Privacy Policy

AbaPay Global Web3 Protocol

Effective Date: April 2026

1. Introduction & Global Data Controller

MASONODE TECHNOLOGIES LIMITED ("we", "us", or "our"), the operator of the AbaPay decentralized application, is committed to protecting your personal data across all jurisdictions we serve.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use AbaPay to bridge digital assets with domestic and international utility services. As a company headquartered in Nigeria, we operate in strict compliance with the Nigeria Data Protection Act (NDPA) 2023, while extending globally recognized privacy principles (such as GDPR) to protect our international users.

2. The Data We Collect

To provide you with seamless borderless utility vending, we must collect specific data points. We classify this into two categories:

A. On-Chain & Web3 Data

  • Public Wallet Addresses: We collect your Celo/EVM public wallet address to facilitate stablecoin escrow and transaction tracking.
  • Transaction Hashes: Public blockchain metadata confirming your payment.
  • Strict Self-Custody Guarantee: AbaPay NEVER collects, stores, or requests access to your private keys, seed phrases, or wallet passwords.

B. Utility & Fiat Data

  • Utility Identifiers: Local and international phone numbers, Smartcard numbers, Meter numbers, and Bank Account numbers you provide for vending.
  • Verified KYC Data: When you verify an account, our API may retrieve the associated Customer Name, physical meter address, and Account Type from the relevant national or international grid/banking network to ensure you are paying the correct bill.
  • Contact Information: Email addresses optionally provided for transaction receipts or support tickets.

3. How We Use Your Data

We strictly use your data for the following purposes:

  • Service Execution: To route your payment accurately to the specified domestic or international DisCo, Telco, or Bank.
  • Transaction History: To maintain an encrypted ledger so you can track your past cross-border payments and request refunds if a network fails.
  • Fraud Prevention & AML: To monitor for duplicate transactions, prevent API abuse, and comply with global Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) directives.

4. Third-Party & Cross-Border Data Sharing

AbaPay is a global aggregator interface. To successfully vend your utility, we must securely share your Utility Identifiers (Phone/Meter numbers) with licensed domestic and international third parties.

  • Utility Aggregators: We share necessary vending data with our API partners (e.g., VTpass Global) strictly for the purpose of executing your transaction across borders.
  • Blockchain Networks: Your public wallet address and transaction amount are permanently broadcasted to the public, immutable Celo blockchain.
  • Law Enforcement: If compelled by a valid subpoena or directive from relevant local or international law enforcement (e.g., EFCC, SEC, or FATF-aligned agencies), we may disclose metadata to prevent cross-border financial crimes.

5. Data Security & Retention

Your transaction metadata and utility identifiers are stored securely on encrypted cloud servers. We implement strict access controls and API rate limiting to protect our database from unauthorized access, regardless of your geographical location.

Retention: We retain your transaction history for a minimum of five (5) years as required by international financial compliance regulations, after which it may be anonymized or securely deleted.

6. Your Privacy Rights & Data Deletion

Under the NDPA 2023 and equivalent global privacy laws, you possess the right to access, rectify, and request the erasure of your personal data.

Account & Data Deletion Request: If you wish to permanently delete your transaction history and associated utility data from the AbaPay servers, you may submit a formal Data Deletion Request.

To request deletion, please email privacy@abapay.com with your connected Wallet Address. We will process your deletion request within 30 days, subject to mandatory global AML retention laws.

7. Contact Our Data Protection Officer (DPO)

If you have any questions, complaints, or require clarification regarding how MASONODE TECHNOLOGIES LIMITED handles your international data, please contact our support team and Data Protection Officer at: