Legal

Privacy Policy

Last updated:

GigMoPay ("we", "our", or "us") is committed to protecting your personal information. This policy explains what data we collect, how we use it, and the choices you have.

1. Who we are

GigMoPay is a borderless payments platform enabling African freelancers to receive international payments in USD, EUR and GBP and cash out in local currency via mobile money or bank transfer. Our registered address is available on request at privacy@gigmopay.com.

2. Data we collect

2.1 Account and identity data

  • Full name, date of birth, and nationality
  • Government-issued ID (passport, national ID, driver's licence)
  • Selfie or liveness photo for identity verification (KYC)
  • Email address and phone number

2.2 Financial data

  • Bank account numbers and mobile money numbers you add as payout destinations
  • Transaction history (amounts, dates, counterparties, exchange rates)
  • Virtual account details assigned to you

2.3 Usage data

  • IP address, device type, operating system, and browser
  • Pages visited and features used within the app
  • Referral source and UTM parameters
  • Product analytics events (e.g. onboarding steps, feature usage) — we do not send payment amounts, account numbers, or government ID data to analytics tools

2.4 Marketing and contact data

If you contact us or opt in to product updates, we collect your email address and any details you provide. We use this solely to respond to your enquiry and, where you have consented, to send you news about the Service.

3. How we use your data

PurposeLegal basis
Creating and managing your accountContract performance
Identity verification (KYC / AML)Legal obligation
Processing payments and cash-outsContract performance
Fraud detection and preventionLegitimate interest / Legal obligation
Sending transactional notificationsContract performance
Sending product updates and early-access emailsConsent (you may withdraw at any time)
Improving and debugging the platformLegitimate interest / Consent (website analytics cookies)
Complying with regulatory reporting requirementsLegal obligation

4. Who we share data with

We do not sell your personal data. We share it only with:

  • Licensed banking and payment partners in your country (required to process transactions)
  • KYC/AML providers (e.g. Bridge and licensed verification partners) for identity verification
  • Infrastructure providers (Cloudflare, Convex) who process data on our behalf under data processing agreements
  • PostHog (EU-hosted product analytics) — page views, feature usage, and error reports to improve the product. No advertising profiling; no sale of personal data. Website analytics run only after cookie consent. Mobile and server-side events use pseudonymous user IDs, not email or payment details.
  • Google Analytics 4 — aggregated website traffic and page views on every visit to gigmopay.com. IP anonymization is enabled. Not used for advertising personalization on this site.
  • Regulators and law enforcement when required by law

5. Data retention

We retain account and transaction data for a minimum of 5 years after account closure to meet anti-money-laundering regulations. Marketing and contact data is deleted within 30 days of your request. Product analytics data in PostHog is retained for up to 12 months, then deleted or aggregated.

6. International transfers

GigMoPay operates across multiple jurisdictions. Your data may be processed in countries outside your country of residence. Where we transfer data outside your home jurisdiction, we ensure appropriate safeguards are in place (standard contractual clauses, adequacy decisions, or equivalent protections).

7. Your rights

Depending on your country of residence, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — ask us to delete your data (subject to legal retention obligations)
  • Portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — for any processing based on consent (e.g. marketing emails)

To exercise any right, email privacy@gigmopay.com. We respond within 30 days.

8. Cookies and tracking

We use essential cookies for security and sign-in. Google Analytics runs on every visit to the marketing website. Optional PostHog analytics cookies are loaded only if you click "Accept all" in our cookie banner. We do not use third-party advertising cookies. The mobile app may send product analytics and error reports to PostHog as described in this policy — not for ad profiling. See our Cookie Policy for full details.

9. Security

We use TLS 1.3 for data in transit and AES-256 encryption for data at rest. Access to production data is restricted to authorised personnel with multi-factor authentication. Penetration testing is conducted at least annually.

10. Changes to this policy

We may update this policy periodically. We will notify registered users by email at least 14 days before material changes take effect. The "Last updated" date at the top of this page always reflects the current version.

11. Contact

For privacy-related questions or requests, contact our privacy team at:
privacy@gigmopay.com