Welcome to Cardless Club, operated by Times Six Pty Ltd. The documents below govern your use of our digital loyalty platform. Tap any section to expand it. Questions? Email support@cardlessclub.co.za.

1Customer Terms & ConditionsFor people who collect stamps and rewards
Trading nameCardless Club
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Contactsupport@cardlessclub.co.za
Last updated1 June 2026
Version2.0

1. Introduction

Cardless Club provides digital loyalty cards to customers (“Customers”, “you”). By creating an account or scanning any loyalty QR code, you accept these Terms. Cardless Club is operated by Times Six (Pty) Ltd.

2. How Cardless Club Works

  • Each customer receives a unique personal QR code;
  • Your QR code identifies you to participating stores;
  • Store owners and staff scan your QR code to issue loyalty stamps and digital reward cards;
  • When you reach a store’s stamp threshold, a digital reward card is generated; and
  • Rewards are created and honoured by the store, not by Cardless Club.

You can also store other loyalty cards in your personal Card Wallet for your own convenience (see Section 7).

3. Your Responsibilities

You agree to:

  • Provide accurate account details;
  • Keep your login details secure and not share your personal QR code publicly;
  • Use the Service lawfully; and
  • Not manipulate or attempt to falsify stamp or redemption events.

4. No Fees for Customers

Cardless Club is free for customers. Your account may be suspended or removed only if you violate these Terms.

5. Your Privacy and Contact Sharing

By default, stores cannot see your email address or phone number, and cannot message you. Stores see only your display name and your loyalty activity at their own store.

You may choose to share your email address and/or WhatsApp number with specific stores you interact with. You control this from your loyalty card for each store, with separate options for email and WhatsApp. This is entirely optional and switched off unless you switch it on.

If you opt in to share your details with a store, you agree that the store may contact you directly — including with marketing and promotional messages about that store. The store, not Cardless Club, is responsible for those communications and must give you a way to opt out. You can withdraw sharing at any time from the same screen; the store must then stop using your details.

Please note: if a store downloaded or saved your details while sharing was on, Cardless Club cannot delete that copy for you. You would need to ask the store directly, and the store is obliged under POPIA to honour your request. Our full Privacy Policy explains this in detail.

6. Rewards

Rewards are provided solely by the store. Cardless Club is not responsible for reward availability, reward value, the redemption experience, store behaviour, or store business continuity.

7. Card Wallet

The Card Wallet lets you store details of other loyalty cards (such as supermarket or pharmacy cards) for your own convenience. Cardless Club is not affiliated with, endorsed by, or partnered with any of those third-party brands, and we cannot guarantee their accuracy, availability, or acceptance at any retailer. Your stored cards are private to your account.

8. Liability

To the maximum extent permitted by law, we do not accept liability for lost rewards, incorrect scans, store disputes, service outages, account misuse, or device issues.

9. Account Termination

We may suspend or terminate customer accounts for fraud, abuse, security threats, or fake accounts.

10. Changes to These Terms

We may update these Terms from time to time. Material changes will be notified through the Service or by email, and continued use after the effective date constitutes acceptance.

11. Contact

For any question, contact us at support@cardlessclub.co.za.

2Merchant Terms & ConditionsFor shop owners who subscribe and run a Place
Trading nameCardless Club
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
LocationRandburg, Johannesburg, Gauteng, South Africa
Contactsupport@cardlessclub.co.za
Last updated17 June 2026
Version2.1

1. Introduction

These Terms & Conditions (“Terms”) govern your use of the Cardless Club loyalty system (the “Service”) provided by Times Six (Pty) Ltd (“Company”, “we”, “us”, “our”). By subscribing, creating an account, or using the Service, you (the “Merchant”) agree to be bound by these Terms. If you do not agree, you must not use the Service.

