Privacy Policy
Last Updated: 22 September 2026
Commitment to Privacy
Slippify (Pty) Ltd ("Slippify", "we", "us") is the responsible party (POPIA) / data controller (GDPR) for the personal information described in this Policy. This Policy explains, in plain terms, exactly what we collect, why, who we share it with, how long we keep it, and how you can access, correct, export, or delete it — written to align with South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA"), the EU/UK General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). Where a practice described below differs by regulation, we say so explicitly rather than making one blended claim.
This Policy describes our current data-handling practices, grounded in how the live product actually works rather than aspirational language — and we review and update it as the Service changes.
Slippify is a software-as-a-service (SaaS) financial utility application for tracking, organising, and splitting personal, group, and business/travel expenses — not an authorised or licensed financial services provider, bank, financial institution, financial or investment adviser, credit provider, insurer, payment institution, or tax, accounting, or legal adviser, except where a specific regulated service is provided by an appropriately authorised third party. Our Terms of Service sets this out formally, and explains why you remain responsible for verifying any figure the app captures or calculates on your behalf.
Who We Are
Slippify (Pty) Ltd (CIPC registration 2026/760947/07; Information Regulator registration 2026-067431) operates the Slippify application and websites (slippify.io / slippify.co.za). For all privacy matters — including exercising the rights in Section 8 — contact us at compliance@slippify.io. This mailbox is monitored by our appointed Information Officer, Eugene le Roux, who is responsible for POPIA compliance and for liaising with South Africa's Information Regulator on our behalf. We have not appointed a separate representative in the EU, UK, or Switzerland under Article 27 GDPR; EEA/UK/Swiss users should also use the contact above, and retain the right to contact their local supervisory authority directly (Section 13).
Information We Collect
We collect only what each feature needs to function. Nothing below is inferred — it reflects what the application actually stores today.
- Account & Profile: the email address, name, and profile photo supplied by Google Sign-In; your chosen display currency, language, and theme preferences; your credit/subscription balance.
- Receipts & Scan Data: the receipt image you upload, and everything we extract from it using Google Services — merchant name, address, phone/email if printed on the slip, VAT breakdown, line items and prices, table number, and any waiter name shown on the receipt. If your photo file itself contains embedded EXIF metadata (set by your phone's camera), that can include the camera make/model and the GPS coordinates of where the photo was taken — we read this metadata as part of processing your upload. You can strip this metadata yourself before uploading if you'd prefer not to share it (most phone camera apps offer a "remove location" option when sharing photos).
- Group & Shared Ledger Data: if you join or create a Group, other members can see your display name and profile photo, and the shared expense/settlement history you're part of (amounts, splits, who paid whom). This is inherent to how group expense-splitting works — it is not data we sell or share externally.
- PayShap Directory Number: if you choose to add a PayShap number to your profile, it is visible to fellow members of any group you're in (and to attendees of a bill you host), so they know how to pay you back directly, bank-to-bank. Slippify never processes, verifies, or holds this number or any funds sent to it — it is a self-reported contact detail, shown only to people you're already sharing a bill or group with, never to the public or to other Slippify users outside that context.
- Payment Data: Service Credit purchases are not currently available, so Slippify does not currently collect or pass on any payment data, and does not offer a subscription. Before purchases open we will update this Privacy Policy to name the payment provider and describe exactly what data it receives. We will never see or store your card or bank account credentials.
- Consent & Security Records: when you accept this Policy, we log the timestamp, a hashed device identifier, and your IP address and browser user-agent as evidence that consent was given. Push-notification devices are recorded via an encrypted subscription key.
- Usage & Product Analytics: internal records of how you use spend-categorisation and item-selection features, tied to your account while it exists, used only to improve the product — never sold, and never shared with advertisers.
- Approximate Location (country-level only): to suggest a default currency and language the first time you use the app, we resolve your IP address to a country using an offline database that runs entirely on our own server — your IP address is never sent to an external geolocation API to do this.
- Merchant Partner Accounts: if you are a verified restaurant/merchant partner we've onboarded to the Merchant Intelligence Portal, we hold the login email and a securely hashed password for that account. Merchant owner accounts are provisioned directly by Slippify, not self-service signup, and are a separate identity from any personal Slippify account you may also hold.
Why We Process It, and Our Lawful Basis
Under GDPR Article 6 and the equivalent POPIA Section 11 conditions, every processing activity above rests on one of these grounds:
- Performance of a contract: scanning your receipt, computing splits, running your group ledger, and processing a Service Credit purchase all exist to deliver the service you signed up for.
- Consent: accepting this Policy before your first upload or login (Section 8 explains how to withdraw it); adding a PayShap number is also opt-in and can be removed at any time from your Profile.
- Legitimate interests: consent/security records, rate-limiting, and fraud/abuse prevention, balanced against your right to privacy — we keep this category to the minimum needed for platform integrity.
- Legal obligation: retaining certain financial and consent records for as long as needed to defend against disputes or meet statutory recordkeeping duties.
