Privacy Policy
Contents
- Who We Are
- Scope of This Policy
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Identity Verification (KYC) Data
- Wallet & Transaction Data
- Audit Logs & Security Records
- Telegram Notifications
- Cookies & Tracking
- How We Share Your Information
- International Data Transfers
- Data Retention
- Security
- Your Rights
- Children's Privacy
- Changes to This Policy
- Contact & Complaints
1. Who We Are
paySwapr ("paySwapr", "we", "us", "our") operates a peer-to-peer (P2P) cryptocurrency marketplace accessible at https://payswapr.com. We act as the data controller for personal information collected through the Platform.
paySwapr is operated by [Company Legal Name], a company registered in the Federal Republic of Nigeria with Corporate Affairs Commission registration number [RC 0000000], whose registered office is at [Registered Address, Lagos, Nigeria].
Our Data Protection Officer can be contacted at support@payswapr.com. We are committed to protecting your personal information and handling it responsibly, transparently, and in compliance with applicable data protection laws.
2. Scope of This Policy
This Privacy Policy applies to all personal information we collect when you visit the paySwapr website, register an account, complete identity verification, post or accept trade offers, communicate through our platform, or interact with any paySwapr service.
This Policy forms part of our Terms of Service. By using the Platform, you acknowledge that you have read and understood how we collect and use your information as described here. Where we ask for your consent, you may withdraw it at any time — withdrawal of consent does not affect the lawfulness of processing before the withdrawal.
3. Information We Collect
We collect information in the following categories:
3.1 Account Registration Data
- Username, email address, and encrypted password.
- Security PIN (stored as a one-way hash; we cannot read your PIN).
- PIN attempt counter and lockout timestamp (used to enforce security cooldown after repeated incorrect PIN entries; cleared on successful unlock).
- Account creation date and referral source.
- Two-factor authentication (2FA) configuration data. We do not store generated TOTP codes.
3.2 Identity Verification (KYC) Data
- Full legal name, date of birth, and country of residence.
- Government-issued identity document type, and images of the front and back of the document.
- A live selfie photo taken through the Platform's in-browser camera for liveness verification.
- Proof of address documents (for Level 2 verification), such as a utility bill or bank statement.
- KYC submission status, review outcome, and any rejection reason.
3.3 Trade & Transaction Data
- Offers created: coin, price, payment method, trade limits, and instructions.
- Trade records: participants, amounts, timestamps, status, and trade chat messages, including Voucher ("Buy & Sell") and USDT Escrow trades.
- USDT Escrow records: opt-in status, escrowed USDT amount, locked conversion rate, swap fee, and settlement outcome.
- Coin Swap records: source and destination coins, amounts, provider used, quoted and settled rates, and transaction status.
- Dispute records: raised issues, evidence submitted, and resolution outcomes.
- Feedback and ratings left after completed trades.
- Wallet addresses, deposit and withdrawal history, and on-chain transaction IDs.
3.4 Device & Access Data
- IP address at every login, security action, and key platform event.
- Device type, operating system, browser type and version.
- Session identifiers and timestamps.
- Geographic location derived from IP address (country/region level).
3.5 Communications Data
- In-platform trade chat messages between Buyers and Sellers.
- Support enquiries submitted by email or through the Platform.
- Telegram user ID if you connect your Telegram account for notifications.
3.6 Cookies & Usage Data
See Section 10 — Cookies & Tracking for details.
4. How We Use Your Information
| Purpose | Data used |
|---|---|
| Providing the Platform — account creation, login, wallet management, offer listing, trade execution, and escrow. | Account data, trade data, wallet addresses. |
| Identity verification (KYC) — verifying your identity to comply with anti-money laundering (AML) regulations and unlock higher trade limits. | KYC data (name, DOB, country, ID documents, selfie, address proof). |
| Security & fraud prevention — detecting suspicious activity, preventing account takeover, and protecting the integrity of the marketplace. | Device data, IP address, audit logs, login history. |
| Dispute resolution — reviewing trade evidence, making binding decisions on escalated disputes. | Trade chat, payment evidence, trade records, account history. |
| Notifications — sending transactional alerts (trade updates, login activity, KYC outcomes) by email and optionally via Telegram. | Email address, Telegram ID (if connected). |
| Legal compliance — meeting AML/KYC obligations, responding to lawful authority requests, record-keeping as required by law. | All categories as required. |
| Platform improvement — analysing aggregated, anonymised usage patterns to improve features and performance. | Anonymised usage data, aggregated statistics. |
| Support — responding to enquiries, investigating complaints, and providing account assistance. | Account data, communications data, trade records. |
We do not use your personal information for automated decision-making that produces legal or similarly significant effects without human review.
