Who controls your information
The organisation responsible for deciding why and how information is used.
For personal information collected through this website, GoodPrice GH is the data controller unless another organisation is clearly identified as independently responsible for its own processing.
Payment gateways, mobile-network operators and certain other providers may also act as independent controllers for information they receive directly or process under their own legal and regulatory duties.
Information we collect
Data needed to provide, protect and support the service.
| Category | Examples | Why it is needed |
|---|---|---|
| Order information | Order reference, selected network, package, quantity, price, currency, status and timestamps. | To create, fulfil, reconcile and track a purchase. |
| Contact information | Customer phone number, optional email address and customer name where name collection is enabled. | To provide receipts, updates, support and identity checks. |
| Beneficiary information | The mobile number intended to receive the data bundle and its selected network. | To verify and deliver the selected bundle to the intended number. |
| Payment information | Gateway name, merchant reference, gateway transaction reference, amount, currency and payment status. | To initialise, verify, reconcile and investigate payments. |
| Verification information | Phone-verification status, provider reference and limited provider response messages. | To reduce wrong-network and invalid number submissions. |
| Support information | Messages, complaint details, screenshots or supporting evidence you choose to provide. | To investigate and resolve an order, payment or privacy request. |
| Security and technical data | Hashed IP address, hashed browser identifier, request timestamps, rate-limit records and security event logs. | To prevent fraud, abuse, duplicate submissions and unauthorised access. |
How information is collected
Directly from you and from the services needed to complete an order.
We collect information when you select a package, submit guest-checkout details, pay, track an order, contact support or otherwise interact with the website.
We may also receive transaction or delivery information from payment gateways, verification providers, messaging providers, fulfilment partners and mobile-network-related services involved in your order.
Technical security information is generated automatically when the website receives a request. Where practical, direct identifiers such as IP addresses and user-agent values are converted into hashes before being stored in application logs.
How we use personal information
The specific purposes for which data is processed.
We may use personal information to:
- validate guest-checkout information and create an order;
- verify the beneficiary number and selected network where verification is enabled;
- initialise payment and confirm payment directly with the gateway;
- send the order to a fulfilment provider and monitor its status;
- send transactional SMS, email or WhatsApp communications connected to an order;
- provide secure guest order tracking;
- investigate delays, duplicate payments, delivery disputes, failed orders and refunds;
- detect fraud, abuse, unauthorised access and attempts to manipulate prices or callbacks;
- maintain accounting, audit, security and operational records;
- comply with legal, regulatory or lawful enforcement requirements; and
- establish, exercise or defend legal claims.
We do not use order contact details for unrelated direct marketing unless a separate lawful choice and any required consent are provided.
Why processing is permitted
The justification for using personal information.
Depending on the activity, we process personal information because it is necessary to take steps at your request and perform the purchase contract, comply with legal duties, pursue legitimate business and security interests, protect a person’s vital interests, or because you have given consent where consent is the appropriate basis.
Our legitimate interests include preventing fraud, securing the website, reconciling payments, maintaining reliable records, resolving complaints and improving the operational reliability of the service. We seek to balance those interests against the rights and reasonable expectations of affected individuals.
Where processing depends on consent, you may withdraw that consent. Withdrawal does not make earlier lawful processing unlawful and may not prevent processing that is required under another lawful justification.
Who may receive information
Service providers and authorities that need limited data for a defined purpose.
We may disclose the minimum information reasonably necessary to:
- payment gateways for transaction initialisation, authentication, verification and reconciliation;
- phone-verification providers for checking a beneficiary number;
- fulfilment providers and mobile-network-related services for delivery and status updates;
- SMS, email and communications providers for transactional messages;
- hosting, database, security and technical service providers that support the website;
- professional advisers, auditors or insurers where reasonably necessary; and
- regulators, courts, law-enforcement bodies or other persons where disclosure is required or permitted by law.
Providers acting on our instructions are expected to use personal information only for the agreed service and apply appropriate confidentiality and security safeguards. Independent providers may process information under their own privacy policies and legal obligations.
Payments and phone verification
Data handled by payment and verification providers.
The selected payment gateway may collect information directly from you on its hosted payment interface. This may include a mobile-money number, card details, authentication information or other details required by the gateway. We do not receive or store your mobile-money PIN, card PIN or one-time password.
We receive and store transaction references, payment status, verified amount, currency and limited gateway response information needed for reconciliation, audit and dispute resolution.