We do not make any decision that produces a legal or similarly significant effect on you based solely on automated processing. Google Services provide a first-pass, automated reading of your receipt, but you always review, correct, and confirm the split before it's finalised — that output is a draft, not a determination.
Who We Share Data With
We do not sell personal information, and we do not share it with advertisers. We use a small number of named service providers ("sub-processors") strictly to operate the app:
- Google Services: your uploaded receipt image is sent to Google Services over an encrypted connection to extract merchant, item, and total data. Google's published data-processing terms for this service state that submitted content is not retained beyond what's needed to service the request and is not used to train Google's models; we have not independently audited this. Google also provides the Sign-In service used for authentication.
- Payment provider: none at present, because Service Credit purchases are not currently available. Before they open we will name the provider here and describe the data it receives. Slippify will use any payment provider only to collect payment for Service Credit purchases — never to hold or move funds on your behalf between other people.
- Push notification services: if you enable notifications, your browser's own push provider (e.g. Google FCM, Mozilla, or Apple, depending on your device) relays the notification — they see only an anonymous delivery endpoint, never the notification's content in readable form.
- Error monitoring: we may use an error-monitoring tool (Sentry) to catch and diagnose application crashes. Our configuration strips authentication headers and cookies before any error report is sent, and our code does not currently attach your name or account identity to these reports.
- Legal disclosure: we may disclose information if required by law, court order, or to protect the rights, property, or safety of Slippify, our users, or the public.
International Data Transfers
Some of our service providers may process personal information outside South Africa. Where personal information is transferred across borders, Slippify will do so only where permitted by applicable data-protection law and subject to appropriate safeguards.
For South African data subjects, cross-border transfers are made in accordance with section 72 of POPIA, including where the recipient is subject to an adequate level of protection, where an appropriate binding agreement or other lawful safeguard applies, where the data subject has consented where required, or where another lawful transfer mechanism under POPIA applies.
For users in the European Economic Area, United Kingdom or Switzerland, personal information may be transferred to South Africa or other countries where our service providers operate. Such transfers will be made using an applicable transfer mechanism and appropriate safeguards required by GDPR or other applicable data-protection law.
You may contact us at compliance@slippify.io if you require further information about the safeguards applicable to a particular international transfer.
Loading the app itself also causes a small, low-sensitivity cross-border transfer: your IP address is sent to the operators of the fonts and code libraries the app loads directly from their own servers (Google Fonts, and the CDNs jsdelivr, unpkg, and cdn.socket.io), each of which is outside South Africa. These requests are tightly scoped and cryptographically pinned to an exact, unmodifiable file, but we want to name this flow explicitly rather than leave it implicit.
How Long We Keep Your Data
- Abandoned scans: if you start a split but never upload a receipt, that session is deleted after 2 hours.
- Solo Bill Split (Free/Basic tier): receipt images, line items, and split details are purged 30 days after creation. If that split has no completed payment history tied to it, the record is deleted outright; if it does (e.g. a merchant payment was recorded against it), we anonymise it instead — the receipt image and OCR text are erased, guest names are replaced with "Guest", and only the anonymised amount/date remains, so financial history stays reconstructable without retaining your personal details.
- Paid/Pro tier Solo Bill Split: excluded from the 30-day purge — your receipt archive remains intact for as long as your account carries an active Pro balance.
- Group Tabs (shared group expenses): a confirmed group expense's receipt photo and extracted data are not subject to the 30-day rule above, regardless of tier — they are kept for as long as the expense remains part of an active group's shared ledger, because the group's other members rely on that record for their own settlement history. Unconfirmed, discarded scan drafts are purged after 30 days like any other stale draft.
- Consent records: retained for as long as reasonably necessary to demonstrate that lawful consent was obtained — including after you delete your account, since that's precisely when we may need to show a regulator or a former user that consent was validly given and later withdrawn. This is a deliberate, narrow exception to our general deletion practice, kept under periodic review rather than as an indefinite default.
- Push subscriptions: an inactive, unclaimed push subscription is purged after 30 days.
- Backup copies: for disaster-recovery purposes, we keep a rolling local database backup covering roughly the last 7 days. If your data was deleted or anonymised during that window, a backup taken shortly beforehand can still contain the pre-deletion version until that backup itself ages out — a standard trade-off of any backup system, not a separate copy we keep indefinitely.
Your Rights
Regardless of where you live, you can exercise all of the following. Section 8 explains exactly how.
- Access & Portability: download a machine-readable copy of your profile, sessions, and transaction records (Section 8 lists the exact scope, including what isn't yet included).
- Correction: fix inaccurate profile details (name, currency, PayShap number) at any time from Profile settings. Note that this is distinct from the accuracy of automatically extracted receipt or expense data itself — we make every reasonable effort to extract it correctly, but you remain responsible for reviewing and correcting it before relying on it, as set out in Terms of Service Section 4.
- Erasure ("right to be forgotten"): delete your account, profile, and receipt images. As explained in Section 8, shared group-ledger history you were part of is anonymised rather than erased outright, to preserve the accuracy of other members' own financial records.
