Your trust matters. This policy describes what we collect, why, who we share it with, and the choices and rights you have — written to reflect how Reback actually works across the countries we serve.
1. Overview and scope
This Privacy Policy explains how Reback Finance (“Reback”, “we”, “us”) collects, uses, shares and protects personal information when you use our invoicing, payments and escrow services, apps, websites and APIs (the “Services”). It applies to sellers and businesses who hold a Reback account, staff users they invite, and buyers/customers who pay or interact through Reback.
Reback operates across multiple countries and currencies. Where local data-protection law (such as the EU/UK GDPR, or applicable African data-protection laws such as Nigeria’s NDPA) gives you specific rights, this policy is intended to support them.
2. Who is responsible for your data
The data controller for your personal information is [Registered legal entity name — to be confirmed by legal/compliance] (registration number [Company registration number — to be confirmed by legal/compliance]), registered at 21, Olatunde Sule Street, Olowora, Lagos State, Nigeria..
The precise controller/processor roles for each country of operation, the identity of any local entity or representative, and whether a Data Protection Officer has been appointed are [to be confirmed by legal/compliance]. Where a DPO or EU/UK representative is appointed, their contact details will be added here.
3. Information we collect
Account and profile information
When you register and use Reback, we collect information such as your name (first, middle, last), email address, phone number, country, preferred language, date of birth and gender, profile and business logo images, and social-media handles you choose to add. For business accounts we also collect your business name, type and category.
Identity verification (KYC / KYB) information
To meet our legal obligations, we collect and verify identity information appropriate to your country and verification level. This can include government identity numbers and documents — for example a Bank Verification Number (BVN) and National Identification Number (NIN) and business registration (CAC/RC) in Nigeria; a Ghana Card and SSNIT in Ghana; a National ID and KRA PIN in Kenya; a national ID in South Africa; an SSN/ITIN and government ID in the United States; a passport in the United Kingdom; and a Personalausweis in Germany — along with proof of address, business-registration details, and documents such as passports, driver’s licences or voter’s cards. We also collect a live selfie for a liveness/face check during verification.
Transaction, invoice and escrow information
We collect the details needed to process your activity: invoices and their line items (including product descriptions and images), offers and negotiations, amounts, currencies, taxes and fees, escrow status and inspection periods, delivery and shipment details (such as carrier and tracking), counterparties’ names and shipping details, and transaction records including sender and recipient names.
Payment and payout information
We collect the payout destinations you add — bank name and code, account number and the account name resolved by our partners, or a mobile-money phone number and provider. For card payments, we do not store your full card number. Card details are collected and tokenized by our PCI-DSS-compliant payment processors; Reback stores only a payment token and limited metadata such as the card brand and the last four digits.
Device and location information
We collect device and technical information such as device type, operating system, IP address and login location, and (where you enable it) precise device GPS location. As described in our Terms, device GPS is required for certain money-moving actions such as creating an invoice or completing a transaction. We capture the coordinates, accuracy and a timestamp and derive an approximate country/region/city; comparing this with your IP-based location helps us detect fraud and meet AML obligations.
Communications and support
When you contact support, respond to a dispute, or receive notifications, we collect the content of those communications, including one-time passcodes sent by SMS or email and any evidence you upload to a dispute.
Usage and cookies
We collect usage and analytics data about how you interact with our websites and apps, and we use cookies and similar technologies as described in our Cookie Policy.
4. How we use your information
We use personal information to:
- provide, operate and maintain the Services and your account;
- process invoices, payments, escrow, payouts, subscriptions and refunds, including through our payment partners;
- verify your identity and your business, and meet our anti-money- laundering, know-your-customer, sanctions-screening and other legal and regulatory obligations (see our AML & KYC Statement);
- detect, investigate and prevent fraud, abuse and security incidents, including by comparing device-GPS and IP location;
- resolve disputes and appeals and enforce our Terms and Acceptable Use Policy;
- communicate with you about transactions, security, service changes and support;
- improve and develop the Services, including analytics and troubleshooting; and
- send marketing where permitted, which you can opt out of at any time.
