Contents
1What This Policy Covers
This Policy applies to:
- merchants and merchant team members who use Inttegro;
- developers who use our APIs, SDKs, documentation, and developer tools;
- Customers who interact with Inttegro-hosted checkout, invoice, payment, receipt, file upload, OTP, or communication flows;
- people whose information is submitted to Inttegro for onboarding, ownership, control, signatory, account-holder, support, transaction, communication, upload, or compliance purposes;
- visitors to Inttegro websites, documentation, and dashboards.
This Policy does not replace a merchant's own privacy policy. If you are a Customer of a merchant, the merchant is often the primary organization deciding why your data is processed. You should also review that merchant's privacy policy and contact the merchant for questions about its products, services, orders, refunds, marketing, and privacy practices.
2Our Roles
Inttegro acts in different roles depending on the processing.
We usually act as a processor or service provider when we process Customer Data to provide Inttegro services to a merchant on that merchant's instructions. This includes many order, customer, hosted checkout, payment, notification, OTP, file, and dashboard workflows.
We act as an independent controller or business for some purposes, including:
- creating and administering Inttegro accounts;
- onboarding, KYB, KYC, ownership, signatory, and financial account review;
- authenticating users and securing the platform;
- fraud prevention, risk management, payment integrity, dispute handling, chargebacks, refunds, reserves, and financial reconciliation;
- complying with law, regulator requests, sanctions, tax, accounting, Provider rules, and legal process;
- operating, debugging, analyzing, improving, and supporting the Services;
- enforcing our Terms and protecting Inttegro, merchants, Customers, Providers, and the public.
3Personal Data We Collect
Account and organization data
We may collect legal name, trading name, website, industry, legal entity type, operating model, place of registration, support email, support phone, tax identifiers, registration numbers, registration authority, business address, app details, settings, statement descriptors, and related onboarding or compliance data.
User and team data
We may collect user name, email address, authentication provider identifier, role, status, preferences, organization membership, dashboard activity, support activity, and login/session data.
Ownership, control, and compliance data
We may collect information about beneficial owners, directors, authorized representatives, signatories, control persons, account holders, and other people associated with a merchant. This may include full name, date of birth, nationality, email, phone, address, ownership percentage, capacities, verification status, and supporting documentation.
Customer and order data
We may process Customer name, email, phone, billing address, shipping address, customer ID, guest checkout status, merchant reference, custom data, orders, line items, products, quantities, prices, taxes, fees, shipping, discounts, invoices, receipts, due dates, status, refunds, cancellations, and support information.
Payment and financial data
We may process payment amount, currency, payment status, payment attempts, payment method type, masked payment details, mobile money number/network, bank account details, account holder details, card or wallet summaries where available, mandate details, verification state, provider references, balance transactions, payout destinations, payout records, FX settings, refund and dispute records, and related financial metadata.
Some payment details may be collected directly by Providers or through Provider-controlled/tokenized flows. In those cases, Inttegro may receive tokens, identifiers, masked details, summaries, status updates, and provider references rather than the full underlying payment credential.
Communications and OTP data
We may process recipient names, phone numbers, email addresses, sender IDs, from addresses, reply-to addresses, message content, email subject/text/HTML, templates, variables, URLs, purposes, delivery status, transmission IDs, gateway IDs, safety scan results, OTP transaction status, token metadata, expiry, and verification attempt information. OTP token values are not exposed in plain text in API responses.
File and content data
We may process uploaded files, product images, videos, downloads, support documents, generated invoices, receipts, reports, exports, file metadata, filename, MIME type, size, checksum, scan status, purpose, source, created-by actor, upload request details, file link details, access counts, and file-link or upload activity.
Technical, security, and usage data
We may collect API keys and key metadata, session metadata, tokens, delegated credential metadata, idempotency keys, request metadata, IP address, user agent, device/browser data, timestamps, request IDs, logs, traces, metrics, errors, audit events, workflow/job metadata, feature usage, documentation usage, and diagnostic data.
