Privacy Policy

This Privacy Policy explains how Phonix Pay collects, uses, stores, shares, discloses, protects, and retains personal information across our website, mobile applications, payment features, merchant tools, customer support channels, documents, notifications, and related services.

Last updated: July 3, 2026 Effective date: July 3, 2026 Version 1.0

Phonix Pay is a smartphone financing and device-management platform provided by Apex Arbitrage Ventures. For purposes of this Privacy Policy, "Apex Arbitrage Ventures," "Phonix Pay," "we," "us," or "our" refers to Apex Arbitrage Ventures and its Phonix Pay product.

This Privacy Policy applies to:

  • The Phonix Pay marketing website;
  • The Phonix Pay admin and merchant platform;
  • The Phonix Pay mobile DPC app;
  • The Phonix Pay support, documents, payments, reporting, and device-management services.

1. Important notice

Phonix Pay provides smartphone financing and device-management solutions. Where a customer receives a financed device, certain device-management features may be used during the active repayment period, subject to the customer's financing agreement, device management consent, applicable policy profile, and relevant laws.

These features may include:

  • Device enrollment or provisioning;
  • Payment reminders and payment status sync;
  • Device lock or unlock status, restricted mode, and policy application;
  • Lost Mode support and factory reset protection support, where applicable;
  • Device health and security monitoring;
  • Release after full payment.

We do not use the DPC app to read private messages, listen to calls, access private photos, read personal files, or monitor browsing activity.

2. Who this Privacy Policy applies to

This Privacy Policy applies to:

  • Website visitors and prospective customers;
  • Customers using financed devices or the DPC app;
  • Merchants, approved retailers, merchant owners, and staff users;
  • Platform administrators, support users, finance users, and collections users;
  • Guarantors or emergency contacts, where provided;
  • People who submit forms, requests, complaints, or interact with payment, document, or support systems.

3. Our role as data controller or data processor

Depending on the situation, Apex Arbitrage Ventures may act as a data controller, joint controller, or data processor.

We may act as a data controller when we determine why and how personal information is processed for Phonix Pay account creation, customer onboarding, platform security, DPC app operations, payment status management, audit logs, customer support, legal compliance, marketing website leads, and system monitoring.

We may act as a data processor when we process personal information on behalf of a merchant or retailer according to their instructions, such as when a merchant uses the Admin Platform to manage its own customers, contracts, payments, or inventory. Merchants may also be independent data controllers for information they collect from customers in connection with device sales, financing, customer support, and repayment enforcement.

4. Personal information we collect

The personal information we collect depends on your relationship with Phonix Pay and the services you use.

5. Information from customers and prospective customers

We may collect:

  • Full name, phone number, WhatsApp number, email address, and residential address;
  • City, town, region, or location;
  • Ghana Card or other identity information;
  • Passport picture or profile photo;
  • Preferred phone brand or model, preferred repayment cycle, budget, or deposit range;
  • Customer support messages.

6. Ghana Card, identity, and document information

Where a customer applies for or receives a financed device, we or an approved merchant may collect Ghana Card number, name on Ghana Card, Ghana Card front and back images, passport picture, signature, agreement documents, proof of address if required, and guarantor documents if required.

This information is used for customer identification, contract administration, fraud prevention, dispute handling, recovery support, compliance, and audit purposes.

7. Emergency contact and guarantor information

Where required by a merchant, financing plan, risk policy, or contract, we may collect information about an emergency contact or guarantor, including full name, relationship to customer, phone number, address, email address, identity information if required, and guarantor agreement or consent.

Customers must ensure they have authority or consent to provide emergency contact or guarantor information. We may contact an emergency contact or guarantor only where reasonably necessary for customer support, repayment follow-up, device recovery, dispute resolution, or contract-related purposes.