5. Legal bases for processing
Where the GDPR or a similar law applies, we rely on the following legal bases:
- Performance of a contract — to provide the Services you have signed up for (accounts, invoicing, payments, escrow, payouts, subscriptions).
- Legal obligation — to carry out identity verification, sanctions screening, transaction monitoring, record-keeping and reporting required of a payments/escrow business.
- Legitimate interests — to prevent fraud and abuse, keep the Services and your account secure, and improve our products, balanced against your rights.
- Consent — for optional cookies, certain marketing, and access to precise device location on your device, which you can withdraw at any time (note that some features may not work without required location access).
6. How we share information
We do not sell your personal information. We share it only as needed to run the Services and meet our obligations, including with the categories of service providers (“sub-processors”) below:
| Purpose | Providers |
|---|---|
| Payment, payout and virtual-account processing | Paystack, Flutterwave |
| Bank-account verification | Paystack account resolve, NUBAPI |
| Identity verification (KYC/KYB) and liveness | QoreID (African markets), Sumsub (US/UK/Germany) |
| SMS (one-time passcodes) | Termii |
| Email delivery | SendGrid, Postmark |
| Cloud hosting, file storage and secrets management | Amazon Web Services (S3, Secrets Manager) |
| Sign-in with Google |
We also share information with the other party to a transaction (for example, a buyer and seller see the information needed to complete an invoice, payment or dispute); with regulators, law-enforcement, courts, or our financial partners where required by law or to prevent fraud; and with professional advisers or an acquirer in connection with a corporate transaction, subject to appropriate safeguards.
The complete, current list of sub-processors, and the contractual data- protection terms in place with each, are [to be confirmed and maintained by legal/compliance].
7. International data transfers
Reback operates across several countries, and our service providers may process data in countries other than yours. Where personal data is transferred across borders, we take steps to ensure it remains protected in line with applicable law, for example by using recognised transfer mechanisms such as standard contractual clauses. The specific transfer mechanisms and safeguards for each provider and corridor are [to be confirmed by legal/compliance].
8. How long we keep your data
We keep personal information for as long as needed to provide the Services and for the periods required by law — in particular, financial and identity-verification records must be retained for regulatory and audit purposes after your relationship with us ends. Some specifics of how we handle data:
- transaction and dispute audit records are kept in an append-only, tamper-evident ledger and are not deleted;
- identity verification is time-limited and typically requires re-verification after a validity window (currently around 24 months);
- short-lived items such as one-time passcodes and idempotency keys expire automatically; and
- other account records may be soft-deleted and then removed or anonymised in line with our retention schedule.
A documented retention schedule with exact periods per data category is [to be confirmed by legal/compliance].
9. How we protect your data
We use technical and organisational measures to protect your information, including encryption in transit, encryption at rest for stored files, hashing of credentials, access controls, and monitoring. You can read more on our Security page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal information:
- access a copy of the data we hold about you;
- correct inaccurate or incomplete data;
- request deletion, subject to our legal obligations to retain certain financial and verification records;
- restrict or object to certain processing;
- data portability;
- withdraw consent where we rely on it; and
- lodge a complaint with your local data-protection authority.
If you are in a US state with privacy laws (such as California), you may also have rights to know, delete, correct, and opt out of certain sharing; we do not sell personal information. To exercise any right, contact us using the details below. We may need to verify your identity before we act, and some requests may be limited by law.
11. Fraud prevention and automated processing
We use automated tools to help prevent fraud and meet AML obligations — for example, sanctions and watchlist screening before a payout, and risk signals such as a mismatch between device-GPS and IP location. These tools can lead to a transaction, payout or account being delayed, held or blocked.
The extent to which any decision is made solely by automated means, and the human-review and appeal process for such decisions, are [to be confirmed by legal/compliance]. Where the law gives you the right to human review of an automated decision, you can request it using the contact details below.
12. Children
The Services are not directed to children, and you must be at least 18 to hold a Reback account. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “last updated” date and, for material changes, provide additional notice where required.
14. Contact us
For privacy questions or to exercise your rights, contact us:
- Support: Reback support portal
- Post: 21, Olatunde Sule Street, Olowora, Lagos State, Nigeria.