Personal Information
This is a Privacy Notice for Global Money Exchange Co LLC (doing business as Global Pay and Global Pay Business) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
• Download and use our mobile application (Global Pay and Global Pay Business), or any other application of ours that links to this Privacy Notice.
• Engage with us in other related ways, including any sales, marketing, or events
Global Pay/Global Pay Business: A comprehensive digital payment platform enabling seamless transactions and integration across:
o Remittance: Facilitating Cross border money transfers for individuals
o P2P (Person-to-Person local transfers): Direct money transfers between individuals.
o P2B/B2B (Person-to-Business & Business-to-Business local transfers): Payments between consumers and businesses.
o E-wallet: Loading e-money into wallets,withdrawal of funds from wallets through our branches.
Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. With the acceptance of our Terms and Conditions, End User License Agreement and Privacy Policy, you explicitly provide us your consent to collect and process the data as mentioned in this policy. If you do not agree with our Terms and Conditions, policies and practices, please do not use our Services. If youstill have any questions or concerns, please contact us at globalho@globalmoneyexchange.net
Definitions:
In this policy the below words have the meaning as explained:
Account(s):
refers to the User’s e-Wallet Account under Global Pay/Global Pay Business.
Agreement:
means the Terms and Conditions and End User License Agreement for which consent is given by the user.
AML law:
Anti Money laundering law of the Sultanate of Oman i.e. Royal Decree 30/2016
Device:
means a mobile device owned by the User and on which Global Pay/Global Pay Business Application is installed and/or downloaded.
Email:
refers to the User’s registered email with GMEC.
Instruction:
means any request or instruction by the User, which is affected through the Global Pay/Global Pay Business.
Licensor:
refers toGlobal Money exchange Co LLC
Mobile Number:
refers to the User’s registered mobile number on the Global Pay/Global Pay Business.
Party:
means both GMEC and the User.
Personally identifiable information (PII): is information that, when used alone or with other relevant data, can identify an individual.
PIN:
Personal Identification Number set by the User pursuant to the User’s initial signup to the Global Pay/Global Pay Business. The PIN shall be used for Authorizing transactions and must be kept confidential at all times.
Processing:
Means the usage of information given by the customer to provide the services
Products/Services:
means services offered in the Global Pay/Global Pay Business mobile application.
Remittance:
means cross border transfer of funds using Global Pay mobile application
TT/IMT:
Telegraphic transfer and International Money Transfer. TT is done using direct bank arrangements and IMT is done using the services of agents like Moneygram, Western Union etc.
User/You/Your:
means the user accessing and using the Global Pay/Global Pay Business mobile application, who has accepted the Terms and Conditions, Privacy policy and End User License Agreement.
Wallet Account:
means an Account maintained in electronic form in the Global Pay/Global Pay Business mobile application.
Wallet Balance:
means the funds available in the Global Pay/Global Pay Business Wallet Account.
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on theServices, or otherwise when you contact us.
When the Customer registers with us for the first time on the platform or uses the services, we collect the data such as name, date and place of birth, present address, source of funds, name of employer or business, contact numbers, email address, ID number and ID expiry date to comply with AML Law 30/2016.
Personal information provided by you:The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use.
The personal information we collect based on the availed services may include the following:
• Name
• Mobile number
• email address
• mailing address
• usernames, passwords
• contacts, favorite contacts
• authentication data
• debit card details
• national ID details
• bank account details
• commercial registration details
• Occupation, employment details
• monthly income
• beneficiary details
Payment Data: We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is handled by Omannet. We are storing your payment instrument data in tokenized format shared by Omannet.
Application Data: If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
• Geolocation Information: We may request access or permission to track location-basedinformation from your mobile device, either continuously or while you are using our mobileapplication(s), to provide certain location-based services. If you wish to change our access or permissions, you may do so in your device's settings.
• Mobile Device Access: We may request access or permission to certain features from yourmobile device, including your mobile device's Bluetooth, camera, sms messages, contacts and otherfeatures. If you wish to change our access or permissions, you may do so in your device'ssettings.
•Push Notifications: We may request to send you push notifications regarding your account orcertain features of the application(s). If you wish to opt out from receiving these types ofcommunications, you may turn them off in your device's settings.
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
2. HOW DO WE PROCESS YOUR INFORMATION?
We obtain and process your information in line with the guidelines of Personal Data Protection Law, promulgated by Royal Decree 6/2022 (PDPL), Sultanate of Oman. We process your information to provide, improve, and administer our Services,communicate with you, for security and fraud prevention, and to comply with the law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interactwith our Services, including:
• To facilitate account creation and authentication and otherwise manage user accounts: We may process your information so you can create and log in to your account, as well as keep your account in working order.
• To deliver and facilitate delivery of services to the user: We may process your information to provide you with the requested service.
• To respond to user inquiries/offer support to users: We may process your information torespond to your inquiries and solve any potential issues you might have with the requestedservice.
• To send administrative information to you: We may process your information to send youdetails about our products and services, changes to our Terms& Conditions, policies, and other similar information.
• To fulfill and manage your orders: We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
• To send you marketing and promotional communications: We may process the personalinformation you send to us for our marketing purposes, if this is in accordance with yourmarketing preferences. You can opt out of our marketing emails at any time. For moreinformation, see "WHAT ARE YOUR PRIVACY RIGHTS?".
• To protect our Services: We may process your information as part of our efforts to keep ourServices safe and secure, including fraud monitoring and prevention.
