Privacy Policy
Last updated: July 8, 2026
1. What we collect
For merchants (account holders):
- account details: name, email address, hashed password;
- optional profile photo and business logos you upload;
- business data you enter: business names, payout account names and numbers, payment QR images, webhook URLs, API key metadata;
- transaction records created through your account.
For customers paying a merchant through a checkout page:
- details the merchant's integration passes along: name, email, phone number, order title and reference;
- the payment channel chosen and any bank reference number the customer submits.
We never see or store bank passwords, PINs, card numbers, or wallet credentials — payments happen entirely inside the customer's own banking or mobile-money app.
2. How we use it
- to operate the Service: show checkout pages, match payments, deliver webhooks;
- to secure accounts: session management, email verification, abuse prevention;
- to communicate essential service messages (e.g. verification emails).
We do not sell personal data, run advertising, or use tracking cookies. The only cookies set are functional: your session and your selected business.
3. Where data lives
Data is stored in a managed Postgres database (Neon) and served through Vercel's hosting infrastructure; both may process data outside Ethiopia. Verification emails are delivered through a transactional email provider. These processors handle data only on our instructions.
4. Sharing
Checkout pages necessarily show customers the merchant's business name, logo, payout account details, and payment QR codes — that is the product. Webhook payloads containing transaction data are sent to endpoints the merchant configures. Beyond that, we disclose data only if required by law.
5. Retention and deletion
Account and business data is kept while your account is active. Transaction records are retained for record-keeping integrity. You can delete payout accounts, webhooks, API keys, and businesses without transactions from the dashboard; to delete your entire account, contact us and we will remove it along with associated personal data, subject to any legal retention needs.
6. Security
Passwords are stored using scrypt hashing; API secrets are stored hashed and shown only once; sessions use signed, httpOnly cookies; webhooks are HMAC-signed. No system is perfectly secure, but we design so that a leak of stored data exposes as little as possible.
7. Your rights
You may access, correct, or delete your personal data at any time — most of it directly in the dashboard, the rest by contacting us. Customers who paid a merchant should contact that merchant first, as the merchant controls the commercial relationship.
8. Changes and contact
We may update this policy; the date above reflects the latest revision. Questions: dagm.dev.