Legal
Privacy Policy
Last updated:
GigMoPay ("we", "our", or "us") is committed to protecting your personal information. This policy explains what data we collect, how we use it, and the choices you have.
1. Who we are
GigMoPay is a borderless payments platform enabling African freelancers to receive international payments in USD, EUR and GBP and cash out in local currency via mobile money or bank transfer. Our registered address is available on request at privacy@gigmopay.com.
2. Data we collect
2.1 Account and identity data
- Full name, date of birth, and nationality
- Government-issued ID (passport, national ID, driver's licence)
- Selfie or liveness photo for identity verification (KYC)
- Email address and phone number
2.2 Financial data
- Bank account numbers and mobile money numbers you add as payout destinations
- Transaction history (amounts, dates, counterparties, exchange rates)
- Virtual account details assigned to you
2.3 Usage data
- IP address, device type, operating system, and browser
- Pages visited and features used within the app
- Referral source and UTM parameters
- Product analytics events (e.g. onboarding steps, feature usage) — we do not send payment amounts, account numbers, or government ID data to analytics tools
2.4 Marketing and contact data
If you contact us or opt in to product updates, we collect your email address and any details you provide. We use this solely to respond to your enquiry and, where you have consented, to send you news about the Service.
3. How we use your data
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Contract performance |
| Identity verification (KYC / AML) | Legal obligation |
| Processing payments and cash-outs | Contract performance |
| Fraud detection and prevention | Legitimate interest / Legal obligation |
| Sending transactional notifications | Contract performance |
| Sending product updates and early-access emails | Consent (you may withdraw at any time) |
| Improving and debugging the platform | Legitimate interest / Consent (website analytics cookies) |
| Complying with regulatory reporting requirements | Legal obligation |
4. Who we share data with
We do not sell your personal data. We share it only with:
- Licensed banking and payment partners in your country (required to process transactions)
- KYC/AML providers (e.g. Bridge and licensed verification partners) for identity verification
- Infrastructure providers (Cloudflare, Convex) who process data on our behalf under data processing agreements
- PostHog (EU-hosted product analytics) — page views, feature usage, and error reports to improve the product. No advertising profiling; no sale of personal data. Website analytics run only after cookie consent. Mobile and server-side events use pseudonymous user IDs, not email or payment details.
- Google Analytics 4 — aggregated website traffic and page views on every visit to gigmopay.com. IP anonymization is enabled. Not used for advertising personalization on this site.
- Regulators and law enforcement when required by law
5. Data retention
We retain account and transaction data for a minimum of 5 years after account closure to meet anti-money-laundering regulations. Marketing and contact data is deleted within 30 days of your request. Product analytics data in PostHog is retained for up to 12 months, then deleted or aggregated.
6. International transfers
GigMoPay operates across multiple jurisdictions. Your data may be processed in countries outside your country of residence. Where we transfer data outside your home jurisdiction, we ensure appropriate safeguards are in place (standard contractual clauses, adequacy decisions, or equivalent protections).
7. Your rights
Depending on your country of residence, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete your data (subject to legal retention obligations)
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — for any processing based on consent (e.g. marketing emails)
To exercise any right, email privacy@gigmopay.com. We respond within 30 days.
8. Cookies and tracking
We use essential cookies for security and sign-in. Google Analytics runs on every visit to the marketing website. Optional PostHog analytics cookies are loaded only if you click "Accept all" in our cookie banner. We do not use third-party advertising cookies. The mobile app may send product analytics and error reports to PostHog as described in this policy — not for ad profiling. See our Cookie Policy for full details.
9. Security
We use TLS 1.3 for data in transit and AES-256 encryption for data at rest. Access to production data is restricted to authorised personnel with multi-factor authentication. Penetration testing is conducted at least annually.
10. Changes to this policy
We may update this policy periodically. We will notify registered users by email at least 14 days before material changes take effect. The "Last updated" date at the top of this page always reflects the current version.
11. Contact
For privacy-related questions or requests, contact our privacy team at:
privacy@gigmopay.com