Overview
We collect and process personal data only where we have a lawful basis to do so. We are committed to compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable data protection laws in every country where we operate.
By using Banasave, you agree to the collection and use of information described in this policy. If you do not agree, please discontinue use of our services.
Information we collect
Information you provide directly
- Full name, email address, and phone number when you register an account
- Date of birth to verify you meet the minimum age requirement
- Government-issued identity documents (passport, national ID, driver's licence) submitted for KYC verification
- Proof of address documents (utility bills, bank statements)
- Profile photo, if you choose to upload one
- Bank account or mobile money details to facilitate payouts
- Communications you send us via chat, email, or support tickets
Information collected automatically
- Device identifiers, operating system, browser type, and version
- IP address and approximate geographic location
- Pages visited, features used, and time spent in the app
- Transaction history — contribution amounts, dates, and payout records
- Log data including errors and crash reports
Information from third parties
- Identity verification results from our KYC provider
- Payment status and reference data from payment processors (Paystack, Flutterwave, Stripe)
- Fraud signals from fraud prevention services
How we use your data
We use your personal data to:
- Create and manage your account and group memberships
- Process contributions and disburse payouts to the correct member
- Verify your identity in compliance with anti-money laundering (AML) and know-your-customer (KYC) regulations
- Send transactional notifications — payment confirmations, reminders, payout alerts
- Detect and prevent fraud, money laundering, and other illegal activity
- Respond to your support requests
- Comply with legal obligations, court orders, or regulatory requirements
- Improve our product through anonymised usage analytics
- Send product updates and marketing communications (only where you have opted in)
We do not sell your personal data to third parties. We do not use your data to train AI or machine learning models without your explicit consent.
Data retention
We keep your data only for as long as necessary:
- Account data is retained for the life of your account, plus 7 years after closure to comply with financial record-keeping obligations
- KYC documents are retained for 5 years after your last transaction, as required by AML regulations
- Transaction records are retained for 7 years to comply with UK financial services law
- Support communications are retained for 3 years
- Marketing preferences are retained until you withdraw consent or delete your account
- Anonymised analytics data may be retained indefinitely as it cannot identify you
When your data is no longer needed, we securely delete or anonymise it.
Your rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — ask us to delete your data, subject to legal retention obligations
- Right to restrict processing — ask us to pause processing of your data in certain circumstances
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making — not to be subject to solely automated decisions that significantly affect you
Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256
- KYC documents are stored in isolated, access-controlled environments
- Access to production systems is restricted to authorised personnel and requires multi-factor authentication
- We conduct regular security audits and penetration tests
- All employees handling personal data receive annual data protection training
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours of becoming aware of it.
Children's privacy
Banasave is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@banasave.com and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the 'Last updated' date at the top of this page
- Notify you via email and in-app notification at least 14 days before the changes take effect
- In some cases, ask for your renewed consent
Your continued use of Banasave after the effective date constitutes acceptance of the updated policy.
Contact us
If you have any questions about this Privacy Policy or how we handle your data: