Privacy Policy
Effective: [EFFECTIVE DATE] · Version 1.0
[COMPANY LEGAL NAME] ("SP-Heavy", "we") operates a payment platform for businesses in Cameroon and the wider CEMAC region. This policy explains what personal data we handle, why, and what rights you have.
Contact for anything in this policy: [PRIVACY EMAIL] Data protection officer / responsible person: [DPO CONTACT]
1. Who this policy is for
We handle personal data about three groups, and our role differs for each. This distinction matters, because it decides who you ask to exercise your rights.
| You are… | Our role | What that means |
|---|---|---|
| A merchant (or a director, owner or staff member of one) | Controller | We decide why and how your data is used, largely because the law obliges us to verify and monitor you. |
| A payer paying a merchant through SP-Heavy | Processor for the merchant | The merchant decides why your data is used. Ask the merchant first — they are the business you bought from. |
| A website visitor | Controller | Basic analytics and security logging. |
For payer data we act on the merchant's instructions under the Data Processing Agreement. Where we are a processor, we will pass your request to the relevant merchant. We also handle a narrow set of payer data as a controller in our own right — specifically for fraud prevention and anti-money-laundering, where the law requires us to act independently of the merchant's instructions.
2. What we collect
From merchants
- Identity and contact — business name, registered number, address, your name, email, phone.
- Verification (KYC) — identity documents for directors and beneficial owners, proof of address, business registration documents, and evidence of your commercial activity.
- Financial — bank account details for settlement, wallet balance, transaction history, fees.
- Account and technical — hashed password, second-factor secret (encrypted), API key metadata, IP addresses, device and browser information, audit logs of security-relevant actions such as sign-in, key creation and password change.
We store hashes of passwords and API secret keys, never the values themselves. Two-factor secrets are encrypted at rest.
From payers (on behalf of merchants)
- Mobile-money number (MSISDN)
- Payment amount, currency and status
- Transaction references, including the provider's own reference
- Any metadata the merchant attaches, such as an order number
- Technical data such as IP address and timestamp, used for fraud prevention
We do not collect or store payment-card numbers. We do not have access to a payer's mobile-money PIN — authorisation happens on the payer's handset, with their operator.
From visitors
Pages visited, referring page, approximate location derived from IP, and device type. See the Cookie Policy.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the payment service, maintaining your wallet and settling funds | Performance of a contract |
| Verifying your identity (KYC), sanctions and PEP screening | Legal obligation (AML/CFT) |
| Monitoring transactions for money laundering and fraud, and reporting suspicion | Legal obligation; substantial public interest |
| Keeping records after your account closes | Legal obligation |
| Securing the platform, rate limiting, investigating abuse | Legitimate interests — running a payment system safely |
| Support and service communications | Performance of a contract |
| Product improvement and aggregate analytics | Legitimate interests |
| Marketing about our own services | Consent, withdrawable at any time |
We do not sell personal data. We do not use your transaction data to build advertising profiles.
4. Automated decision-making
We run automated fraud and risk checks on transactions and accounts. These can result in a payment being declined, a settlement being held, or an account being suspended.
You may ask for a human review of any automated decision that significantly affects you. Write to [PRIVACY EMAIL].
We may not be able to explain a decision in detail where doing so would reveal our fraud controls, or where anti-money-laundering law forbids us from telling you that a report has been made. This restriction is imposed by law, not by preference.
5. Who we share it with
- Payment providers — MTN Mobile Money and Orange Money. We must send the payer's number and the amount to move the money.
- Banks — to settle your balance to your nominated account.
- Verification and screening providers — for identity checks and sanctions screening.
- Infrastructure providers — hosting, database, email delivery, error monitoring. See the Sub-processors list.
- Regulators, law enforcement and courts — where legally required, including suspicious-transaction reports to Cameroon's financial intelligence unit (ANIF). We are generally prohibited by law from telling you when such a report has been made.
- Professional advisers — lawyers, auditors, accountants, under confidentiality.
- An acquirer — if the business is sold or reorganised, subject to this policy continuing to apply.
We do not share your data with anyone else for their own purposes.
6. International transfers
Some providers process data outside Cameroon and outside the CEMAC region. Where that happens we require appropriate safeguards — contractual protections equivalent to those that apply here, and, where relevant, standard contractual clauses.
[Confirm with counsel which transfer mechanism applies under current Cameroonian law, and list the countries involved once the hosting region is fixed.]
7. How long we keep it
| Data | Retention |
|---|---|
| Transaction records and ledger entries | [RETENTION PERIOD] after the transaction — AML rules typically require at least 10 years |
| KYC documents | [RETENTION PERIOD] after the relationship ends |
| Account and profile | Duration of the relationship, then per the above |
| Security and audit logs | [LOG RETENTION — e.g. 12–24 months] |
| Support correspondence | [SUPPORT RETENTION — e.g. 3 years] |
| Marketing consent records | Until withdrawn, plus proof of withdrawal |
Financial records cannot be deleted on request. A deletion request does not override a legal retention obligation; we will explain what we must keep and why.
8. Your rights
Subject to applicable law, you may ask to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete data, where no legal obligation requires us to keep it
- Restrict or object to processing based on legitimate interests
- Port data you gave us, in a machine-readable format
- Withdraw consent, where consent is the basis
- Not be subject to a purely automated decision with significant effect — see §4
To exercise a right, email [PRIVACY EMAIL]. We will respond within [RESPONSE PERIOD — e.g. 30 days]. We may need to verify your identity first; we will not use that verification data for anything else.
If you are a payer, contact the merchant you paid. We will forward your request to them and support them in answering it.
If you are unhappy with our response, you may complain to the relevant supervisory authority in Cameroon — [CONFIRM CURRENT AUTHORITY AND CONTACT DETAILS WITH COUNSEL].
9. Security
We protect data with, among other measures:
- Encryption in transit (TLS) for all API and dashboard traffic
- Passwords stored as salted scrypt hashes; API secret keys stored as peppered hashes; two-factor secrets encrypted with AES-256-GCM at rest
- Short-lived access tokens with rotating, revocable refresh sessions
- Rate limiting and account lockout against brute-force attempts
- Signed webhooks so you can verify messages genuinely come from us
- An append-only ledger, so financial history is auditable and tamper-evident
- Access controls limiting staff access to what their role requires
No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will notify you and the relevant authority as the law requires, without undue delay.
10. Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact [PRIVACY EMAIL] and we will delete it.
11. Changes
We will post any change here with a new effective date. If a change materially affects you, we will notify you by email or in the dashboard before it takes effect.
Legal framework
This policy is written to align with the data-protection, e-commerce, cybersecurity and anti-money-laundering frameworks applicable in Cameroon and the CEMAC region, and with the GDPR where we handle data of people in the European Union.
For counsel: Cameroon's data-protection landscape has been developing, and the applicable statute, the competent supervisory authority, and the required international-transfer mechanism must all be confirmed against the law in force at publication. Sections 6, 8 and 11 in particular depend on that answer.
[COMPANY LEGAL NAME] · [REGISTERED ADDRESS] · RCCM [RCCM NUMBER]