Privacy Policy
This policy explains what data we collect about you, why, who we share it with, how long we keep it, and what rights you hold over it.
1. Scope of this policy
This policy explains what data WFR collects about you, why it is collected, who it is shared with, how long it is kept, and what rights you hold over it. It covers the app, the website, and every official contact channel.
Using the platform means you accept what is set out here. If you do not accept a clause, do not use the service.
2. What we collect
We collect what the service actually needs, and no more:
- Account data: your name, phone number, email if you add one, and preferred language.
- Verification data: national number or passport number, a photo of the document, and a live selfie for matching.
- Addresses: country, city, area, written description, landmark, coordinates, and the recipient name and number.
- Order data: the service requested, the execution details you enter, your notes, and your attachments.
- Financial data: the order amount, the payment channel, and the transfer receipt. We never receive or store your card details.
- Technical data: device type and fingerprint, IP address, and sign-in logs.
3. Why we collect it
- To carry out the service you ordered and deliver it to the beneficiary.
- To verify your identity, which is a regulatory obligation and not a commercial choice.
- To prevent fraud and money laundering and to detect suspicious patterns.
- To notify you of your order status and to provide support when needed.
- To meet our accounting and legal obligations.
4. Identity data is handled differently
Identity images are the most sensitive thing we hold, and they carry stricter controls than any other data:
- Encrypted at rest and stored in a container separate from the main database.
- Served through short-lived signed links, never through public URLs.
- Every single document view is logged with the employee name and timestamp.
- The national number is masked on every operational screen and shown in full only to the compliance role.
- Image metadata is stripped on upload, including the coordinates where the photo was taken.
5. Notes and attachments
Our staff read your notes and attachments in order to price and carry out your order. Do not put card numbers, passwords, or anything the execution does not need into those fields.
Whatever does reach us there is subject to the same access limits as your identity data.
6. Who we share it with
We share only what is necessary, and only with parties the execution requires:
- Payment providers and card gateways, to complete collection.
- Shipping companies and licensed customs brokers, for cross-border physical services.
- Delivery couriers, who see the delivery details of the order assigned to them only.
- The institution the service is carried out with, to the extent execution requires.
- The messaging provider (the official WhatsApp platform) to deliver notifications.
- Regulatory and judicial authorities, on a binding official request.
7. What we do not do
- We do not sell or rent your data to anyone.
- We do not use your identity data for any marketing purpose.
- Your card details never pass through our servers and are never stored by us.
8. Notifications and your consent
Order notifications are operational and necessary to perform the service; you receive them while you have an active order.
Marketing messages require your explicit consent and you can stop them at any time without affecting operational notifications.
9. Retention
We keep transaction data for as long as accounting and regulatory obligations require.
Identity documents are deleted after the published retention period, or when you close your account, whichever is later, unless a legal obligation prevents it.
Financial records are never hard-deleted; an entry is cancelled logically and corrected with a reversing entry.
10. Your rights
- To see the data we hold about you.
- To correct anything inaccurate.
- To request deletion of your data, within the limits of any legal obligation.
- To withdraw your consent to marketing messages.
- To object to a particular processing, and to be told why it happens.
11. Security
We apply encryption in transit and at rest, separation of duties, and an immutable audit log of every administrative action.
No system is perfectly secure. If a breach affects your data, we will notify you and the competent authority as the law requires.
12. Age
The service is for people aged eighteen and over. We do not open accounts below that age, and if we discover one it is closed and its data deleted.
13. Changes to this policy
We may amend this policy. You will be notified of any material change before it takes effect, and the revision date at the top of this page will be updated.
14. Contact
For any question about your data, or to exercise any of the rights above, reach us through the official support channels inside the app.
The other documents
This document is read together with the Terms of Use and Refund policy and Delete account.