ePay Reach
Back to home

Privacy Policy

How ePay Reach collects, uses and protects personal information across the agent and merchant acquisition network.

Last updated: January 1, 2026

1. Who we are

ePay Reach is a merchant-acquisition and field-force platform operated by ePay ("ePay", "we", "us"), based in Ethiopia. This Privacy Policy explains what personal information we collect, how we use it, and who we share it with when you use the ePay Reach mobile app and web dashboard (together, the "Service").

The Service is used by field agents and staff to recruit and onboard merchants onto the ePay payment network, track field activity, and manage commissions.

Questions about this Policy or your data can be sent to info@digicom.et.

2. Information we collect

We collect the following categories of information:

  • Account & identity: your name and phone number. Phone number is your primary login identifier and receives one-time passcodes (OTPs) by SMS. For agent applications we may also collect a selfie photo and Fayda national-ID verification data.
  • Device & session: a device fingerprint (a unique identifier generated on your device), device model and OS version, trusted-device status, and session records (login times, session issue/expiry and revocation). We also log the IP address and device associated with sensitive actions.
  • Location while on shift: when you check in to a shift, we collect your precise GPS location (latitude/longitude, accuracy, speed and device battery level), captured continuously in the foreground and background until you check out. We also capture a one-time GPS reading when you start a merchant registration.
  • Agent network data: your agent code, tier, status, sponsor/hierarchy relationships and assigned territories.
  • Merchant & business data (submitted by agents): business name, TIN (tax ID), license and VAT numbers, business contact (phone, email, website), category, region/city, and the owner's name and phone. Agents also upload business documents such as TIN certificates, business/trade licenses and owner identification.
  • Commissions & payouts: commission and payout records tied to your agent account, including amounts, holds, clawback reasons and payout channel references.
  • Activity, monitoring & support: app activity and audit logs (who did what, and when), fraud and geofence-monitoring flags, and notifications we send you.

Stored only on your device (not collected by us): if you enable the biometric or PIN app-lock, your PIN is stored on your device as a salted hash and your biometric data is held by your device's operating system. Neither is ever sent to us.

3. How we use information

We use personal information to:

  • authenticate you (phone + OTP) and recognise your trusted devices;
  • onboard and verify merchants, including identity and document checks;
  • track field-force location while you are on shift, and run geofence and anti-fraud monitoring;
  • calculate and pay agent commissions and overrides, and manage holds and clawbacks;
  • provide support and send you notifications;
  • secure the Service and meet legal, tax and regulatory obligations.

4. Location tracking

Location tracking runs only while you are checked in to a shift. When you check in, the app captures your GPS position at regular intervals (in both foreground and background) and sends it to us in batches. On Android a persistent notification is shown while tracking is active; on iOS background location is used during the shift. You consent to tracking when you check in, and it stops when you check out.

We use this location data to show live and historical field coverage to supervisors, to detect when an agent leaves an assigned territory (geofence monitoring), and to help prevent fraud (for example, location on merchant registrations). Location history is retained for a period of 90 days and then deleted.

5. How we share information

We share information with the following third parties:

  • ePay Core / payment-gateway partner: when a merchant is registered, we forward business and compliance details (name, TIN, license, VAT, contact, category, region/city, staff size, owner email) together with your agent code for attribution, so the merchant can be activated on the payment network.
  • Fayda (national identity verification): identity verification is performed through Fayda (Ethiopia's national ID service) via our gateway partner. We initiate a verification session and receive back the verification result; we do not store the raw national ID number.
  • Ethio Telecom object storage (OBS): uploaded business documents are stored in Ethio Telecom's OBS object storage via the partner. Documents are uploaded directly from your device to storage; we keep only references and metadata.
  • SMS provider: we send your phone number to an SMS gateway to deliver one-time passcodes and account notifications.
  • Map providers: map tiles are loaded from a mapping provider to display locations and coverage.
  • Approved B2B partners: approved business partners can query limited agent information through our scoped partner API, specifically an agent's ID, code, name, tier, status and recruitment permission. Phone numbers and sponsor-tree details are not exposed through this API.

We may also disclose information to authorities where required by law. We do not sell your personal information.

6. Data retention

We retain personal information for as long as necessary to provide the Service and to satisfy legal, tax, accounting and regulatory requirements, after which it is deleted or anonymised. Location history is kept for a configurable retention window; short-lived data such as OTP codes expire within minutes.

7. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal information, and object to or restrict certain processing. The app also lets you delete your account. To exercise these rights, contact us at info@digicom.et.

8. Security

We apply technical and organisational measures to protect personal information, including encryption in transit, role-based access controls, hashing of secrets such as session tokens and PINs, and one-time passcodes that expire after a short period. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Children

The Service is intended for authorised agents and staff who are 18 or older. It is not directed at children, and we do not knowingly collect personal information from anyone under 18.

10. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you through the Service.

11. Contact us

Questions about this Policy can be sent to info@digicom.et, or by post to ePay, Addis Ababa, Ethiopia.