Who we are: BoxGames ("BoxGames", "we", "us", "our") is a South African online gaming and entertainment platform, registered at boxgames.co.za. We are the data controller of personal information processed through the Platform. Our general data-protection contact is
boxgames@boxgames.co.za and our compliance contact is
compliance@boxgames.co.za.
This Privacy Policy has been prepared in accordance with the Protection of Personal Information Act No. 4 of 2013 (POPI) and the Electronic Communications and Transactions Act No. 25 of 2002 (ECTA). It explains how we collect, use, store, protect and share your personal information when you access or use the BoxGames Platform.
By registering an account with, or otherwise using, BoxGames you confirm your acceptance of this Privacy Policy. If you do not agree, you may not use the Platform.
POPI
ECTA
FICA
KYC
PCI DSS
1. Information We Collect
1.1 Account Registration Data
When you register an account we collect and process:
- Full legal name and surname
- Date of birth (to verify you are 18+)
- Identity / passport number and a copy of your identity document
- Residential address (street address, suburb, city/town, province and postal code)
- Proof of residence (utility bill dated within the last 3 months)
- Telephone number(s) and email address
- Banking and payment account details (account holder name, branch code, account number)
- Source of funds declaration
- Username and account security credentials (passwords in salted-hash format only; raw passwords are not stored)
1.2 Financial & Transactional Data
- Deposit method, amount, date and status of each deposit
- Withdrawal method, amount, date and status of each withdrawal
- Details of all bets placed — event, sport, selection type, odds and stake
- Winnings, losses and current account balance
- Bonus funds credited, wagering progress and bonus wallet activity
- The final four (4) digits of your card number, cardholder name and expiry date for account identification only (full card numbers are never stored by BoxGames)
PCI DSS: All card payments are facilitated and secured by certified third-party payment service providers (PSPs). Card transactions are 3D Secure protected. Full credit card data is not stored, transmitted or accessible by BoxGames. All PSPs engaged by BoxGames are PCI DSS Level 4 or higher compliant.
1.3 Device, Technical & Usage Data
- IP address and approximate geo-location
- Device type, operating system and version
- Browser type and version
- Pages visited, clickstream data, referring source, date and time of access
1.4 Cookies & Similar Technologies
The Platform uses the following categories of cookies:
- Strictly necessary — essential for core Platform operation (session management, authentication, security)
- Functional — remember your preferences and settings
- Performance & analytics — aggregate usage statistics without personal identifiers
- Targeting & advertising — behavioural interest data for marketing purposes
Blocking or restricting cookies via your browser settings may impair certain Platform features. Decisions are not taken solely on the basis of automated profiling unless, as required by ECTA and POPI, it is either authorised by law, necessary for a contract, in our legitimate interests (subject to your right to object) or consented to by you.
2. How We Use Your Personal Information
We only use Personal Information for lawful, explicitly defined and compatible purposes. Primary purposes include:
- Account opening and identity / age / KYC verification; compliance with FICA and applicable anti-money laundering legislation
- Processing deposits, withdrawals, account management and bet settlement
- Fraud prevention and routine transaction monitoring, including anti-money laundering controls
- Settlement of bets and communicating results to you
- Managing Platform security, booking transactions and your betting partner details
- Customer support, disputes, account management and Platform improvement
- Communicating with you via email, SMS, WhatsApp and in-platform notification
- Complying with legal and regulatory obligations, including reporting to regulators, SARS and FIC
- Marketing and promotional communications — only where you have given express consent
- Improving our products, website, Platform and service generally
Where Personal Information is processed for direct marketing, ECTA requires that each such communication provides you with a simple and free mechanism to unsubscribe.
3. How We Share Your Information
We do not sell your Personal Information. We may share it only in the following circumstances:
- Service providers: Payment processors, identity / KYC verification agents, anti-fraud providers, hosting and analytics providers. Each provider is contractually required to maintain security standards equivalent to those in this Policy.
- Regulatory bodies and law enforcement: where required by law, regulation or valid court order, including SARS, FIC and the provincial gambling regulator.
- Business transfers: In the event of a merger, acquisition, asset sale or corporate reorganisation Personal Information may be transferred as part of the assets. You will be notified of any such event.
- Anonymised aggregate data: For analytics, research and strategic planning where no Data Subject can be identified.
4. Data Security
BoxGames maintains and continuously improves a security programme that includes encryption in transit (TLS 1.2+), salted hashing of passwords, strict access controls on all systems, ongoing monitoring and penetration testing and an incident response procedure designed to contain, investigate and mitigate security events, and report them to the Information Regulator and/or affected customers within the timelines prescribed by POPI.
Despite these measures, no online system can be 100% secure. You are encouraged to use a strong, unique password and to notify BoxGames immediately if you suspect any unauthorised access to your account.
5. Your Rights (POPI)
You have the following rights under POPI:
- Right of access: Confirm whether we hold Personal Information about you and request a copy. We will respond generally within 30 days of receipt.
- Right to correction: Request that inaccurate, outdated or incomplete Personal Information be corrected, updated or completed.
- Right to restriction / deletion: Request the restriction or deletion of your Personal Information where it is no longer necessary to retain it.
- Right to withdraw consent: Withdraw previously given consent at any time by emailing boxgames@boxgames.co.za; withdrawal does not affect processing occurring before your notice.
- Right to object to automated profiling: Object to automated targeting or profiling decisions that have a significant adverse effect on your legal rights or interests, and have the decision reviewed.
- Right to complain: Lodge a complaint directly with the Information Regulator:
Information Regulator of South Africa, 10th Floor, Mega City, 310 Madiba Street, Pretoria. Tel: (012) 406 4000 — PAIA.InfoRegulator@justice.gov.za — www.justice.gov.za/inforeg
To exercise any of these rights contact boxgames@boxgames.co.za. We will respond within the period required by POPI.
6. Retention of Personal Information
- Account registration data — retained for the life of your account and the minimum statutory period thereafter.
- Proof of residence documents — retained for no longer than 3 months after submission unless an extension is agreed in writing.
- Transaction and betting history — retained in the active account environment until account closure and then for the minimum period required by South African law.
- Regulatory compliance records (FICA standard filing requirements, AML records) — retained for the minimum period required by适用的 industry and legislature booking requirements.
- Cookies and analytics tokens — expire no later than 366 days after placement or at active user deletion.
Upon expiry of each applicable retention period Personal Information will be securely deleted, irreversibly anonymised or otherwise removed in a manner consistent with POPI requirements.
If you have any specific concern relating to a retention period, please contact the helpdesk at boxgames@boxgames.co.za.
7. Cross-Border Data Transfers
Personal Information will primarily be processed and stored in South Africa. Cross-border transfer will occur only where: (a) the receiving country offers an adequate level of protection; (b) adequate contractual safeguards (standard contractual clauses or equivalent) are in place; (c) you have given express, informed consent; or (d) transfer is specifically required by law or valid court order.
8. Gaming Activity Data & Biometric Information
Within the context of POS terminals and physical betting venues BoxGames employs CCTV surveillance in accordance with applicable legislation. Biometric personal information (for example facial recognition data at venue entry) is collected only for explicitly defined, purpose-limited purposes, is retained only for the minimum period required for each purpose and is shared with no third party except where required by law.
9. ECTA & Electronic Communications
All electronic communications (including SMS, email, WhatsApp and in-platform messages) sent to your registered email address or mobile number constitute valid legal communications under ECTA. You agree to accept and rely on electronic confirmations as conclusive evidence of the transactions they relate to. Direct electronic marketing communications will always include a free and simple unsubscribe mechanism.
10. Changes to This Privacy Policy
BoxGames may update this Privacy Policy materially from time to time. When material changes are made, the effective date above will be updated, the new version will be published on the Platform and affected account holders will be notified by direct email or SMS. Continued use of the Platform following such notification will constitute acceptance of the updated Policy.
This Privacy Policy must be read together with the BoxGames Terms & Conditions, both of which together form the complete contractual framework between you and BoxGames.