Legal
Privacy Policy
Last updated: 13 August 2026
ecash is a payment service provider licensed by the Central Bank of Syria under Resolution No. 844. This policy explains what personal and transaction data we collect, how it is processed and protected, where it is stored, and the rights available to you.
1. Data we collect
- Identity and contact data: name, business name, national or commercial registration identifiers, phone number, email, and address.
- Merchant onboarding data: licence documents, bank account details, beneficial ownership, and compliance screening results.
- Transaction data: amount, currency, timestamp, acquiring and issuing institution, tokenized card reference, terminal or channel, and authorisation result.
- Technical data: IP address, device and browser type, session identifiers, and security event logs.
2. Why we process it
- To authorise, clear, settle, and reconcile payments across connected banks.
- To meet legal obligations under Anti-Money Laundering, Banking Secrecy, and Central Bank reporting requirements.
- To detect and prevent fraud, abuse, and unauthorised access.
- To provide merchant support, statements, and service communications.
3. Data storage and sovereignty
Customer data is processed within Syria in compliance with Central Bank Resolution No. 844. Disaster recovery infrastructure is geographically distributed within national borders.
We do not transfer customer transaction data outside Syria except where a cross-border card scheme authorisation strictly requires it, and then only the minimum data set required to complete the transaction.
4. Security and encryption
- Transport encryption using TLS 1.2 or higher on every public endpoint.
- Encryption at rest using AES-256 for stored payment and identity data.
- Card data is tokenized by default; full card numbers are never stored in merchant-facing systems.
- Role-based access control, least-privilege administration, and a full immutable audit trail on privileged actions.
5. Cookies
We use strictly necessary cookies for session security, language preference, and fraud prevention. These are required for the service to function.
Analytics and preference cookies that are not strictly necessary are blocked until you accept them in the cookie banner. You can change your choice at any time by clearing site data in your browser.
6. Retention
Transaction and compliance records are retained for the period required by Syrian financial regulation, and are then securely destroyed or irreversibly anonymised.
7. Your rights
These rights are provided under the Syrian Electronic Transactions Law and related regulations. Requests are answered within 30 days.
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure where no legal or regulatory retention obligation applies.
- Object to or restrict processing that is not required by law or contract.
- Withdraw consent for non-essential cookies and marketing communications.
8. Third parties
We share data only with connected banks, card schemes, regulators, and vetted service providers acting under contract. We never sell personal data.
9. Contact
Data protection enquiries: privacy@ecash-pay.com — ecash, Vektoria, Opposite the Mail, Damascus, Syria.