2. The Service

Cardless Club provides a digital loyalty system enabling merchants to:

  • Create and manage a loyalty “Place” (store listing);
  • Issue stamps digitally by scanning customer QR codes;
  • Issue and redeem digital reward cards;
  • Configure self-service QR security modes (PIN, geofence, staff approval, one-time use);
  • Add and manage staff members who issue or redeem on the Merchant’s behalf;
  • Operate multiple linked branches as a franchise sharing one combined loyalty card, where configured; and
  • Access reporting and analytics (stamps, redemptions, staff activity, customer tiers, and — for opted-in customers only — shared contact details).

The Service is delivered solely through our website and related infrastructure. We do not supply hardware. Branded starter-kit materials are provided as part of activation, as set out in clause 3.1.

3. Merchant Subscriptions

3.1 Activation and starter kit

New merchants pay a once-off activation fee of R499 per Place. This activation fee includes the Merchant’s first month of the Service and a branded starter kit: a counter / table NFC + QR sign-up stand; a branded PVC loyalty card carrying the Stamp QR on one side and the Redeem QR on the other (with NFC for one-tap customer sign-up); an NFC keyring; three branded pens; and the Merchant’s choice of 20 A6 flyers or 15 coasters for quick customer sign-up. Each Place (including each franchise branch) receives its own starter kit.

3.2 Ongoing subscription

After the included first month, the subscription fee is R499 per month per Place, billed monthly in advance via Paystack through Paid Memberships Pro. Each additional Place requires its own subscription, subject to the franchise rates in clause 3.5 where applicable.

3.3 Cancellation

You may cancel at any time. Cancellation takes effect at the end of the current paid month — you keep access until the month you have paid for runs out, and you are not charged again. No pro-rata refund is given for the remainder of that month.

3.4 Single-shop discount

A discounted rate of R399 per month may be offered at our discretion, applied via a discount code at sign-up. Where applied, R399 becomes the ongoing monthly rate for that Place.

3.5 Franchise (multi-branch) pricing

Where two or more branches are linked as a franchise sharing one combined loyalty card, each branch is charged at a volume rate: R399 per month per branch for 2–9 branches, and R299 per month per branch for 10 or more branches. The once-off activation fee per branch equals that branch’s monthly rate. Each branch still receives its own starter kit. The franchise is managed from a single account via the franchise hub.

3.6 Discounts and custom terms

We may, at our sole discretion, offer discounts, promotional codes, or custom payment terms to selected merchants. Any such arrangement applies only to the merchant and period specified, does not create an entitlement for any other merchant, and may be withdrawn for future billing cycles on reasonable notice.

3.7 Non-refundable

All payments are final and non-refundable, except as set out in our Refund Policy (continuous platform outage exceeding 45 days attributable to Cardless Club infrastructure).

3.8 Failure to pay

If a payment fails, a 7-day grace period applies. After 7 days, your Place and all associated staff accounts are suspended until payment resumes.

4. Use of the Service

By using Cardless Club, you agree:

  • Not to misuse the system or interfere with its operation or security;
  • To ensure your staff comply with these Terms and with applicable law;
  • To use customer QR data only for legitimate stamp and redemption purposes;
  • Not to attempt to reverse engineer, copy, scrape, or replicate the platform; and
  • To ensure your content, logos, and trade marks are lawfully yours to use.

We may suspend or terminate access if misuse is detected.

5. Your Content

You may upload your logo, images, brand colours, reward titles and descriptions, and reward-specific terms. You confirm that you own or are licensed to use all such content, you grant us permission to display it for the purpose of operating your Place, and you understand that we do not claim ownership of it. We do not use your content outside the context of the loyalty platform.

6. Customer Data and Contact Sharing

This clause has changed. Please read it carefully. It replaces any previous statement that merchants have no access to customer contact details or cannot export data.

6.1 Default position

By default, you can see only a customer’s display name and their loyalty activity at your own Place. You cannot see a customer’s password or login credentials, and you cannot see their activity at any other store.

