Privacy Policy
Contents
1. Who we are
TsaraPay ([COMPANY LEGAL NAME], registered in [JURISDICTION], no. [REG. NO.], [REGISTERED ADDRESS]) is the controller of personal data described in this Policy, except where we process data on behalf of a Merchant, in which case the Merchant is the controller and we act as processor.
2. Data we collect
Depending on how you interact with us, we may collect:
- Business & identity data (KYB/KYC): company details, beneficial owners, directors, government-issued IDs, proof of address, licensing information, and verification results.
- Contact data: name, email, phone, role, and messages you send us.
- Transaction data: amounts, currencies, payment methods, timestamps, wallet or account identifiers, and related metadata. We do not store full card numbers; card data is handled by PCI-compliant partners.
- Technical data: IP address, device and browser information, and usage/analytics data.
- Compliance data: sanctions, PEP, and adverse-media screening results, and records required to meet legal obligations.
3. How we use data
We use personal data to provide and operate the Services; verify identity and prevent fraud, money laundering, and terrorist financing; process and settle Transactions; provide support; maintain security; comply with legal and regulatory obligations; and improve and market our Services where permitted.
4. Legal bases
Where applicable data-protection law (such as the GDPR) applies, we rely on: performance of a contract; compliance with legal obligations; our legitimate interests (such as fraud prevention, security, and running our business); and consent where required (for example, certain marketing or cookies).
5. Sharing & disclosure
We may share personal data with: payment partners, acquirers, and financial institutions that help deliver the Services; identity-verification, screening, and fraud-prevention providers; cloud, hosting (including our CDN), and analytics providers; professional advisers; and competent authorities, regulators, or law-enforcement where required or permitted by law. We may also share data in connection with a merger, acquisition, or reorganisation. We do not sell personal data.
6. International transfers
We may transfer personal data to countries other than your own. Where required, we implement appropriate safeguards, such as standard contractual clauses or reliance on an adequacy decision. Details are available on request at the contact below.
7. Retention
We retain personal data for as long as necessary to provide the Services and to meet legal, regulatory, tax, accounting, and AML record-keeping obligations (which for certain records is typically [FIVE (5)] years or longer after the end of the business relationship), after which we delete or anonymise it.
8. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. Some rights are limited where we must retain data to meet legal obligations (for example, AML records). To exercise a right, contact us below. You may also complain to your local data-protection authority.
10. Cookies
Our site uses essential cookies to function and may use analytics cookies to understand usage. You can control cookies through your browser settings. Where required, we will request consent for non-essential cookies.
11. Children
The Services are for businesses and are not directed to children. We do not knowingly collect data from anyone under [18].
12. Changes
We may update this Policy from time to time and will post the revised version with a new "Last updated" date.
13. Contact
For privacy questions or requests: contact@tsarapay.com.
© 2026 TsaraPay. All rights reserved.