Legal

Privacy Policy

Last updated: January 2025

1. Introduction

AmanExchange ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payment gateway services and website.

By using AmanExchange, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

We collect several types of information:

  • Personal Information: Name, email address, phone number, business name, and business registration details when you create an account or contact us.
  • Financial Information: Bank account details, transaction data, and payment card information (processed through our PCI DSS compliant systems).
  • Technical Information: IP address, browser type, device information, operating system, and usage patterns.
  • Business Information: Transaction volume, settlement data, API usage, and merchant performance metrics.

3. How We Use Your Information

We use the collected information for:

  • Processing and managing payment transactions
  • Verifying merchant identity and conducting KYC (Know Your Customer) procedures
  • Detecting and preventing fraud, money laundering, and security threats
  • Providing customer support and responding to inquiries
  • Improving our services and developing new features
  • Complying with legal obligations and regulatory requirements
  • Sending important service updates and notifications

4. Data Security

We implement industry-standard security measures to protect your information:

  • PCI DSS Level 1 compliance for payment card data
  • End-to-end encryption for data transmission
  • Secure data storage with regular backups
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Employee training on data protection and privacy

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

5. Data Sharing and Disclosure

We may share your information with:

  • Banks and Payment Networks: To process transactions and settlements
  • Service Providers: Third-party vendors who assist in our operations (under strict confidentiality agreements)
  • Regulatory Authorities: When required by law or to comply with Central Bank of Iraq regulations
  • Legal Processes: In response to court orders, subpoenas, or legal proceedings

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6. Data Retention

We retain your information for as long as necessary to:

  • Provide our services and maintain your account
  • Comply with legal obligations (minimum 7 years for financial records)
  • Resolve disputes and enforce our agreements
  • Prevent fraud and maintain security

7. Your Rights

You have the right to:

  • Access your personal information
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal requirements)
  • Object to processing of your information
  • Request data portability
  • Withdraw consent where processing is based on consent

To exercise these rights, please contact us at privacy@aman.exchange

8. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Maintain your session and authentication
  • Remember your preferences
  • Analyze usage patterns and improve our services
  • Prevent fraud and enhance security

You can control cookies through your browser settings, but disabling them may affect the functionality of our services.

9. International Data Transfers

Your information is primarily processed and stored within Iraq. If we transfer data internationally (e.g., for cloud services), we ensure appropriate safeguards are in place to protect your information in accordance with Iraqi law and international standards.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new policy on our website
  • Sending an email notification to registered merchants
  • Displaying a notice in your dashboard

Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact:

  • Email: privacy@aman.exchange
  • Phone: +964 773 043 7312
  • Address: Baghdad, Iraq