6.2 Opt-in contact details

A customer may voluntarily choose to share their email address and/or WhatsApp number with your specific Place. Where, and only where, a customer has opted in, you will be able to view those details in your reporting dashboard and include them in a report you download. You may only receive and use contact details obtained through this opt-in feature. You must never attempt to collect, infer, scrape, or otherwise obtain customer contact details by any other means.

6.3 You are an independent Responsible Party

When you receive a customer’s contact details through the opt-in feature, you become an independent Responsible Party (controller) for those details under POPIA. From that point, you — not Cardless Club — are solely responsible for how you store, use, secure, and dispose of them. You agree to:

  • Process the details lawfully, for legitimate purposes, and in accordance with POPIA;
  • Comply with section 69 of POPIA when sending any direct marketing — including identifying yourself, providing a means to opt out in every communication, and immediately honouring any opt-out or “stop” request;
  • Only contact the customer through the channel(s) they shared (for example, do not WhatsApp a customer who shared only an email address);
  • Not sell, rent, on-share, or transfer the details to any third party;
  • Keep the details secure and delete them on the customer’s request or when no longer needed; and
  • Recognise that a customer may withdraw consent at any time, after which you must stop using the details and honour the withdrawal.

6.4 Exported data is your responsibility

Any report or data you download is a point-in-time snapshot. Once downloaded, it sits in your own systems and under your sole control and responsibility. If a customer later withdraws consent, Cardless Club cannot retrieve or delete the copy you hold; you remain obliged under POPIA to act on the customer’s request yourself.

6.5 Indemnity

You indemnify and hold harmless Times Six (Pty) Ltd, its directors, and personnel against any claim, complaint, fine, penalty, loss, or cost (including reasonable legal costs) arising from your handling of customer contact details or other personal information, including any breach of POPIA, any unlawful or unsolicited direct marketing, any failure to honour an opt-out, or any onward disclosure by you or your staff.

6.6 Rewards

You alone are responsible for defining and honouring the rewards you offer.

7. Franchises and Linked Stores

If you operate multiple branches as a franchise, you may link them so that customers earn stamps toward a single shared loyalty card across all linked branches. You are responsible for ensuring that all linked branches and their staff comply with these Terms, and that customer data is handled consistently and lawfully across the group. Franchise pricing is set out in clause 3.5. A subscription is payable per branch unless we agree otherwise in writing.

8. Data Processing Agreement

Our processing of personal information in connection with your Place is governed by the Data Processing Agreement (DPA), which forms part of these Terms. Where there is a conflict between these Terms and the DPA on data-protection matters, the DPA prevails.

9. System Availability & SLA

We strive for 99% uptime, excluding scheduled maintenance and upstream outages. Scheduled maintenance is communicated at least 24 hours in advance where reasonably possible. Our service levels and exclusions are set out in the separate Service Level Agreement (SLA), which forms part of these Terms.

10. Liability & Disclaimers

To the maximum extent permitted by law:

  • The Service is provided “as is” and “as available”;
  • We do not guarantee uninterrupted uptime, customer conversions, or revenue; and
  • We are not liable for business losses, data loss, indirect or consequential damages, loss of profits, or staff misuse.

Our total aggregate liability to you is limited to the value of one (1) month’s subscription fee. Nothing in these Terms limits liability that cannot lawfully be limited.

11. Termination

We may suspend or terminate a merchant account immediately if Terms are violated, fraud is detected, the system is abused, or illegal activity is identified. We may also terminate the Service on 30 days’ notice. On termination, your right to use the Service ends and your Place is deactivated.

12. Dispute Resolution

The Parties will first attempt to resolve any dispute through good-faith arbitration in South Africa. If unresolved, the dispute may proceed to the South African courts. These Terms are governed by the laws of the Republic of South Africa.

13. Changes to These Terms

We may update these Terms. When we do, we will notify merchants by email at least 7 days before the changes take effect. Continued use after the effective date constitutes acceptance.

14. Contact

For support or any question about these Terms, contact us at support@cardlessclub.co.za.

