Privacy policy
Last updated· Version1.0
Notice —This document is a draft. The bracketed items must be completed before the service goes live.
This policy explains what personal data the Quick Wallet application processes, why, who it is shared with, how long it is kept, and how to exercise your rights.
It supplements the terms of service.
1. Who is responsible for your data
The data controller is [TO BE COMPLETED: exact legal name], with its registered office at [TO BE COMPLETED: full postal address], registered under number [TO BE COMPLETED: registration number].
Contact for any question about personal data: [TO BE COMPLETED: data protection officer or contact email].
2. The data we process
We collect only what the service needs to work.
2.1 Identity and account data
Email address, password (stored as an irreversible hash, never in clear text), first and last name, profile picture if you add one, phone number and its country code, chosen language and theme.
Your email address and password belong to your Quick Account, the identity shared across the Quick Business ecosystem (see section 5).
2.2 Identity verification data (KYC)
Where regulation requires it: type and number of your identity document, images of that document, proof of address, verification selfie, date and place of birth, nationality, address.
2.3 Operation data
Amounts, currencies, dates, status, fees applied, exchange rate used, payment method, transaction reference, beneficiary or merchant identifier, savings plans and their maturity dates, and the free-text label you write to describe an operation.
An operation label is a free-text field: do not write sensitive information in it (health, opinions, a third party’s family situation). It is stored with the operation and visible to the beneficiary.
2.4 Security and technical data
A 6-digit PIN — it never leaves your device in clear text; only a cryptographic proof travels. One-time codes sent by email or SMS, and their expiry. Sign-in and operation logs (date, outcome, device type), sign-in IP addresses, a technical device identifier, the push notification token, the application and operating system versions.
2.5 Biometric data
None. If you enable fingerprint or face unlock, the check is performed by your phone, locally. No biometric template is sent to us and we have no access to it. Biometric unlock replaces entering the PIN to open your session; it never authorises an operation on its own.
2.6 What we do not collect
We do not process your location, not your address book, and the application contains no advertising tracker and no third-party analytics.
2.7 Permissions the application asks for
| Permission | What it is for |
|---|---|
| Camera | Scanning a merchant’s QR code, photographing an identity document |
| Photos | Attaching an identity document already stored on your phone |
| Fingerprint / Face ID | Unlocking the session instead of entering the PIN (processed locally) |
| Notifications | Alerting you to an operation, a maturity date or a security event |
Every permission is optional and requested at the point it becomes useful. Refusing one does not prevent you from using the service; it disables the corresponding feature.
3. Why we process this data
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and managing your account | 2.1 | Performance of the contract |
| Carrying out your operations | 2.1, 2.3 | Performance of the contract |
| Verifying your identity, fighting money laundering and fraud | 2.2, 2.3, 2.4 | Legal obligation |
| Securing access to your account | 2.4, 2.5 | Performance of the contract and legitimate interest |
| Notifying you of account events | 2.1, 2.4 | Performance of the contract |
| Answering your requests and complaints | 2.1, 2.3 | Performance of the contract |
| Diagnosing incidents and improving the service | 2.4 | Legitimate interest |
| Responding to a request from an authority | as requested | Legal obligation |
[TO BE COMPLETED: confirm the legal-basis terminology against the applicable regulation — the wording above follows the GDPR and must be adapted if another law applies.]
4. Messages you receive
We send you messages tied to the running of the service: operation confirmations, security alerts, one-time codes, savings plan maturity reminders. These cannot be switched off: they are part of the service.
Promotional messages, if any, are only sent with your consent and each one carries a way to opt out.
5. Who your data is shared with
We do not sell your data. It is shared only with:
- Quick Account — the federated identity of the Quick Business ecosystem, which holds your email address, password and profile information;
- FedaPay and Feexpay — payment service providers, to carry out top-ups and withdrawals;
- Twilio — sending SMS messages, in particular verification codes;
- Firebase Cloud Messaging (Google) — delivering push notifications;
- Amazon Web Services (S3) — storing the documents you upload;
- [TO BE COMPLETED: name and country of the host of the application servers and database];
- [TO BE COMPLETED: transactional email provider, if separate];
- the beneficiary of a transfer or the merchant you pay — who sees your name and the amount, just as you see theirs;
- the competent authorities, where the law requires it.
