Privacy policy
Last updated 10 October 2026
Dala is a money app for small traders in South Africa. This policy explains what personal information we collect, why, where it is kept and what you can ask us to do with it. It follows the Protection of Personal Information Act, 2013 (POPIA).
Where Dala is today
Dala is in testing. The app runs on sample data for a made-up business, and no trader's real bank statements have gone into it yet. Today the only personal information we collect is what you type into the waitlist form on this website.
Before anyone's real statements go into Dala, we will update this policy to list every service that processes them, what each one does and which country it is in. We will tell everyone on the waitlist when that happens.
What we collect on this website
| What | Why | How long we keep it |
|---|---|---|
| Your name, WhatsApp number or email, and your trade if you choose it | To contact you about joining Dala's testing and launch | Until you ask us to remove it, or 12 months after Dala launches, whichever comes first |
| Your internet address (IP address), briefly | To stop spam and abuse: we limit how many times one connection can send the form | Kept in memory for at most an hour, and in server logs for up to 30 days |
We use your details only to contact you about Dala, and only because you agreed to that on the form. You can withdraw that agreement at any time.
This website sets no cookies and uses no advertising or tracking tools. Fonts and images are served from this site.
Who can see it
Only the Dala team, through a staff website that requires a sign-in code and records every time the waitlist is opened. We never sell your information or share it for marketing.
Two companies run the services this website uses. They store or carry the information for us and may not use it for anything else:
- Railway (Railway Corporation, USA) runs our servers and database, in a data centre in the Netherlands.
- Cloudflare (Cloudflare, Inc., USA) delivers this website and protects it from attacks. Traffic passes through its network, including its servers in South Africa.
Because the database is in the Netherlands, your information leaves South Africa. The Netherlands is bound by the EU's General Data Protection Regulation, which gives protection at least as strong as POPIA, as section 72 of POPIA requires.
How we protect it
All traffic is encrypted (HTTPS). The database is not reachable from the internet. Staff access is limited by role, and every look at personal information is logged.
Your rights
You may ask us to:
- tell you what information we hold about you, and give you a copy;
- correct it;
- delete it, or stop contacting you.
Email [email protected] from the address you gave us, or tell us the WhatsApp number you used. We will reply within 30 days.
If you are not happy with how we handle your information, you can complain to the Information Regulator: inforegulator.org.za.
Changes
If we change this policy, we will update the date at the top. If a change affects how we use information you have already given us, we will tell you first.