purposes outlined in this Privacy Policy. This duration will vary depending on legal, regulatory, or contractual requirements. Once the retention period expires, we will securely delete or anonymize the data, ensuring compliance with applicable legal obligations.



10.YOUR RIGHTS IN TERMS OF POPIA

10.1You have certain rights concerning your personal information. These include the right to access the data we hold about you, request corrections to inaccuracies, and request the deletion of your information in specific circumstances. You also have the right to object to certain processing activities, such as marketing communications. Requests regarding your data can be made by contacting our data protection team, and we will endeavour to fulfil your request in accordance with applicable legal requirements.
10.2For any inquiries related to this Privacy Policy or your personal data, you may contact us at [xxx].



11.CHANGES TO POLICY

11.1We reserve the right to modify this Privacy Policy from time to time in response to changes in our business, legal obligations, or advancements in technology. Any significant updates will be posted on our website, and it is your responsibility to regularly access our website to ensure that you are aware of these updates. The effective date at the top of this Policy will reflect the latest revision. Continued use of our services following these changes will be considered your acceptance of the updated Policy.