1. Who we are
StaffPayAi (Pty) Ltd, a company registered in the Republic of South Africa ("StaffPay", "we", "us"), operates the StaffPay AI workforce management and payroll service, including the StaffPay AI Admin, StaffPay AI Staff, StaffPay AI Registry, StaffPay AI Sales, and StaffPay HeadOffice mobile applications, as well as the staffpayai.com web application. This Privacy Policy describes how we collect, use, store, and protect personal information.
We comply with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), South Africa's data protection law.
2. Two roles: customer data vs employee data
Our service involves two distinct types of personal information:
- Customer (account holder) data: Information about the business that subscribes to StaffPay — company name, billing email, admin contact name, payment information. We are the "responsible party" under POPIA in respect of this information.
- Employee data uploaded by customers: Information about your staff — names, ID numbers, photos, sign-in/out records, payslips, leave records, biometric face templates. You are the responsible party under POPIA in respect of this information; StaffPay acts as an "operator" processing it strictly on your instructions and only as needed to provide the Service.
3. What customer data we collect
- Company name and slug
- Admin name and email address
- Hashed password for account login
- Subscription plan, billing history, invoice numbers
- PayFast subscription token (we never see or store card details)
- Login timestamps and IP addresses for security audit
- Support ticket messages and chat history with the in-app AI assistant
- Date of acceptance of these Terms and Privacy Policy
4. What employee data your business uploads
- Staff names, surnames, contact details, addresses
- South African ID numbers and tax (SARS) numbers
- Bank account details for salary payment
- Profile photographs and biometric face templates (where face-scan sign-in is enabled)
- Sign-in / sign-out timestamps, GPS or zone location at time of scan
- Hours worked, overtime, leave taken, payslip records
- Loan, savings, and statutory deduction balances (PAYE, UIF, SDL)
- Next-of-kin contact information
5. Why we collect it (lawful basis)
- Contractual necessity: to provide the Service you have paid for;
- Legal obligation: tax records, invoice retention, fraud prevention, statutory payroll deductions;
- Legitimate interest: security, abuse prevention, product improvement;
- Consent: for biometric face-scan sign-in (each staff member must be enrolled by your business with their consent), and for any optional features or marketing communications.
6. Mobile app permissions
Our mobile applications request the following Android / iOS device permissions. We access these permissions only for the purposes described below; we do not collect or transmit data outside of these purposes.
- Camera (android.permission.CAMERA): used to (a) capture face images for biometric sign-in and sign-out verification; (b) scan QR codes for staff identification at sign-in stations; and (c) capture staff profile photographs at the time of enrolment. The camera is only activated within these specific app screens; it is never accessed in the background.
- Biometric / Fingerprint (android.permission.USE_BIOMETRIC, USE_FINGERPRINT):used to unlock the app using the device's built-in fingerprint or face-unlock sensor. This fingerprint data never leaves the device; we only receive a yes/no authentication result from the operating system.
- Photos / Storage (READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE): used so you can attach a profile photo, supporting documents, or upload payroll spreadsheets. We only access files you explicitly select.
- Internet (android.permission.INTERNET): required to communicate with our backend servers at api.staffpayai.com over encrypted HTTPS.
- Location (where applicable): used in the Staff app to record the geographic zone at the time of sign-in or sign-out, so the employer can verify the employee was on-site. Location is recorded only at the moment of a scan and never tracked in the background.
All permissions can be revoked at any time via your device's system settings. Some app features (notably face-scan sign-in) will not work if their underlying permission is denied.
7. Biometric (face) data — special category
Where your business enables face-scan sign-in, the StaffPay AI Staff app captures a still image of the employee's face and converts it into a mathematical face template (a numerical representation of facial features), matched against your organisation's own records via AWS Rekognition. This template is treated as special personal information under POPIA section 26. As the responsible party for your staff's data, your business must obtain each employee's informed consent before enrolling them — the product does not itself capture, timestamp, or store a record of that consent, so we recommend keeping your own (for example, a signed acknowledgement).
