Privacy Policy
How we collect, use, share, store, and protect personal information when you use Payes.
01Scope
This Privacy Policy explains how Payes (“we,” “us,” or “our”) collects, uses, shares, stores, and protects personal information when you access or use our websites, mobile applications, POS terminals, admin console, and developer tools (APIs/SDKs) (collectively, the “Services”). If you do not agree with this Policy, please discontinue use of the Services.
02Information We Collect
We collect personal information on a lawful, legitimate, and necessary basis, which may vary by feature, region, and regulatory requirements.
2.1Account & Profile
- Name, nickname, nationality/residency, contact details (email/phone), language and time zone
- Login credentials, authentication factors (e.g., 2FA), account preferences and settings
2.2Identity Verification (KYC/AML/CFT)
- Government ID details (e.g., ID card/passport), selfie/liveness checks
- Address evidence, tax residency, occupation, source of funds/wealth
- Sanctions/adverse media results, PEP checks and other compliance outcomes
2.3Transactions & Financial Activity
- On-chain data: deposit/withdrawal addresses, transaction hashes, network and confirmations
- Card & payments: card identifiers/tokens, payment currency whitelist, authorization/clearing/refund records, 3-D Secure results
- Fiat on/off-ramp: bank or payment method identifiers, remittance and debit records
- P2P/OTC: listings, orders, counterparties, escrow/dispute materials and outcomes
2.4Device & Technical Data
- Device model, OS/browser, app version, IP address, device identifiers
- Network and (where permissioned) location, crash/performance logs, security logs
2.5Communications & Support
Emails, in-app messages, chat transcripts/tickets, call recordings and related metadata.
2.6Public/Third-Party Sources
Supplementary data from lawful public sources or partners (e.g., sanctions lists, risk databases) to the extent permitted by law and necessary for the purposes described in this Policy.
03How We Use Personal Information
We process personal information for one or more of the purposes below and under the legal bases indicated (which may vary by jurisdiction).
3.1Service Delivery (Contractual necessity)
Account creation and maintenance; transfers and conversion; card issuance and payments; POS acceptance; P2P/OTC execution; statements, reconciliation, invoices; status updates and notifications.
3.2Compliance Obligations (Legal obligation)
KYC/AML/CFT; sanctions screening; transaction monitoring and suspicious activity reporting; responding to lawful requests from tax authorities, courts, and regulators.
3.3Risk Management & Security (Legitimate interests / Legal obligation)
Identity and device checks; fraud and abuse prevention; rate limits and currency whitelists; intrusion/anti-scraping detection; incident response and continuity of service.
3.4Product Improvement (Legitimate interests / Consent, where required)
Analytics, performance and UX optimization; developing and evaluating de-identified or anonymized models for risk/fraud prevention and service enhancement.
3.5Customer Support & Communications (Contract / Legitimate interests)
Ticket handling, after-sales and dispute resolution, policy or service updates and essential notices.
3.6Marketing & Promotions (Consent / Legitimate interests)
With your permission where required, sending offers, surveys, and product updates. You may opt out at any time.
If you refuse to provide information necessary for core functionality, some Services may be unavailable.
04Cookies & Similar Technologies
We use cookies, pixels, and local storage to support sign-in, preferences, security, and analytics. You can manage cookies in your browser/OS settings. Disabling cookies may impact certain features or performance.
05Sharing, Transfer, and Disclosure
5.1Sharing with Service Providers and Partners
- Compliance and risk providers (KYC/AML/CFT, sanctions/adverse screening, risk scoring)
- Financial and payment partners (fiat on/off-ramp, card networks and issuing/acquiring partners, clearing/settlement, payment channels)
- Infrastructure and security vendors (cloud hosting/CDN, logging, monitoring, security assessment)
- Analytics and operations tools
5.2Business Transfers
In the event of a merger, reorganization, or asset/business transfer, we will provide notice as required by law and ensure the recipient continues to be bound by this Policy.
5.3Public Disclosure
We disclose information publicly only where required by law or with your explicit consent (e.g., regulatory or judicial requests).
06International Data Transfers
For compliance, clearing/settlement, operations, and customer support, personal information may be transferred to countries/regions outside your own. We implement appropriate safeguards (e.g., Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms) and technical/organizational measures as required by applicable laws.
07Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, taking into account:
- Duration of our contractual relationship and accounting/reconciliation needs
- Statutory or industry retention periods (e.g., AML recordkeeping)
- Dispute resolution and the establishment, exercise, or defense of legal claims
- Technical, security, and audit requirements
When retention ends, we delete or anonymize data unless a longer period is required by law.
08Security
We maintain reasonable technical and organizational security measures, including access controls and least-privilege practices; encryption in transit and at rest; privileged access review and audit logs; vulnerability management and periodic penetration testing; backup and disaster recovery; and incident response procedures. However, the internet and digital systems are not absolutely secure; no method can guarantee 100% security.
09Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access and obtain a copy of your personal information
- Rectify inaccurate or incomplete data
- Delete personal information in certain circumstances
- Restrict or object to specific processing activities (especially those based on legitimate interests or direct marketing)
- Data portability, where technically feasible
- Withdraw consent for processing based on consent (without affecting prior lawful processing)
- Contest automated decisions, including profiling, and request human review where required by law
To exercise these rights, use in-app Settings → Privacy or contact us via the channels in Section 13. We may need to verify your identity and will respond within the time limits required by law.
10Children’s Privacy
The Services are intended for users with full legal capacity. If you are a minor, use the Services only with the consent and supervision of a legal guardian, who may exercise rights on your behalf. If we become aware of personal information collected from minors without appropriate consent, we will delete or appropriately handle such data.
11Third-Party Services and Links
The Services may integrate or link to third-party websites, apps, plugins, or SDKs. Those third parties process personal information under their own privacy policies. Please review such policies before use. Payes is not responsible for the actions or omissions of third parties.
12Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated through in-product notices, announcements, or other reasonable means. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
13Contact Us
If you have questions, feedback, or complaints about this Policy or our handling of personal information, contact us via in-app Settings → Help & Support or email [email protected]. We will respond within a reasonable timeframe. If you are unsatisfied with our response and local law permits, you may also contact your data protection authority.
Questions about this policy?
Email [email protected] and we will respond as soon as we can.