8. Merchant and retailer information

For merchants, shop owners, and retailer accounts, we may collect:

  • Business name, registration details, tax identification number where applicable, business type, address, and branch information;
  • Owner or primary contact name, business phone number, business email address, payment settlement information, and account status;
  • Merchant staff users, inventory, plans, reports, and support communications;
  • Performance and operational information such as plans managed, payments collected, overdue accounts, inventory assigned, active contracts, payout or settlement records, customer onboarding activity, and audit logs.

9. Staff information

For users of the Admin Platform, we may collect name, email address, phone number, role, department, merchant or branch assignment, login credentials, MFA status, permissions, access level, session details, IP address, device/browser details, login history, role changes, approval actions, admin activity, and audit logs.

We collect this information to manage access, prevent unauthorised use, maintain accountability, protect customer data, and record sensitive platform actions.

10. Payment information

Phonix Pay uses third-party payment providers to process, verify, or reconcile payments. We may collect or process:

  • Payment amount, reference, provider transaction ID, channel, status, date, and time;
  • Mobile money number or masked account details;
  • Receipt number, customer contract balance, installment schedule, failed payment reason, refund, reversal, or dispute status.

Mobile money processing is handled by payment providers.

11. Device and DPC app information

Where the Phonix Pay DPC app or customer app is installed on a financed device, we may collect device and app information needed to provide financing, device status, support, security, and release features.

This may include:

  • Device brand, model, IMEI or serial number, Android version, DPC app version, device ID, and app installation ID;
  • Provisioning token, QR provisioning status, Device Owner status, policy version, and policy result status;
  • Lock or unlock status, restricted mode status, last sync time, last seen online, network status, battery level, and storage status;
  • Tamper alert, Lost Mode status, release status, factory reset protection status where applicable, command delivery status, and telemetry events.

This information is used to ensure the device is linked to the correct customer, contract, merchant, plan, and policy profile.

12. Location information

Phonix Pay may process location-related information only where it is needed and permitted for device support, Lost Mode, recovery, security, audit, or consented device-management purposes. Location information may include last known device location, location timestamp, location accuracy, approximate IP-derived location, merchant branch location, customer-provided address, and device recovery location events.

Location collection is limited to what is necessary for the feature being used. Lost Mode or recovery location features are governed by the customer's device management consent and applicable financing documents.

13. App usage, diagnostics, and telemetry

We may collect app usage, diagnostics, and telemetry data to maintain reliability and security, including app crashes, error logs, sync failures, command failures, policy apply failures, network connectivity state, feature usage, and device compatibility information.

14. Website and browser information

When you visit the Phonix Pay marketing website, we may collect IP address, browser type, device type, operating system, referring website, pages visited, time spent on page, buttons clicked, form submissions, cookie preferences, analytics events, and approximate location.

We use this information to operate the website, measure campaign performance, prevent abuse, improve content, and respond to inquiries.

15. Cookies and similar technologies

We may use cookies, local storage, session storage, device identifiers, push notification tokens, SDK identifiers, and similar technologies for authentication, security, preferences, analytics, payment status, device/account linking, push notifications, audit logs, fraud prevention, and system performance. More details are provided in our Cookie and Similar Technologies page.

16. Information from third parties

We may receive information from merchants and retailers, payment providers, identity verification providers, mobile money providers, email and SMS providers, support tools, device management infrastructure, analytics and monitoring tools, public or official sources where lawful, customer-authorised contacts, and guarantors.

We may combine information from these sources with information already held by Phonix Pay where necessary for the purposes described in this Policy.

How we use personal information

17. Main purposes of processing

We may use personal information to:

  • Provide and operate Phonix Pay;
  • Create customer and merchant accounts;
  • Create and manage contracts;
  • Assign and provision devices;
  • Manage repayment schedules, process or verify payments, generate receipts, and send reminders;
  • Display payment status, store and display documents, and send documents for signature;
  • Provide support, manage device status, apply DPC policies, and lock, unlock, release, or recover devices where authorised;
  • Enable Lost Mode where authorised, monitor device health and compliance, and detect tamper or misuse;
  • Prevent fraud, maintain audit logs, generate reports, manage merchants and staff users, comply with legal obligations, improve services, and protect the platform.

