GIVMO PRIVACY & COOKIE POLICY
Version 2.1 · Last updated [DATE] · givmotech.com/privacy
1. WHO WE ARE
Givmo Tech ("Givmo", "we", "us") is a company registered in Ghana, registration number [COMPANY NUMBER], of 42 Giffard Road, Cantonments, Accra, Ghana. We are registered with the Ghana Data Protection Commission as a data controller, registration number [DPC REGISTRATION NUMBER]. This Policy explains how we collect, use, share and protect personal information when you use Givmo — by SMS, by scanning a Givmo code, through our website at givmotech.com, or through the merchant dashboard. Data protection contact: [NAME / ROLE] — privacy@givmotech.com
2. WHO CONTROLS YOUR DATA
This matters, because two different organisations hold information about you and they are responsible for different things. Givmo is the controller of your Givmo account, your balance, your claim and redemption history across the network, your gift cards, and your interactions with our website and SMS service. Each merchant is a separate controller of the customer information they hold about you in their own systems, including the customer list they export from their dashboard. What a merchant does with that list is governed by their own privacy practices, and we require every merchant to comply with Act 843 and not to market to you without your consent. If you have a concern about how a specific merchant is using your information, raise it with them, and tell us — we act on it.
3. WHAT WE COLLECT
If you're a customer What Why we have it Name To identify you to merchants at the till Mobile number It's your account, and how we send you rewards and codes Ghana Card details, if you choose to verify To verify identity, unlock higher limits, and prevent fraud Transactions, claims, approvals, denials, redemptions To run the rewards programme and resolve disputes Balance, expiry dates, gift cards held To run your account Which merchants you transact with, and when To operate the network and show you your history Referrals you make To award referral credit SMS interaction logs To confirm what was sent and received, and to resolve disputes Ghana Card: verification is optional. We collect it only to verify your identity and never share it with merchants. [CONFIRM WITH COUNSEL: whether the card image is retained or only the verification result and a reference. Retaining only the result is the stronger position.] If you're a merchant Business name and legal name, address, opening hours, category, logo; representative name, position, mobile number and email; authorised approver details; agreement record (reference, timestamp, terms version, verified number); reward settings and campaigns; transaction, claim, approval and settlement history; settlement account details. Everyone using the website Browser type, device type, IP address, pages visited, QR scan events, and referral source. See §9 on cookies. What we don't collect We don't ask for and don't want: your card or bank account numbers as a customer, your health information, or any of the special categories of personal data under Act 843. Don't send them to us.
4. WHY WE USE IT
We use personal information to:
- Run the rewards programme — issue, track, expire and redeem Cash Back Rewards
- Issue and redeem gift cards
- Send you service messages: claim confirmations, balance updates, one-time codes, expiry warnings, and notices when a merchant leaves
- Verify identity and prevent fraud and abuse
- Operate merchant accounts, settlement and reconciliation
- Provide merchants with analytics about their own customers and performance
- Respond to your questions and resolve disputes
- Send you marketing messages about deals and offers, where you have not opted out
- Meet our legal, tax and regulatory obligations
- Improve the service, using aggregated and anonymised data
Our legal bases are your consent (which you give by enrolling, and can withdraw), performance of our contract with you, our legitimate interests in operating and securing the platform, and compliance with law.
5. WHO WE SHARE IT WITH
We do not sell or rent your personal information. We never have and we will not. We share it only in these situations: With merchants you actually transact with. A merchant sees your name, mobile number, and your claim and redemption activity at their business. A merchant never sees your activity at any other business, your total network balance, or your Ghana Card details. With service providers, strictly to run the service, and only what they need: SMS gateway and telecoms providers; cloud hosting and storage; our banking partner, which holds gift card balances and processes settlement to merchants; payment and settlement providers; identity verification providers; analytics providers; customer support tooling. Each is bound by contract to protect your information and to use it only for the service they provide to us. [LIST THE ACTUAL NAMED SUB-PROCESSORS HERE — a named list is significantly more trustworthy than a category list, and it is increasingly expected.] With regulators, courts or law enforcement, where we are legally required to. With a buyer, if Givmo is sold or merged. We would tell you before your information moved, and this Policy would continue to apply until you were given a new one. In aggregated, anonymised form. We may publish insights about consumer behaviour across the network — for example, spending patterns by category or area. No individual customer, and no individual merchant's performance, is identifiable in any such publication. Individual-level data is never sold or licensed.
6. WHEN A MERCHANT LEAVES GIVMO
If a merchant closes their Givmo account:
- They may export the customer list and transaction history for their own customers — this is their data as a separate controller, and they continue to be bound by Act 843 and by our Merchant Terms, including the restriction on marketing to you without your consent.
- Your Givmo account is unaffected. Your balance with that merchant follows the 30-day grace and conversion process in the Customer Terms, and we will SMS you about it.
- We retain the transaction records as set out in §7 — we need them for reconciliation, tax and dispute resolution.
7. HOW LONG WE KEEP IT
Data Retention Active customer account data While your account is open Customer data after account closure [12 months], then deleted or anonymised Transaction and settlement records [6 years] — required for tax and accounting [CONFIRM against Ghana Revenue Authority requirements] Merchant account and agreement records [6 years] after termination Ghana Card verification records [CONFIRM — recommend retaining only the verification result and reference, for the life of the account plus 12 months] SMS logs [24 months] Marketing opt-out records Indefinitely — we have to remember that you opted out Website analytics [26 months] We may keep data longer where we're legally required to, or where it's needed for an unresolved dispute or investigation.
8. YOUR RIGHTS
Under the Data Protection Act, 2012 (Act 843) you have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Request deletion of your data (subject to records we must legally keep — see §7)
- Object to processing, and withdraw consent for marketing at any time
- Prevent processing likely to cause you unwarranted damage or distress
- Complain to the Ghana Data Protection Commission
To exercise any of these: email hello@givmotech.com or privacy@givmotech.com, or call/WhatsApp +233 50 211 7144. We'll verify your identity and respond within [30] days. Marketing opt-out: reply STOP to any marketing SMS, or change it in your account settings. This does not affect service messages (see below) and does not affect your rewards. Service messages — claim confirmations, one-time codes, balance updates, expiry warnings and merchant-departure notices — are part of the service. You can't opt out of them while you hold an account, because the service can't work without them. Closing your account stops them.
9. COOKIES
Our website uses cookies to:
- Keep you logged in and keep your session secure (strictly necessary — the site won't work without these)
- Remember your preferences
- Measure how the site is used, through analytics such as Google Analytics (analytics)
- Attribute sign-ups to a campaign, merchant QR code or creator link (analytics/attribution)
[If you deploy advertising or remarketing pixels, they must be listed here and must be opt-in via a consent banner.] You can block or delete cookies in your browser settings, but strictly necessary cookies can't be turned off and parts of the site will stop working without them. [RECOMMENDED: implement a cookie consent banner that loads analytics and attribution cookies only after consent. This is the direction of travel in Ghanaian practice and it costs little to do now.]
10. SECURITY
We protect your information with:
- One-time code (OTP) authentication for account access and for redemptions above GHC 2,000
- Role-based access — merchants and staff only see what they need to
- Encryption of data in transit and at rest
- Access logging and regular security review
- Staff training and confidentiality obligations
- A documented breach response process
If a breach affects your personal data, we will notify you and the Ghana Data Protection Commission as required by Act 843, without undue delay. No system is perfectly secure. Keep your one-time codes to yourself — Givmo staff will never ask you for an OTP. If someone claiming to be from Givmo asks for your code, it is a scam. Hang up and tell us.
11. CHILDREN
Givmo is for people aged 18 and over. We don't knowingly collect information from children. If you believe a child has enrolled, tell us and we'll delete the account.
12. INTERNATIONAL
Givmo is based in Ghana and complies with Ghanaian data protection law. Some of our service providers — cloud hosting and analytics in particular — process data outside Ghana. Where that happens we require appropriate contractual protections. [COUNSEL: confirm the cross-border transfer requirements under Act 843 and identify the destination countries.]
13. CHANGES TO THIS POLICY
We may update this Policy. For material changes we'll notify you by SMS or dashboard alert at least 30 days before they take effect. The current version, with its date, is always at givmotech.com/privacy.
14. CONTACT
Privacy questions and rights requests: privacy@givmotech.com or hello@givmotech.com Phone / WhatsApp: +233 50 211 7144 Post: Givmo Tech, 42 Giffard Road, Cantonments, Accra, Ghana To complain to the regulator: Ghana Data Protection Commission — dataprotection.org.gh
Privacy & Cookie Policy v2.0 — draft for legal review, September 2026.