- The original face image is stored only as the staff profile photograph;
- The face template is used solely to verify identity at sign-in and sign-out;
- Face templates are never shared with any third party, never used for advertising, and never sold;
- Face templates are deleted automatically whenever a staff member's record is removed by the employer. When an entire StaffPay account is closed, this same deletion of the underlying AWS facial-recognition record is a step we are still completing full automation of — contact us if you need it confirmed for a specific account (see section 9);
- Employees who do not consent to face scanning may sign in via QR code instead.
8. Children
StaffPay AI is a workforce management tool intended for use by employees aged 15 or older (the South African minimum working age under the Basic Conditions of Employment Act). The Service is not directed at children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has been enrolled in error, contact us at support@staffpayai.com and we will delete the record.
9. How long we keep your data
While your subscription is active: we retain all data for as long as you remain a customer.
After cancellation: your data is retained for 90 days, during which time you can reactivate without data loss. We will email you reminders at day 60, 80, and 89 before deletion.
After 90 days: your account's application data — staff records, sign-ins, payslips, rosters, uploaded files, and chat history — is permanently deleted from our live systems. Biometric face templates and photographs for any staff member already removed individually are deleted at that same time; see section 7 for the current status of that same deletion when an entire account closes. Payment records are retained on PayFast's merchant terminal for SARS audit purposes; we do not retain these locally after deletion.
10. Where your data is stored
Customer and employee data — including the database, uploaded files and photographs, and biometric face templates — is stored and processed on Amazon Web Services infrastructure in the AWS Europe (Ireland) region. AWS's South African region does not currently offer the facial-recognition service our biometric sign-in relies on, so we run our infrastructure from the Ireland region rather than splitting it across regions; this is common practice for South African SaaS providers built on global cloud infrastructure. Email is sent via Postmark, our transactional email provider, whose servers are in the United States — so e-mail we send on your behalf is processed outside South Africa. Payment processing is handled by PayFast (Pty) Ltd — see PayFast's own privacy policy atpayfast.co.za/privacy-policy.
11. Third-party sub-processors
We use the following sub-processors to provide the Service:
- PayFast (Pty) Ltd — payment processing
- Amazon Web Services, Inc. (AWS) — cloud hosting of the application, database and file storage, and AWS Rekognition for biometric face-scan matching, all in the AWS Europe (Ireland) region
- Anthropic PBC — AI features (conversational assistant). Your conversation history is stored locally; only the active conversation is sent to Anthropic per request.
- AC PM, LLC (Postmark) — transactional email delivery (verification, payslip and report e-mail), processed in the United States
- Google LLC (Firebase) — push notification routing and crash reporting in the mobile apps
- Cloudflare, Inc. — TLS termination and DDoS protection at the network edge
- Vercel, Inc. — hosting of the staffpayai.com web frontend
12. How we protect your data
- HTTPS / TLS encryption for all data in transit
- Bcrypt hashing for all stored passwords
- Database access scoped to per-organisation tenancy boundaries (no cross-tenant data leakage)
- Head office runs behind its own admin-only authentication guard, separate from customer logins
- Daily database backups with point-in-time recovery
- Rate limiting and brute-force protection on authentication endpoints
- Biometric face templates stored separately from identifying personal information
13. Your POPIA rights
Under POPIA you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information (subject to retention exceptions)
- Withdraw consent for biometric processing at any time
- Object to processing for direct marketing
- Lodge a complaint with the Information Regulator
To exercise any of these rights, email support@staffpayai.com. We will respond within 30 days. If you are an employee whose data was uploaded by your employer, please direct your request to your employer first, as they are the responsible party for that data.
14. Information Regulator
If you believe StaffPay has not handled your personal information lawfully, you may lodge a complaint with the South African Information Regulator atinforegulator.org.za.
15. Cookies
The Service uses cookies (and equivalent local storage) only as necessary to maintain your login session. We do not use third-party tracking, analytics cookies, or marketing pixels.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email at least 14 days before they take effect. The current version is identified at the top of this page.