Privacy Policy
Last updated 1 January 2026
In short: We collect what a payment, an order and a support conversation actually need - and not more. We never see your Mobile Money PIN, we never sell your data, and verification codes are never written to our logs.
This document is a template prepared for VerifyGH and has not yet been reviewed by legal counsel. Have it reviewed before relying on it commercially.
1. What we collect
You give us
- Your email address, and your name if you provide one.
- Your Mobile Money number, so a payment prompt can be sent to it.
- Your password, stored only as an Argon2 hash - never in a readable form.
Created by using the service
- Your wallet ledger: every deposit, purchase, refund and adjustment, with amounts, references and timestamps.
- Your orders: which service and country, the price, the phone number assigned, and the order's status history.
- Security records: sign-in attempts, the IP address a request came from, and a salted hash of a coarse device fingerprint (browser type plus IP). We store the hash, never the raw fingerprint, and use it only to detect one device driving many accounts.
What we do not collect
- Your Mobile Money PIN. It is entered on your own handset and never passes through VerifyGH.
- Card details. We do not accept cards, so we never ask for them.
- Location, contacts, or advertising identifiers. We do not use tracking or advertising cookies.
2. Why we use it
- To provide the service: take payment, place your order with our provider, and show you your number and status.
- To keep money correct: maintain an auditable ledger, reconcile payments, and resolve disputes.
- To prevent abuse: detect fraud, account takeover and breaches of our Acceptable Use Policy.
- To meet legal obligations: keep financial records, and respond to lawful requests.
- To contact you: transactional email about payments, orders and security. We do not send marketing email unless you ask us to.
3. Verification codes and messages
Where our provider agreement permits it, a verification message is shown to you on your order screen. Codes and message bodies are excluded from our application logs, are never included in notification emails, and are not shown in staff list views. Support staff can see that a message arrived, not what it said, unless a specific dispute requires it.
4. Who we share it with
We share the minimum necessary, and only with:
- Our payment provider, to collect your Mobile Money payment. They receive your phone number, the amount and a reference.
- Our verification provider, to place your order. They receive the service and country requested - not your identity.
- Our infrastructure providers, who host the application and database under contract.
- Authorities, where we are legally required to, or where there is a serious risk of harm.
We do not sell your data, and we do not share it for advertising.
5. How long we keep it
- Financial records (ledger entries, payments, orders): retained for the period Ghanaian financial record-keeping law requires. These are immutable by design and are not deleted on request.
- Verification codes and SMS text delivered to a rented number: erased 30 days after the order finishes. The order itself stays as a financial record.
- Security records: typically 12 months.
- Account details: until you close your account, after which we remove what we are not required to keep.
6. How we protect it
- Everything is served over HTTPS.
- Passwords are hashed with Argon2; reset tokens are stored only as hashes.
- Session tokens live in httpOnly cookies that JavaScript cannot read, with a separate anti-forgery token required on every write.
- Staff access is role-based and least-privilege. Sensitive actions require a written reason and are permanently logged.
- Credentials and API keys live only in server environment variables.
7. Your rights
Under Ghana's Data Protection Act, 2012 (Act 843) you can ask us to access, correct or delete your personal data, and to explain how we use it. Email privacy@verifygh.example and we will respond within the statutory period.
Some data cannot be deleted on request - financial records we are legally required to keep, and records needed to investigate an open abuse case.
8. Cookies
We use cookies only to keep you signed in and to protect against cross-site request forgery. There are no analytics, advertising or tracking cookies.
9. Changes
If we make a material change we will tell you before it takes effect.