Privacy Policy for PesaX Pro
1. Overview & Commitment to Privacy
At PesaX Pro, a financial product developed and operated by PESA INTERNET INDUSTRY CONSULTING COMPANY LIMITED, we are committed to protecting your personal and financial information. As a provider of digital financial services—including credit assessment, loan facilitation, and user data analysis—we understand the importance of handling your information with transparency, integrity, and care. This Privacy Policy outlines how we collect, use, store, and share your information when you use our services. It also describes your rights and choices regarding your data, and the measures we take to ensure its security. By using PesaX Pro, you agree to the terms of this policy and acknowledge our company’s commitment to safeguarding your privacy at every stage of your interaction with our product.
2.Types of Data We Collect and Why
a. To provide secure, efficient, and personalized financial services, PesaX Pro collects the following types of data:
Personal Identification Information: such as your full name, national ID or passport number, phone number, and email address. This helps us verify your identity and comply with regulatory requirements.
Financial and Employment Information: including your income level, occupation, employment status, and loan application history. These details are necessary for evaluating creditworthiness and processing loan applications.
Device and Technical Information: such as device model, operating system, unique device identifiers, and IP address. This data helps us ensure app compatibility, detect fraud, and improve system performance.
Usage Data: including in-app behavior, interaction logs, and session activity. We use this information to optimize user experience and enhance service delivery.
b. Sensitive Permissions
To deliver secure, efficient, and responsible financial services, PesaX Pro requests access to the following sensitive permissions. All collected data is uploaded securely to our servers for analysis and service provision. We do not share this information with third parties for marketing or unrelated purposes.
SMS Messages: To assess your creditworthiness and ensure accurate risk evaluation, we request your permission to access SMS messages.
With your consent, our system will first scan SMS messages locally using financial-related keywords. Only messages identified as financial (e.g., from banks or mobile money providers) will be collected — including the sender, message content, and date sent.
These financial messages will be encrypted and securely uploaded to our servers(https://ol.pxfunds.co/kopa/) via HTTPS. The data helps us analyze your financial behavior and identify potential risks.
Your information is kept strictly confidential and will never be shared without your consent. You may decline SMS access at any time, though this may affect the accuracy of your credit assessment.
Approximate Location :
We collect your IP address to help determine whether you are located within the countries or regions where our services are available. This information is also used to support fraud prevention and account security. The data is uploaded to our servers and used solely for geographic eligibility checks and risk assessment. We do not use location data for tracking or marketing purposes.
Device Information:
We collect technical and device-specific information, including but not limited to your device model, operating system version, Android ID, screen resolution, language settings, and network type. This information is encrypted and securely uploaded to our servers, and is used solely for verifying device identity, preventing fraud, ensuring compatibility across different devices, and supporting technical diagnostics. We do not use this data for profiling, advertising, or tracking purposes. All collected information is stored on secure servers with strict access controls and industry-standard encryption protocols to protect your privacy and ensure the safety of your data throughout its lifecycle.
Installed Applications List:
We analyze your list of installed apps using specific keyword filters to assess the risk of multi-loan behavior and detect patterns linked to financial risk. This data is uploaded to our servers, used solely for risk assessment, and is not shared externally.
Camera Access:
We use your device’s camera during identity verification, requiring you to complete a liveness check before applying for a loan. A single selfie image is captured and uploaded to our secure server for facial comparison to confirm that the applicant is the legitimate user. The photo is used only for one-time verification and is not shared or repurposed.
3. How Collected Information is Used in Credit Evaluation & Service Delivery
The information we collect is used strictly to support the delivery of our financial services, and in particular, to evaluate your creditworthiness, process loan applications, and manage ongoing account relationships. Specifically, your personal and financial data helps us verify your identity, assess risk levels, determine eligibility, and tailor loan offers appropriately. Technical and behavioral data, such as device information, location (via IP), SMS analysis, and installed apps (filtered), contribute to fraud prevention, multi-loan risk assessment, and system optimization.
All data collected is encrypted and uploaded securely to our servers and used exclusively for internal analysis and service provision. We do not use your personal information for advertising, profiling, or third-party marketing. Our data processing framework follows strict access controls and ensures that each data point is used only for its defined purpose within the lending and credit decision workflow.
4. Third-Party Access, Sharing Practices & Legal Disclosures
We do not sell, rent, or disclose your personal or financial information to third parties for marketing or advertising purposes. However, to deliver our services effectively and understand how users interact with our app, we may share certain data with trusted third parties under the following circumstances:
Analytics and Attribution Tools:
We integrate AppsFlyer to help us analyze the effectiveness of our advertising campaigns, including install attribution and user acquisition performance. Additionally, we use the Google Advertising ID (GAID) to evaluate the results of our marketing efforts. These tools help us understand how users discover our app and improve our outreach strategies.
We do not use these tools for personalized advertising or cross-app behavioral profiling. All data collected through these tools is handled securely and solely for internal analytics purposes.
Service Providers:
We may share specific data with verified third-party providers who support credit scoring, cloud infrastructure, identity verification, or system operations. These providers are contractually bound to use the data strictly for service delivery and to comply with our data protection standards.