Each provider acts on our instructions, for the stated purpose only, and is bound by a confidentiality undertaking.
6. Transfers outside your country
Some of these providers host or process data outside your country of residence, in particular in the United States and in the European Union (Amazon Web Services, Google, Twilio). These transfers are framed by [TO BE COMPLETED: safeguard relied on — standard contractual clauses, adequacy decision, consent, or the equivalent under applicable law].
7. How long we keep your data
| Data | Retention |
|---|---|
| Active account | For the lifetime of the account |
| Account data after deletion | [TO BE COMPLETED: period] |
| Identity documents and verification file | [TO BE COMPLETED: statutory retention period] from closure |
| Operation history | [TO BE COMPLETED: statutory accounting retention period] |
| Sign-in and technical logs | [TO BE COMPLETED: period] |
| One-time codes | A few minutes, then deleted |
| Deletion requests submitted on this site | [TO BE COMPLETED: period] after processing |
An important point. Deleting your account does not erase everything immediately. The regulation applicable to payment services requires us to keep, after closure, your identity documents and your operation history for the period stated above. That data is then locked: it serves only to answer a legal obligation or an official request, and is no longer used to run any service. When the period expires, it is deleted or irreversibly anonymised.
8. How your data is protected
- All traffic between the application and our servers is encrypted in transit (TLS).
- Passwords are stored as irreversible hashes, never in clear text.
- The PIN never leaves your device in clear text.
- Access to data by our teams is limited to what their duties require, and is logged.
- Sessions expire, and sensitive actions require re-authentication.
No system is infallible. In the event of a data breach likely to create a high risk for you, we will inform you and notify the competent authority within the timeframes set by applicable law.
9. Your rights
You have the right:
- to access the data we hold about you and obtain a copy of it;
- to have it corrected if it is inaccurate;
- to request its erasure, within the limits of section 7;
- to request the restriction of a processing operation or to object to it;
- to the portability of the data you provided to us;
- to withdraw your consent at any time, where the processing relies on it;
- to give instructions about what happens to your data after your death.
To exercise these rights, write to [TO BE COMPLETED: rights request email]. We answer within [TO BE COMPLETED: response time set by applicable law]. We may ask you to prove your identity before acting — that is a protection against impersonation, not an obstacle.
If our answer does not satisfy you, you may lodge a complaint with [TO BE COMPLETED: competent data protection authority, with its address].
10. Deleting your account
The request is made from the application [TO BE COMPLETED: location of the in-app screen once shipped] or from the public Delete my account page, reachable without an account and without installing anything.
The request covers your Quick Wallet account. Your Quick Account, shared with the other Quick Business services, is the subject of a separate procedure, explained on the same page.
The timeframes, the cases that prevent deletion (non-zero balance, operation in progress, open dispute, active savings plan) and what is kept afterwards are described on that page and in section 7.
11. This website
This site sets no advertising cookie and no analytics cookie. It loads no third-party script. Fonts are served from our own servers, which avoids a request to a third party.
The deletion request page processes the information you enter there for the sole purpose of handling your request. Your IP address is used in memory to limit abuse; it is not stored in clear text.
12. Minors
The service is not intended for people under [TO BE COMPLETED: minimum age]. We do not knowingly collect their data. If you become aware that an account was opened by a minor, report it to [TO BE COMPLETED: contact email]: the account will be closed and the data deleted, subject to retention obligations.
13. Changes to this policy
We may update this policy. The applicable version is the one published on this page, with its update date. Any substantial change is flagged to you [TO BE COMPLETED: channel and notice period] before it takes effect.
14. Contact
[TO BE COMPLETED: legal name] — [TO BE COMPLETED: postal address] Data protection: [TO BE COMPLETED: data protection officer or contact email]