How Send2Bank collects, uses, and protects your personal information. We believe in transparency and data minimization.
Send2Bank collects only what we need to operate your account safely. We never sell your personal data to third parties. You can request a copy of your data or close your account at any time by contacting [email protected].
Send2Bank is a multi-currency payment and billing platform operating in Uganda, Kenya, and across East Africa. We provide mobile money, Bitcoin, and multi-currency wallet services to individuals and businesses. References to "Send2Bank", "we", "us", or "our" refer to the Send2Bank platform and its operators.
We are committed to protecting your privacy and handling your personal data with care. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have regarding your data. Our approach is guided by the principle of data minimization — we only collect information that is necessary to provide our services, comply with legal obligations, and protect the security of your account.
This policy applies to all Send2Bank services, including our web platform, mobile applications, APIs, and any other service that links to this policy. By using Send2Bank, you consent to the data practices described in this policy.
We collect different categories of information depending on how you interact with our platform. All collection is done with a specific purpose and legal basis.
When you create a Send2Bank account, we collect your phone number, which serves as your primary account identifier. You set a 4-digit PIN which is immediately hashed using bcrypt — we never store your PIN in plain text or in any recoverable format. We also collect your full name, email address if provided, country of residence, and preferred currency.
To comply with financial regulations and unlock full platform features, you must complete identity verification through our certified KYC partner, didit.me. During this process we collect your government-issued identification document — such as a national ID card, passport, or driver's licence — along with facial biometric data captured through a live selfie. The KYC results and verification status are stored on your account.
Biometric data is processed solely for identity verification purposes and is handled in accordance with our data processing agreement with didit.me. We do not use biometric data for any other purpose.
Every financial activity on your account is recorded for operational, regulatory, and audit purposes. This includes all deposits, withdrawals, transfers, invoice payments, subscription charges, and currency conversions. For each transaction we record the amount, currency, timestamp, payment method used, counterparty details, and a unique reference number. For mobile money transactions we record the phone number used; for Bitcoin transactions we record the wallet addresses involved.
When you access our platform, we automatically collect certain technical information including your IP address, browser type and version, device type and operating system, referring URLs, pages visited, and features used. This information helps us diagnose technical issues, detect unauthorized access, and improve our platform experience.
Every piece of data we collect serves a specific, legitimate purpose. We use your information to:
We do not use your personal data for automated decision-making that produces legal effects or similarly significant consequences without human review.
We do not sell, rent, or trade your personal information to anyone. We share data only in the following limited and necessary circumstances:
MTN Mobile Money, Airtel Money, and BTCPay Server receive transaction data necessary to process your payments. They are contractually bound to protect your data.
didit.me receives your identification document and facial biometric data solely for identity verification. Data processing is governed by a strict DPA.
Lago receives subscription and usage data required for invoice generation and billing automation.
We disclose data to regulatory authorities, financial intelligence units, law enforcement, or courts when required by valid legal process.
All third-party service providers are carefully vetted and contractually obligated to implement appropriate security measures, process data only as instructed, and delete or return data upon termination of services.
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law. Specifically:
You may request deletion of any non-regulatory personal data at any time by contacting [email protected]. We will respond to deletion requests within 30 days, subject to our legal obligation to retain certain records.
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. All data transmitted between your device and our servers is encrypted using 256-bit TLS 1.3. Data at rest is encrypted using AES-256. Passwords and PINs are hashed using bcrypt with per-user salts and are never stored in plain text or recoverable format.
Our infrastructure includes Web Application Firewall protection, rate limiting on all authentication and transaction endpoints, automated intrusion detection, regular penetration testing, and continuous vulnerability scanning. Access to production data is strictly controlled through role-based access controls, multi-factor authentication, and comprehensive audit logging.
For more detailed information about our security practices, please review our Security page.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Request a copy of all personal data we hold about you in a structured, machine-readable format.
Correct inaccurate or incomplete personal information we hold about you.
Request deletion of personal data that is no longer necessary, subject to legal retention requirements.
Object to processing of your data for direct marketing purposes at any time.
Receive your data in a portable format and transfer it to another service provider.
Close your account at any time. Remaining balances will be returned after verification.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days and may require identity verification before processing your request to prevent unauthorized disclosures.
Send2Bank uses only essential session cookies that are strictly necessary for the operation of our platform. These cookies maintain your authenticated session, protect against cross-site request forgery, and remember your preferences during your visit. They expire when you close your browser or log out.
We do not use advertising cookies, tracking cookies, third-party analytics cookies, or any form of cross-site tracking. We do not build advertising profiles or share browsing data with advertising networks. Our platform is built for financial services, not for surveillance capitalism.
Most browsers allow you to control cookies through their settings. However, disabling essential cookies will prevent you from logging into and using the Send2Bank platform, as session management is required for secure authentication.
Send2Bank is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. Our identity verification process requires government-issued identification, which inherently verifies age. If we become aware that a minor has provided us with personal data without verifiable parental consent, we will take immediate steps to delete such information and close the account.
If you are a parent or guardian and believe your child has created a Send2Bank account, please contact us at [email protected] so we can take appropriate action.
Send2Bank operates primarily from data centers in East Africa. However, certain third-party service providers — such as our KYC partner didit.me — may process data in other jurisdictions including the European Union. When your data is transferred internationally, we ensure that appropriate safeguards are in place, including standard contractual clauses, data processing agreements, and adequacy decisions where applicable.
By using Send2Bank, you acknowledge that your data may be transferred to and processed in countries outside your country of residence. We take all reasonably necessary steps to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by SMS or email at least 14 days before the changes take effect. The "Last Updated" date at the top of this page will always reflect the most recent revision.
Continued use of the Send2Bank platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may close your account before they take effect.
We encourage you to review this policy periodically. The latest version will always be available at send2bank.com/privacy.