Privacy Policy
Last updated: 01/07/2026
Last updated: 01/07/2026
IFIAAS ("WinetPay") attaches paramount importance to the minimization and protection of data. This policy describes the data processed, the purposes for which it is processed and its retention periods.
1. Data controller
IFIAAS, Zinvié, Bénin. Data protection contact: [to be completed].
2. Data processed and purposes
End customer (no account): WinetPay creates no customer account. When a purchase is made, the following data is processed:
- Phone number: used for the Mobile Money payment and delivery of the ticket. It is encrypted at rest and automatically purged after 90 days; only a permanent fingerprint (hash) is retained for fraud and duplicate prevention, together with a masked version for display purposes.
- Transaction data (amount, offer, router, status, timestamp): retained for accounting and legal purposes.
Operator: trade name, WhatsApp number, e-mail (optional), withdrawal information, visual identity, activity log — for the provision of the service.
3. Legal basis
Performance of the contract (provision of the service and of the paid access), legal obligations (accounting, anti-fraud measures) and legitimate interest (security of the platform).
4. Retention periods
- Customer phone number: 90 days (then purged; hash and masked version retained).
- Financial / transactional data: 10 years (legal and accounting obligations).
- Operator data: for the duration of the contractual relationship, then legal archiving.
5. No marketing
WinetPay uses no customer data for marketing purposes. Communications are strictly transactional.
6. Masked display
By default, customer contact details are masked in the interfaces (operator and administration), in accordance with the minimization principle.
7. Recipients and processors
Only the strictly necessary data is transmitted to the payment providers (FedaPay, FeexPay) in order to carry out the transactions, and to the host ([to be completed]). No data is disclosed to third parties for commercial purposes.
8. Security
Encryption of secrets at rest, end-to-end HTTPS, access control, logging. See the Security Policy.
9. Your rights
Access, rectification, erasure (subject to the limits of legal retention obligations), restriction and objection. Requests via [to be completed]. You may refer the matter to the competent authority (APDP — Autorité de Protection des Données Personnelles (Bénin)).
10. Ticket recovery
The customer retrieves their ticket by reference, QR or secure link, without any account or additional data.
11. Amendments
This policy may change; the applicable version is the one published on the date of consultation.