Privacy Policy

Your data, your trust.

Effective January 1, 2026

QRPayLink (“we”, “our”, “us”) operates the QRPayLink website, mobile applications and payment platform (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the rights you have over it.

1. Information we collect

We collect the minimum information needed to provide a secure payments experience:

  • Account information: name, email address, password (stored as a one-way hash) and role (merchant or admin).
  • Business information: business name, country, bank account number, account name and settlement currency — required to create your Paystack subaccount.
  • KYC information: government ID document, live selfie, business registration where applicable.
  • Transaction data: payment references, amounts, currency, status, customer email and order details necessary to process and reconcile payments.
  • Device & usage data: IP address, browser type, pages visited, timestamps and crash diagnostics, collected via standard server logs.
  • Cookies: we use HttpOnly session cookies to keep you signed in. We do not use third-party advertising cookies — see our Cookie Policy.

2. How we use your information

  • To create and operate your QRPayLink account.
  • To verify your identity and business (KYC/KYB) as required by Ghanaian and Nigerian AML law.
  • To process payments and settle funds to your registered bank account via Paystack.
  • To prevent fraud, abuse and unauthorised access.
  • To provide customer support and respond to your enquiries.
  • To comply with applicable financial, tax and anti-money-laundering regulations.
  • To improve the Service through aggregated analytics — never to identify you for marketing without consent.

3. Sharing your information

We do not sell your personal data. We share information only with:

  • Paystack — our regulated payment processor, to complete transactions and settle funds.
  • Cloud infrastructure providers — to host our application and database, under strict data-protection agreements.
  • Regulators & law enforcement — when we are legally required to disclose information (e.g. court order, tax authority request, suspicious-transaction report).

4. How we protect your data

  • All connections to QRPayLink are encrypted using TLS 1.2+ (HTTPS).
  • Passwords are stored using industry-standard bcrypt hashing — we cannot recover your password.
  • Authentication tokens are issued as HttpOnly, Secure, SameSite cookies to mitigate XSS and CSRF risks.
  • KYC documents are encrypted at rest and accessible only to authorised compliance reviewers.
  • Card data never touches our servers — it is captured directly by Paystack’s PCI-DSS Level 1 infrastructure.
  • Access to production data is restricted and audited. See our Security page for full details.

5. Your rights

You have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete your account and associated personal data (subject to legal retention requirements).
  • Export a copy of your transaction history.
  • Withdraw consent for non-essential processing at any time.

To exercise any of these rights, email privacy@qrpaylink.com.

6. Data retention

We retain account and transaction records, including KYC documents, for at least 7 years to comply with Ghanaian and Nigerian AML regulations. Marketing preferences and support correspondence are retained for 2 years unless you ask us to delete them sooner.

7. Children's privacy

QRPayLink is not intended for individuals under 18. We do not knowingly collect personal data from children.

8. International transfers

Your data may be processed in Ghana, Nigeria, the European Union or the United States. Wherever we process your data, we apply the same protection standards described in this Policy.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or via a prominent in-app banner. The latest version is always at qrpaylink.com/privacy.

10. Contact us

Questions about this Privacy Policy or how we handle your data? Reach our team at privacy@qrpaylink.com.