Privacy Policy
Last updated: July 1, 2026
1. Who we are
HostPay is a payment infrastructure platform operated by Heuristic of Science and Technology SL Limited ("HOST SL", "we", "us") — providing wallets, deposits, transfers, payouts, and escrow for African businesses through our API and dashboard. This Privacy Policy explains how we handle personal information across the HostPay website, dashboard, and API. You can reach us at host.sl.co@gmail.com.
2. Who this applies to
HostPay serves two groups, and our role differs for each:
- Merchants — businesses that hold a HostPay account and integrate our API. For merchant account data, we are the data controller.
- End users — the customers of a merchant, whose details a merchant submits to us to create users, wallets, and transactions. For this data, we act as a processor on the merchant's behalf; the merchant is the controller.
3. Information we collect
Merchant account information: business and contact name, email address (verified by one-time code), a securely hashed password, and application configuration (such as base currency and webhook endpoints).
End-user information submitted by merchants: the merchant's own user identifier (app_user_id), name, phone number, and optionally email, username, and a Stripe Connect account identifier.
Transaction information: amounts, currency, wallet balances and history, payment method, escrow holds and releases, and payment-provider reference identifiers, with timestamps.
Technical information: API request logs, IP addresses, device and session information (used for per-device sign-in management), and webhook delivery logs.
We do not store full payment card numbers. Card data is handled directly by our PCI-compliant payment gateway (Stripe).
4. How we use information
- To operate the service — process deposits, transfers, payouts, and escrow, and maintain wallet balances.
- To authenticate access via API keys and dashboard sign-in, and to manage sessions and devices.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To meet legal, regulatory, financial record-keeping, and anti-money-laundering obligations.
- To send service communications such as verification codes, security alerts, and account notices.
5. Payment providers and other third parties
We share information with service providers only as needed to deliver HostPay:
- Stripe — card payments and Connect payouts.
- Monime — mobile money payments and payouts in Sierra Leone (e.g. Orange Money, Africell Money).
- Resend — delivery of transactional email such as verification codes.
These providers process data under their own terms and privacy policies. We do not sell personal information.
6. How we store and protect data
Each merchant application's data is held in isolated database schemas, with separate test and live environments. Data is encrypted in transit using TLS, outbound webhooks are signed with HMAC-SHA256, credentials and passwords are stored hashed, and API activity is audit-logged. No method of transmission or storage is completely secure, but we work to protect information using industry-standard measures.
7. Data retention
We retain information for as long as a merchant account is active and as needed to provide the service. Transaction and financial records may be retained longer where required for legal, accounting, or regulatory purposes.
8. Merchant responsibilities
Merchants must have a lawful basis to collect and share their end users' information with HostPay, and must maintain their own privacy notices and obtain any consents required by law. Merchants are responsible for the accuracy of the data they submit.
9. Your rights
Depending on your location, you may have rights to access, correct, or delete personal information, subject to our legal retention obligations. Merchants can manage account data from the dashboard or by contacting us. End users should direct requests to the merchant that holds their account; we will assist that merchant as their processor.
10. International processing
Our providers may process information in countries other than your own. Where this happens, we rely on the safeguards offered by those providers.
11. Children
HostPay is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
13. Contact
Questions about this policy or your data can be sent to host.sl.co@gmail.com.