Privacy Policy
Raoufi ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our mobile application and financial services.
1. Account Information
When you register for a Raoufi account we collect your full name, email address, date of birth, phone number, and country of residence. This information is required to create and maintain your account, communicate important notices, and comply with financial services regulations.
You may update your personal information at any time through the app. We store account data on encrypted servers located within secure data centres and do not sell your information to third parties.
2. Identity Verification (KYC)
To comply with anti-money laundering (AML) and know-your-customer (KYC) obligations under Algerian financial law and applicable international standards, we collect:
- A government-issued photo ID (national identity card, passport, or driving licence — front and back)
- A selfie photograph taken at the time of submission
These documents are transmitted over encrypted connections, stored in a secure document vault, and reviewed solely by our authorised compliance personnel. They are never sold, rented, or shared with third parties except as required by law or a competent regulatory authority. KYC documents are retained for a minimum of five years after account closure as mandated by financial regulations.
3. Transaction Information
We collect and permanently record all transactions conducted through our platform, including peer-to-peer transfers, mobile top-ups, bill payments, and QR code payments. Recorded data includes transaction amounts, timestamps, sender and recipient identifiers, currency, status, and any reference notes you attach.
Transaction records are essential for delivering our services, generating your account statements, resolving disputes, and meeting regulatory reporting requirements. These records are retained for a minimum of five years in accordance with applicable financial law.
4. Payment Providers
We partner with regulated payment processors, banking institutions, and mobile network operators to execute your transactions. When you initiate a payment or top-up, the minimum necessary transaction data is shared with the relevant partner for the sole purpose of processing that payment.
All payment partners operate under binding data processing agreements and are required to maintain security standards equivalent to or exceeding our own. We do not share your data with payment partners for their independent marketing or advertising purposes.
5. Fraud Prevention
To protect you and the integrity of our platform, we analyse account and transaction activity for indicators of fraudulent behaviour, unauthorised access, or financial crime. This analysis may involve:
- Transaction patterns and amounts
- Device identifiers and operating system information
- Account activity timestamps
- Failed login or authentication attempts
If suspicious activity is detected, we may place a temporary hold on your account, request re-verification, or contact you directly. We may disclose relevant information to law enforcement or financial intelligence authorities when required by law or court order.
6. Security
All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher. Sensitive data stored on our servers is encrypted at rest using AES-256 encryption.
Your account is protected by password authentication and optionally by a device PIN or biometric lock (Face ID / Touch ID). Biometric templates and PIN codes are stored exclusively on your device using the operating system's secure enclave — they are never transmitted to or stored on our servers.
In the event of a security incident affecting your personal data, we will notify you within the timeframe required by applicable law.
7. Data Retention
We retain your personal data for as long as your account remains active and for up to seven years after permanent account closure, as required by Algerian financial regulations and international AML standards.
Non-mandatory data (such as optional profile information or marketing preferences) is deleted within 90 days of your request. After the applicable retention period, all personal data is securely and irreversibly deleted or anonymised so that it can no longer be attributed to you.
8. Your Rights
Subject to applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete information
- Erasure — request deletion of data we are not legally required to retain
- Restriction — request that we limit how we process your data in certain circumstances
- Portability — receive your data in a structured, commonly used format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for any processing activity based solely on your consent
To exercise any of these rights, email us at founder@raoufi.app. We will acknowledge your request within 72 hours and provide a substantive response within 30 days.