Privacy Policy
Last updated: April 9, 2026
1. Introduction
Divispend ("we," "our," or "us") operates the Divispend platform, a payment and commerce service that enables users to send, receive, and manage money as well as list and purchase products and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
By using Divispend, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access or use our services.
2. Information We Collect
Personal Information
- Name, email address, and phone number
- Payment details (processed securely via Stripe and PayPal)
- Bank account or payout details for withdrawals
- Profile information including username, bio, and avatar
- Business information for seller accounts
Automatically Collected Information
- Device type, browser type, and operating system
- IP address and approximate location
- Usage data: pages visited, features used, time spent
- Transaction history and wallet activity
3. How We Use Your Information
- To create, maintain, and secure your account
- To process payments, transfers, and withdrawals
- To send transaction receipts and notifications
- To detect and prevent fraud, unauthorized access, and abuse
- To improve and personalize our services
- To communicate updates, promotions, and support messages
- To comply with legal obligations and regulatory requirements
4. Third-Party Services
We share information with trusted third-party service providers to operate our platform:
- Stripe — Payment processing, Stripe Connect for payouts. Subject to Stripe's Privacy Policy.
- PayPal — Alternative payment processing. Subject to PayPal's Privacy Policy.
- Resend — Transactional email delivery.
- Google — Social login authentication.
We do not sell your personal information to third parties.
5. Data Security
We implement industry-standard security measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS 1.2+)
- Field-level encryption for sensitive PII (phone, address, KYC documents) using Fernet (AES-128-CBC + HMAC-SHA256)
- Hashed and salted password storage (bcrypt, cost factor 12)
- Tamper-evident audit chain for privileged actions — each entry hash-linked to the previous, with admin verification on demand
- Header-only auth tokens stored in localStorage; no cross-site cookies
- Two-Factor Authentication (TOTP) for account security
- Fraud detection and monitoring systems
- SOC 2 Type II observation window in progress — see our Trust & Security page for the full controls inventory
- Quarterly access reviews and incident-response drills
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We notify affected users of any confirmed data incident within the timeframes required by applicable law.
6. Cookies & Local Storage
Divispend uses local storage (not cookies) to maintain your authentication session. We do not use third-party tracking cookies. Service workers may cache static assets for offline functionality as part of our Progressive Web App features.
7. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the following rights:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your personal data
- Portability — Request an export of your data in a portable format
- Restriction — Request that we limit processing of your data
- Objection — Object to the processing of your data
- Withdraw Consent — Withdraw consent for data processing at any time
To exercise any of these rights, visit your Privacy Settings page or contact us at the email below.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Transaction records are retained for a minimum of 7 years to comply with financial regulations. You may request deletion of your account and associated data at any time through your Privacy Settings.
9. Children's Privacy
Divispend is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal data, we will delete such information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Divispend Support
Email: privacy@divispend.com
