Privacy policy
Last updated 2026-04-24
WhileSmart Pay processes payments for merchants across African and global markets. We only collect what we need to operate those payments, stay compliant with card network and mobile money rules, and prevent fraud. We never sell your data.
What we collect
- Merchant account: business name, contact email and phone, company registration documents you submit during onboarding.
- Transaction data: amount, currency, payment rail, timestamps, and a reference to the customer who paid. Card PANs are never stored on our servers: they live inside our PCI-certified processor.
- Product telemetry: dashboard session metadata and minimal error logs so we can fix bugs. No third-party advertising trackers.
How we use it
To process payments, settle funds to your payout accounts, meet our KYC and AML obligations, prevent fraud, and send you transactional email about your account. That's the whole list.
Data residency and encryption
Data in transit is protected with TLS 1.2 or higher. Data at rest is encrypted with AES-256. Payment data is processed inside a PCI DSS Level 1 environment. Mobile money webhooks are signed with HMAC-SHA256 so you can verify they came from us.
Subprocessors
MTN and Orange for mobile money rails, Stripe for card processing in certain markets, AWS for compute and storage, Postmark for transactional email.
Your rights
You can export, correct, or delete the data associated with your merchant account at any time. Where required by local law we honor access, portability, and erasure requests. Records we are legally required to retain (tax, AML) are kept for the mandated period.
Contact
Questions or requests: privacy@whilesmart.com.