Skip to content
Last updated|21 September 2026

Privacy policy

CorpoPay builds payment orchestration and settlement software for merchants. This policy explains what personal data we collect when you visit corpopay.site, use the merchant dashboard or integrate the CorpoPay API — and how we use, share and protect it.

1.Who we are

This policy covers corpopay.site, the merchant dashboard at app.corpopay.site, the API at api.corpopay.site, and our documentation.

  • When you hold a CorpoPay account, or apply for one, we are the controller of the personal data described here.
  • When we process transaction data on behalf of a merchant who uses the platform, that merchant is the controller and we are a processor acting on their instructions.

2.Data we collect

  • Account and contact data — your name, business name, email address, phone number, a hash of your password, and the language and theme you choose.
  • Identity and business verification data — for merchants who need to accept payments, the company details and documents our payment partners require for onboarding and know-your-customer checks.
  • Transaction data — amounts, currencies, references, timestamps, statuses, and the ledger entries and settlement statements behind them.
  • Technical data — IP address, device and browser information, request timestamps and error logs.
  • Usage data — the pages you visit on this site and the actions you take, collected as described in Cookies and analytics.

We ask for the data a stated purpose requires. Where a field is optional we say so, and you can decline it — though some features need it to work.

3.How we use your data

  • To create, secure and administer your account.
  • To route payments through our payment partners, apply the rules you configure, and keep the double-entry ledger balanced.
  • To produce the reports, reconciliation views and settlement statements you export.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To provide support and answer your questions.
  • To meet legal, accounting, tax and anti-money-laundering obligations.
  • To understand how the product is used so we can improve it.

We do not sell personal data, and we do not use it for third-party advertising.

4.Legal bases

Where the GDPR or comparable law applies, we rely on: performance of our contract with you (providing the service); our legitimate interests (securing the platform, preventing fraud, improving the product); legal obligation (accounting, tax, anti-money-laundering); and your consent (optional analytics and marketing, which you can withdraw at any time).

Where Moroccan law 09-08 on the protection of individuals with regard to the processing of personal data applies, we process personal data for the purposes described above and make the notifications the CNDP requires.

5.Payments, funds and your customers

CorpoPay is not a bank and does not hold your funds. Money moves between your customers, our payment partners — such as Payzone and CMI for local cards and Stripe for international cards — and a bank account you designate. Card details are entered on pages operated by those partners and are never stored on CorpoPay infrastructure.

When a payment runs, the merchant is responsible for their own customers’ personal data, including having a lawful basis for processing it and giving a privacy notice. We process that data to route the payment, keep the ledger, resolve disputes and meet our legal obligations. We do not use it for our own marketing.

6.Google sign-in and Google user data

If you choose to sign in with Google, we receive your name, email address, profile picture and a stable Google account identifier. We use them to authenticate you, create your account or link it to an existing one, and keep your sign-in secure.

CorpoPay’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising or to train models, we do not sell it, and we do not transfer it to third parties except as needed to provide or secure the service, to comply with the law, or as part of a merger or acquisition. No human reads your Google user data unless you ask us to, we need to for security or abuse reasons, or the law requires it.

7.Cookies and analytics

We use strictly necessary browser storage for the language and theme you select, your session, and to keep you signed in.

We use PostHog to collect event-level product analytics — for example which pages and calls to action are used — so we can see what is working. We do not use advertising cookies, we do not run cross-site tracking pixels, and we do not share analytics data with advertising networks. Where the law requires consent for analytics, we ask for it before those events are sent.

8.Who we share data with

  • Payment partners — banks, card acquirers and providers such as Payzone, CMI and Stripe, to process payments and settle funds.
  • Infrastructure and service providers — cloud hosting, database, email delivery, error monitoring and analytics providers, acting on our instructions under contract.
  • Professional advisers and authorities — where the law requires disclosure, or to establish, exercise or defend legal claims.

We require every processor to protect personal data to at least the standard described in this policy, and we do not allow them to use it for their own purposes.

9.International transfers

Some of our providers operate outside Morocco. Where personal data is transferred abroad we rely on appropriate safeguards — such as an adequacy decision or standard contractual clauses — and we keep a record of the transfers we make and the safeguards that cover them.

10.How long we keep data

Account data is kept while your account is open. Transaction, ledger and settlement records, and the documents behind them, are kept for the period that accounting, tax and anti-money-laundering rules require after our relationship ends — which in Morocco runs to several years. Analytics data is kept in a form that identifies you for a limited period and is then aggregated.

When a retention period ends we delete the data or irreversibly anonymise it, and we delete it earlier if you ask us to and no legal obligation requires us to keep it.

11.Security

Data is encrypted in transit and at rest, access is limited to the people who need it and reviewed regularly, and actions taken on the platform are written to an audit trail. No system is perfectly secure: if a breach affects your personal data, we will notify you and the competent authority as the applicable law requires.

12.Your rights

Depending on where you live, you can ask us to:

  • confirm what personal data we hold about you, and give you a copy;
  • correct data that is wrong or incomplete;
  • delete data we no longer need;
  • restrict or object to particular processing, including direct marketing;
  • give you the data you provided in a portable, machine-readable format;
  • withdraw consent you gave earlier, without affecting what we did before you withdrew it.

We answer requests within the period the applicable law sets — normally one month, and we will tell you if we need longer. If you are not satisfied with our answer you can complain to your data protection authority, which in Morocco is the CNDP.

13.Children

CorpoPay is a business product. It is not directed at children and is not intended for anyone under 18, and we do not knowingly collect their personal data.

14.Changes to this policy

When we make a material change we update the date at the top of this page. If the change significantly affects you, we will tell you by email or in the dashboard before it takes effect.

Questions about this policy

Write to us at the address below and we will respond within the period the applicable law sets — normally one month.

ayman.errarhiche@corpopay.site

Terms of service