Divispend

Privacy Policy

Last updated: April 9, 2026

1. Introduction

Divispend ("we," "our," or "us") operates the Divispend platform, a payment and commerce service that enables users to send, receive, and manage money as well as list and purchase products and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

By using Divispend, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access or use our services.

2. Information We Collect

Personal Information

  • Name, email address, and phone number
  • Payment details (processed securely via Stripe and PayPal)
  • Bank account or payout details for withdrawals
  • Profile information including username, bio, and avatar
  • Business information for seller accounts

Automatically Collected Information

  • Device type, browser type, and operating system
  • IP address and approximate location
  • Usage data: pages visited, features used, time spent
  • Transaction history and wallet activity

3. How We Use Your Information

  • To create, maintain, and secure your account
  • To process payments, transfers, and withdrawals
  • To send transaction receipts and notifications
  • To detect and prevent fraud, unauthorized access, and abuse
  • To improve and personalize our services
  • To communicate updates, promotions, and support messages
  • To comply with legal obligations and regulatory requirements

4. Third-Party Services

We share information with trusted third-party service providers to operate our platform:

  • Stripe — Payment processing, Stripe Connect for payouts. Subject to Stripe's Privacy Policy.
  • PayPal — Alternative payment processing. Subject to PayPal's Privacy Policy.
  • Resend — Transactional email delivery.
  • Google — Social login authentication.

We do not sell your personal information to third parties.

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encrypted data transmission (HTTPS/TLS 1.2+)
  • Field-level encryption for sensitive PII (phone, address, KYC documents) using Fernet (AES-128-CBC + HMAC-SHA256)
  • Hashed and salted password storage (bcrypt, cost factor 12)
  • Tamper-evident audit chain for privileged actions — each entry hash-linked to the previous, with admin verification on demand
  • Header-only auth tokens stored in localStorage; no cross-site cookies
  • Two-Factor Authentication (TOTP) for account security
  • Fraud detection and monitoring systems
  • SOC 2 Type II observation window in progress — see our Trust & Security page for the full controls inventory
  • Quarterly access reviews and incident-response drills

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We notify affected users of any confirmed data incident within the timeframes required by applicable law.

6. Cookies & Local Storage

Divispend uses local storage (not cookies) to maintain your authentication session. We do not use third-party tracking cookies. Service workers may cache static assets for offline functionality as part of our Progressive Web App features.

7. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you may have the following rights:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your personal data
  • Portability — Request an export of your data in a portable format
  • Restriction — Request that we limit processing of your data
  • Objection — Object to the processing of your data
  • Withdraw Consent — Withdraw consent for data processing at any time

To exercise any of these rights, visit your Privacy Settings page or contact us at the email below.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Transaction records are retained for a minimum of 7 years to comply with financial regulations. You may request deletion of your account and associated data at any time through your Privacy Settings.

9. Children's Privacy

Divispend is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal data, we will delete such information promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Divispend Support

Email: privacy@divispend.com

Divispend

© 2026 Divispend. All rights reserved.