Privacy Policy

Last updated · Version 1.1

What we collect

Two kinds of information: what you give us, and what using the wallet produces.

What you give us:

  • Your phone number. Required, and unique to one account — it is your identity here.
  • Your full name, your date of birth, your country, and the type and number of an identity document. Asked for once, when you complete your profile.
  • Photographs of that identity document — both sides, where it has two — and a photograph of your own face. Asked for when we check who you are.
  • An email address, if you choose to give one. Optional.
  • If you apply to run an agent counter: the name you would trade under, the town or market you would serve, anything you write in the note, and a photograph or scan of the business registration and of something showing the counter’s address.

What using the wallet produces:

  • A record of each session we open for you — when it started, when it expires, when it was last used, whether it was ended, and the IP address and the browser or app it was used from.
  • A record of each one-time code we send — which channel carried it, how many attempts have been spent against it, and when it expires.
  • Your ledger: every movement of money in or out of your wallets, as double-entry records carrying the amount, the currency, the date, and the account on each side.
  • Each price we quote you — who the transfer was for, the amount, the rate and the fee — kept so a receipt can still be reconstructed after that rate and that fee have moved on.
  • A record of each message we send you: what it was about, which channel carried it, whether it was delivered, why it failed if it did, and the number or address it went to, masked rather than whole.
  • For each photograph you send: what the file turned out to be, how large it was, when it arrived, and a fingerprint of its contents.
  • A record of each time a member of our staff opens one of your photographs — who opened it, which one, and when.

When our own staff act on your account — suspending it, correcting a record, approving an agent — we record who did it, what they did, and the IP address they did it from.

Why we collect it

Each item above is here for a reason:

  • Your phone number, so you can sign in and so people can send money to you.
  • Your name, date of birth, country and identity document, because a business that holds and moves money for people has to know who they are.
  • Your photographs, so a member of our staff can look at the document, compare it with the photograph of your face, and decide whether you are who you say you are. An agent handles other people’s cash, so an agent’s counter is checked the same way.
  • The fingerprint of each file, so the same document sent twice can be recognised as the same document.
  • The record of who opened a photograph, so every look at your identity document can be traced to the person who took it.
  • Session records, so you and we can see where your account has been used, and so a session can be ended.
  • Code records, so a code can be spent once and only once, and so repeated wrong attempts can be stopped before they succeed.
  • The ledger, because it is the record of your money. Without it there is no balance to show you.
  • Quotes, so a receipt still adds up after the rate and the fee behind it have changed.
  • Message records, so we can tell you whether a message you were owed was sent, and so the same message is not sent to you twice.
  • Staff records, so a change we made to your account can be traced to the person who made it.

Lawful basis

Different information rests on a different footing.

  • To do what you asked. Signing you in, quoting a transfer, moving money, sending you a receipt — we cannot do these without the information they need.
  • Because we are required to. Identity details, the photographs you send to support them, and financial records are kept because a business handling money is obliged to keep them.
  • To stop fraud. Session records, IP addresses, attempt counts and staff records exist so we can tell an account’s owner from somebody using it without permission.
  • Because you chose. Your email address, and an application to run an agent counter. You can take either back.

Which rules apply to you depends on the country you are in.

Sharing

We pass on what a job needs and nothing beyond it.

  • The provider that delivers our text messages receives your phone number and the message. Every sign-in code goes through them.
  • The provider that delivers our email receives your email address and the message, on the occasions we send you one.
  • The company that hosts our systems holds the database all of this lives in, and the company that stores our files holds your photographs. Both act on our instruction rather than their own.
  • An agent you transact with sees the name on your account and the amount of that one movement. They do not see your balance, your other wallets, or your other movements.
  • A court or a public authority, where the law requires us to give it.

We do not sell your information, we do not share it for advertising, and there is no advertising or analytics code on this site to share it with.

International transfers

VpayAfrica operates in more than one country. It is one system, not one system per country: your information is held in one place and reached from the countries we operate in, so information you give us in one country is processed in another.

The same is true of the ledger. When money moves between two countries, both sides of that movement are entries in one ledger — there is no separate national copy to hold apart from the rest.

