Legal

Privacy Policy

Last updated:

P2PSwap ("we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and your rights regarding it.

1. Data We Collect

We collect the following categories of personal data:

  • Identity data: Full name, government-issued ID number, date of birth (collected during KYC verification).
  • Contact data: Email address, phone number.
  • Financial data: Payment method details you submit (bank account names, mobile money numbers). We do not store full card numbers.
  • Transaction data: Trade history, amounts, counterparty identifiers, timestamps.
  • Technical data: IP address, browser type, device identifiers, log data.
  • Usage data: Pages visited, features used, session duration.

2. Legal Basis for Processing

We process your data under the following lawful bases:

  • Contract: Processing necessary to provide the P2PSwap service, including escrow and trade execution.
  • Legal obligation: KYC/AML compliance, responding to lawful requests from regulators and law enforcement.
  • Legitimate interests: Fraud prevention, platform security, abuse detection.
  • Consent: Marketing emails (you may withdraw consent at any time).

3. How We Use Your Data

  • Verify your identity and comply with AML/KYC obligations
  • Process and settle trades via our escrow system
  • Detect and prevent fraud, abuse, and money laundering
  • Send transactional notifications (trade confirmations, alerts)
  • Improve platform performance and user experience
  • Respond to support requests and disputes

4. Data Sharing

We do not sell your personal data. We may share it with:

  • Counterparties: Your display name and payment method details are shared with your trading counterparty to complete a trade.
  • Service providers: Hosting, analytics, email delivery (under data-processing agreements).
  • Regulators and law enforcement: Where required by applicable law or court order.

5. Data Retention

We retain your account data for the duration of your account plus 5 years to meet regulatory requirements. KYC documents are retained for a minimum of 5 years after the end of the business relationship. You may request deletion of non-mandatory data by contacting us.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Request erasure of data we are not legally required to retain
  • Object to or restrict certain processing
  • Port your data to another service
  • Lodge a complaint with a data protection authority

To exercise your rights, contact privacy@p2pswap.io. We will respond within 30 days.

7. Cookies

We use strictly necessary cookies (session authentication) and optional analytics cookies. You can manage cookie preferences via your browser settings. Disabling analytics cookies will not affect your use of the platform.

8. Security

We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits. However, no system is completely immune to breaches. You are responsible for keeping your credentials secure.

9. Changes to this Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before they take effect.

10. Contact Us

Data protection enquiries: privacy@p2pswap.io