Privacy policy
CorpoPay builds payment orchestration and settlement software for merchants. This policy explains what personal data we collect when you visit corpopay.site, use the merchant dashboard or integrate the CorpoPay API — and how we use, share and protect it.
1.Who we are
This policy covers corpopay.site, the merchant dashboard at app.corpopay.site, the API at api.corpopay.site, and our documentation.
- When you hold a CorpoPay account, or apply for one, we are the controller of the personal data described here.
- When we process transaction data on behalf of a merchant who uses the platform, that merchant is the controller and we are a processor acting on their instructions.
2.Data we collect
- Account and contact data — your name, business name, email address, phone number, a hash of your password, and the language and theme you choose.
- Identity and business verification data — for merchants who need to accept payments, the company details and documents our payment partners require for onboarding and know-your-customer checks.
- Transaction data — amounts, currencies, references, timestamps, statuses, and the ledger entries and settlement statements behind them.
- Technical data — IP address, device and browser information, request timestamps and error logs.
- Usage data — the pages you visit on this site and the actions you take, collected as described in Cookies and analytics.
We ask for the data a stated purpose requires. Where a field is optional we say so, and you can decline it — though some features need it to work.
3.How we use your data
- To create, secure and administer your account.
- To route payments through our payment partners, apply the rules you configure, and keep the double-entry ledger balanced.
- To produce the reports, reconciliation views and settlement statements you export.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To provide support and answer your questions.
- To meet legal, accounting, tax and anti-money-laundering obligations.
- To understand how the product is used so we can improve it.
We do not sell personal data, and we do not use it for third-party advertising.
4.Legal bases
Where the GDPR or comparable law applies, we rely on: performance of our contract with you (providing the service); our legitimate interests (securing the platform, preventing fraud, improving the product); legal obligation (accounting, tax, anti-money-laundering); and your consent (optional analytics and marketing, which you can withdraw at any time).
Where Moroccan law 09-08 on the protection of individuals with regard to the processing of personal data applies, we process personal data for the purposes described above and make the notifications the CNDP requires.
5.Payments, funds and your customers
CorpoPay is not a bank and does not hold your funds. Money moves between your customers, our payment partners — such as Payzone and CMI for local cards and Stripe for international cards — and a bank account you designate. Card details are entered on pages operated by those partners and are never stored on CorpoPay infrastructure.
When a payment runs, the merchant is responsible for their own customers’ personal data, including having a lawful basis for processing it and giving a privacy notice. We process that data to route the payment, keep the ledger, resolve disputes and meet our legal obligations. We do not use it for our own marketing.
6.Google sign-in and Google user data
If you choose to sign in with Google, we receive your name, email address, profile picture and a stable Google account identifier. We use them to authenticate you, create your account or link it to an existing one, and keep your sign-in secure.
CorpoPay’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising or to train models, we do not sell it, and we do not transfer it to third parties except as needed to provide or secure the service, to comply with the law, or as part of a merger or acquisition. No human reads your Google user data unless you ask us to, we need to for security or abuse reasons, or the law requires it.
9.International transfers
Some of our providers operate outside Morocco. Where personal data is transferred abroad we rely on appropriate safeguards — such as an adequacy decision or standard contractual clauses — and we keep a record of the transfers we make and the safeguards that cover them.
10.How long we keep data
Account data is kept while your account is open. Transaction, ledger and settlement records, and the documents behind them, are kept for the period that accounting, tax and anti-money-laundering rules require after our relationship ends — which in Morocco runs to several years. Analytics data is kept in a form that identifies you for a limited period and is then aggregated.
When a retention period ends we delete the data or irreversibly anonymise it, and we delete it earlier if you ask us to and no legal obligation requires us to keep it.
11.Security
Data is encrypted in transit and at rest, access is limited to the people who need it and reviewed regularly, and actions taken on the platform are written to an audit trail. No system is perfectly secure: if a breach affects your personal data, we will notify you and the competent authority as the applicable law requires.
12.Your rights
Depending on where you live, you can ask us to:
- confirm what personal data we hold about you, and give you a copy;
- correct data that is wrong or incomplete;
- delete data we no longer need;
- restrict or object to particular processing, including direct marketing;
- give you the data you provided in a portable, machine-readable format;
- withdraw consent you gave earlier, without affecting what we did before you withdrew it.
We answer requests within the period the applicable law sets — normally one month, and we will tell you if we need longer. If you are not satisfied with our answer you can complain to your data protection authority, which in Morocco is the CNDP.
13.Children
CorpoPay is a business product. It is not directed at children and is not intended for anyone under 18, and we do not knowingly collect their personal data.
14.Changes to this policy
When we make a material change we update the date at the top of this page. If the change significantly affects you, we will tell you by email or in the dashboard before it takes effect.
Questions about this policy
Write to us at the address below and we will respond within the period the applicable law sets — normally one month.
ayman.errarhiche@corpopay.site