1. Who controls the data
Four One Financial Services Limited, based in Kampala, Uganda, operates the Mayicard platform. Where Mayicard is provided for a SACCO, MFI, investment entity, or another participating organisation, that organisation may control its members' financial records while Four One Financial Services processes those records to provide the service. Contact us if you need help identifying the organisation responsible for your account.
2. What personal data is collected
The information processed depends on the products connected to your account. It may include:
- Account and identity data: customer or member identifier, name, organisation membership, and identity information supplied to a participating financial organisation where verification is required.
- Contact data: registered phone number and, where supplied, email address.
- Financial data: account balances, savings and investment activity, deposit or withdrawal requests, payment status, ledger entries, and transaction references. Mayicard does not ask for or store your Mobile Money PIN.
- Security and session data: authentication tokens stored securely on your device, sign-in and USSD session records, IP address, and records needed to prevent abuse or investigate account access.
- Optional app diagnostics: if you allow diagnostics in the Mayicard app, we process app interactions, performance timings, crashes, technical errors, app version, device model, operating system, network type, and network-level information such as IP address. These events are configured not to include your name, phone number, PIN, balances, transaction amounts, or transaction references.
- Support and rights requests: information you submit when asking for support, account access changes, or deletion.
3. Why the data is processed
We process information to authenticate you, show the accounts you are authorised to use, provide balances and transaction history, submit financial requests, maintain accurate ledger records, prevent fraud, protect the service, respond to support or deletion requests, meet legal obligations, and—with your choice—improve app reliability.
Essential account and financial processing is necessary to provide the service and is not affected by your optional diagnostics choice.
4. Service providers and sharing
We do not sell personal data. We share information only where needed to provide, secure, or support Mayicard; comply with law; or follow your instructions. Current categories of recipients include:
- Your participating organisation and payment providers: to operate your financial account and process the requests you initiate.
- Datadog: to process optional app performance, crash, and reliability diagnostics after you allow this in the app.
- Flagsmith: to deliver remote feature configuration. Flagsmith analytics are disabled in the Mayicard app.
- Hosting, infrastructure, and communications providers: to run the platform, verify requests, and deliver support. The account-deletion web form submits directly to the Mayicard API.
- Authorities or professional advisers: where disclosure is required by law or necessary to establish, exercise, or defend legal rights.
Service providers are permitted to use data only for the contracted service and must apply appropriate safeguards.
5. Your choices and rights
You can allow or decline optional app diagnostics on first use and change the choice later under Profile → Legal & Privacy. Declining diagnostics does not prevent you from using your account.
Subject to applicable law and the responsibilities of your participating organisation, you may request access, correction, restriction, objection, portability, or deletion of eligible personal data. Use our Account Deletion page to request closure of your app access profile and deletion of eligible associated data.
6. Data retention
We retain account and profile information while it is needed to provide Mayicard and then delete or de-identify it unless a longer period is required for accounting, audit, dispute resolution, fraud prevention, or legal compliance. Core financial records and ledger entries may therefore remain after app access is closed.
Optional diagnostic events are retained only for as long as reasonably necessary to investigate reliability and security issues, subject to the retention controls in our Datadog service. Support and deletion requests are retained while the request is handled and for a limited period afterwards to document the outcome.
7. Security and children
We use access controls, encryption in transit, secure device storage, monitoring, and operational controls designed to protect Mayicard data. No system can guarantee absolute security; report concerns through our Security page.
The Mayicard app is a financial service and is not directed to children. A participating organisation must apply any legal requirements that govern accounts held for or used by minors.
8. Contact us
For privacy questions or requests, email mayicardplatform@gmail.com. Include the organisation connected to your account, but never send your PIN, password, or Mobile Money approval code.
We may update this policy when our services or legal obligations change. The effective date above identifies the current version.