🔒 Legal · Last Updated 1 June 2026

Privacy Policy

How Send2Bank collects, uses, and protects your personal information. We believe in transparency and data minimization.

🔐

📋 Summary

Send2Bank collects only what we need to operate your account safely. We never sell your personal data to third parties. You can request a copy of your data or close your account at any time by contacting [email protected].

01Our Commitment to Your Privacy

Send2Bank is a multi-currency payment and billing platform operating in Uganda, Kenya, and across East Africa. We provide mobile money, Bitcoin, and multi-currency wallet services to individuals and businesses. References to "Send2Bank", "we", "us", or "our" refer to the Send2Bank platform and its operators.

We are committed to protecting your privacy and handling your personal data with care. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have regarding your data. Our approach is guided by the principle of data minimization — we only collect information that is necessary to provide our services, comply with legal obligations, and protect the security of your account.

This policy applies to all Send2Bank services, including our web platform, mobile applications, APIs, and any other service that links to this policy. By using Send2Bank, you consent to the data practices described in this policy.

02Information We Collect

We collect different categories of information depending on how you interact with our platform. All collection is done with a specific purpose and legal basis.

Account Information

When you create a Send2Bank account, we collect your phone number, which serves as your primary account identifier. You set a 4-digit PIN which is immediately hashed using bcrypt — we never store your PIN in plain text or in any recoverable format. We also collect your full name, email address if provided, country of residence, and preferred currency.

Identity Verification (KYC)

To comply with financial regulations and unlock full platform features, you must complete identity verification through our certified KYC partner, didit.me. During this process we collect your government-issued identification document — such as a national ID card, passport, or driver's licence — along with facial biometric data captured through a live selfie. The KYC results and verification status are stored on your account.

Biometric data is processed solely for identity verification purposes and is handled in accordance with our data processing agreement with didit.me. We do not use biometric data for any other purpose.

Transaction Data

Every financial activity on your account is recorded for operational, regulatory, and audit purposes. This includes all deposits, withdrawals, transfers, invoice payments, subscription charges, and currency conversions. For each transaction we record the amount, currency, timestamp, payment method used, counterparty details, and a unique reference number. For mobile money transactions we record the phone number used; for Bitcoin transactions we record the wallet addresses involved.

Device and Usage Data

When you access our platform, we automatically collect certain technical information including your IP address, browser type and version, device type and operating system, referring URLs, pages visited, and features used. This information helps us diagnose technical issues, detect unauthorized access, and improve our platform experience.

03How We Use Your Information

Every piece of data we collect serves a specific, legitimate purpose. We use your information to:

  • Process your payments and maintain accurate wallet balances across all currencies
  • Verify your identity and comply with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations
  • Send you real-time transaction confirmations via SMS and email so you always know the status of your money
  • Detect and prevent fraud, money laundering, unauthorized access, and other illegal activities through automated monitoring systems
  • Generate professional invoices, receipts, account statements, and accounting reports for your business
  • Provide customer support, investigate disputes, and resolve technical issues
  • Analyze platform usage patterns to improve performance, fix bugs, and develop new features
  • Communicate important account updates, security alerts, and changes to our policies or terms

We do not use your personal data for automated decision-making that produces legal effects or similarly significant consequences without human review.

04Information Sharing & Third Parties

We do not sell, rent, or trade your personal information to anyone. We share data only in the following limited and necessary circumstances:

💳

Payment Processors

MTN Mobile Money, Airtel Money, and BTCPay Server receive transaction data necessary to process your payments. They are contractually bound to protect your data.

🪪

KYC Provider

didit.me receives your identification document and facial biometric data solely for identity verification. Data processing is governed by a strict DPA.

🧾

Billing Partner

Lago receives subscription and usage data required for invoice generation and billing automation.

⚖️

Legal Obligations

We disclose data to regulatory authorities, financial intelligence units, law enforcement, or courts when required by valid legal process.

All third-party service providers are carefully vetted and contractually obligated to implement appropriate security measures, process data only as instructed, and delete or return data upon termination of services.

05Data Retention & Deletion

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law. Specifically:

  • Transaction records are retained for a minimum of 7 years as required by financial regulations in Uganda and Kenya
  • KYC documents and identity verification records are retained for the duration of your account plus 5 years after account closure
  • Account information is retained while your account is active and for a reasonable period after closure to handle any residual matters
  • Non-regulatory data such as usage logs and support communications may be deleted earlier upon request or as part of routine data hygiene

You may request deletion of any non-regulatory personal data at any time by contacting [email protected]. We will respond to deletion requests within 30 days, subject to our legal obligation to retain certain records.

06Security Measures

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. All data transmitted between your device and our servers is encrypted using 256-bit TLS 1.3. Data at rest is encrypted using AES-256. Passwords and PINs are hashed using bcrypt with per-user salts and are never stored in plain text or recoverable format.

Our infrastructure includes Web Application Firewall protection, rate limiting on all authentication and transaction endpoints, automated intrusion detection, regular penetration testing, and continuous vulnerability scanning. Access to production data is strictly controlled through role-based access controls, multi-factor authentication, and comprehensive audit logging.

For more detailed information about our security practices, please review our Security page.

07Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

📋

Right to Access

Request a copy of all personal data we hold about you in a structured, machine-readable format.

✏️

Right to Rectification

Correct inaccurate or incomplete personal information we hold about you.

🗑️

Right to Erasure

Request deletion of personal data that is no longer necessary, subject to legal retention requirements.

🚫

Right to Object

Object to processing of your data for direct marketing purposes at any time.

📤

Data Portability

Receive your data in a portable format and transfer it to another service provider.

🔒

Account Closure

Close your account at any time. Remaining balances will be returned after verification.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days and may require identity verification before processing your request to prevent unauthorized disclosures.

08Cookies & Tracking Technologies

Send2Bank uses only essential session cookies that are strictly necessary for the operation of our platform. These cookies maintain your authenticated session, protect against cross-site request forgery, and remember your preferences during your visit. They expire when you close your browser or log out.

We do not use advertising cookies, tracking cookies, third-party analytics cookies, or any form of cross-site tracking. We do not build advertising profiles or share browsing data with advertising networks. Our platform is built for financial services, not for surveillance capitalism.

Most browsers allow you to control cookies through their settings. However, disabling essential cookies will prevent you from logging into and using the Send2Bank platform, as session management is required for secure authentication.

09Children's Privacy

Send2Bank is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. Our identity verification process requires government-issued identification, which inherently verifies age. If we become aware that a minor has provided us with personal data without verifiable parental consent, we will take immediate steps to delete such information and close the account.

If you are a parent or guardian and believe your child has created a Send2Bank account, please contact us at [email protected] so we can take appropriate action.

10International Data Transfers

Send2Bank operates primarily from data centers in East Africa. However, certain third-party service providers — such as our KYC partner didit.me — may process data in other jurisdictions including the European Union. When your data is transferred internationally, we ensure that appropriate safeguards are in place, including standard contractual clauses, data processing agreements, and adequacy decisions where applicable.

By using Send2Bank, you acknowledge that your data may be transferred to and processed in countries outside your country of residence. We take all reasonably necessary steps to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

11Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by SMS or email at least 14 days before the changes take effect. The "Last Updated" date at the top of this page will always reflect the most recent revision.

Continued use of the Send2Bank platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may close your account before they take effect.

We encourage you to review this policy periodically. The latest version will always be available at send2bank.com/privacy.

Questions About Your Privacy?

Contact our Data Protection team. We're here to help.

[email protected]

Ready to Get Started?

Open your free Send2Bank account today and start collecting payments from anywhere.

Open Free Account →