Privacy Policy
Last updated: March 23, 2026
1. Introduction
JaallePay (“we,” “us,” or “our”) is a cross-network mobile money payment platform operated by JAALLE. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our mobile applications (Android and iOS), website (jaallepay.com), desktop application, and related services (collectively, the “Services”).
By using our Services, you agree to the collection and use of information in accordance with this policy. We are committed to protecting your privacy and complying with applicable data protection laws, including regulations set forth by the Central Bank of Somalia (CBS).
2. Information We Collect
2.1 Information You Provide
- Account Registration: Phone number, full name, email address, date of birth, and preferred language (Somali, English, or Arabic).
- Identity Verification (KYC): Government-issued ID (national ID, passport), selfie photographs, proof of address, and biometric data for liveness detection. Your KYC tier (L0–L4) determines your transaction limits.
- Transaction Data: Payment amounts, recipient details, payment networks used, transaction notes, and payment references.
- Financial Information: Wallet balances, linked mobile money accounts, bank card details (processed by Stripe — we never store full card numbers).
- Communication: Messages you send through our support channels, dispute filings, and scam reports.
2.2 Information Collected Automatically
- Device Information: Device model, operating system, unique device identifiers, browser type, and app version.
- Security Data: Device integrity status (root/jailbreak detection), biometric authentication events, SIM card information (hashed), and device trust scores.
- Usage Data: Pages visited, features used, transaction patterns, and session duration.
- Network Information: IP address (hashed for storage), mobile network operator, and connection type.
- Location: We do not collect precise GPS location. Network-based country detection is used solely for regulatory compliance.
3. How We Use Your Information
- Process Payments: Execute transfers across 11 payment networks (EVC+, ZAAD, eDahab, Golis, Premier, Waafi, M-Pesa, Telebirr, M-Gurush, Stripe, SIPS).
- Identity Verification: Verify your identity through our JaalleID system to comply with KYC/AML regulations.
- Fraud Prevention: Detect and prevent fraudulent transactions using our 27-rule fraud detection engine, device fingerprinting, velocity checks, and risk scoring.
- Security: Protect your account through biometric authentication, session management, and device trust verification.
- Customer Support: Respond to inquiries, resolve disputes, and process refunds.
- Regulatory Compliance: Meet CBS reporting requirements, AML/CFT obligations, and suspicious activity reporting to the Financial Reporting Centre (FRC).
- Service Improvement: Analyze anonymized usage patterns to improve features, fix bugs, and optimize performance.
- Communications: Send transaction confirmations, security alerts, and service updates via SMS and push notifications.
5. Data Security
We implement bank-grade security measures to protect your data:
- Encryption at Rest: All sensitive data is encrypted using AES-256-GCM. Phone numbers, PINs, and financial data use field-level encryption with rotating keys.
- Encryption in Transit: All communications use TLS 1.3. Mobile apps implement certificate pinning.
- API Security: HMAC-SHA256 signed requests, idempotency keys for payment operations, and rate limiting at multiple tiers.
- Authentication: Biometric authentication (Face ID, fingerprint), 5-digit PIN with bcrypt hashing and 5-attempt lockout, and device trust scoring.
- Database Security: PostgreSQL Row-Level Security (RLS) ensures users can only access their own data. All financial operations use atomic RPC functions.
- Audit Trail: Immutable, Merkle-chained audit logs record all financial operations and cannot be tampered with.
- Device Integrity: Mobile apps detect root/jailbreak, Frida instrumentation, Xposed modules, emulators, and debugging — compromised devices are restricted.
- Duress Protection: A separate duress PIN silently alerts administrators if you are coerced into making a transaction.
6. Data Retention
- Transaction Records: Retained for 7 years as required by CBS anti-money laundering regulations.
- KYC Documents: Retained for the duration of your account plus 5 years after closure.
- Security Logs: Device fingerprints and IP reputation data are automatically purged after 90 days.
- Account Data: Retained while your account is active. Upon deletion request, personal data is anonymized within 30 days (transaction records are retained per regulatory requirements).
- Session Data: Active sessions expire after 24 hours of inactivity.
7. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of your personal data at any time through the app settings or by contacting support.
- Correction: Update or correct inaccurate personal information through your profile settings.
- Deletion: Request account deletion. We will anonymize your personal data within 30 days, subject to regulatory retention requirements.
- Data Portability: Export your transaction history in standard formats (CSV, PDF).
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing of your data for marketing purposes (we do not engage in targeted advertising).
9. Children's Privacy
JaallePay is a financial service available only to individuals aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we discover that a child under 18 has provided us with personal information, we will promptly delete the account and associated data.
10. International Data Transfers
JaallePay operates across Somalia, Somaliland, Puntland, Djibouti, Kenya, and Ethiopia, and serves diaspora communities in the USA, UK, UAE, Canada, Sweden, and Norway. Your data may be processed in any of these regions. Our infrastructure is hosted on Supabase (cloud-hosted PostgreSQL) with data encrypted at rest and in transit. Cross-border payment data is shared only with the specific payment network required to complete your transaction.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through in-app notifications and by updating the “Last updated” date at the top of this page. Continued use of the Services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
- Email: privacy@jaallepay.com
- Support: support@jaallepay.com
- Address: JAALLE, Mogadishu, Somalia