Home

Privacy Policy

Last updated: 16 June 2026

PechPay ("we", "us", "our") is a digital wallet and payments product operated by Pech Group Holdings. This policy explains what personal data we collect when you use PechPay, why we collect it, and the rights you have over it. It is written to comply with Nigeria's Data Protection Act 2023 and the Nigeria Data Protection Regulation (NDPR).

1. Information we collect

  • Account details: name, email, phone number, date of birth, and password (stored as a salted hash, never in plain text).
  • Identity verification (KYC): BVN, NIN, government ID images, and selfie liveness checks, collected when you upgrade your wallet tier, as required by CBN regulation.
  • Financial activity: wallet balance, transaction history, linked bank accounts/cards, and savings pocket data.
  • Security data: your 4-digit transaction PIN (stored only as a salted SHA-256 hash) and, if enabled, TOTP two-factor authentication secrets (stored and verified by our authentication provider, never visible to PechPay staff).
  • Device and usage data: IP address, device identifiers, app version, and approximate location, used for fraud detection and service delivery.

2. How we use your information

  • To create and operate your wallet, process payments, and provide statements and receipts.
  • To verify your identity and meet Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) obligations under Nigerian law.
  • To detect and prevent fraud, unauthorized access, and abuse of the platform.
  • To send you transactional notifications (payment confirmations, security alerts) and, where you've opted in, product updates.
  • To comply with regulatory, tax, and law-enforcement requests where legally required.

3. Who we share data with

We share data only where necessary to operate PechPay: our licensed payment processing and banking partners, identity verification providers (for BVN/NIN checks), our cloud infrastructure provider (Supabase), and regulators or law enforcement when legally compelled. We do not sell your personal data to third parties.

4. Data security

Transaction PINs and passwords are never stored in plain text. Sensitive operations require PIN or 2FA confirmation, and service-role database credentials are kept server-side only. Despite these measures, no system is perfectly secure — report any suspected compromise immediately to the contact below.

5. Data retention

We retain account and transaction records for as long as your account is active and for the period required by CBN/AML record-keeping rules thereafter (currently a minimum of 5 years after account closure), after which data is deleted or anonymized.

6. Your rights

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data, subject to our regulatory record-keeping obligations.
  • Withdraw consent for non-essential communications at any time.

To exercise any of these rights, contact us using the details below.

7. Changes to this policy

We may update this policy as PechPay's features evolve or regulations change. Material changes will be announced in-app before they take effect.

Questions? Contact pay@pechgroupholdings.com