Where a provider outside your country handles your information, what they may do with it is set by our agreement with them and not by them.

Security

One-time codes are stored only as a salted hash. The six digits we text you are not kept: when you type them in, we hash what you typed and compare it with the hash we stored. A copy of that table hands nobody a working code.

Session tokens are the same. The token your browser holds is issued once and never written down; what we keep is a hash of it, so a leaked table does not hand over live sessions.

Customers have no password, so there is no customer password held here at all. Signing in needs your phone number and a code sent to it.

Traffic between your device and us travels over an encrypted connection, and the cookie carrying your session is flagged so that a browser will not send it over an unencrypted one and no script on the page can read it.

Your photographs are not held in the database with the rest of your record. They go to a separate private store, under a name that is a random identifier and says nothing about you, and nothing in that store answers to a public address.

A member of staff who opens one gets a link made at the moment they ask for it, which stops working a few minutes later. Making that link is what writes the record of who looked.

Access to customer records is limited by role to the staff whose work needs it, and each action they take on an account is recorded against them. Opening a photograph of an identity document takes more than the role that reads records.

If something goes wrong that affects your information, we will tell you what happened and what it means for you.

Retention

Different information is kept for different lengths of time.

Financial records — the ledger, and the quotes and journals behind it — are kept for as long as the rules that apply to this business require. That period is not ours to shorten.

Identity details, and the photographs you sent to support them, are kept while you hold an account, and after it closes for as long as those same rules require.

If you replace a photograph with a clearer one, the one it replaced is deleted when the new one lands.

Session and code records are short-lived by design: a session expires and a code expires, and expired ones are cleared. There is one exception — where a movement of money points at a code, that code’s record is part of the evidence that you confirmed the movement, and it stays for as long as the movement does.

Message records are kept so that a question about a message you were owed can still be answered.

Closing your account

When your account closes you can no longer sign in, and nobody can send money to it. Take your balance out before you ask us to close it.

Your profile — your name, your date of birth, your country, your identity document and the photographs you sent — is kept for as long as the rules above require, and then removed.

Your account is closed rather than deleted. The record holding your phone number stays, because the movements of money point at it and a movement must not be left pointing at nothing.

The ledger is not removed. A double-entry ledger works by summing entries that were never edited: your balance, and the balance of everyone who sent money to you or received money from you, is derived from those entries. Removing yours would make all of them impossible to prove. We are also required to keep financial records. So the ledger is the one thing a request to delete cannot reach.

Children and age

VpayAfrica is for adults. You must be 18 or older to hold a wallet, which is why we ask for your date of birth.

We do not set out to hold information about a child. If you think we are holding some, tell us using the details at the end of this document and we will look and remove what we should not have.

Your rights

You can ask us to:

  • show you what we hold about you;
  • correct something that is wrong;
  • give you a copy in a form you can take elsewhere;
  • stop using your information for a particular purpose, or object to a use of it;
  • limit what we do with it while a question about it is open;
  • delete it.

Deletion has a limit. We remove what we are free to remove. We cannot remove your ledger entries, for the reason set out under “Closing your account”.

Ask using the details at the end of this document. We have to be sure it is you asking — for a wallet identified by a phone number, that means a code sent to that number.

Which of these you can insist on, and how long we have to answer, depends on the country you are in.

Cookies

The wallet sets two cookies. There is no third.

  • vpay_session — your sign-in. Written when you sign in, cleared when you sign out, and expiring on its own.
  • vpay_challenge — which step of signing in you are on. It holds the reference of the code we texted you, and it is gone once you use the code or the code expires.

Both are set so that no script on the page can read them and a browser will not send them over an unencrypted connection.

We set no advertising cookie and no analytics cookie, which is why nothing on this site asks you to accept any.

How to contact us

Your information is held by the company that operates VpayAfrica.

Write to us, email us, or call. Use these for a question about your information, or to make any of the requests above.

1 Example StreetAccraGhanasupport@vpayafrica.com+233 00 000 0000Monday to Friday, 08:00 to 17:00 GMT