18. Customer financing and account management

We use customer information to create and manage financing records, including customer identity, device selected, plan amount, deposit, installment amount, payment cycle, due dates, outstanding balance, payment history, signed documents, device management consent, and completion status.

This helps customers and merchants understand the financing arrangement and manage repayments.

19. Payment processing and verification

We use payment information to initiate payments, verify payment status, update outstanding balances, generate receipts, confirm payment completion, detect failed or reversed payments, reconcile payments, trigger unlock after confirmed payment, trigger release after final payment, handle disputes, and prepare reports.

20. Device management and DPC app operations

We use DPC app and device information to verify Device Owner status, apply policy profiles and repayment enforcement rules, show device status, send device commands, receive policy results, verify lock/unlock status, apply release after full payment, monitor device compliance, detect tamper signals, support lost device recovery, and provide customer support.

Device-management features operate according to the applicable financing agreement, DPC app notice, device management consent, and policy profile.

21. Notifications and communications

We may use contact information to send payment reminders, payment due notices, payment received confirmations, overdue notices, grace-period notices, device status updates, document alerts, signature requests, support messages, merchant messages, security alerts, plan completion notices, and marketing communications where permitted.

Customers may opt out of non-essential marketing communications, but operational, payment, security, legal, and device-management notices may still be sent where necessary.

22. Security, fraud prevention, and audit logging

We use information to protect Phonix Pay and its users, including login monitoring, MFA verification, role and permission checks, IP monitoring, suspicious activity detection, payment fraud detection, device tamper detection, report export audit, and admin action logging.

Audit logs help establish who did what, when, from where, on which record, and why.

23. Reports and analytics

We may use data to generate merchant reports, payment reports, receivables reports, inventory reports, policy compliance reports, DPC health reports, audit reports, system health reports, and operational dashboards.

Reports may include aggregated, anonymised, or account-level information depending on user permissions and business need.

Sharing and disclosure

28. Who we may share information with

We may share personal information with:

  • Approved merchants and retailers;
  • Payment providers;
  • Push notification providers;
  • Support service providers;
  • Analytics and monitoring providers;
  • Professional advisers;
  • Legal and regulatory authorities;
  • Law enforcement where legally required;
  • Business partners involved in providing Phonix Pay services;
  • Apex Arbitrage Ventures affiliates, where applicable.

We share only what is necessary for the relevant purpose.

29. Sharing with merchants

Merchants may access customer information related to customers, contracts, devices, payments, documents, and support cases connected to that merchant. Merchant users may only access information according to their role and permissions. Merchants are responsible for using customer information lawfully and for protecting information exported or accessed from the Admin Platform.

30. Sharing with payment providers

Payment information may be shared with payment providers to process, verify, reconcile, refund, or investigate payments. Payment providers may collect data directly or automatically through their services, including payment information, contact information, device information, usage information, IP-derived location, and related transaction data.

31. Sharing with service providers

We may use service providers for hosting, database storage, security monitoring, email delivery, SMS delivery, push notifications, analytics, error monitoring, customer support, document generation, digital signature workflows, and payment reconciliation.

Service providers may only process personal information for authorised purposes and should be subject to confidentiality, security, and data-processing obligations.

32. Legal disclosure

We may disclose personal information where necessary to:

  • Comply with law or respond to lawful requests;
  • Protect rights or property;
  • Prevent fraud or abuse;
  • Enforce agreements;
  • Investigate security incidents;
  • Protect customers, merchants, staff, or the public;
  • Defend legal claims;
  • Comply with regulators.

Data retention

33. How long we keep information

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required for legal, accounting, audit, security, dispute, contract, or regulatory reasons.

Retention depends on the type of information, purpose for collection, contract period, payment and accounting requirements, audit requirements, legal obligations, dispute resolution needs, device release status, and security requirements.

34. Example retention approach

Data type Suggested retention approach
Marketing website inquiriesRetain for a limited lead-management period unless converted into an account.
Customer financing recordsRetain during the contract and for required legal or audit period after completion.
Payment records and receiptsRetain according to finance, accounting, tax, and dispute requirements.
Signed agreementsRetain for the contract period and required legal limitation period.
Ghana Card and identity documentsRetain only as long as needed for verification, contract, legal, fraud, or audit purposes.
DPC device status recordsRetain during active financing and required audit or release period.
Device release recordsRetain to prove full payment and release.
Admin audit logsRetain according to security and compliance retention rules.
System logsRetain for security, debugging, and incident response periods.
Support ticketsRetain for service history and dispute handling.

35. Deletion and anonymisation

When information is no longer required, we may delete, anonymise, aggregate, or securely archive it. Some information may not be immediately deleted if it is required for legal compliance, payment records, fraud prevention, audit logs, dispute resolution, contract enforcement, device release proof, or security investigations.

User rights

36. Your privacy rights

Depending on applicable law and your relationship with Phonix Pay, you may have rights to:

  • Request access to your personal information;
  • Request correction of inaccurate information;
  • Request deletion where permitted;
  • Object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Request restriction of certain processing;
  • Request information about how your data is used;
  • Complain to a relevant data protection authority.

37. How to make a privacy request

To make a privacy request, contact Phonix Pay at info@phonixpay.one, by phone on 0556516139, or at HNO. CM26 Love Avenue, Amasaman. We may need to verify your identity before responding.

If your information is controlled by a merchant, we may refer your request to the relevant merchant or coordinate with them to respond.

38. Limits on privacy requests

We may decline, limit, or delay a request where permitted by law, including where necessary for:

  • Verifying identity;
  • Protecting another person's rights;
  • Retaining payment records;
  • Maintaining audit logs;
  • Complying with legal obligations;
  • Investigating fraud or abuse;
  • Resolving disputes;
  • Enforcing contracts;
  • Protecting system security.

39. Marketing communications

You may opt out of non-essential marketing communications by using the unsubscribe link, updating your preferences, or contacting us. You may still receive essential service messages, including payment notices, security alerts, device status notices, contract notices, support responses, legal notices, and plan completion notices.

40. Cookies and website tracking

Website users may manage cookies through the cookie banner, cookie settings page, or browser settings. Rejecting non-essential cookies may limit analytics, personalisation, or campaign measurement but should not prevent access to basic website content.

41. DPC app permissions and settings

The DPC app may require certain permissions or device-management capabilities while the financing contract is active. Some features may be essential for provisioning, payment status, device-management policy, lock/unlock status, release after full payment, security monitoring, Lost Mode where authorised, and customer support.

Disabling required permissions or tampering with the DPC app may affect service availability, device status, policy sync, or support.

Security

42. How we protect personal information

We use reasonable technical and organisational safeguards to protect personal information. These may include encryption in transit, encryption at rest where appropriate, role-based access controls, multi-factor authentication, session timeout, audit logging, access approvals, staff access controls, system monitoring, backups, and incident response procedures.

43. Staff and merchant access controls

We restrict access to personal information based on role and business need. Sales staff may create customer onboarding records, finance users may view payment records, operations users may manage provisioning, superadmins may manage system settings, support users may view support cases, and merchants may access only their assigned customers.

Sensitive actions may require MFA, reason notes, manager approval, audit logging, and session verification.

44. Security incidents

If we become aware of a data security incident affecting personal information, we will take appropriate steps, which may include investigating the incident, containing the risk, restoring service integrity, notifying affected users or regulators where required, improving safeguards, and recording incident evidence.

45. Where information may be processed

Phonix Pay may use cloud, payment, analytics, support, messaging, and infrastructure providers that process data in Ghana or other countries. Where personal information is transferred internationally, we will take reasonable steps to ensure appropriate safeguards are used, such as contractual protections, security controls, vendor due diligence, access restrictions, data minimisation, and applicable transfer safeguards.

