Effective Date: August 14, 2026
<aside> 💡
This Privacy Policy explains how Broco Technologies, Inc. (“Broco,” “we,” “us” or “our”) collects, uses, shares and protects personal data when you use Broco's websites, mobile applications, accounts, business tools, dashboards, APIs and related financial, payment, cash, merchant and logistics services (the “Services”).
Broco's Terms of Service apply separately to your use of the Services. Certain services, including BrocoCash and services provided through regulated financial or other partners, may also be subject to separate country-specific terms, privacy notices or partner terms.
</aside>
Who is responsible for your data. Broco Technologies, Inc., 1111b S Governors Avenue Ste 96387, Dover, Delaware 19904, United States, is responsible for personal data where Broco determines why and how that data is processed. You may contact us at [email protected]. Certain regulated financial institutions, banks, BaaS providers, card issuers, payment providers, identity-verification providers and logistics partners may process personal data under their own legal responsibilities and privacy notices. This controller/processor distinction is consistent with current fintech and KYC-provider practice.
Personal data we collect. Depending on the Services you use, we may collect identity and verification information such as your name, date of birth, nationality, address, government identification documents, photographs, selfie/liveness or biometric-verification information, KYC/KYB information, source-of-funds information, business-registration information and beneficial-ownership information. Identity verification may be carried out by Sumsub, regulated financial partners or other authorized providers, and the information required may vary by service, country and risk profile. Sumsub documents automated identity-document verification and sanctions/PEP screening as part of its KYC processing.
We may also collect your phone number, email address, account and profile data; payment, wallet, remittance, cash-in/cash-out, merchant, card and transaction information; sender, recipient and beneficiary details; device identifiers, IP address, operating-system and application information; approximate or precise location where enabled or necessary for a feature; merchant, driver, agent, fleet, shipping, delivery, scan and cash-reconciliation information; support communications and complaints; and marketing, cookie and analytics information. Device information, IP addresses and online activity are also standard categories disclosed in current payment-platform privacy notices.
We obtain information directly from you, through your use of the Services, and from regulated financial partners, KYC providers, banks, payment providers, merchants, logistics providers, telecom or billing providers, business-account administrators, public sources and other parties involved in providing or protecting the Services.
How we use personal data. We use personal data to create and operate accounts; verify identity and businesses; support KYC, KYB, anti-money-laundering and sanctions requirements; provide payments, transfers, remittance, card and cash-in/cash-out services; facilitate merchant payments, shipping, delivery and cash-on-delivery reconciliation; authenticate users; provide customer support; investigate disputes; detect and prevent fraud, misuse and security incidents; comply with legal and regulatory requirements; maintain and improve the Services; communicate operational information; and send permitted marketing communications.
Where applicable data-protection law requires a legal basis, we rely as appropriate on performance of our contract with you, compliance with legal obligations, our legitimate interests or those of relevant third parties, and your consent. Consent is used only where appropriate and may be withdrawn where the law provides that right. These are recognized GDPR lawful bases, and processing based on legitimate interests must take account of individuals' rights and freedoms. Sensitive or biometric information is processed only where an additional lawful condition, consent or other authorization required by applicable law is available.
We and our partners may use automated systems to assist with identity verification, fraud prevention, transaction monitoring, sanctions screening and security. Where applicable law gives you rights in relation to a decision based solely on automated processing that has legal or similarly significant effects, those rights remain available to you. GDPR transparency rules specifically contemplate disclosure of relevant automated decision-making, and Sumsub describes automated document and screening processes in its KYC documentation.
How we share personal data. We may share personal data where necessary with regulated financial partners, banks and BaaS providers; card issuers and payment processors; KYC and identity-verification providers including Sumsub; cash-in/cash-out and agent-network partners; merchants, ecommerce and fulfillment providers; logistics companies, carriers, fleets and delivery partners; telecom operators and billers; cloud, communications, security and analytics providers; the business or organization you represent and its authorized account administrators; professional advisers; regulators, courts, law-enforcement bodies and government authorities; and other parties where you instruct or authorize us to share information.
These parties may act as service providers processing data for Broco, or may act as separate controllers under their own laws and privacy notices. Current fintech notices similarly distinguish financial partners, service providers and third parties whose own privacy policies govern their processing.
International transfers. Broco is based in the United States and provides cross-border services. Your personal data may therefore be processed in the United States, the European Economic Area, the United Kingdom, countries in which Broco offers Services, and countries in which our partners or providers operate. Where applicable law restricts international transfers, we use the mechanism required for the relevant transfer, which may include adequacy decisions, contractual safeguards such as Standard Contractual Clauses, equivalent contractual mechanisms, regulatory approvals or authorizations, consent where legally appropriate, or another lawful transfer mechanism. EU SCCs are an officially recognized mechanism for qualifying GDPR transfers, while individual African jurisdictions may impose their own transfer procedures.
How long we keep data. We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing your account and Services, meeting KYC/AML and other legal or partner requirements, maintaining transaction and accounting records, resolving complaints or disputes, preventing fraud and security abuse, and establishing or defending legal claims. Retention periods therefore differ by category of data, service, jurisdiction and regulatory requirement. Closing your Broco account does not necessarily mean that all information can immediately be deleted. This purpose- and law-based retention model is also used by established regulated fintechs.
Your rights and choices. Depending on where you live and the law applicable to the relevant processing, you may have the right to request access to your personal data; correct inaccurate or incomplete data; request deletion; restrict certain processing; object to processing, including certain processing based on legitimate interests; receive eligible data in a portable format; withdraw consent where processing relies on consent; and opt out of direct marketing. GDPR and UK GDPR frameworks recognize these categories of rights, although individual rights such as erasure are subject to exceptions.
To exercise a privacy right, contact [email protected]. We may verify your identity before completing a request. We may refuse or limit a request where permitted or required by law, including where information must be retained for financial-crime compliance, transaction records, fraud prevention, legal claims or the rights of another person. Where applicable, you may also complain to the data-protection authority responsible for your jurisdiction.
Security. We use technical and organizational measures designed to protect personal data against unauthorized access, misuse, alteration, loss or disclosure. These may include access controls, authentication, secure transmission, monitoring, security controls and restrictions on personnel and service-provider access appropriate to the relevant risk. No electronic storage or transmission system can be guaranteed to be completely secure. GDPR principles require appropriate technical and organizational security measures, and major fintech notices similarly describe access-control and organizational security programs.
Marketing. We may send information about Broco products, features or promotions where permitted by law. Where consent is required for a particular marketing channel, we will request it. You may opt out of marketing communications at any time, but we may continue to send necessary account, transaction, security, legal and service messages. UK guidance, for example, makes clear that where electronic-communications rules require consent, legitimate interests cannot replace that consent.
Age requirement. Broco Services are intended for people aged 18 or older. We do not knowingly open Broco accounts for children under 18.
Third-party services. The Services may link to or integrate services operated by banks, financial institutions, merchants, logistics providers or other third parties. Their collection and use of personal data may be governed by their own privacy notices and terms.