3Privacy PolicyHow we collect, use, and protect your information
Responsible PartyTimes Six (Pty) Ltd (Registration No. 2020/072163/07), trading as Cardless Club
Information OfficerTimes Six (Pty) Ltd, attention: The Founder
LocationRandburg, Johannesburg, Gauteng, South Africa
Contactsupport@cardlessclub.co.za
Effective date1 June 2026
Version2.0

Aligned with the Protection of Personal Information Act, 2013 (POPIA) and, where applicable, the GDPR.

1. Introduction

This Privacy Policy explains how Times Six (Pty) Ltd (“we”, “us”, “our”, or “Cardless Club”) collects, uses, shares, and protects personal information when you use the Cardless Club digital loyalty platform (the “Service”), available at cardlessclub.co.za.

We are committed to processing your personal information lawfully, transparently, and only for the purposes set out in this Policy, in accordance with the Protection of Personal Information Act, 2013 (“POPIA”). Where we deal with users in jurisdictions to which the General Data Protection Regulation (“GDPR”) applies, we apply equivalent protections.

Important — please read Section 4 carefully. Cardless Club includes a feature that lets you voluntarily choose to share your contact details (email address and/or WhatsApp number) with specific stores you interact with. This sharing is off by default and only happens if you explicitly switch it on.

2. Who We Are and Our Role

Times Six (Pty) Ltd is the Responsible Party (in GDPR terms, the “controller”) for the personal information you provide when you create and use a Cardless Club account. Our Information Officer is registered with the Information Regulator of South Africa and is accountable for our compliance with POPIA.

Our role changes depending on the type of data and activity:

  • Customer accounts: We are the Responsible Party. We decide how and why your account data is processed.
  • Loyalty interactions on a store’s Place (stamps, redemptions): We act as an Operator (processor) on behalf of the participating store for the loyalty activity recorded against that store, while remaining Responsible Party for the underlying account.
  • Contact details you choose to share with a store: When you opt in to share your email or WhatsApp number with a specific store, that store becomes an independent Responsible Party for the contact details it receives. From that point, the store — not Cardless Club — is responsible for how it uses your contact details. See Section 4.

3. Information We Collect

3.1 Customers (free users)

  • Email address
  • Display name
  • WhatsApp / mobile number (optional — only if you choose to provide it)
  • Login and authentication activity
  • Loyalty activity (stamps earned, rewards generated and redeemed, and the stores at which this occurred)
  • Stored loyalty card details you add to your personal Card Wallet (card names, numbers, and barcode formats you enter or scan)
  • Per-store contact-sharing preferences (your opt-in / opt-out choices)
  • Device and browser data, and limited technical logs, for security and performance

3.2 Merchants (shop owners and staff)

  • Name and business details
  • Email address and contact details
  • Payment details, processed entirely by Paystack — we never store bank or card numbers
  • Staff member names and accounts created by the merchant
  • Store configuration, branding, and loyalty settings

We do not knowingly collect special categories of personal information, and we do not knowingly collect personal information from children. Customers must be 18 or older, or have the consent of a parent or guardian, to create an account.

4. Sharing Your Contact Details With Stores (Opt-In)

This is the most important section of this Policy. By default, stores you visit cannot see your email address or phone number. They see only your display name and your loyalty activity at their own store.

You may, entirely at your discretion, choose to share your email address and/or your WhatsApp number with one or more specific stores. You do this from your loyalty card for each store, using separate tick-boxes for email and for WhatsApp. Each choice is:

  • Voluntary — it is switched off unless you switch it on;
  • Specific — it applies only to the individual store you select, not to all stores;
  • Granular — you can share your email only, your WhatsApp only, both, or neither;
  • Informed — at the point of opting in, we tell you what sharing means and what the store may use your details for; and
  • Withdrawable — you can switch sharing off again at any time from the same screen.

What the store may do with your details. When you opt in, you consent to the relevant store contacting you directly — including for marketing and promotional communications about that store, in addition to messages about your loyalty rewards. This consent is the lawful basis on which the store may send you direct marketing under section 69 of POPIA. The store is required, as an independent Responsible Party, to identify itself, to honour any request you make to stop, and to comply with POPIA when contacting you.

Withdrawing consent. If you switch sharing off, we stop disclosing your details to that store going forward, and the store is required to stop using the details it received and to honour your opt-out. Please understand an important limitation: if a store exported or saved your details while sharing was switched on (for example, downloaded them into its own records), we cannot retrieve or delete that copy on your behalf. You would need to contact the store directly, and the store remains obliged under POPIA to delete it on request. We log when sharing changes and when stores export data, so that we can assist you and the Information Regulator if a dispute arises.

How stores receive your details. Opted-in contact details are shown to the relevant store inside its own reporting dashboard and may be included in a report the store can download. Details are shown and exported only for customers who have opted in to that specific store.

5. How We Use Your Data

We process personal information for the following purposes and on the following lawful bases under POPIA:

  • To operate the loyalty system (create and authenticate accounts, issue your QR code, record stamps and rewards) — necessary to perform our agreement with you;
  • To provide the Card Wallet feature (store the loyalty cards you choose to add) — necessary to perform our agreement with you;
  • To enable contact sharing with stores you select — on the basis of your explicit consent (Section 4);
  • To provide support and respond to your requests — legitimate interest and performance of our agreement;
  • To maintain security, prevent fraud, and keep records — legitimate interest and compliance with law; and
  • To comply with South African law and lawful requests from authorities.

We do not sell your personal information, and we do not share it with third parties for their own marketing except through the opt-in contact-sharing feature you control in Section 4.

6. Data Sharing and Operators

To run the Service we use trusted service providers (Operators) who process personal information on our behalf under written agreements requiring POPIA-compliant safeguards:

  • Hosting provider — secure hosting of the platform and database;
  • Paystack — payment processing for merchant subscriptions (we do not receive or store card or bank numbers);
  • Google Maps Platform — to display store locations in the directory;
  • Email delivery provider — to send transactional emails; and
  • WordPress plugin and infrastructure providers — only to the extent necessary to deliver platform functionality.

Separately from the above, when you opt in under Section 4, we disclose your selected contact details to the specific store you have chosen. That store then acts as an independent Responsible Party.

7. Merchant Access to Customer Data

Subject to Section 4, a participating store can see, for its own Place only:

  • Your display name;
  • Your loyalty activity at that store (stamps, rewards, visit history, customer tier); and
  • Your email address and/or WhatsApp number only if you have opted in to share them with that specific store.

A store cannot see your password or login credentials, and cannot see your activity at any other store. Where stores form part of a franchise group that shares a single loyalty card, your loyalty activity is shared across the linked stores of that franchise so that your stamps count toward one combined total (see Section 8).

8. Franchises and Linked Stores

Some businesses operate multiple branches as a franchise under one combined loyalty card. Where this applies, your stamps and loyalty activity earned at any branch count toward a single shared total across that franchise group, and the franchise owner and their linked staff may view your loyalty activity across those branches. Your contact-sharing choices continue to apply on a per-Place basis as described in Section 4.

9. Cross-Border Processing

Some of our Operators may process or store data on servers located outside South Africa. Where this occurs, we take reasonable steps to ensure the recipient is subject to laws, binding rules, or contractual terms that provide an adequate level of protection comparable to POPIA, as required by section 72 of POPIA.

10. Data Retention

  • We retain account data for as long as your account is active.
  • If you delete your account, we remove personal identifiers within 30 days, except where we are required or permitted by law to retain certain records (for example, transaction and tax records, and security logs).
  • Loyalty cards you store in your Card Wallet are retained until you delete them or close your account.
  • Consent and data-sharing logs are retained for a reasonable period to evidence compliance and assist with disputes.

11. How We Protect Your Data

We implement appropriate, reasonable technical and organisational measures to safeguard personal information, including encryption in transit, access controls and per-user data isolation, secure hosting, and regular security updates. No system is perfectly secure, but we work to protect your information and to notify you and the Information Regulator of a compromise where the law requires.

12. Your Rights (Data Subjects)

Subject to POPIA, you have the right to:

  • Request access to the personal information we hold about you;
  • Request correction of inaccurate or incomplete information;
  • Request deletion or destruction of your information where appropriate;
  • Object to or request restriction of certain processing;
  • Withdraw consent you have given (including contact-sharing), without affecting processing already carried out lawfully;
  • Not be subject to unsolicited direct marketing in breach of section 69 of POPIA; and
  • Lodge a complaint with the Information Regulator (see Section 14).

To exercise any of these rights, contact us at support@cardlessclub.co.za. We may need to verify your identity before acting on a request.

13. Cookies

We use only essential, performance, and security cookies. We do not use advertising or cross-site tracking cookies. Please see our separate Cookie Policy for details.

14. Information Regulator

You have the right to complain to the Information Regulator of South Africa:

  • Website: inforegulator.org.za
  • Complaints email: POPIAComplaints@inforegulator.org.za
  • General enquiries: enquiries@inforegulator.org.za

15. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

16. Contact Us

For any privacy question or to exercise your rights, contact our Information Officer at support@cardlessclub.co.za.

4Cookie PolicyThe cookies we use and how to manage them
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Contactsupport@cardlessclub.co.za
Last updated1 June 2026
Version2.0

1. Introduction

This Cookie Policy explains how Cardless Club uses cookies and similar technologies on cardlessclub.co.za. It should be read together with our Privacy Policy.

2. What Cookies Are

Cookies are small text files placed on your device when you visit a website. They help the site function, remember your session, and operate securely.

3. Cookies We Use

We use only the following categories of cookies:

  • Strictly necessary cookies — required for the site to work, including login, session management, and security (such as CSRF protection);
  • Performance cookies — to understand how the site is used so we can improve it; and
  • Security cookies — to help protect accounts and detect misuse.

We do not use advertising cookies or cross-site tracking cookies, and we do not sell data collected through cookies.

Your per-store contact-sharing choices are stored securely in our database against your account, not in advertising cookies.

4. Managing Cookies

Most browsers let you refuse or delete cookies through their settings. Please note that disabling strictly necessary cookies may prevent parts of the Service — including login — from working.

5. Third-Party Services

Some features rely on third-party services (for example, Google Maps Platform to display store locations and Paystack for payments) that may set their own cookies, governed by their respective policies.

6. Changes and Contact

We may update this Policy from time to time. For any question, contact us at support@cardlessclub.co.za.

5Acceptable Use PolicyThe rules that apply to everyone using the Service
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Contactsupport@cardlessclub.co.za
Last updated1 June 2026
Version2.0

1. Purpose

This Acceptable Use Policy (“AUP”) sets out the rules that apply to everyone who uses the Cardless Club Service — customers, shop owners, and staff. It forms part of our Terms & Conditions. Breaching this AUP may result in suspension or termination.

2. General Rules (All Users)

You must not:

  • Use the Service for any unlawful, fraudulent, or harmful purpose;
  • Attempt to gain unauthorised access to accounts, data, or systems;
  • Interfere with, disrupt, or place undue load on the Service;
  • Reverse engineer, copy, scrape, or replicate the platform or its code; or
  • Misrepresent your identity or affiliation.

3. Customer Rules

Customers must not:

  • Share their personal QR code publicly or allow others to use their account;
  • Manipulate, falsify, or automate stamp or redemption events; or
  • Create fake or duplicate accounts to obtain rewards dishonestly.

4. Merchant and Staff Rules

Merchants and their staff must not:

  • Issue or redeem stamps dishonestly, or coerce customers into sharing their contact details;
  • Use the QR security features to harass or disadvantage customers; or
  • Allow staff to act outside the scope of their assigned Place(s).

