privacy
Privacy Policy
BetXchange (Pty) Ltd
Effective date: [[DATE — e.g. 1 October 2026]] Last updated: [[DATE]] Version: 1.0
1. Introduction
This Privacy Policy explains how BetXchange (Pty) Ltd ("BetXchange", "we", "us", "our"), a company incorporated in the Republic of South Africa with registration number [[COMPANY REGISTRATION NUMBER]] and registered address [[REGISTERED ADDRESS]], collects, uses, stores, shares, protects and deletes personal information.
It covers:
- our websites, including [[www.betxchange.co.za]] and any sub-domains we operate;
- our betting products and customer accounts;
- our internal marketing and business-intelligence systems; and
- our application "[[APP NAME — the name shown on the Google OAuth consent screen]]", which connects to the Google Ads API and to other Google APIs.
Section 4 of this policy is written specifically to satisfy Google's requirements for applications that access Google user data, including the Google API Services User Data Policy and its Limited Use requirements. If you only want to know how we handle data obtained from Google, read section 4.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and, where it applies to us, the EU General Data Protection Regulation ("GDPR") and the UK GDPR.
2. Who is responsible for your information
Responsible Party / Data Controller
| Entity | BetXchange (Pty) Ltd |
| Registration number | [[REG NUMBER]] |
| Physical address | [[ADDRESS]] |
| Licence | [[GAMBLING LICENCE NUMBER AND ISSUING BOARD — e.g. Western Cape Gambling and Racing Board bookmaker licence no. ...]] |
Information Officer (as required by section 55 of POPIA)
| Name | [[FULL NAME OF REGISTERED INFORMATION OFFICER]] |
| [[privacy@betxchange.co.za]] | |
| Telephone | [[+27 ...]] |
| Postal address | [[ADDRESS]] |
Our Information Officer is registered with the Information Regulator of South Africa. All privacy queries, access requests and complaints should be sent to the address above.
3. Definitions
- Personal information / personal data — information relating to an identifiable living natural person and, where applicable under POPIA, an identifiable existing juristic person.
- Google user data — any data that we obtain from a Google API using credentials authorised by a Google Account, including all data returned by the Google Ads API.
- Processing — any operation performed on personal information, including collection, storage, use, transmission, modification and deletion.
- Data subject — the person to whom personal information relates.
- Sub-processor / Operator — a third party that processes personal information on our behalf and on our instructions.
4. Google user data and the Google Ads API
This section describes, in full, how our application accesses, uses, stores, shares, protects, retains and deletes data obtained from Google APIs.
4.1 What our application does
[[APP NAME]] is an internal business-intelligence and reporting application. It is operated by BetXchange for BetXchange's own use. It is not offered to, sold to, or made available to third parties, advertisers, agencies or the public.
Its function is to automatically retrieve advertising performance data from the Google Ads accounts that BetXchange itself owns or is authorised to manage, load that data into our internal data warehouse, and present it to our marketing and finance staff as dashboards and reports alongside data from our other advertising channels. This lets us measure campaign performance, control marketing spend and report accurately to management and regulators.
If this is not accurate, amend it. Google reviews this description against what your app actually does. If you also write to Google Ads (create or pause campaigns, upload conversions, manage audiences), say so here — see sections 4.5 and 4.11.
Access is limited to authorised BetXchange employees and contractors who are authenticated against our internal identity system and who have a business need for the data.
4.2 Which Google APIs and scopes we use
We request the narrowest set of OAuth scopes that allows the application to function:
| Scope | Why we request it |
|---|---|
https://www.googleapis.com/auth/adwords | Required to call the Google Ads API. This is the only scope Google publishes for the Google Ads API; there is no read-only variant. Although the scope permits write access, our application's credentials and code paths are restricted to read operations only. [[Delete the previous sentence if you perform write operations.]] |
openid, email, profile | [[Only if used]] To identify which BetXchange staff member authorised the connection, and to display that account in our administration interface. |
| [[ADD ANY OTHER SCOPES]] | [[REASON]] |
Authorisation is granted by a BetXchange employee signing in with a BetXchange-controlled Google Account that already has access to the relevant Google Ads accounts. We do not ask members of the public to authorise this application.
