Legal
Privacy Policy
Last updated:
P2PSwap ("we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and your rights regarding it.
1. Data We Collect
We collect the following categories of personal data:
- Identity data: Full name, government-issued ID number, date of birth (collected during KYC verification).
- Contact data: Email address, phone number.
- Financial data: Payment method details you submit (bank account names, mobile money numbers). We do not store full card numbers.
- Transaction data: Trade history, amounts, counterparty identifiers, timestamps.
- Technical data: IP address, browser type, device identifiers, log data.
- Usage data: Pages visited, features used, session duration.
2. Legal Basis for Processing
We process your data under the following lawful bases:
- Contract: Processing necessary to provide the P2PSwap service, including escrow and trade execution.
- Legal obligation: KYC/AML compliance, responding to lawful requests from regulators and law enforcement.
- Legitimate interests: Fraud prevention, platform security, abuse detection.
- Consent: Marketing emails (you may withdraw consent at any time).
3. How We Use Your Data
- Verify your identity and comply with AML/KYC obligations
- Process and settle trades via our escrow system
- Detect and prevent fraud, abuse, and money laundering
- Send transactional notifications (trade confirmations, alerts)
- Improve platform performance and user experience
- Respond to support requests and disputes
4. Data Sharing
We do not sell your personal data. We may share it with:
- Counterparties: Your display name and payment method details are shared with your trading counterparty to complete a trade.
- Service providers: Hosting, analytics, email delivery (under data-processing agreements).
- Regulators and law enforcement: Where required by applicable law or court order.
5. Data Retention
We retain your account data for the duration of your account plus 5 years to meet regulatory requirements. KYC documents are retained for a minimum of 5 years after the end of the business relationship. You may request deletion of non-mandatory data by contacting us.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request erasure of data we are not legally required to retain
- Object to or restrict certain processing
- Port your data to another service
- Lodge a complaint with a data protection authority
To exercise your rights, contact privacy@p2pswap.io. We will respond within 30 days.
7. Cookies
We use strictly necessary cookies (session authentication) and optional analytics cookies. You can manage cookie preferences via your browser settings. Disabling analytics cookies will not affect your use of the platform.
8. Security
We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits. However, no system is completely immune to breaches. You are responsible for keeping your credentials secure.
9. Changes to this Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before they take effect.
10. Contact Us
Data protection enquiries: privacy@p2pswap.io