Privacy Policy
Last updated: 9 June 2026 · Drafted with reference to the Protection of Personal Information Act, 2013 (POPIA)
1. Responsible party
Dragonstone Fintech ("DSF"), a product of Dragon Stone Ventures, is the responsible party for personal information collected through this website and our merchant onboarding platform. Contact: contact@dragonstone.ventures.
2. What we collect
- Website enquiries: your name, business name, email address, and anything you write in your message, together with the business profile options you select on this site.
- Merchant onboarding: business registration details, VAT and tax numbers, addresses, director and beneficial-owner details (including ID numbers), and supporting KYC/KYB documents you upload.
- Technical data: our hosting providers log standard request data (IP address, browser type) for security and reliability.
3. Why we process it
- To respond to your enquiry and assess fit for our services.
- To onboard and verify merchants as required by the Financial Intelligence Centre Act (FICA) and related anti-money-laundering law: this is a legal obligation we cannot opt out of.
- To provision payment services on the Eclipse platform operated by EFT Corporation.
- To maintain the security and integrity of our systems.
4. Who we share it with (operators/processors)
- EFT Corporation (Eclipse platform): merchant business details are used to create your payment organisation and wallet, and KYC/KYB verification is performed on the platform.
- Supabase (database, authentication and document storage, including delivery of website enquiries) and Vercel (website hosting).
Some of these providers process data outside South Africa (primarily in the EU and US). We only use providers that apply appropriate security safeguards, in line with section 72 of POPIA.
5. Security
Data is encrypted in transit (TLS) and at rest. Access to merchant records is restricted by role-based access controls. KYC documents are stored in a private bucket accessible only to you and authorised DSF staff.
6. Retention
Enquiry data is kept for as long as needed to handle your enquiry. Merchant and KYC records are retained for the periods required by FICA and tax legislation (generally five years after the end of the business relationship), after which they are deleted or de-identified.
7. Your rights under POPIA
- Ask what personal information we hold about you, and request correction or deletion (subject to legal retention duties).
- Object to processing, where the processing is not required by law.
- Complain to the Information Regulator (South Africa): inforegulator.org.za.
To exercise any of these rights, email contact@dragonstone.ventures.
8. Cookies and local storage
This website sets no cookies at all: no marketing, no analytics, no tracking. We use a small amount of essential storage in your browser to make the site work:
- Notice preference (localStorage): remembers that you dismissed the storage notice, so we do not show it on every visit.
- Your selection (sessionStorage): remembers the model you picked on the landing page for the length of your visit, so your enquiry reaches us with the right context.
Our merchant onboarding platform uses strictly necessary session storage to keep you signed in. If we ever introduce analytics or any non-essential cookies, we will ask for your consent first and update this policy before they are set.
9. Changes
We will update this policy as the service evolves and change the date at the top when we do.