Privacy Policy
Effective date: 19 July 2026
Last updated: 19 July 2026
This Privacy Policy explains how APK Digital Exchange LLC, trading as ApkXchange ("ApkXchange", "we", "us" or "our"), collects, uses, stores and shares personal data when you use our website, mobile application, customer support, trade chat, wallet, gift-card marketplace, payout and bill-payment services (together, the "Services").
This Policy should be read with our Terms and Conditions, Refund Policy and Cookie Policy.
1. Who Controls Your Personal Data
APK Digital Exchange LLC is responsible for the personal data described in this Policy unless a payment, identity-verification, communications or other partner explains that it acts as a separate controller.
Privacy questions and requests may be sent to support@apkxchange.com with the subject Privacy Request. To protect your account, we may need to verify your identity before acting on a request.
2. Scope and Regional Application
This Policy applies to personal data processed through the Services. Some rights described below apply only when the relevant law covers our processing.
Selecting a display or transaction currency—such as GHS, NGN, USD, GBP, EUR, CAD or AUD—does not, by itself, determine your country, residence, governing law or privacy rights. Applicable mandatory rights depend on factors such as where you live, where the Services are offered to you, and where the processing takes place.
3. Personal Data We Collect
Depending on how you use ApkXchange, we may collect:
- Account and contact data: name, email address, phone number, country, username, account identifiers, password credentials in protected form, profile image or chosen avatar, and communication preferences.
- Identity and compliance data: date of birth or age confirmation, identity-document images, selfie or likeness, document number, verification result, payout-account ownership information, sanctions or fraud-screening results, and information required for know-your-customer, anti-money-laundering or legal checks.
- Order and transaction data: products viewed or ordered, gift-card type, value and region, buy or sell order details, rates, fees, currency, wallet entries, biller and customer reference, payout destination, payment status, delivery status, refunds, disputes and transaction references.
- Payment data: payment method, provider, transaction token or reference, billing details and confirmation status. Card or Mobile Money providers may collect payment credentials directly. We do not state that we store full card numbers unless the relevant checkout expressly tells you otherwise.
- Gift-card and delivery data: card images or codes submitted for a sell trade, proof of ownership, code-delivery records, reveal status, product restrictions and evidence used to investigate a faulty or disputed code.
- Communications: trade-chat messages, uploaded images and files, support requests, notification content, delivery/read status and call or correspondence records where permitted.
- Device, log and security data: IP address, browser and device type, operating system, app version, language, timestamps, pages or screens used, session identifiers, cookie identifiers, error logs, authentication events and suspected-abuse signals.
- Preference and marketing data: saved settings, language, consent choices and whether you opened or interacted with a permitted service message.
Please do not send identity documents, payment credentials, gift-card codes or other sensitive information through an unapproved channel.
4. How We Collect Data
We collect data:
- directly from you when you register, verify an account, update a profile, place an order, submit a card, use chat, request a payout, pay a bill or contact support;
- automatically from your device and use of the Services;
- from payment, identity, communications, fraud-prevention, blockchain, bill-payment and payout providers;
- from an administrator or support agent handling your transaction; and
- from public or lawful sources where necessary for security, sanctions, fraud or legal checks.
5. Why We Use Personal Data
We use personal data to:
- create, authenticate and secure accounts;
- display products, calculate rates and fees, process buy and sell orders, deliver codes, credit wallets, make supported payouts and fulfil bill payments;
- verify identity, payout-account ownership and transaction legitimacy;
- operate trade chat, notifications, read receipts, receipts and transaction history;
- provide customer support and investigate failed, duplicate, unauthorised, defective or disputed transactions;
- prevent fraud, account takeover, money laundering, sanctions violations and other misuse;
- maintain, debug, analyse and improve the Services;
- keep accounting, tax, compliance and audit records;
- send service, security, legal and transaction communications; and
- send marketing only where permitted and subject to available opt-out rights.
Where a law requires a legal basis, we rely on one or more of the following: performance of a contract, steps requested before a contract, compliance with law, our legitimate interests (including security, fraud prevention and service improvement), protection of vital interests, or consent. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
6. Automated Checks
We may use rules or risk signals to flag an order, account, payout or message for review. These checks may delay, restrict or refer a transaction to a human administrator. We do not intend to make a solely automated decision that produces legal or similarly significant effects where applicable law prohibits it without appropriate notice, safeguards or human review.
7. When We Share Personal Data
We may share the minimum data reasonably necessary with:
- payment, card, bank, Mobile Money, wallet, USDT, payout and bill-payment providers;
- identity-verification, fraud-prevention, security, cloud-hosting, email, SMS, chat, analytics and customer-support vendors;
- product suppliers and fulfilment partners needed to deliver or validate an order;
- professional advisers, auditors, insurers, investors or transaction counterparties subject to appropriate confidentiality;
- regulators, courts, law-enforcement bodies or other persons where disclosure is required or lawfully requested; and
- a buyer, successor or affiliate in a merger, financing, reorganisation or sale, subject to applicable safeguards.
Third parties may process data under their own privacy notices. ApkXchange is not responsible for an independent provider's privacy practices, but we aim to use providers appropriate to the service and information involved.
We do not sell personal data for money. If a regional law treats certain advertising or analytics disclosures as a "sale" or "sharing", we will provide the notices and choices that law requires when such processing is used.
8. International Data Transfers
Our providers and users may be located in different countries. When personal data is transferred across borders, we use safeguards required by applicable law, which may include contractual protections, adequacy decisions, transfer-risk assessments or another lawful mechanism. Laws in the destination country may differ from those where you live.
9. Data Retention
We keep personal data only as long as reasonably needed for the purposes described above, including to complete transactions, maintain security, meet accounting, tax, anti-money-laundering and recordkeeping duties, resolve disputes and enforce agreements.
Retention depends on the data and context. Account preferences may be deleted or anonymised after closure when no longer needed. Transaction, wallet, payment, identity-verification and dispute records may be retained longer where law, a regulator, a payment provider or the defence of legal claims requires it. Gift-card images and chat attachments are restricted and deleted or anonymised when no longer required for fulfilment, fraud review, support or legal records.
Deletion of an account does not require deletion of data that we must or are lawfully entitled to retain. When retention ends, we delete, anonymise or securely isolate the data.
10. Security
We use administrative, technical and physical measures designed to protect personal data, including access controls, authentication, logging, encryption in transit where supported, restricted administrative access and security monitoring. No service or transmission method is completely secure.
You are responsible for using a strong password and wallet PIN, protecting your device and verification codes, checking recipient and network details, and telling us promptly about suspected unauthorised access. ApkXchange staff should not ask you to disclose your password or full wallet PIN in chat.
11. Your Choices and Rights
Subject to applicable law and exemptions, you may have the right to:
- request access to or a copy of personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to certain processing;
- withdraw consent;
- receive certain data in a portable format;
- opt out of direct marketing or certain targeted advertising; and
- complain to a privacy regulator.
You may update some profile information in Settings. For other requests, email support@apkxchange.com. We may ask for information needed to verify your identity and scope the request. We will not discriminate against you for exercising a right protected by law.
12. Regional Privacy Information
Ghana
Where Ghana's Data Protection Act, 2012 (Act 843) applies, we process personal data in accordance with applicable data-protection principles and recognise rights available under that Act. You may raise a concern with the Data Protection Commission of Ghana.
Nigeria
Where the Nigeria Data Protection Act 2023 applies, eligible data subjects may exercise the rights and complaint routes provided by that Act and the Nigeria Data Protection Commission.
European Economic Area and United Kingdom
Where the EU General Data Protection Regulation or UK data-protection law applies, the legal bases in Section 5 apply. Eligible persons may also complain to the competent supervisory authority and may have rights to restriction, objection, portability and safeguards for international transfers.
Canada, Australia and Japan
Where applicable, we handle personal data consistently with relevant requirements under Canada's private-sector privacy law, Australia's Privacy Act and Australian Privacy Principles, and Japan's Act on the Protection of Personal Information. The exact rights and exceptions depend on whether the law covers ApkXchange and the processing concerned.
California and Other United States Privacy Laws
If a United States state privacy law applies to ApkXchange and you, we will provide the access, correction, deletion, opt-out, appeal and non-discrimination rights that law requires. The California Consumer Privacy Act applies only when its statutory scope and thresholds are met; this Policy does not claim that every regional statute applies to every user or transaction.
13. Cookies and Similar Technologies
We use cookies and similar storage for authentication, security, preferences and other purposes described in our Cookie Policy. Non-essential technologies will be subject to consent where required.
14. Children's Privacy
The Services are not intended for anyone under 18, or under the age of legal majority required to enter these transactions where they live. We do not knowingly offer accounts to children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
15. Third-Party Links
The Services may link to providers, billers, product issuers, block explorers or other third parties. Their services and privacy notices are separate from ours. Review them before providing information.
16. Changes to This Policy
We may update this Policy to reflect changes in law, providers or Services. We will post the revised version and update the date above. If a change materially affects your rights, we will provide additional notice where required.
17. Contact and Complaints
Email support@apkxchange.com with the subject Privacy Request or Privacy Complaint. Include enough detail for us to identify the issue, but do not email passwords, wallet PINs, full card credentials or unredacted gift-card codes.
If you are not satisfied with our response, you may complain to the privacy authority available under the law that applies to you.