Support and free-form data
We may collect support messages, notes, custom data, metadata, template variables, uploaded evidence, screenshots, correspondence, and other information you or a merchant chooses to provide. Merchants should not place unnecessary sensitive data in free-form fields.
4How We Collect Personal Data
We collect personal data:
- directly from merchants, users, developers, and Customers;
- through dashboards, APIs, SDKs, hosted checkout pages, invoice pages, receipt pages, file upload pages, documentation sites, and support channels;
- from merchants who submit Customer, team, owner, account-holder, or transaction data to Inttegro;
- from public sources or business records where used for onboarding, website profile sync, KYB/KYC, sanctions, fraud prevention, risk, compliance, or support;
- from Customers who pay, upload files, verify OTPs, open hosted pages, or otherwise interact with Inttegro;
- from Providers, such as payment processors, mobile money operators, banks, card networks, payout providers, messaging providers, email providers, KYC/KYB vendors, fraud prevention vendors, cloud providers, and analytics/logging providers;
- automatically through cookies, logs, sessions, device data, and similar technologies.
5How We Use Personal Data
We use personal data to:
- provide, maintain, secure, and improve Inttegro;
- create and administer accounts, organizations, apps, dashboard access, roles, API keys, sessions, and credentials;
- onboard merchants and verify businesses, owners, representatives, signatories, account holders, and financial accounts;
- create and manage customers, products, prices, orders, invoices, checkout flows, receipts, refunds, disputes, payment methods, financial accounts, balances, payouts, reserves, FX, and transaction records;
- process payments, payment confirmations, saved payment methods, mandates, refunds, chargebacks, disputes, reversals, payouts, and Provider updates;
- send, schedule, broadcast, track, and troubleshoot SMS, WhatsApp, email, and OTP messages;
- upload, validate, store, scan, deliver, link, delete, and audit files;
- provide idempotency, retries, logs, metrics, traces, audit trails, support, debugging, and incident response;
- prevent, detect, investigate, and respond to fraud, abuse, spam, phishing, malware, unauthorized access, security incidents, prohibited activity, and violations of our Terms;
- comply with laws, sanctions, tax, accounting, regulator requests, court orders, Provider rules, and legal process;
- communicate with merchants and users about the Services, support, security, updates, incidents, account activity, billing, compliance, and product changes;
- analyze usage, reliability, performance, risk, and product quality;
- enforce agreements, collect fees, recover negative balances, and protect legal rights;
- create aggregated, de-identified, or statistical data.
6Legal Bases, Conditions, or Justifications
Where Ghanaian data protection law requires a legal basis, processing condition, or other justification, we rely on one or more of the following as applicable:
- contract: to provide the Services and administer accounts;
- legitimate interests: to secure, operate, improve, support, and protect the platform; prevent fraud and abuse; manage risk; analyze performance; and enforce our Terms;
- legal obligation: to comply with tax, accounting, sanctions, financial, payment, consumer, data protection, regulator, law enforcement, and other legal requirements;
- consent: where required for certain communications, cookies, saved payment methods, marketing, or other processing;
- vital or public interests: only where Ghanaian law recognizes such basis and the circumstances require it.
When we process Customer Data as a processor on behalf of a merchant, the merchant is responsible for identifying the applicable legal basis for its processing and for providing required notices and consents.
9Data Hosting and Transfers
Inttegro merchant accounts are currently available only to Ghana-based merchants. We may still process, store, or transfer personal data outside Ghana where needed to provide the Services through our affiliates and Providers.
Customer Data is currently stored in the United States.
Where Ghanaian data protection law requires safeguards for those transfers, we use appropriate contractual, technical, organizational, or other lawful transfer mechanisms.
10Retention
We retain personal data for as long as needed to provide the Services, operate the platform, comply with law and Provider rules, resolve disputes, enforce agreements, prevent fraud and abuse, maintain financial and audit records, support Customers and merchants, and protect legal rights.