5. Handling of Customer Contact Details

These rules are mandatory for any Merchant that receives customer contact details through the opt-in feature. Breach is a serious violation and may also breach POPIA.

You must not:

  • Use contact details obtained other than through a customer’s explicit opt-in;
  • Send unsolicited or spam communications, or any direct marketing that does not comply with section 69 of POPIA;
  • Contact a customer through a channel they did not share (for example, do not WhatsApp a customer who shared only their email, or vice versa);
  • Continue contacting a customer after they have opted out or withdrawn consent;
  • Sell, rent, on-share, or transfer customer contact details to any third party; or
  • Retain customer contact details longer than necessary, or fail to delete them on request.

You must include a clear and simple opt-out mechanism in every marketing communication, and act on opt-out requests promptly.

6. Reporting Abuse

If you become aware of any misuse of the Service or of customer data, report it to us at support@cardlessclub.co.za.

7. Enforcement

We may investigate suspected breaches and may suspend or terminate access immediately where we reasonably believe this AUP has been breached, without limiting any other remedy available to us or to affected customers under law.

6Refund PolicyWhen subscription refunds and extensions apply
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Contactsupport@cardlessclub.co.za
Last updated17 June 2026
Version2.1

1. General Position

All payments are final and non-refundable, save for the limited exception set out below. This includes the once-off R499 activation fee (which covers your first month and starter kit) and each monthly subscription payment thereafter. Subscriptions are billed monthly in advance.

2. Cancellation

You may cancel at any time. Cancellation takes effect at the end of the current paid month — you keep access until the month you have paid for runs out, and you are not charged again. No pro-rata refund is given for the unused portion of that month.

3. Outage Exception

A refund or equivalent subscription extension applies only where the Service experiences a continuous outage of 45 (forty-five) days or more caused by Cardless Club infrastructure.

This exception does not apply where the outage is caused by:

  • Hosting provider outages;
  • Google Maps Platform or other third-party API issues;
  • Third-party plugin failures; or
  • Merchant WiFi or device issues.

4. Discounts and Custom Terms

Where a discount, promotional code, franchise volume rate, or custom payment arrangement applied to your subscription, any refund or extension is calculated on the amount actually paid, not the standard fee.

5. How to Request

To request a refund or extension under the outage exception, contact us at support@cardlessclub.co.za.

6. Consumer Rights

Nothing in this Policy limits any rights you may have under the Consumer Protection Act, 2008 or other applicable South African law.

7Service Level Agreement (SLA)Our uptime targets and support response times
Legal entityTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Contactsupport@cardlessclub.co.za
Last updated1 June 2026
Version2.0

1. Scope

This Service Level Agreement (“SLA”) forms part of the Merchant Terms & Conditions and sets out the service levels we aim to provide for the Cardless Club Service.

2. Availability

  • Target uptime: 99%, measured monthly, excluding scheduled maintenance and upstream outages;
  • Scheduled maintenance is communicated by email at least 24 hours in advance where reasonably possible.

3. Support Response Times

  • General support enquiries: response within 48 hours;
  • System issues affecting core functionality: priority escalation with response within 12 hours.

Response times refer to our initial response, not guaranteed resolution times, and are measured during normal business hours in South Africa.

4. Exclusions

This SLA does not cover, and we are not responsible for, downtime or degradation caused by:

  • Merchant devices;
  • Merchant WiFi or internet connectivity;
  • Hosting provider failures;
  • Third-party plugin failures; or
  • Google Maps Platform or other third-party API failures.

5. Compensation

The sole remedy under this SLA is an extension of the subscription period where a continuous outage attributable to Cardless Club infrastructure exceeds 45 consecutive days, as set out in the Refund Policy. No cash refund is offered except as stated there.

6. Contact

To report a system issue, contact us at support@cardlessclub.co.za.