• To evaluate and improve our Services, products, marketing, and your experience: Wemay process your information when we believe it is necessary to identify usage trends, determine the effectiveness of our promotional campaigns, and to evaluate and improve our Services, products, marketing, and your experience.
• To comply with our legal obligations: We may process your information to comply with ourlegal obligations, respond to legal requests, and exercise, establish, or defend our legal rights. When the Customer uses our Mobile application, we collect information sent to us by the Customer’smobile phone in order to provide the Customer with the usage of the platform and to help us personalize and improve the Customer’s experience.
3.WHENAND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We may share information in specific situations described in this section and/or with the following third parties. We may need to share your personal information in the following situations:
• TT/IMT/Other businesspartners: We may share your information with our business partners to offer you certain products, services, or promotions.
• Business Transfers: We may share or transfer your information in connection with, or duringnegotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
• Regulatoryauthorities:We may share your information with regulatoryauthorities as per the applicable laws of sultanate of Oman.We may share your information with third-party service providers, including but not limited to Malaa, Omannet, MPCSS, SMS, and mail servers, to support our operations, such as communication, processing, and delivery of services.When the Customer uses our Mobile application, we collect information sent to us by the Customer’s mobile phone in order to provide the Customer with the usage of the platform and to help us personalize and improve the Customer’s experience.Users can not opt out of the data sharing with the third parties.
4. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law. We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).The data retention period as per the Central Bank of Oman is at least 10 years: i) After the termination of the business relationship ii) After Completion of an occasional transaction (in respect of a customer with whom there is no established business relationship). No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us apart from the requirements as per the statutory guidelines. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
The protection of the Customer’s personal data, in paper and electronic format, is imperative to us and we take judicious steps to protect it from misuse, loss, alteration, and unofficial revelation by setting up physical and technical security measures. We are bound to keep the Customer’s KYC (Know Your Customer) and transaction records for a minimum 10 years in adherence with the requirement of the Central Bank of Oman.
5. HOW DO WE KEEP YOUR INFORMATION SAFE?
We aim to protect your personal information through a system of organizational andtechnical security measures. We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. Both physical and technical security measuresare implemented to protect customer data from misuse and unauthorized access. Our Mobile application is: -
OWASP (Open Web Application Security Project)compliant ensuring robust security at various layers of the platform. Below are some general security policies of the application:
1. Confidentiality: Sensitive data is kept encrypted throughout the system. This includes user passwords, web access key, API key etc.
2. Authentication and Authorization: Authentication and authorization is maintained with JWTtokens. A time-based expiry is set to the tokens so they can be refreshed from time to time.
3. Audit Logs: Audit logs are in place to ensure every action on the API are recorded. Sensitive information in the audit logs is also masked.
4. Secured Access: The API end points are https only.
5. GDPR compliant
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
* JWTs are self-contained, stateless tokens that carry all the necessary information for authentication and authorization within the token itself.
6. WHAT ARE YOUR PRIVACY RIGHTS?
You may view all the user information, change few user information (e.g. email ID,deletion of beneficiaries added through app etc.), or request to terminate your account depending on the laws of Sultanate of Oman.
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable laws, you have the right to withdraw your consent. You can withdraw your consent by visiting us at any of our branches in the Sultanate of Oman. However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent. The data obtained from Mala’a registry i.e. Personally Identifiable Information, cannot be changed or deleted by the user.
If you would at any time like to terminate your account, you can: Visit us at any of our branches in Sultanate of Oman
Global Pay/Global Pay Business customer consent for account Deletion
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our database to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements as well as well data retention requirements.
If you have questions or comments about your privacy rights, you may email us at gmecho@globalmoneyexchange.net
7.CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobileapplications include a Do-Not- Track ("DNT") feature or setting you can activate to signal your privacy preference not to have dataabout your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
8.GLOBAL PAY/GLOBAL PAY BUSINESS PRIVACY POLICY
Data Collection:The personal and financial data collected from users of the Global Pay and Global Pay Business mobile applications includes information such as names, contact details, payment information, transaction history, and device information.
Usage of Data:Collected data is used within the mobile applications for purposes such as processing transactions, verifying user identities, complying with legal requirements, providing customer support, and enhancing user experience through app improvements and personalization.
Data Sharing: User data may be shared with third parties, including payment processors, service providers, and regulatory authorities. The policy outlines the conditions under which data is shared.
Security Measures:Mobile application employs security protocols to protect user data. This includes encryption, secure authentication methods, and regular security audits to prevent unauthorized access, data breaches, and other cyber threats.
User does not have the right to correct or delete their PersonallyIdentifiable Information (PII) within the mobile applications other than accessing those to view. Any amendment of PII needs to be done in National ID first. User may proceed for re-KYC to update those changes in mobile application.
Cookies and Tracking:Our mobile applications use cookies and similar technologies to track user activity. This helps with session management, analytics, and personalization. Cookies are used in the context of managing user sessions to provide seam less experience. Communication with server is over HTTPS only.
Users will be informed of any changes to the privacy policy through notifications or prompts within the mobile application. The updated policy will be available for users to view to ensure they are aware of the latest terms.
9. DO WE MAKE UPDATES TO THIS NOTICE?
We will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, you will be informed through notifications or prompts within the mobile application. We encourage you to review this Privacy Notice frequently to be informedof how we are protecting your information.
10. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may contact at:
Data Protection Officer
Global Money Exchange Company LLC
Corporate Head Office, Muscat
PB 726, PC 131, Ruwi
Muscat,Sultanate of Oman
Email: globalho@globalmoneyexchange.net
Contact Number: +968 9983 8325
Landline: +968- 24799454