GoGoCard

Updated5 months ago

Security Policy

The Service takes the security of Users' data and funds seriously and applies technical and organisational measures designed to protect them. This page describes those measures in general terms. It is informational; the binding rules on account security, suspension and risk control are set out in the Terms of Service, the AML & KYC Policy and the Privacy Policy.

1. Data security

The Service protects User information using measures that include:

  • encrypted data transmission using SSL/TLS;
  • restricted access controls, with access granted on a need‑to‑know basis;
  • multi‑factor and risk‑based authentication controls;
  • secure, monitored hosting environments;
  • confidentiality obligations on all personnel with access to User data.

These measures are reviewed periodically in light of technological and legal developments.

2. Account security

The Service uses automated controls to help detect and prevent unauthorised access, including monitoring for suspicious sign‑in activity and controls that restrict account creation from prohibited or high‑risk sources. Where the Service detects a risk to an account, it may pause activity, request re‑verification, or apply the measures described in the Terms of Service.

The Service identifies the User by the Login Details. Keeping those details confidential is essential to security — see Section 5.

3. Transaction monitoring and fraud prevention

The Service monitors activity for indicators of fraud, account compromise, and other risks, and may hold or review individual transactions where a concern arises. This is carried out in line with the AML & KYC Policy.

4. Card security

Cards are issued by a third‑party Issuer, not by the Service. Card data and card transactions are handled under the security standards of the Issuer and the relevant card networks. The Service shares card‑related information only as needed to provide the Services and to prevent fraud and financial crime.

5. The User's role in security

Security is a shared responsibility. The User can help protect their account by:

  • keeping Login Details — email, phone, Google sign‑in and any password or code — confidential;
  • securing the email account and phone number used with the Service, and being alert to phishing and SIM‑swap attempts;
  • signing out at the end of each session, especially on shared devices;
  • reporting anything suspicious promptly (see Section 6).

6. Reporting a security issue

If the User believes their account, email, phone or Card may have been compromised, or notices anything suspicious, the Service should be informed immediately — through support in the app, or by email to [email protected]. Reports of potential vulnerabilities are also welcome at the same address.