Last updated: 13th May, 2024
INTRODUCTION
Welcome to myStash Limited (“myStash”, “We”, “Our”, “Us”) Privacy Notice (“Notice”). We
understand how important your personal information is to you, and are committed to
protecting your personal data. This Notice covers the personal information myStash collects
or processes from its various sources. The information contained in this Notice is information
we are required to provide to data subject by virtue of the United Kingdom Data Protection
Act, 2018 and General Data Protection Regulation 2016.
We urge you to read the whole Notice to understand how we process your personal
information.
DATA PROTECTION OFFICER (DPO)
myStash has in compliance with the GDPR appointed a Data Protection Officer to guide and
manage our processing activities. If you have any question and issue regarding this Notice,
kindly contact our DPO - gerrad@mystashapp.com
information we collect about you
In connection with the services, we offer you, we will collect, use and store the following
categories of personal information about you:
Registration data: These are information we collect when you sign into our savings
application. This information includes your name, email address, next of kin, photo,
country, phone number, location, house address, identification card such as government
issued Identification (ID). We collect this information in order to provide our services to
you.
Financial data: This includes bank account, card details, financial records. We collect
this information in order to provide our services and to comply with legal obligations.
Collected data are stored for no longer than three (3) months.
Biometric data: This includes information obtained from fingerprint scan. We obtain the
customer's express consent before processing this information.
Marketing/Communication: We use this data to provide information about our services
or new products to you. We also use this information to communicate with you in order to
provide inquiry and support. The information includes phone number, call log, email
address and email content.
Technical data: When you visit our website our servers may automatically log the
standard data provided by your web browser. It may include your device’s Internet
Protocol (IP) address, your browser type and version, the pages you visit, the time and
date of your visit, the time spent on each page, the location and other details about your
visit.
Other Data- we may collect data from you to be processed in relation to administrative
or judicial proceedings.
Information about other people
If you provide information to us about any person other than yourself, your employees,
counterparties, your advisers or your suppliers, you must ensure that they understand how
their information will be used, and that they have given their consent for you to disclose it to
us and for you to allow us, and our outsourced service provid
CHILDREN'S DATA
We do not aim any of our products or services directly at children or persons under the age
of thirteen (13) years and we have put appropriate measures in place to block a person
below the age of 13 years from registering into our platforms. In the event that need arises
for us to process personal information of a person below 13 years we will obtain a valid
consent of the parent or guardian.
COOKIES
We use cookies and other tracking technologies on our website. Cookies are small pieces of
text that are saved on your Internet browser when you use our website. The cookies are
sent back to our computer each time you visit our website. Cookies make it easier for us to
give you a better experience online. You can stop your browser from accepting cookies, but
if you do, some parts of our website or online services may not function appropriately.
HOW IS YOUR PERSONAL INFORMATION COLLECTED
We use different methods to collect personal information about your and they include:
Direct Interactions: These are information you provide to us when you sign up for our
services or products, communicate with us or create a wallet / account with us.
Automated technilogical interactions: We collect these personal information as you
interact with our website or application. These include personal data about your
equipment, browsing actions and patterns, location data. We collect this personal data
by using cookies, server logs and other similar technologies.
Third parties or publicly available sources: We may receive personal information
about you from various third parties and public sources available to us such as your
financial institution, open government sources, agencies amongst others.
HOW WE USE YOUR PERSONAL DATA
We process your personal data for the following reasons:
To provide our services or products to you.
To comply with our obligation under the law.
To resolve dispute resolution that may arise in the course of providing services or
products to you.
To carry out know your customer (KYC) due diligence.
To provide marketing communication to you.
To ensure fraud prevention and investigation.
To respond to your inquiries and correspondence.
To establish, defend, investigate and exercise our legal right.
For our own legitimate business interests.
We process your personal information in order to enhance security, monitor and verify
identity or service access, combat other malware or security risks, and to comply with
applicable security laws and regulations in our jurisdiction.
Further Purpose
We will only process your personal information for the particular purposes for which we
collect it. We will notify you and rely on an appropriate lawful basis if we intend to use it for
another purpose and such further purpose is not compatible with the original purpose.
LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA
We may process your personal data on one or more lawful grounds depending on the
specific purpose for which we are using your personal data. Kindly contact us if you need
further details or clarity about the specific legal ground, we are relying on to process your
personal information where more than one ground has been stated. We will rely on any of
the legal bases listed below depending on the processing activities:
We will ask you for your consent in certain processing activities, especially where it
involves collection of biometric information. Where we obtain your consent, kindly note
that you can withdraw the consent at any time, and we will comply by not further
processing your personal data.