Financial Partners and Credit Bureaus:
With your explicit consent, we may share relevant information with licensed financial institutions or credit reference agencies to process loans and assess credit risk.
Regulatory and Legal Requirements:
We may disclose your information when legally required, including for anti-money laundering (AML), know-your-customer (KYC), or tax compliance purposes.
All third-party integrations are governed by strict data processing agreements. We ensure that your information is used only for legitimate business needs, protected by appropriate safeguards, and never misused or repurposed beyond the original intent.
5. Your Rights: Access, Consent, and Control over Your Data
We respect your rights and provide transparent options for you to manage your personal data. As a user of PesaX Pro, you have the following rights and controls:
Access and Correction: You may view, update, or correct your personal information through the app’s account settings or by contacting our support team.
Permission Management: You can manage or revoke access to sensitive permissions (such as SMS, Camera, or Location) at any time through your device settings. Please note that revoking certain permissions may limit access to specific core features of the app, including loan eligibility assessment.
Account Deletion and Data Erasure: You have the right to request permanent deletion of your account and all associated data. You may do so through the app or by contacting us directly. Once verified, we will delete your data from our active systems, except where retention is required by applicable laws or regulatory obligations.
Withdraw Consent: If you have previously granted consent for specific data processing (e.g., marketing analytics), you may withdraw that consent at any time.
Support and Inquiries: If you have any questions about your data, or if you would like to exercise any of your rights, please contact us at the details provided in the “Contact Us” section of this policy. We respond to all privacy-related inquiries in a timely and respectful manner.
6. Data Security, Retention Periods & Infrastructure Safeguards
At PesaX Pro, data security is a fundamental priority. We implement strict technical and organizational measures to ensure that your personal and financial information is collected, stored, and processed in a safe and secure manner. All sensitive data transmitted to our servers is encrypted during transmission and storage, and protected using industry-standard security protocols such as firewalls, secure access controls, and encryption technologies.
Access to your data is strictly limited to authorized personnel who require it for service delivery, and all access is monitored and logged for accountability. We regularly audit our systems to detect and prevent potential vulnerabilities or unauthorized access.
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including legal, regulatory, and operational requirements. In accordance with financial regulations in Tanzania, data related to financial transactions, loan processing, and identity verification is retained for a minimum of five (5) years. Non-essential data is deleted or anonymized as soon as it is no longer needed for service delivery.
Upon account deletion, your personal information will be securely erased from our active systems, unless further retention is legally required. We do not store data beyond its legitimate purpose, and we ensure that expired data is permanently and securely removed from our servers.
7. Use of SDKs, Analytics, and External Technology Partners
To support the functionality, performance, and security of the PesaX Pro app, we integrate a limited number of third-party software development kits (SDKs) and technology services. These partners help us monitor system health, understand user behavior, measure marketing performance, and ensure smooth app operation. All data accessed or processed through these SDKs is handled securely and only for clearly defined, service-related purposes.
The SDKs we currently use include:
AppsFlyer: We use AppsFlyer to perform advertising attribution and measure the effectiveness of our user acquisition campaigns. This SDK may collect device information (e.g., device model, OS version, advertising ID), install referrer data, and engagement metrics. The collected data is encrypted and used solely for internal analytics; it is not used for personalized advertising.
Google Advertising ID (GAID): We use the Google Advertising ID to measure the performance of our marketing activities. The GAID helps us understand how users discover our app and where installs originate. We do not use this identifier for user profiling or behavioral advertising.
Firebase (Google LLC): Firebase is used for crash reporting, app performance monitoring, and notification services. It may collect anonymized device and usage data to help us identify errors and improve stability. No personal or financial data is stored or shared through Firebase.
All third-party SDK integrations are governed by strict data handling agreements and comply with relevant data protection regulations. We review these tools regularly to ensure that they align with our privacy standards and do not collect or process more information than is necessary.
8. Minors and Data Collection Limitations
PesaX Pro is not intended for use by individuals under the age of 18. We do not knowingly collect or process personal information from minors. Our financial services are designed exclusively for adults who meet the legal age and eligibility criteria for credit and financial products in their respective jurisdictions.
If we become aware that we have inadvertently collected personal information from a minor, we will take immediate steps to delete such data from our systems. Parents or guardians who believe that we may have collected information from a child may contact us directly to request data removal.
9. Policy Updates & User Notification Methods
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal obligations, or regulatory requirements. When we make significant changes, we will notify users through appropriate means—such as in-app notifications, email alerts, or updated prompts within the app interface—before the new terms take effect.
We encourage users to review this Privacy Policy periodically to stay informed about how their information is collected, used, and protected. Your continued use of the PesaX Pro app after any changes to this policy constitutes your acceptance of the revised terms.
10. Contact & Regulatory Support Information
If you have any questions, concerns, or requests related to this Privacy Policy or the handling of your personal data, please contact us through the following channels:
Email:
help@pxfunds.co
business@pxfunds.com
Phone Number: +255795870966
We are committed to responding to all privacy-related inquiries promptly and transparently.