Data controller
PayMeDaba is not open yet: its services will only open after Bank Al-Maghrib approval is obtained. Details of the legal entity responsible for processing, and references of the formalities completed with the CNDP (Morocco's national personal data protection commission), will be published on this page before launch.
Data we collect
- Account: last name, first name, email address, mobile number, public @username.
- Identity check: photos of the front and back of your CNIE and a selfie, only if you want to withdraw to a bank or raise your limits.
- Operations: amounts, dates, senders, recipients and messages attached to transfers and requests.
- Bank accounts: RIB and holder of the accounts you add for withdrawals.
- Technical: the device's notification token.
PayMeDaba never collects your card number: you enter it on your bank's secure 3-D Secure page. Your PIN is never stored in plain text.
Why we use your data
- To create and manage your account.
- To carry out your transfers, requests, top-ups and withdrawals.
- To meet our legal obligations, including anti-money laundering and counter-terrorist financing rules.
- To prevent fraud and secure your account.
- To send notifications about your account (money received, requests, withdrawals).
- To answer your support requests.
Your data is never sold or used for advertising.
What other users see
When someone looks you up by @username or number, they only see your first name, the initial of your last name and your @username. Your mobile number and email are never shown. People you exchange money with see the amount and message of that operation.
Who receives the data
Only authorised PayMeDaba staff access your data, within their role; access to identity documents is limited to the compliance team. Some data is shared with providers strictly needed to run the service (hosting, notification delivery, banks for top-ups and withdrawals), and with authorities when the law requires it.
Retention
Account data is kept while the account is open. Operation and identity check data is kept after the account is closed for the legal period that applies to payment services, then deleted.
Hosting and security
Data is hosted on secure infrastructure, and traffic with the app is encrypted (TLS). Every money movement is recorded in an accounting ledger reconciled with balances. If any data is hosted outside Morocco, that transfer will follow the conditions of law 09-08. More on the security page.
Cookies and the website
The paymedaba.com website uses no cookies and no tracking or analytics tools. If you join the waitlist, only the email address you give and the site language are kept, to tell you about the launch.
Your rights
Under law 09-08, you have the right to access and correct your data, and to object to its processing on legitimate grounds. To use these rights, email privacy@paymedaba.com from your account's email address. You can also contact the CNDP.
To delete your account, follow the steps on the delete account page.
Contact
Personal data: privacy@paymedaba.com. Help with the service: support@paymedaba.com. This policy will be finalised before launch, and any later change will be announced in the app.