1. General
This Privacy Policy explains how GGC – Technology Company Limited (licence AA00623, registered office 3 Kennedy Ave, office 314, Roseau, Dominica) (the "Service") collects, processes, stores and uses Personal Information that the User provides when accessing or using the website https://gogocard.me and its subdomains (the "Website"), and any products or services offered by the Service (the "Services").
For the purposes of this Policy, "Personal Information" means any information relating to an identified or identifiable natural person, including but not limited to name, address, email address, and financial and banking information. Aggregated and anonymised data that does not identify an individual is not Personal Information.
This Privacy Policy should be read together with the Cookie Policy.
The Service acts as a data controller within the meaning of Regulation (EU) 2016/679 (the "GDPR") and applicable European data protection law, where that law applies. The Website and Services are not intended for use by United States Persons, and this Privacy Policy does not address or apply to any U.S. federal or state privacy laws, including the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA).
This Policy explains: the categories of Personal Information collected and the purposes of processing; the legal bases for processing; the categories of recipients to whom Personal Information may be disclosed; international transfers; the User's rights; and the security and retention measures applied.
2. Personal Information collected
The Service may collect and process the following categories of Personal Information:
- Contact information — name, country of residence, and email address;
- Account information — username, authentication credentials, and account identifiers;
- Financial information — account balances, transaction history, and applicable fees and commissions;
- Identity verification data — an image of a government‑issued identity document (passport, national ID card or driving licence), the country that issued it, and a selfie with a liveness check, as required by AML/KYC procedures;
- Compliance‑related information — information on source of funds or financial background, where the Service requests it as part of enhanced due diligence.
The Service may also automatically collect technical and usage data when the User accesses the Website or Services. Such data is generally aggregated and does not directly identify an individual, and may include device and browser information, operating system, IP address and device identifiers; access times, pages viewed and referral URLs; and performance‑related metrics. The Service may collect and process such information even if the User does not complete registration or onboarding.
3. Legal bases for processing
Where the GDPR applies, the Service relies on the following legal bases:
- Performance of a contract — to provide the Services under the Terms of Service;
- Compliance with legal obligations — to meet AML/CFT, KYC, sanctions‑screening and record‑keeping requirements;
- Legitimate interests — to secure the Services, prevent fraud and financial crime, and improve the Services, balanced against the User's rights;
- Consent — for cookies and similar technologies, and for any marketing, where consent is required (which the User may withdraw at any time).
4. How Personal Information is used
The Service processes Personal Information to: register and verify the User; provide and operate the Services and process transactions; meet AML/CFT, KYC and sanctions obligations; detect, prevent and investigate fraud and other unlawful activity; communicate with the User about the Services; and comply with the law and respond to lawful requests from competent authorities.
5. Disclosure of Personal Information
The Service may disclose Personal Information to the following categories of recipients, under appropriate confidentiality and data‑protection obligations:
- the card issuer;
- an identity‑verification (KYC) provider;
- payment and deposit‑processing providers;
- cloud hosting and IT‑infrastructure providers;
- professional advisers (such as legal and audit);
- affiliated entities or entities under common control, subject to obligations no less protective than those in this Policy;
- regulators, law enforcement and other authorities, where required by law.
The Service does not disclose the names of its individual service providers for security reasons. Personal Information may also be disclosed: with the User's consent or at the User's instruction; where necessary to protect the rights, property or security of the Service or its affiliates; to detect, prevent or investigate fraud, financial crime or unauthorised or illegal activity; where required to investigate violations of this Policy or any agreement between the User and the Service; and where required by applicable law or regulatory obligation.
6. International transfers of Personal Information
Personal Information may be stored and processed in data centres located in various jurisdictions where the Service or its providers operate. Any international transfer is carried out in accordance with applicable data protection law and is protected by appropriate technical and organisational safeguards.
7. Cookies and similar technologies
The Service uses cookies and similar technologies to improve Website functionality and the User experience. Details are provided in the Cookie Policy.
8. External websites
The Website may contain links to third‑party websites ("External Websites"). The Service does not control and is not responsible for the content, policies or practices of External Websites. The User accesses External Websites at their own risk and is encouraged to review the applicable policies independently.
9. The User's rights
Subject to applicable law and to the Service's AML/CFT and record‑keeping obligations, the User may exercise the following rights:
- the right to be informed about the processing of their Personal Information;
- the right of access to their Personal Information;
- the right to rectification of inaccurate or incomplete Personal Information;
- the right to data portability, where applicable;
- the right to object to processing;
- the right to restriction of processing;
- the right not to be subject to automated decision‑making, where such processing is not necessary for performance of the contract;
- the right to withdraw consent;
- the right to erasure ("right to be forgotten"), where legally permissible.
Requests may be submitted to [email protected]. The Service may request additional information to verify the User's identity before acting on a request. Where deletion or withdrawal of consent prevents the Service from meeting its legal or contractual obligations, the Service may be unable to continue providing the Services and may end the relationship accordingly.
10. Security of Personal Information
The Service applies appropriate technical and organisational measures to protect Personal Information, including: encrypted data transmission using SSL/TLS; restricted access controls and multi‑factor authentication; secure hosting environments; and confidentiality obligations on authorised personnel. Security measures are reviewed periodically in light of technological and legal developments.
11. Retention of Personal Information
Personal Information is retained only for as long as necessary to fulfil the purposes described in this Policy and to comply with applicable legal and regulatory obligations. In line with record‑keeping requirements, certain Personal Information is retained for at least five (5) years following the end of the relationship, or longer where the law or a competent authority requires it.
12. Updates to this Privacy Policy
The Service may revise or update this Privacy Policy at any time. Updated versions are published on the Website and take effect upon publication.