4.3 What Google user data we access
Through the Google Ads API we retrieve the following categories of data. The large majority of it is aggregated advertising performance data and contains no personal information about any individual.
Account and structural data
- Google Ads customer IDs, manager (MCC) account IDs, account names, descriptive names, currency codes, time zones and account status
- Campaign, ad group, ad, keyword, asset, extension and audience structure, names, settings, status and targeting configuration
- Bidding strategies, budgets and budget settings
- Conversion action definitions and conversion tracking configuration
Performance and reporting data
- Impressions, clicks, cost, click-through rate, average cost per click and equivalent metrics
- Conversions, conversion value, all-conversions, view-through conversions, conversion lag and attribution data
- Video, display, shopping, app and Performance Max metrics where relevant
- Search terms reports, which contain the search queries that led to our ads being shown. These are supplied by Google in aggregated form and Google removes queries that could identify an individual. We do not attempt to re-identify anyone from them.
- Segmentations of the above by date, device, network, geographic area, ad schedule and demographic band. These segmentations are aggregate and do not identify individuals.
Billing and financial data
- Billing setups, payment account and payments profile identifiers, invoices, account budgets, spend and credit information
Data that may contain personal information
Two areas of the Google Ads API return information about identifiable people. We disclose them explicitly:
- Account user access records (for example the
customer_user_accessandcustomer_user_access_invitationresources): the email addresses, access roles and invitation status of the individuals who have access to our Google Ads accounts. - Change history (the
change_eventresource): the email address of the user who made each change to an account, together with what was changed and when.
In both cases the individuals concerned are BetXchange employees, contractors or our authorised agency staff. We use this data solely for internal access control, audit and change-tracking purposes.
Credentials
- OAuth 2.0 access tokens, refresh tokens and the associated client identifiers, and the identifier and email address of the Google Account that granted authorisation.
What we do not receive. The Google Ads API does not return the identity, contact details, device identifiers or browsing history of the individual people who see or click our advertisements, and we do not attempt to obtain that information through it.
4.4 How we use Google user data
We use Google user data only for the following purposes, all of which are user-facing features of the application that requested the data:
- Reporting and dashboards. Presenting campaign, channel and account performance to authorised BetXchange staff in our internal dashboards.
- Cross-channel measurement. Combining Google Ads performance data with data from our other advertising platforms and from our own first-party systems so that marketing performance can be compared on a like-for-like basis.
- Budget and spend control. Monitoring advertising spend against budget, reconciling advertising invoices, and producing financial and management reporting.
- Marketing effectiveness analysis. Calculating cost per acquisition, return on ad spend and similar internal metrics, and analysing which campaigns perform best.
- Operational monitoring. Detecting failed data loads, data-quality problems and anomalies in the integration itself.
- Access control and audit. Using account access and change-history records to know who has access to our advertising accounts and who changed what.
- Legal and regulatory compliance. Meeting our obligations as a licensed gambling operator, including advertising compliance records, and responding to lawful requests from regulators, auditors and courts.
We do not use Google user data for any purpose materially different from those listed above. If we ever intend to, we will update this policy and obtain fresh consent before doing so.
4.5 Limited Use disclosure
[[APP NAME]]'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, and without limiting that commitment, we confirm that we do not:
- transfer or sell Google user data to advertising platforms, data brokers, information resellers or any other third party, except as set out in section 4.6;
- use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising;
- use Google user data to determine credit-worthiness, or for lending, insurance, employment, housing or similar eligibility decisions;
- use Google user data for any form of user profiling of members of the public;
- use Google user data to train generalised or non-personalised artificial-intelligence or machine-learning models, and we do not send Google user data to any third-party or public AI or large-language-model service;
- allow humans to read Google user data, except (a) with the affected user's express consent, (b) where it is necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymised and is used for internal operations such as debugging a failed data load; or
- combine Google user data with data from other sources in a way that would identify an individual end user of Google's services.