- Objection & restriction: object to processing based on legitimate interests, or ask us to restrict processing while a dispute about accuracy is resolved. We don't yet have a dedicated self-service control for this — email compliance@slippify.io and we'll action it manually; if you'd rather stop all processing immediately, deleting your account (Section 8) does that today.
- Withdraw consent: at any time, without affecting the lawfulness of processing carried out before withdrawal. The reliable way to withdraw consent in full today is to delete your account (Section 8), which stops all further processing; for a narrower withdrawal, email compliance@slippify.io and we'll action it manually while we build a dedicated self-service control for this.
- Lodge a complaint: with a data protection regulator (Section 13) at any time, including before contacting us first.
Exercising Your Rights & Deleting Your Account
Most rights are self-service, from Profile → Danger Zone:
- Export Data generates an immediate JSON download of your profile, sessions, and transaction history. This export does not currently include individual receipt line items or group-contribution breakdowns; email compliance@slippify.io if you need those specifically.
- Delete Account permanently removes your account. Two conditions must be resolved first, and the app will tell you which applies: (1) if you're the sole full member of a group with no one else to take it over, you'll need to add another member or archive the group first; (2) if you have an outstanding balance in any group, it needs to be settled first. This exists to protect other members' ledgers, not to make deletion difficult — most accounts can delete immediately.
When account deletion completes, here is exactly what happens: your receipt image files are deleted from our servers; your name and profile photo on any group or session you belonged to are replaced with "Deleted User"; your account record is permanently removed; your email address is one-way hashed into a pseudonymised block-list entry — hashing makes it unreadable, not anonymous, since we can still recompute the same hash from an email address to check it against the list — kept solely to prevent the same address from re-registering to evade this deletion, and reviewed periodically rather than retained by default forever; and your active session is signed out everywhere. What is not deleted: the amounts, dates, and splits on any shared group ledger you were part of remain visible to your former groupmates, stripped of your name — this is the "anonymise, don't erase" approach referenced in Section 7, and it exists because those figures are also part of other people's financial records, which we cannot unilaterally alter on your request alone. We replace your name with "Deleted User," but if your former groupmates already know which figure was yours from context (for example, they know who paid a specific amount), that context can make you identifiable to them even after this anonymisation — we cannot erase what people already remember. Consent records (Section 6) are likewise retained as proof of consent.
Prefer not to use the in-app flow, or have a request that doesn't fit the self-service options above (e.g. correcting data you can't edit yourself, or a formal access/portability request in a specific format)? Email compliance@slippify.io. We will acknowledge your request promptly and respond substantively within 30 days; if your request is complex, GDPR permits us to extend this by up to two further months, and we'll tell you if that's needed and why.
How We Protect Your Data
We use HTTPS/TLS encryption for data in transit between your device and our servers. Sensitive credentials used to integrate with our payment processor are encrypted at rest (AES-256-GCM). Access to production data is restricted to authorised personnel.
If Slippify experiences a security compromise involving personal information, we will take appropriate steps to contain, investigate and remediate the incident, preserve relevant evidence and assess the potential impact on affected data subjects.
Where required by POPIA, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after becoming aware of the security compromise, subject to any lawful requirement or direction that affects the timing or manner of notification.
Where GDPR or another applicable data-protection law applies, we will also comply with the notification and communication requirements applicable to that jurisdiction.
We use four first-party cookies that are strictly necessary for authentication, session management and the operation of the service. We do not use advertising cookies or third-party tracking cookies for behavioural advertising. Each is set with the HttpOnly, Secure, and SameSite=Strict flags:
- slippify_jwt: your signed-in session token.
- slippify_refresh: used to silently renew your session; longer-lived.
- merch_owner_sess: merchant-portal owner session (Merchant Intelligence Portal only).
- merch_sess: merchant-portal session (Merchant Intelligence Portal only).
Children's Privacy
Slippify is not directed at, and is not intended to be used by, anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
California Residents (CCPA/CPRA)
We do not sell or share (as CPRA defines "share," including for cross-context behavioural advertising) your personal information, and never have. You have the right to know what we collect (Section 2), delete it (Section 8), correct it (Section 8), and not be discriminated against for exercising these rights — we will never degrade your service for doing so. Because we don't sell or share data, there is no "opt-out" toggle to offer; if that ever changes, this Policy and a dedicated opt-out link will be updated first.
Changes to This Policy
We'll update the "Last Updated" date above whenever this Policy changes. For material changes — anything that meaningfully expands what we collect or who we share it with — we'll also prompt you to review and re-accept the updated Policy the next time you use the app, rather than silently applying it.
Complaints & Regulatory Contacts
We'd rather resolve any concern directly — email compliance@slippify.io first. But you are never required to contact us before exercising your right to complain to a regulator:
- South Africa: the Information Regulator, inforegulator.org.za/complaints, or by emailing POPIAComplaints@inforegulator.org.za.
- EEA/UK/Switzerland: your local data protection supervisory authority.