This policy explains what information MartX collects when you create an account, activate your wallet, buy or sell gift cards, purchase an eSIM, convert stablecoin to local currency, or use any other MartX service, and the choices you have. By using MartX, you agree to the practices described here.
Information we collect
We collect the details you provide directly and data generated as you use MartX:
- Account details, name, email address, phone number, and authentication data when you sign in with Google or create a MartX account.
- Identity verification data, when required to activate wallet features, we and our identity verification partner process a live selfie and government ID information to confirm your identity. We do not store the underlying biometric images ourselves; they are held by our verification partner under its own data protection standards.
- Transaction data, wallet funding and withdrawals, gift card and eSIM purchases, prepaid card activity, stablecoin conversions, referral and payout history, and order records.
- Payment data, processed by our regulated payment partners. We do not store full card numbers, card verification codes, or complete bank account credentials on our own servers.
- Usage and device data, pages viewed, app interactions, IP address, browser type, device identifiers, and approximate location inferred from your IP address.
- Communications, messages you send our support team, and your preferences for marketing and service communications.
How we use your information
We use your data to operate MartX safely and reliably: to create and secure your account, process and deliver orders, activate and manage your wallet, verify your identity where required by law or by our payment partners, calculate and pay referral commissions, detect and prevent fraud and abuse, provide customer support, personalize what you see, and send service updates and, where you have not opted out, product updates.
Identity verification and compliance
Certain features, including wallet activation, higher-value transactions, and stablecoin conversion, require identity verification under applicable anti-money-laundering (AML) and know-your-customer (KYC) obligations. This is performed through a licensed identity verification partner, which checks your identity against government records and screens for sanctions, politically exposed person status, and adverse media. We retain verification outcomes as required by applicable financial regulation, even if you later close your account.
Payments and financial data
Different payment rails handle different parts of your MartX experience, each under its own regulated security standards:
- Naira wallet funding and withdrawals are processed by our licensed payment infrastructure partner and settle through a dedicated virtual bank account issued in your name.
- Global card payments are processed by a PCI-DSS compliant payment processor. Your card details are transmitted directly to the processor and never touch MartX's own servers.
- Cryptocurrency and stablecoin payments are processed by a regulated crypto payment partner. Wallet addresses and transaction hashes are recorded for compliance and support purposes.
Data encryption and security
Protecting your data is treated as a first-class requirement, not an afterthought:
- Encryption in transit, all data moving between your device and MartX, and between MartX and its infrastructure and payment partners, is encrypted using TLS.
- Encryption at rest, your account and transaction data is stored using industry-standard encryption (AES-256) at the database and storage layer.
- Access controls, internal access to production data is restricted to authorized personnel on a least-privilege basis, and sensitive administrative actions are logged.
- Secrets and credentials, API keys and service credentials used to connect to payment and identity partners are stored in encrypted, access-controlled environment configuration, never in application code.
- Payment isolation, MartX never stores full card numbers or card security codes; that data is handled exclusively within our PCI-DSS compliant payment processors' own secure environments.
- Continuous review, we review access permissions and security configuration on an ongoing basis as MartX grows.
Where your data is stored
MartX's primary databases and application infrastructure are hosted with cloud infrastructure providers operating data centers located in the United States. Customer account, transaction, and order data is stored and processed in the United States as part of this infrastructure. Where MartX works with regional payment, identity verification, or delivery partners outside the United States to serve customers in specific countries, limited data necessary to complete that transaction, such as your name, contact details, and payment reference, may be transferred to and processed by that partner in the relevant country, under contractual data protection obligations consistent with this policy.
How we share data
We do not sell your personal data. Information is shared only as necessary to operate MartX, and only with:
- Payment processors, to fund, charge, withdraw, or convert value on your behalf.
- Identity verification partners, to confirm your identity and screen for compliance purposes where required.
- Infrastructure and cloud hosting providers, who store and process data on our behalf under contract and are not permitted to use it for their own purposes.
- eSIM, gift card, and delivery partners, limited to what is needed to fulfil your specific order.
- Referral program participants, only the minimum information needed to attribute and pay a commission, your identity as a purchaser is never shared with the referring user.
- Authorities and regulators, when required by law, legal process, or to protect the rights, safety, and property of MartX, our users, or the public.
Data retention
We retain your account and transaction data for as long as your account is active, and afterward for as long as necessary to meet legal, tax, accounting, and anti-money-laundering record-keeping obligations, which can require retention of identity verification and transaction records for a minimum of five years after an account closes or a transaction completes, or longer where applicable law requires. Data no longer needed for these purposes is deleted or anonymized.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, restrict or object to certain processing, and withdraw consent where processing is based on consent. You can manage notification preferences directly in your account settings, or contact us to exercise any of these rights. Deletion requests are honored except where we are legally required to retain specific records, such as identity verification and transaction data subject to financial regulation.
Cookies and tracking
We use cookies and similar technologies to keep you signed in, remember your preferences, understand how MartX is used, and measure performance. Some cookies are essential to core functionality, such as authentication, and cannot be disabled without affecting your ability to use MartX. You can control non-essential cookies through your browser settings.
Children's privacy
MartX is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.
Data breach notification
In the event of a data security incident that affects your personal data, we will notify affected users and, where required by applicable law, relevant regulators without undue delay, and provide information about the nature of the incident and the steps we are taking in response.
Changes to this policy
We may update this policy as MartX evolves. Material changes will be highlighted in the app or by email, and the “last updated” date above will always reflect the current version. Continued use of MartX after a change takes effect constitutes acceptance of the revised policy.
Reach our data protection team any time, we typically respond within 48 hours.
✉ support@martx.io