8Data Processing Agreement (DPA)Data-protection terms between us and merchants
CompanyTimes Six (Pty) Ltd (Registration No. 2020/072163/07)
Information OfficerTimes Six (Pty) Ltd, attention: The Founder
Contactsupport@cardlessclub.co.za
Last updated1 June 2026
Version2.0

Between Times Six (Pty) Ltd (trading as Cardless Club) and the Merchant.

1. Purpose and Scope

This Data Processing Agreement (“DPA”) forms part of the Merchant Terms & Conditions and governs the processing of personal information in connection with a Merchant’s use of the Cardless Club Service. It is intended to give effect to the requirements of the Protection of Personal Information Act, 2013 (“POPIA”).

2. Roles of the Parties

The roles of the parties depend on the activity:

  • Customer accounts: Times Six (Pty) Ltd is the Responsible Party. We determine the purpose and means of processing customer account data.
  • Loyalty interactions on the Merchant’s Place: Times Six (Pty) Ltd acts as Operator (processor) on behalf of the Merchant for the loyalty activity recorded at that Place, while remaining Responsible Party for the underlying account.
  • Opt-in contact details: Where a customer voluntarily shares their email and/or WhatsApp number with the Merchant’s Place, Cardless Club facilitates a consent-based disclosure from one Responsible Party to another. Upon receipt, the Merchant is an independent Responsible Party for those details, and does not process them on our behalf.

3. What We Process

In our capacity as Operator for loyalty interactions, we process:

  • Customer display name;
  • Stamps and redemptions recorded at the Merchant’s Place;
  • Staff actions; and
  • Place branding and configuration.

We process opted-in customer contact details only to transmit them to the Merchant the customer selected. We do not process those details for our own purposes, and we do not use them for marketing.

4. Our Obligations as Operator

We will:

  • Process personal information only for the purpose of providing the Service and on the documented instructions reflected in the Terms;
  • Implement appropriate, reasonable technical and organisational security measures — including encryption in transit, access controls, per-user data isolation, secure hosting, and regular security updates;
  • Ensure persons authorised to process the data are subject to confidentiality;
  • Notify the Merchant without undue delay on becoming aware of a compromise affecting the Merchant’s customer data, as required by section 22 of POPIA; and
  • On termination, cease processing and delete or return data, save where retention is required by law.

5. Merchant Obligations

The Merchant must:

  • Ensure its staff comply with this DPA and with POPIA;
  • Not misuse customer data, and not attempt to collect, scrape, or infer customer contact details by any means other than the opt-in feature;
  • Handle opt-in contact details as an independent Responsible Party, including full compliance with section 69 of POPIA for any direct marketing;
  • Honour customer requests to access, correct, or delete their details, and honour withdrawals of consent;
  • Keep any exported (downloaded) data secure and recognise that, once exported, it is solely under the Merchant’s control; and
  • Indemnify Times Six (Pty) Ltd against claims arising from the Merchant’s handling of personal information, as set out in the Merchant Terms & Conditions.

6. Sub-Operators

We engage trusted sub-operators to deliver the Service (for example, our hosting provider, Paystack for payments, Google Maps Platform, and our email delivery provider). We require each to provide POPIA-compliant safeguards. Customer card and bank numbers are handled by Paystack and are never stored by us.

7. Cross-Border Processing

Where a sub-operator processes data outside South Africa, we take reasonable steps to ensure protection comparable to POPIA, consistent with section 72 of POPIA.

8. Liability and Term

This DPA remains in force for as long as we process personal information in connection with the Merchant’s Place. Liability under this DPA is subject to the limitations in the Merchant Terms & Conditions, except for liability that cannot lawfully be limited. Where this DPA conflicts with the Terms on data-protection matters, this DPA prevails.

9. Contact

Data-protection queries should be directed to our Information Officer at support@cardlessclub.co.za.

Cardless Club is operated by Times Six Pty Ltd Registration No. 2020/072163/07, Randburg, Johannesburg, Gauteng, South Africa.
Merchant Terms and Refund Policy last updated 17 June 2026 Version 2.1. All other documents last updated 1 June 2026 Version 2.0.