46. Minors

Phonix Pay is not intended for use by children who cannot legally enter into binding contracts. If a customer is below the applicable age of contractual capacity, a parent, guardian, or legally authorised representative may be required. We do not knowingly provide financing directly to minors without required legal authority.

47. Automated or rule-based decisions

Phonix Pay may use automated rules or decision-support tools for payment reminders, grace period calculation, overdue status, auto-lock eligibility, auto-unlock after confirmed payment, policy assignment, risk flags, fraud signals, DPC status checks, and customer support routing.

Where an automated rule affects a customer's device status or financing experience, the customer may contact their merchant or Phonix Pay support to request review.

48. Risk scoring and alerts

Phonix Pay may generate risk signals based on overdue payments, repeated missed payments, device offline status, SIM change events, policy drift, tamper signals, failed commands, Lost Mode events, and payment disputes.

These signals are used to support operational review and do not replace human review where required by policy, agreement, or law.

Platform-specific disclosures

49. Customer marketing website

On the customer marketing website, we may process information to provide information about Phonix Pay, receive customer inquiries and retailer requests, help users find approved merchants, respond to support requests, measure website performance, improve marketing campaigns, and provide legal notices.

We may collect website analytics and form submissions, subject to cookie and consent settings where applicable.

50. Admin platform

On the Admin Platform, we may process information to authenticate staff and merchants, manage users and roles, create customers and contracts, assign devices, manage payments, provision phones, send DPC commands, manage policy profiles, maintain audit logs, generate reports, and monitor system health.

Admin Platform activity is logged for security, accountability, fraud prevention, and compliance.

51. Mobile DPC app

In the DPC app, we may process information to show payment status, balance, receipts, and assigned documents; send reminders and alerts; sync policy status; apply lock or unlock commands where authorised; apply release after full payment; provide support; report device status; detect device-management issues; and support Lost Mode where authorised.

52. No sale of personal information

We do not sell customer personal information.

53. No unrelated personal surveillance

We do not use the DPC app to:

  • Read private messages;
  • Listen to phone calls or record conversations;
  • Access unrelated private photos or unrelated private files;
  • Track unrelated web browsing;
  • Sell personal data to advertisers;
  • Use customer data for unauthorised surveillance.

54. No unauthorised device control

Device control features are used only for purposes connected to active financing agreements, device support, security, lost device recovery, payment status, release after full payment, and contractual obligations.

Merchants and staff are prohibited from using device controls for harassment, retaliation, or unauthorised purposes.

55. Third-party terms and privacy policies

Third-party services used with Phonix Pay may have their own terms and privacy policies. These may include payment providers, email providers, SMS providers, push notification providers, analytics providers, support tools, maps or location providers, and identity verification providers.

Users should review the privacy policies of relevant third-party providers.

56. Links to third-party websites

The customer marketing website or Admin Platform may include links to third-party websites. We are not responsible for the privacy practices, content, or security of third-party websites that we do not control.

57. Corporate transactions

If Apex Arbitrage Ventures or Phonix Pay undergoes a merger, acquisition, restructuring, financing, sale of assets, transfer of business, or similar transaction, personal information may be transferred as part of that transaction, subject to appropriate safeguards and applicable law.

58. Changes

We may update this Privacy Policy from time to time to reflect new features, legal requirements, payment providers, DPC app functionality, integrations, security measures, or changes to how we process information.

If we make material changes, we may notify users through website notice, Admin Platform notice, DPC app notice, email, SMS, push notification, or an updated consent prompt.

59. Privacy contact

For privacy questions, requests, or complaints, contact:

Apex Arbitrage Ventures / Phonix Pay
Email: info@phonixpay.one
Phone: 0556516139
Address: HNO. CM26 Love Avenue, Amasaman
Website: phonixpay.one

If your request relates to a merchant-controlled customer account, we may coordinate with the relevant merchant.