5. Legal Bases for Processing
We rely on the following legal bases to process your personal information:
- Contract performance: Processing necessary to provide the services you requested, including account operation, trade execution, escrow, and wallet management.
- Legal obligation: Processing required to comply with anti-money laundering laws, KYC regulations, tax record-keeping, and lawful authority requests.
- Legitimate interests: Security monitoring, fraud prevention, dispute resolution, audit logging, and improving the Platform — where these do not override your rights.
- Consent: Sending Telegram notifications (you may withdraw consent at any time by disconnecting Telegram in your account settings).
6. Identity Verification (KYC) Data
KYC documents — including identity document images, selfies, and proof of address — are treated with the highest level of care. These files are stored in an encrypted private storage volume that is not publicly accessible. Access is restricted to authorised paySwapr compliance staff only.
Your selfie is captured live through your device's camera directly within the Platform browser session. We do not support selfie uploads; this design prevents submission of pre-existing photographs and ensures liveness.
What KYC data is used for:
- Verifying your identity against your submitted government-issued document.
- Determining your trade tier and daily trading limit under our AML policy.
- Meeting regulatory obligations to identify and verify platform participants.
- Investigating potential fraud, impersonation, or Terms of Service violations.
KYC data is not shared with other Users, advertisers, or commercial third parties. It may be disclosed to regulatory authorities or law enforcement where required by law.
KYC records are retained for a minimum of five years following your last activity on the Platform, in accordance with anti-money laundering record-keeping requirements. Where tax obligations apply, records may be retained for up to seven years.
7. Wallet & Transaction Data
paySwapr provides each registered User with a platform cryptocurrency wallet. Wallet private key material is generated and managed through our blockchain infrastructure provider and is stored in an encrypted form. We do not display raw private keys or seed phrases are available only to users who have enabled Two-Factor Authentication (2FA). When a verified user requests their seed phrase, the encrypted mnemonic is decrypted server-side and transmitted to the user over an authenticated, encrypted session. The seed phrase is not stored in plaintext.
All on-chain transactions — deposits, withdrawals, and escrow movements — are recorded on the relevant public blockchain and are inherently public by the nature of blockchain technology. Your wallet address may be visible to counterparties in trades and is recorded in our internal audit systems.
Transaction records, including amounts, counterparty wallet addresses, timestamps, and trade references, are retained as part of our AML record-keeping obligations and for dispute resolution purposes.
By using the platform wallet, you acknowledge that:
- Blockchain transactions are irreversible once broadcast.
- Your wallet data is processed by our blockchain infrastructure provider in accordance with their terms and security standards.
- Wallet activity may be reviewed by our compliance team where suspicious activity is flagged.
8. Audit Logs & Security Records
paySwapr maintains append-only audit logs of all significant platform events. This includes:
- Every login, failed login attempt, and session termination.
- Security-sensitive actions such as PIN changes, email updates, 2FA configuration, and withdrawal requests.
- All trade actions: offer creation, trade initiation, payment marking, escrow release, dispute escalation, and resolution.
- All KYC submissions, reviews, approvals, rejections, and admin actions on KYC records.
- Administrative actions taken by all staff members, including senior administration.
Each audit log entry records the actor (user or staff account), the action taken, the affected record, the IP address, device information, and timestamp. These logs are write-once and cannot be modified or deleted by any user or administrator.
Audit logs are used for security investigations, dispute resolution, AML compliance, and internal accountability. They are not shared with other Users and are only disclosed to legal authorities in response to lawful requests.
9. Telegram Notifications
paySwapr offers optional Telegram-based notifications for trade updates, login alerts, and KYC status changes. This feature requires you to connect your Telegram account to your paySwapr account.
When you enable Telegram notifications:
- Your Telegram user ID is stored in your paySwapr account and used to deliver messages via the Telegram Bot API.
- Messages sent through Telegram are subject to Telegram's own Privacy Policy and Terms of Service.
- We do not store the content of messages sent through Telegram on our servers beyond the point of delivery.
