This Privacy Policy explains what information Epsilon Nexus Ltd ("EpsilonPAY", "we", "us" or "our") collects, how we use and share it, and how you can control it. It covers the EpsilonPAY app, EpsilonPAY Merchant, EpsilonPAY POS, the merchant back office, our admin tools, this website, and the APIs behind them.
We wrote it to support Apple App Store and Google Play disclosure requirements. Notices shown inside the app, and disclosures from our payment, banking, identity-verification and mobile-money partners, still apply on top of it.
1. Information we collect
| Category | Examples | Purpose |
|---|---|---|
| Account and profile data | Name, phone number, email address (optional for consumer accounts), username, EpsilonPAY ID, country, role, account status, signup method, Apple or Google sign-in identifiers, password hash, PIN hash, verification timestamps. | Create accounts, authenticate users, protect accounts, route users to the correct consumer, merchant, or admin experience. |
| Identity, KYC, KYB, and compliance data | Ghana Card or other national ID number, passport or ID document images, extracted ID data, date of birth, gender, nationality, selfie, proof of address, source of funds, occupation, employer, income bracket, business name, TIN, business address, MCC, expected volume, KYC/KYB status, rejection reasons, sanctions-screening results, provider references. | Verify identity, meet financial-services, anti-fraud, anti-money-laundering, sanctions, chargeback, audit, and regulatory obligations. |
| Payment and transaction data | Transaction history records, transfers, QR payments, NFC card payments, palm payments, payment intent references, payer and recipient details, amount, currency, fees, status, timestamps, transaction descriptions, device and request metadata, linked Mobile Money and bank payout details, provider tokens or mandate IDs. EpsilonPAY records transactions; it does not hold balances. | Process payments through your linked accounts, show receipts and history, settle merchant sales, detect fraud, provide support, and keep legally required transaction records. |
| NFC, card, and QR data | NFC card UID or token, card status, printed card QR token, QR versions, signatures, card PIN hash, failed PIN attempts, card freeze status. | Enable tap-to-pay, card QR payments, card security controls, replay prevention, lost-card rotation, and transaction verification. |
| Palm biometric data | Palm template or embedding vector, template version, linked date, liveness, quality, confidence, and match scores, accepted or rejected palm-payment attempt records, merchant or terminal context. | Enable optional Palm Pay, prevent spoofing, audit disputed palm payments, tune fraud thresholds, and protect users and merchants. We do not use palm data for advertising. |
| Merchant and POS data | Business profile, stores, terminals, employees, roles, timecards, products, categories, prices, inventory, suppliers, customers entered by a merchant, discounts, taxes, sales, refunds, voids, receipts, shift reports, and back-office access logs. | Run merchant payment acceptance, POS checkout, inventory, reporting, customer management, and employee permissions. |
| Device, notification, and technical data | Push notification tokens, device type, IP address, user agent, request path, timestamps, status codes, crash or operational logs, device or browser information, approximate location inferred from IP or compliance metadata when available. | Deliver notifications, protect accounts, prevent abuse, debug issues, maintain availability, and investigate security incidents. |
| Support and communications | Support tickets, chat messages, categories, attachments, ratings, feedback, email messages, SMS/OTP delivery metadata, newsletter email address if you subscribe on the website. | Provide customer support, verify account actions, resolve disputes, communicate product and safety notices, and send requested updates. |
Data we do not collect
We do not collect your contacts, call logs, SMS inbox, microphone audio, background GPS location, health data, browsing history, or advertising identifiers. If that ever changes, we will update this policy and the store disclosures first.
2. Device permissions
| Permission | Used for |
|---|---|
| Camera | KYC document and selfie capture, palm scanning, QR scanning, payment verification, and merchant product/store images. |
| Photos or media | Optional upload of KYC documents, proof of address, product images, store images, or support attachments. |
| NFC | Reading supported EpsilonPAY cards for tap-to-pay and contactless payment flows. |
| Notifications | Transaction alerts, security alerts, KYC status updates, merchant operations alerts, and optional marketing where enabled. |
| Internet and network | Connecting the app to EpsilonPAY APIs and payment, identity, notification, and support services. |
| Vibration or haptics | Confirming taps, payment states, and notification feedback. |
3. How we use information
- Create, authenticate, secure, and administer user, merchant, staff, and POS accounts.
- Verify identity and business information and comply with KYC, KYB, AML, sanctions, tax, accounting, audit, and risk obligations.
- Process transfers, QR payments, NFC card payments, palm payments, refunds, receipts, and merchant settlements through your linked Mobile Money, card, or bank accounts.
- Operate POS features including products, inventory, terminals, shifts, employees, receipts, and reports.
- Detect, prevent, and investigate fraud, replay attempts, abuse, account compromise, chargebacks, and security incidents.