4.6 Who we share Google user data with
We do not sell Google user data and we do not share it for anyone else's commercial purposes. It is disclosed only to:
| Recipient | Purpose | Location |
|---|---|---|
| Authorised BetXchange personnel | Marketing, analytics, finance and engineering staff with a business need | South Africa [[+ any other country where staff are based]] |
| [[CLOUD / HOSTING PROVIDER]] | Hosting the application, database and data warehouse | [[COUNTRY / REGION]] |
| [[BI OR VISUALISATION TOOL — e.g. Grafana]] | Displaying dashboards to internal users | [[COUNTRY / REGION]] |
| [[MONITORING OR ERROR-TRACKING SERVICE]] | Application monitoring and error reporting. Configured to exclude Google user data from payloads wherever technically possible. | [[COUNTRY / REGION]] |
| [[EXTERNAL AUDITORS / REGULATORS]] | Where required by law, licence condition or audit | South Africa |
Each sub-processor is bound by a written agreement that requires it to process the data only on our documented instructions, to apply appropriate security safeguards, and to return or delete the data at the end of the engagement, as required by section 21 of POPIA and, where applicable, Article 28 of the GDPR.
We may also disclose Google user data where we are legally compelled to do so, or in connection with a merger, acquisition or sale of assets — in which case we will give affected users advance notice and, where the Google API Services User Data Policy requires it, obtain their explicit prior consent.
Where a proposed transfer would breach the Limited Use requirements, we will delete the data rather than transfer it.
4.7 Where Google user data is stored
Google user data is stored in [[COUNTRY / REGION]], on infrastructure operated by [[PROVIDER]].
Where data is stored or accessed outside South Africa, we rely on the transfer grounds in section 72 of POPIA — namely that the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA. Where the GDPR applies, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. A copy of the relevant safeguards is available on request from our Information Officer.
4.8 How long we keep Google user data, and how we delete it
| Data | Retention period | What happens at the end |
|---|---|---|
| OAuth refresh tokens and access tokens | For as long as the connection is active. Revoked and deleted within 24 hours of a user disconnecting the integration, and automatically after [[180]] days of continuous inactivity. | Permanently deleted from the database and from encrypted backups on the next backup rotation. |
| Raw Google Ads API responses (landing/staging layer) | [[30]] days | Permanently deleted by an automated job. |
| Modelled campaign performance data (daily aggregates) | [[26]] months, matching Google Ads' own reporting horizon | Permanently deleted or irreversibly aggregated to a level that contains no account identifiers. |
| Billing, invoice and advertising spend records | [[7]] years | Retained to meet our obligations under the Companies Act 71 of 2008, the Tax Administration Act 28 of 2011 and our gambling licence conditions, then deleted. |
| Account user access and change-history records (containing staff email addresses) | [[24]] months | Permanently deleted. |
| Application and access logs | [[12]] months | Permanently deleted. |
| Encrypted backups | [[35]] days rolling | Overwritten on rotation. Data deleted from the live system will persist in backups for at most this period. |
Deletion on revocation. When authorisation for a Google Ads account is revoked — whether by a user disconnecting it in our application, or by revoking access at myaccount.google.com/permissions — we stop retrieving data from that account immediately, delete the stored credentials within 24 hours, and delete all Google user data retrieved from that account within 30 days, except where we are legally required to retain financial records as set out above.
Deletion on request. Any individual whose personal information appears in Google user data we hold (for example a staff member appearing in change-history records) may request its deletion using the process in section 9.
4.9 How we protect Google user data
We apply the following technical and organisational measures, as required by section 19 of POPIA and Article 32 of the GDPR:
- Encryption in transit. All connections to Google APIs and to our own systems use TLS 1.2 or higher. HTTP is redirected to HTTPS and HSTS is enforced.
- Encryption at rest. OAuth client secrets and refresh tokens are encrypted at rest with AES-256 using keys held in [[SECRETS MANAGER]]. Database volumes and backups are encrypted.
- Secrets management. Credentials are never committed to source control, never written to application logs, and never exposed in the user interface after they are entered.
- Least privilege. Access to production systems and to the data warehouse is restricted to named individuals by role. Service accounts are scoped to the minimum permissions required.
- Authentication. Multi-factor authentication is enforced on the Google Accounts used to authorise the integration, on our Google Cloud project, and on administrative access to our own systems.
- Network controls. Production databases are not exposed to the public internet. Administrative access is via [[VPN / bastion host / IP allowlist]].
- Logging and monitoring. Access to Google user data is logged. Logs are monitored for anomalous access patterns and retained as set out in section 4.8.
- Change control. Changes to the integration are made through version control, peer review and an automated deployment pipeline. Direct manual changes to production are prohibited.
- Separation of environments. Development and testing use separate Google Cloud projects and separate credentials from production, and do not use production data.
- Vendor diligence. Sub-processors are assessed before engagement and are contractually bound to equivalent standards.
- Review. These controls are reviewed at least annually and after any material change to the integration.
Security incidents. If Google user data is subject to unauthorised access or disclosure, we will notify the Information Regulator of South Africa and the affected data subjects as soon as reasonably possible after establishing the facts, as required by section 22 of POPIA, and within 72 hours where the GDPR applies. We will also notify Google where the incident affects Google user data.
4.10 How to review or revoke our access
A user who has authorised our application may withdraw that authorisation at any time by:
- disconnecting the account inside [[APP NAME]] at [[URL OF YOUR CONNECTIONS PAGE]]; or
- visiting Google Account permissions, selecting [[APP NAME]] and choosing Remove access.
Revocation takes effect immediately and triggers the deletion process in section 4.8. Revoking access does not affect the lawfulness of processing carried out beforehand.
4.11 Uploading data to Google
[[Keep this section only if you upload data to Google — offline conversions, Customer Match audiences, store sales data or similar. If you only read from the API, delete section 4.11 entirely.]]
In addition to retrieving data from Google, we send the following data to Google:
- Offline conversion uploads. When a customer who clicked one of our ads later completes a qualifying action, we send Google the Google Click Identifier (GCLID) or Google-supplied click identifier associated with that click, the conversion action, the conversion time and the conversion value. This allows Google to attribute the conversion to the correct campaign. We do not send the customer's name, email address, betting history, transaction detail or account balance in these uploads.
- Enhanced conversions and Customer Match. Where we use these features, customer contact details (email address, telephone number, first and last name, country and postal code) are irreversibly hashed using SHA-256 on our own systems before transmission. Google never receives these details in plain text from us. We use them only to match existing customers to Google accounts for audience targeting and measurement, and we do so only where we have a lawful basis and, where required, the customer's consent.
Where we upload customer data to Google we:
- obtain the consent required by POPIA and, where applicable, the GDPR, and honour any withdrawal of that consent by removing the customer from the relevant audience;
- exclude any customer who has self-excluded from gambling, who has asked not to receive marketing, or who is subject to a responsible-gambling restriction;
- exclude special personal information as defined in section 26 of POPIA; and
- comply with Google's Customer Match policy and the Google Ads gambling and games policy.
Customers may object to this processing at any time using the contact details in section 14.
5. Other personal information we process
Outside the Google Ads integration, we process personal information in the ordinary course of our business.
5.1 Customers and account holders
- Identity and verification data: full name, date of birth, identity or passport number, nationality, proof of address and proof of identity documents. Collected because the National Gambling Act 7 of 2004, our provincial licence conditions and the Financial Intelligence Centre Act 38 of 2001 ("FICA") require us to verify identity and age.
- Contact data: email address, mobile number, postal address.
- Financial data: bank account or card details, deposits, withdrawals, transaction history, source-of-funds information.
- Betting data: bets placed, stakes, settlements, balances, bonuses and promotions used.
- Technical data: IP address, device and browser information, and geolocation to the extent needed to confirm you are betting from a permitted jurisdiction.
- Responsible gambling data: deposit limits, self-exclusion status, cooling-off periods and any interactions with our responsible-gambling team.
- Communications: correspondence with our support team, including recorded calls where we have told you the call is recorded.
5.2 Website visitors and prospective customers
- Pages viewed, referral source, campaign identifiers (including Google Click Identifiers), approximate location derived from IP address, and cookie identifiers — see section 12.
5.3 Job applicants and staff
- Information supplied through our careers portal and in the course of recruitment and employment. This is dealt with in our separate [[Employee and Applicant Privacy Notice]].
5.4 Sources
We collect this information directly from you, from your use of our sites and apps, from advertising and analytics platforms including Google, from payment providers, and from identity-verification, credit and fraud-prevention bureaux where the law permits.
6. Why we process personal information, and our legal basis
| Purpose | Legal basis under POPIA | Legal basis under GDPR (where applicable) |
|---|---|---|
| Opening and operating your betting account | Performance of a contract (s 11(1)(b)) | Art 6(1)(b) contract |
| Age, identity and FICA verification | Compliance with a legal obligation (s 11(1)(c)) | Art 6(1)(c) legal obligation |
| Processing deposits, withdrawals and bets | Performance of a contract (s 11(1)(b)) | Art 6(1)(b) contract |
| Responsible gambling monitoring and self-exclusion | Legal obligation; protection of a legitimate interest (s 11(1)(c), (f)) | Art 6(1)(c), Art 6(1)(f) |
| Fraud prevention, AML and security | Legitimate interest (s 11(1)(f)) | Art 6(1)(f) legitimate interests |
| Marketing analytics, including Google Ads reporting | Legitimate interest (s 11(1)(f)) | Art 6(1)(f) legitimate interests |
| Direct electronic marketing to existing customers | Section 11(1)(f) read with section 69(3) of POPIA | Art 6(1)(f), with soft opt-in where applicable |
| Direct electronic marketing to non-customers | Consent (s 69(1)) | Art 6(1)(a) consent |
| Customer Match and audience uploads | Consent (s 69) | Art 6(1)(a) consent |
| Regulatory, tax and audit reporting | Legal obligation (s 11(1)(c)) | Art 6(1)(c) |
We rely on legitimate interests only where we have satisfied ourselves that our interests are not overridden by your rights. You may object to that processing at any time — see section 9.
7. Automated decision-making
[[Choose one and delete the other.]]
Option A — We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.
Option B — We use automated systems to screen transactions for fraud, money laundering and problem-gambling indicators, and to apply account limits. Where an automated decision significantly affects you, you have the right to be told the reasoning, to make representations, and to have the decision reviewed by a person. Contact our Information Officer to exercise that right.
8. Cross-border transfers
Some of our service providers are located outside South Africa. Where we transfer personal information across a border, we do so only on one of the grounds permitted by section 72 of POPIA:
- the recipient is subject to a law, binding corporate rules or a binding agreement providing a level of protection substantially similar to POPIA;
- you have consented to the transfer;
- the transfer is necessary to perform a contract with you, or a contract concluded in your interest; or
- the transfer benefits you and it is not reasonably practicable to obtain your consent.
Our current principal cross-border recipients are listed in section 4.6 and in our sub-processor register, available on request.
9. Your rights
Subject to the limits the law places on them, you have the right to:
- be told what personal information we hold about you and who has had access to it (section 23 of POPIA; Article 15 GDPR);
- access a copy of that information;
- correct or complete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24 POPIA; Article 16 GDPR);
- request deletion or destruction of information we are no longer entitled to retain (section 24 POPIA; Article 17 GDPR);
- object to processing based on legitimate interests, and to direct marketing at any time (section 11(3) POPIA; Article 21 GDPR);
- withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal;
- data portability — receive information you gave us in a structured, commonly used, machine-readable format, where the GDPR applies (Article 20 GDPR);
- restrict processing in the circumstances set out in Article 18 GDPR; and
- complain to a supervisory authority (section 13).
How to exercise these rights. Email our Information Officer at [[privacy@betxchange.co.za]]. For POPIA access and correction requests we use the prescribed Form 2 and Form 3, which we will send you on request or which are available from the Information Regulator's website. We will respond within 30 days, or within the period prescribed by the Promotion of Access to Information Act 2 of 2000 where that Act applies. Where the GDPR applies we will respond within one month. We may need to verify your identity before acting, and certain records — particularly FICA and gambling records — must be retained by law even if you ask us to delete them.
We do not charge for a first request. A prescribed fee may apply to further copies or to requests under the Promotion of Access to Information Act.