Where phone verification is enabled, the beneficiary number and required API credentials are transmitted securely to the configured verification provider. We retain the outcome, provider reference and limited response information needed to explain whether checkout was approved, rejected or unavailable.
Cookies and technical data
Browser storage and server-generated security information.
The public guest-purchase pages are designed to operate without a customer account. Essential technical cookies or similar storage may still be used where required for security, session management, fraud prevention, administrator access or the correct operation of a provider integration.
At the date of this policy, we do not describe the website as using advertising cookies for personalised advertising. If analytics, advertising or other non-essential cookies are introduced, this policy and any required consent controls should be updated before those tools are activated.
Server logs and security controls may process technical information such as request time, browser type, device information, referring page and network address. Application-level IP and user-agent identifiers are hashed where the system has been designed to do so.
How long information is kept
Retention based on purpose, law and operational need.
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for related accounting, tax, payment reconciliation, fraud prevention, security, dispute, legal and regulatory requirements.
Different records may have different retention periods. For example, an order and verified payment record may need to be kept longer than a temporary rate-limit record or unsuccessful technical log. A record may also be retained while a complaint, refund, investigation or legal claim remains open.
When information is no longer reasonably required, we aim to delete it, anonymise it or restrict its use, subject to technical backup cycles and lawful retention duties.
Security safeguards
Measures used to reduce unauthorised access, alteration and disclosure.
We use administrative, technical and organisational safeguards appropriate to the nature of the information and the risks involved. These may include:
- HTTPS encryption for information transmitted between the browser and website;
- private server-side storage for database and integration credentials;
- encryption of sensitive stored API keys;
- administrator authentication and access controls;
- prepared database queries and server-side validation;
- exact gateway-reference, amount and currency verification;
- webhook-signature validation where supported;
- rate limits, idempotency controls, audit logs and database locking;
- hashed security identifiers where practical; and
- restricted access to information based on operational need.
No website, network or storage system can be guaranteed to be completely secure. You should protect your device, order reference and payment account, and report suspected unauthorised use promptly.
International processing
Providers or infrastructure located outside Ghana.
Some technology, hosting, payment, verification or communications providers may process information using infrastructure located outside Ghana.
Where personal information is transferred or accessed internationally, we seek to use providers and arrangements that offer appropriate confidentiality, security and lawful protection having regard to the nature of the service and applicable data-protection requirements.
Your privacy rights
Requests available under applicable data-protection law.
Subject to applicable law, verification of identity and any lawful exceptions, you may have the following rights:
To protect customers, we may ask for information reasonably necessary to verify that the requester is the person connected to the relevant data. A request may be restricted or refused where the law permits or requires it, including where disclosure would adversely affect another person’s rights.
Automated checks and decisions
Verification, fraud protection and checkout controls.
The website uses automated rules to validate input, apply rate limits, prevent duplicate submissions, check phone-verification results and compare gateway references, amounts and currencies.
These controls may stop or delay checkout, payment confirmation or order processing where information is invalid, inconsistent, unavailable or requires review. Where an automated outcome significantly affects you, contact support with the order reference to request an appropriate manual review.
Children and minors
Use of the service by persons who cannot contract independently.
The service is intended for persons who can lawfully enter into a purchase contract. A minor or another person who cannot contract independently should use the service only with the involvement and permission of a parent, guardian or legally authorised representative.
Contact us if you believe personal information was provided by or about a child without appropriate authority so that we can review and take suitable action.
Security incidents
How suspected compromises are handled.
We investigate suspected unauthorised access, disclosure, alteration, loss or destruction of personal information. Where required, we will take reasonable containment and remediation steps and make notifications to affected individuals, the Data Protection Commission or other authorities in accordance with applicable law.
Report a suspected privacy or security incident promptly using the contact information below. Do not include your mobile-money PIN, card PIN or one-time password in the report.
Changes to this policy
Updates when data practices or legal duties change.
We may update this policy when the website, providers, information collected, security controls, retention practices or legal obligations change. The “Last updated” date identifies the currently published version.
Where a change is material, we may provide an additional notice on the website or through an appropriate communication channel.
Contact and complaints
Privacy requests, corrections and concerns.
Contact GoodPrice GH to ask a privacy question, request access or correction, object to processing, report a concern or request manual review of an automated outcome.
Include enough information to identify the relevant order or record, but do not send a mobile-money PIN, card PIN, one-time password or complete payment credentials.
You may raise an unresolved data-protection concern with the Ghana Data Protection Commission using its official complaint channels.