Retention periods vary by data type and context. For example:
- account, KYB/KYC, tax, compliance, payment, payout, balance, ledger, refund, dispute, and audit records may be retained for legal, regulatory, accounting, Provider, and risk purposes after an Account closes;
- idempotency records may be retained for replay, reliability, audit, and abuse prevention according to the relevant service policy;
- files may be deleted, tombstoned, or retained depending on file purpose, merchant instructions, legal requirements, disputes, evidence needs, and backup schedules;
- logs, metrics, traces, and security records may be retained for security, debugging, incident response, reliability, and compliance;
- marketing preferences and suppression records may be retained to honor opt-out and consent obligations.
When personal data is no longer needed, we delete, de-identify, aggregate, or isolate it according to applicable requirements and operational constraints.
11Security
We use technical and organizational measures designed to protect personal data, including authentication, authorization, access controls, encryption in transit, credential controls, logging, monitoring, least-privilege access, backups, security reviews, and incident response processes.
No system is perfectly secure. You are responsible for securing your accounts, devices, networks, credentials, API keys, sessions, hosted links, file links, upload links, integrations, and access permissions.
12Your Choices and Rights
Under Ghanaian data protection law and depending on the data involved, you may have rights to:
- access or confirm whether we process your personal data;
- correct inaccurate or incomplete personal data;
- delete personal data;
- restrict or object to processing;
- receive a portable copy of personal data;
- withdraw consent where processing is based on consent;
- opt out of certain marketing communications;
- appeal or complain to a data protection authority.
To exercise rights for Inttegro account data, contact us using the privacy contact above.
If you are a Customer of a merchant, please contact the merchant first for requests about your orders, payments, messages, files, refunds, or customer profile. We may forward your request to the merchant or assist the merchant in responding where required.
We may need to verify your identity and request details before fulfilling a privacy request. Some data may be exempt from deletion or access where we need to retain it for legal, tax, accounting, security, fraud prevention, dispute, Provider, or contractual reasons.
13Ghana Data Protection Notice
The Services are currently offered in Ghana only. This Policy is written for the Services as offered in Ghana.
Under Ghana's Data Protection Act, 2012 (Act 843), data subjects may have rights including the right to be informed, object to processing, access personal data, prevent certain processing, request correction or deletion of certain data, withdraw consent where applicable, and complain to the Data Protection Commission.
We and merchants may also have registration, openness, security, retention, accountability, and controller-processor contract obligations depending on our roles and processing activities.
Before making merchant accounts generally available outside Ghana, we expect to update this Policy or publish additional notices for the relevant service scope.
14Marketing Communications
We may send account, service, security, billing, compliance, support, and transactional communications. These are not marketing and may be required for the Services.
We may send marketing communications to merchants or users where permitted by law. You can opt out of marketing emails by using the unsubscribe link or contacting us. Opting out of marketing does not stop transactional or service communications.
Merchants are responsible for marketing messages they send through Inttegro communications services, including consent, opt-out, suppression, and legal compliance.
15Children's Data
Inttegro is not intended for children, and merchants must not use Inttegro to knowingly collect personal data from children unless the use is lawful, covered by appropriate notices and consents, and expressly supported by the Services. If you believe a child has provided personal data to Inttegro unlawfully, contact us.
16Automated Processing
We may use automated rules, models, or risk signals to help detect fraud, abuse, security threats, sanctions risk, payment risk, message abuse, file abuse, provider compliance issues, and Terms violations. These tools may affect access to Services, transaction review, payout holds, message delivery, file handling, or account restrictions.
Where Ghanaian data protection law gives you rights related to automated decision-making, you may contact us using the privacy contact above.
17Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy and change the effective date. If changes are material, we will provide notice where practical through the dashboard, email, documentation, or other reasonable means.
18Contact
For privacy questions or requests, contact [email protected]. For support questions, contact [email protected]. For legal notices, contact [email protected].