- Send requested notifications, account notices, OTPs, service updates, and support replies.
- Maintain, debug, improve, and measure the reliability of the apps and APIs.
- Comply with valid legal process and protect the rights, safety, and property of users, merchants, EpsilonPAY, and the public.
4. How we share information
We share information only where needed for the services, compliance, safety, or legal reasons described in this policy.
- Payment, banking, mobile-money, and settlement providers: to authorize, process, reverse, settle, or verify payments and payouts.
- Identity, KYC, KYB, biometric, and sanctions providers: to verify documents, selfies, business details, and compliance status.
- Merchants and payees: limited transaction details needed to complete a payment, refund, receipt, settlement, or support request.
- Merchant employees and account admins: POS and back-office records within the merchant account, based on configured permissions.
- Cloud, database, storage, email, SMS, notification, monitoring, and support providers: to host data, deliver messages, store files, operate APIs, and support users.
- Law enforcement, regulators, courts, auditors, and dispute handlers: when required or permitted by law or needed to prevent harm or fraud.
- Corporate transactions: if EpsilonPAY is involved in a merger, financing, acquisition, restructuring, or asset transfer, subject to continued protection of user data.
5. Third-party services
Depending on configuration and country availability, EpsilonPAY may use service providers such as Paystack, Hubtel, Wave or other payment rails; Dojah, Smile ID, Sumsub, ComplyAdvantage or other identity and screening services; Firebase Cloud Messaging, Expo push services, and Apple Push Notification service; Twilio, Resend, SMTP/email providers; MongoDB, Redis, AWS S3-compatible storage, Render or other cloud infrastructure; and app store authentication providers such as Apple and Google.
Service providers may process information under their own privacy notices where they act as independent controllers, especially payment, banking, app store, and identity-verification providers. We require vendors that process data for us to protect it and use it only for authorized purposes.
6. Security
- We use HTTPS/TLS for data in transit.
- Passwords, login PINs, and card PINs are stored as one-way hashes, not plain text.
- Access to account, KYC, merchant, and POS data is controlled by authentication, role checks, and audit records.
- Payment and QR/card flows use references, signatures, counters, and other controls to reduce replay and fraud risk.
- We monitor logs and operational signals to investigate abuse, errors, and security events.
No internet service is completely secure. Keep your device, PIN, password, and OTPs to yourself, and contact us straight away if you think someone else has been in your account.
7. Retention and deletion
We keep information only as long as we need it. For most data that means while your account is active. Financial records last longer because tax, accounting, AML, and dispute rules require it.
- Account and profile data: kept while your account is active, then deleted or de-identified unless retention is required for legal, security, fraud, or regulatory reasons.
- KYC, KYB, transaction, ledger, payout, settlement, and audit records: retained for the period required by applicable financial, tax, accounting, AML, and dispute-resolution laws. This is commonly up to seven years and may be longer where required.
- Palm templates: retained while Palm Pay is linked and deleted or disabled when you unlink Palm Pay or close your account, except for short-lived fraud and dispute records.
- Palm authentication attempt records: retained for a limited fraud and dispute window, currently designed for 30 days.
- Push tokens: removed when you log out, remove a device token, close your account, or when tokens become inactive.
- Support records: retained while needed to resolve the issue and for audit, quality, or dispute handling.
- Server logs: retained for a limited security and operations period unless needed to investigate abuse, fraud, or legal claims.
To request account and data deletion, use the in-app Delete account option or visit Account & Data Deletion.
8. Your choices and rights
- Update profile details in the app where available.
- Turn off notifications in the app or in device settings, except required service or legal notices.
- Choose whether to link optional Palm Pay and whether to grant camera, media, NFC, and notification permissions.
- Request access, correction, deletion, restriction, objection, or portability where available under applicable law.
- Request account closure and data deletion at account-deletion.html.
We may need to verify your identity before acting on a privacy request. Some information cannot be deleted immediately where retention is required by law, regulation, fraud prevention, accounting, audit, chargeback, or dispute handling.
9. Children
EpsilonPAY is not for children. You need to be old enough to enter a binding agreement and pass identity verification in your country. If you believe a child has given us personal information, contact us and we will look into it.
10. International transfers
We and our service providers may process information in Ghana and other countries where our cloud, identity, notification, payment, support, or storage providers operate. Where required, we use contractual or legal safeguards for cross-border transfers.
11. Changes to this policy
We update this policy when our services, legal obligations, or store requirements change. The effective date at the top always shows the current version, and we give extra notice for significant changes where the law requires it.
12. Contact us
For privacy, account deletion, support, or store-review questions:
- Email: abudustephen72@gmail.com
- Account deletion: /account-deletion.html
- Support: /support.html
- Operator: Epsilon Nexus Ltd, Accra, Ghana