- You may disconnect Telegram at any time from your account notification settings. Disconnecting immediately stops further Telegram messages.
Telegram notifications are optional. All essential notifications (KYC outcomes, security alerts) are also sent to your registered email address regardless of your Telegram connection status.
10. Cookies & Tracking
The Platform uses the following types of cookies and similar technologies:
- Strictly necessary cookies: Required for the Platform to function. These include session cookies that keep you logged in, CSRF protection tokens, and preference storage. You cannot opt out of these without stopping your use of the Platform.
- Functional cookies: Store your preferences such as theme selection and notification settings so you do not need to reconfigure them on each visit.
- Security cookies: Used to detect and prevent fraud, track suspicious login patterns, and link sessions to audit log entries.
paySwapr does not use third-party advertising cookies or behavioural tracking cookies. We do not integrate advertising networks, social media tracking pixels, or analytics platforms that share your data with third parties for marketing purposes.
You may control cookies through your browser settings. Disabling strictly necessary cookies will prevent you from using the Platform. Disabling functional cookies will not prevent access but may affect your experience.
When you first visit the Platform, a cookie notice may be displayed at the bottom of the page. Clicking Accept & Close dismisses the notice and records your acknowledgement in your browser's local storage (not a cookie). This record is used only to suppress the notice on future visits and is never transmitted to our servers.
11. How We Share Your Information
We share your personal information only in the circumstances described below. We do not sell, rent, or trade your personal information with any party for commercial gain.
- Other Platform Users: Your username, public trade statistics, feedback score, and offer details are visible to other registered Users as part of the marketplace. Your email address, KYC data, wallet private key material, and IP address are never shared with other Users.
- Blockchain Infrastructure Provider: Wallet creation, transaction signing, and on-chain operations are processed through our blockchain infrastructure provider. Your wallet address and transaction data are shared with the provider to the extent necessary to provide wallet services. The provider operates under a data processing agreement with us.
- Swap Providers (Coin Conversions): If you use an on-chain Coin Swap, or where we source a coin for USDT Escrow or the Reserve on-chain, the necessary transaction details — such as source and destination coins, amounts, and the relevant wallet addresses — are shared with the third-party swap provider solely to execute the conversion. We do not share your identity, email, or KYC data with these providers.
- Telegram (Notification Delivery): If you enable Telegram notifications, your Telegram user ID and notification message content are transmitted to Telegram's API for delivery.
- IP Geolocation Providers: To enforce jurisdictional restrictions (see our Terms, Section 3), your IP address is looked up against third-party IP-geolocation services (currently ip-api.com and ipapi.co) to determine your approximate country. Only your IP address is shared for this purpose; the resulting country code may be stored for compliance and audit purposes.
- Error Monitoring (Sentry): We use Sentry to capture technical errors and diagnose problems. Error reports may include technical request data; sensitive values (passwords, PINs, seed phrases, tokens, authentication headers) are automatically redacted before transmission, and we review Sentry's data handling terms.
- Law Enforcement & Regulatory Authorities: We will disclose personal information where required to do so by applicable law, court order, regulatory requirement, or lawful authority request. Where permitted by law, we will notify you of such a request before disclosure.
- Professional Advisers: Lawyers, auditors, and other professional advisers may access data strictly as necessary to provide services to us and are bound by confidentiality obligations.
- Business Transfer: In the event of a merger, acquisition, or sale of all or part of our business, your personal information may be transferred as part of that transaction. We will notify you and, where required, seek your consent before any such transfer takes effect.
12. International Data Transfers
paySwapr and its service providers may process your personal information in countries outside your country of residence. These countries may have different data protection laws to your own.
Where we transfer personal information internationally, we take steps to ensure appropriate safeguards are in place, including:
- Ensuring the recipient country has an adequacy decision from the relevant authority.
- Using standard contractual clauses approved by the relevant data protection authority.
- Conducting Privacy Impact Assessments before transferring to jurisdictions with less robust data protection frameworks.
By using the Platform, you acknowledge that your information may be processed in a country other than your country of residence. If you have questions about specific transfers, contact us at support@payswapr.com.
13. Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy and to comply with our legal obligations. The table below sets out our standard retention periods:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account registration data | Duration of account + 5 years after closure | AML record-keeping obligations |
| KYC documents & identity verification records | Minimum 5 years from last activity; up to 7 years where tax obligations apply | AML/KYC regulatory compliance |
| Trade & transaction records | Minimum 5 years from trade completion | AML record-keeping, dispute resolution, tax obligations |
| Audit logs & security records | Minimum 5 years (append-only; not deleted) | Security investigations, regulatory compliance |
| Trade chat messages | 5 years from trade completion | Dispute resolution, AML evidence |
| Support communications | 3 years from last contact | Service continuity, complaint handling |
| Telegram connection data | Until disconnected by user; deleted within 30 days of disconnection | Notification delivery |
| Session cookies | Until logout or browser closure | Platform operation |
When retention periods expire, data is securely deleted or anonymised. Data subject to active legal proceedings, investigations, or regulatory holds will be retained until those proceedings conclude, regardless of standard retention periods.
14. Security
We implement technical, administrative, and physical safeguards to protect your personal information against unauthorised access, disclosure, alteration, or destruction. Key measures include:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
- Encryption at rest: KYC documents and sensitive files are stored in an encrypted private storage volume. Wallet private key material is encrypted by our blockchain infrastructure provider.
- Password security: Passwords are hashed using a strong one-way algorithm. We cannot retrieve your plaintext password.
- PIN security: Your security PIN is hashed separately from your password using a one-way algorithm. We do not store or transmit your PIN in plaintext. Failed PIN attempts are counted; after five consecutive failures the wallet is placed in a security lockout. The attempt counter and lockout timestamp are stored in your account record.
- 2FA TOTP storage: If you enable two-factor authentication, your TOTP secret key is stored encrypted using AES-256 encryption with a server-side key. The secret key is decrypted only when verifying a TOTP code and is never transmitted to your device.
- Wallet seed phrases: Wallet mnemonics are encrypted at rest. They are only decrypted temporarily to fulfil a verified seed phrase export request from a 2FA-authenticated user; the decrypted phrase is not stored or logged.
- Access controls: Internal access to sensitive data is role-based and restricted to authorised personnel. Admin actions require separate administrator authentication and are fully logged in immutable audit records that senior administration and designated audit-log reviewers can access.
- Append-only audit logs: All significant actions are recorded in immutable logs to enable security investigations and accountability.
- Device & IP logging: Every login and security-sensitive action records the originating IP address and device fingerprint.
Despite these measures, no system is completely secure. In the event of a data breach that creates a risk of significant harm to you, we will notify affected users and the relevant supervisory authority as required by applicable law.
If you believe your account has been compromised, contact us immediately at support@payswapr.com.
15. Your Rights
Depending on your jurisdiction, you may have the following rights in relation to your personal information:
- Right of access: Request a copy of the personal information we hold about you, together with information about how it is used.
- Right to rectification: Request correction of inaccurate or incomplete information.
- Right to erasure: Request deletion of your personal information where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations.
- Right to restriction: Request that we restrict processing of your data in certain circumstances, such as while you contest the accuracy of data we hold.
- Right to data portability: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to object: Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: Where processing is based on consent (e.g., Telegram notifications), withdraw that consent at any time without affecting the lawfulness of prior processing.
Identity verification may be required before we act on your request to protect your data from being accessed or altered by unauthorised parties.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
16. Children's Privacy
The Platform is not intended for and may not be used by anyone under the age of 18. We do not knowingly collect personal information from persons under the age of 18. If we become aware that a person under 18 has provided personal information to us, we will take steps to delete that information promptly.
If you believe we have inadvertently collected information from a minor, please contact us at support@payswapr.com immediately.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to your registered address), by an in-platform notification, or by displaying a prominent notice on the Platform.
The updated Policy will be effective from the date stated at the top of this page. Your continued use of the Platform after that date constitutes acceptance of the updated Policy. If you do not agree to the revised Policy, you must stop using the Platform and may request account closure.
We encourage you to review this Policy periodically. The effective date at the top of the page always shows when it was last updated.
18. Contact & Complaints
If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal information, please contact us:
- Email: support@payswapr.com
- Platform: https://payswapr.com
We aim to respond to all privacy-related enquiries within 5 business days and to fulfil data subject requests within 30 calendar days. For urgent security matters, please mark your email subject line with "URGENT – PRIVACY".
If you are not satisfied with our response to a complaint, you have the right to escalate the matter to the appropriate data protection authority in your jurisdiction.