We may process your personal data in order to fulfill the contract you have entered
with us or we have entered with your company or take pre-contractual steps at your
instruction.
We may rely on our legitimate interest to process your personal data to tailor our
services to suit your needs.
We may process your personal data where law mandates us to do so.
WHO DO WE SHARE YOUR PERSONAL DATA WITH
We disclose your personal data to the following third parties:
To enforcement agencies among others.
To our vendors, agents, and service providers that assist us with certain services.
To financial institutions to enable payment processing.
To judicial authorities where necessary to litigate, establish and defend legal rights.
To our legal counsel where the need arises.
THIRD-PARTY LINKS
This notice applies to our site only and does not cover third-party links. Our site may include
links to third-party websites, plug-ins and applications. Clicking on those links or enabling
those connections may allow third parties to collect or share data about you. We do not
control these third-party websites and are not responsible for their privacy notice. When you
leave our website, we encourage you to read the privacy notice of every website you visit.
MyStash Limited is an agent of Plaid Financial Ltd., an authorised payment institution
regulated by the Financial Conduct Authority under the Payment Services Regulations
2017 (Firm Reference Number: 804718). Plaid provides you with regulated account
information services through MyStash Limited as its agent.
DO WE TRANSFER YOUR PERSONAL DATA OUTSIDE United Kingdom?
No, we do not transfer personal data outside the United Kingdom.
DATA SECURITY
We have put appropriate security measures such as encryption, firewall, fingerprint
identification and two factor authentication to prevent your personal information from being
accidentally lost, used or accessed in an unauthorized way, altered or disclosed. Also, we
limit access to your personal information to those agents, contractors and other third parties
who need it to assist in providing services to products to you. They will only process your
personal information on our instructions and they are subject to a duty of confidentiality.
DATA RETENTION
We will only retain your personal data for as long as reasonably necessary to fulfill the
purposes they were collected and where we are required to assert or defend against legal
claims, pending the final adjudication of the claim. In some circumstances we will anonymise
your personal data so that it can no longer be associated with you for research or statistical
purposes, in which case we may use this information indefinitely without further notice to
you. We will securely destroy your personal information once we fulfill the purpose for which
it was collected.
YOUR LEGAL RIGHTS
You have certain rights under the law which we respect and adhere to and which can be
exercised by you at any time. However, note that these rights are not absolute and may only
apply in certain circumstances. Your rights are as itemized:
Request access to your personal information (commonly known as a "data
subject access request"). This enables you to receive a copy of the personal
information we hold about you and to check that we are lawfully processing it.
Request correction of the personal information that we hold about you. This
enables you to have any incomplete or inaccurate information we hold about you
corrected.
Request erasure of your personal information. This enables you to ask us to
delete or remove personal information where there is no good reason for us
continuing to process it. You also have the right to ask us to delete or remove
your personal information where you have exercised your right to object to
processing.
Object to processing of your personal information where we are relying on a
legitimate interest (or those of a third party) and there is something about your
particular situation which makes you want to object to processing on this ground.
You also have the right to object where we are processing your personal
information for direct marketing purposes.
Request the restriction of processing of your personal information. This
enables you to ask us to suspend the processing of personal information about
you, for example if you want us to establish its accuracy or the reason for
processing it.
What we may need from you
We may need to request specific information from you to help us confirm your identity and
ensure your right to access your personal information or to exercise any of your other rights.
This is a security measure to ensure that personal data is not disclosed to any person who
has no right to receive it. We may also contact you to ask you for further information in
relation to your request to speed up our response.
RIGHT TO COMPLAINT
Kindly note that you have the right to make a complaint at any time to the Information
Commissioner Office or approach a competent court of law to enforce your data protection
rights. We would, however, appreciate the chance to deal with your concerns before you
approach the Information Commissioner Office, so please contact us in the first instance.
CHANGES TO OUR PRIVACY NOTICE
This Notice will be updated from time to time to reflect our processing activities and we will
aim to notify you when this happens.
CONTACT DETAILS
Please address questions, comments and requests regarding this Notice to our DPO @
gerrad@mystashapp.com
Contact Us
If you have questions about these Terms and Conditions or our services or about the myStash app or content thereon, please contact myStash at hello@mystashapp.com
🚀
Scan the QR code
to get the app.
Join the thousands of
people using myStash