10. Age restriction
Our services are strictly for persons aged 18 years or older. We do not knowingly collect personal information from anyone under 18. Our application that connects to the Google Ads API is used only by BetXchange staff and is not directed at children.
If we discover that we hold information about a person under 18, we will close the account, withhold any winnings as required by the National Gambling Act, and delete the information except where we must retain it to demonstrate regulatory compliance.
If you believe a minor has provided us with personal information, contact our Information Officer immediately.
National Responsible Gambling Programme toll-free counselling line: 0800 006 008. Winners know when to stop. No persons under 18 are permitted to gamble.
11. How we keep information secure
In addition to the measures described in section 4.9, which apply to all data in our platform:
- customer passwords are stored only as salted cryptographic hashes;
- payment card data is handled by PCI-DSS compliant payment providers and is not stored on our systems in full;
- identity documents are stored encrypted and access to them is restricted and logged;
- our staff receive privacy and information-security training and are bound by written confidentiality undertakings; and
- we test our systems for vulnerabilities [[FREQUENCY — e.g. quarterly]] and remediate findings on a risk-prioritised basis.
No system is perfectly secure. We cannot guarantee absolute security, but we will act promptly and transparently if something goes wrong.
12. Cookies and similar technologies
We use cookies and similar technologies on our websites to keep you signed in, remember your preferences, measure traffic, and measure the performance of our advertising — including advertising we run through Google Ads.
We set non-essential cookies, including advertising and analytics cookies, only after you have consented through our cookie banner. You can change or withdraw that consent at any time via [[LINK TO COOKIE SETTINGS]].
Google's own use of information collected through its advertising cookies and tags is governed by the Google Privacy Policy and How Google uses information from sites or apps that use our services. You can control the ads Google shows you at Google Ads Settings, and you can opt out of Google Analytics measurement using the Google Analytics opt-out browser add-on.
[[If you maintain a separate Cookie Policy, link it here and keep this section short.]]
13. Complaints
If you are unhappy with how we have handled your personal information, please tell our Information Officer first — we would like the chance to put it right.
You may also complain to the Information Regulator (South Africa):
| Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Post | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
| General enquiries | enquiries@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| Website | https://inforegulator.org.za |
[[Verify these contact details before publishing — the Regulator has changed them before.]]
If you are in the EU or the UK, you may complain to your local data protection authority.
14. Contact us
| Privacy and data protection | [[privacy@betxchange.co.za]] |
| Information Officer | [[name and email]] |
| Customer support | [[support@betxchange.co.za]] |
| Postal address | [[ADDRESS]] |
| Telephone | [[+27 ...]] |
15. Changes to this policy
We review this policy at least annually and whenever we materially change how we process personal information.
If we change how we use Google user data — including using it for a purpose not described in section 4.4, requesting additional OAuth scopes, or sharing it with a new category of recipient — we will update this policy, publish the updated version at this URL, and notify affected users and obtain their consent to the updated policy before the new processing begins, as required by the Google API Services User Data Policy.
The version number and "last updated" date at the top of this policy always reflect the current version. Superseded versions are available on request.
This policy is published at [[https://www.betxchange.co.za/privacy]] and is the privacy policy referenced on the Google OAuth consent screen for the Google Cloud project [[PROJECT NAME / NUMBER]].
betXchange is a licensed betting operator.
betXchange Western Cape (Pty) Ltd is licenced with the
Western Cape Gambling and Racing Board.
betXchange.Com (Pty) Ltd is licenced with the
Eastern Cape Gambling Board (ECBM 041).
betXchange supports the National
Responsible Gambling Programme.
No persons under the age of 18 are permitted to gamble.
South African Responsible Gambling Foundation
toll free counselling line 0800 006 008 or
WHATSAPP HELP to 076 675 0710
or visit www.responsiblegambling.org.za
WINNERS KNOW WHEN TO STOP.
WARNING: Please take note of the following:
Gambling is addictive. Gambling entails risk.
When you gamble on this website, you understand that you may lose.
Email betXchange: customercare@betxchange.co.za
Telephone: 011 712 4610




