Privacy Policy

Last updated: 9 June 2026 · Drafted with reference to the Protection of Personal Information Act, 2013 (POPIA)

1. Responsible party

Dragonstone Fintech ("DSF"), a product of Dragon Stone Ventures, is the responsible party for personal information collected through this website and our merchant onboarding platform. Contact: contact@dragonstone.ventures.

2. What we collect

3. Why we process it

4. Who we share it with (operators/processors)

Some of these providers process data outside South Africa (primarily in the EU and US). We only use providers that apply appropriate security safeguards, in line with section 72 of POPIA.

5. Security

Data is encrypted in transit (TLS) and at rest. Access to merchant records is restricted by role-based access controls. KYC documents are stored in a private bucket accessible only to you and authorised DSF staff.

6. Retention

Enquiry data is kept for as long as needed to handle your enquiry. Merchant and KYC records are retained for the periods required by FICA and tax legislation (generally five years after the end of the business relationship), after which they are deleted or de-identified.

7. Your rights under POPIA

To exercise any of these rights, email contact@dragonstone.ventures.

8. Cookies and local storage

This website sets no cookies at all: no marketing, no analytics, no tracking. We use a small amount of essential storage in your browser to make the site work:

Our merchant onboarding platform uses strictly necessary session storage to keep you signed in. If we ever introduce analytics or any non-essential cookies, we will ask for your consent first and update this policy before they are set.

9. Changes

We will update this policy as the service evolves and change the date at the top when we do.

An Information Officer will be registered with the Information Regulator as part of company incorporation. Until then, privacy queries are handled directly by the founders at the address above.