Privacy Policy

Last updated: January 11, 2025

1. Introduction

Harpoon Labs ("we", "us", or "our") operates Harpoon, a payment verification platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Harpoon, you consent to the data practices described in this policy. If you do not agree with our policies, please do not use our Service.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Phone number (required for account identification)
  • Email address (for account recovery and notifications)
  • Full name
  • Business name (optional)
  • Password (stored securely using industry-standard hashing)

SMS Data

To provide payment verification services, we access SMS messages on your registered device(s). We:

  • Only process SMS messages from known Mobile Money providers (MTN MoMo, Telecel Cash, AirtelTigo Money)
  • Do NOT read personal messages, social media notifications, or other non-payment SMS
  • Extract only transaction details: amount, sender/recipient, transaction ID, date/time, and reference codes
  • Encrypt all SMS data before transmission to our servers

Device Information

We collect information about devices registered with your account:

  • Device model and manufacturer
  • Operating system version
  • App version
  • Device identifiers (for security and fraud prevention)

Usage Data

We automatically collect certain information when you use our Service:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • API usage patterns
  • Error logs for troubleshooting

3. How We Use Your Information

We use the information we collect to:

  • Provide payment verification: Match incoming SMS to payment requests and notify you of verified payments
  • Maintain your account: Authenticate you and secure your account
  • Improve our Service: Analyze usage patterns to enhance features and fix bugs
  • Communicate with you: Send service updates, security alerts, and support messages
  • Prevent fraud: Detect and prevent unauthorized access or suspicious activity
  • Comply with legal obligations: Respond to legal requests and enforce our Terms

4. Data Storage and Security

We implement robust security measures to protect your data:

  • Encryption in transit: All data transmitted between your device and our servers uses TLS/SSL encryption
  • Encryption at rest: Sensitive data is encrypted in our databases
  • Password security: Passwords are hashed using Argon2id, a state-of-the-art algorithm
  • Access controls: Strict internal access policies limit who can view your data
  • Regular audits: We regularly review and update our security practices

While we take every precaution to protect your information, no method of transmission over the Internet or electronic storage is 100% secure.

5. Data Retention

We retain your data as follows:

  • Account data: Retained while your account is active
  • Transaction data: Retained based on your subscription tier (30-365 days)
  • Deleted accounts: Data is deleted within 90 days of account closure, except where retention is required by law

6. Data Sharing and Disclosure

We do NOT sell your personal information. We may share your data in the following circumstances:

  • Service providers: Third-party vendors who help us operate our Service (hosting, analytics, email delivery)
  • Legal requirements: When required by law, court order, or government request
  • Business transfers: In connection with a merger, acquisition, or sale of assets
  • With your consent: When you explicitly authorize us to share your information

7. Third-Party Services

We use the following third-party services that may collect data:

  • Cloud hosting: For storing and processing your data securely
  • Analytics: To understand how users interact with our Service
  • Email services: For sending transactional emails and notifications

These services have their own privacy policies governing their use of your data.

8. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal requirements)
  • Export: Request a portable copy of your data
  • Withdraw consent: Withdraw consent for data processing at any time

To exercise these rights, contact us at [email protected].

9. Cookies and Tracking

Our website uses cookies and similar technologies to:

  • Keep you signed in to your account
  • Remember your preferences
  • Analyze site traffic and usage

You can control cookies through your browser settings, though this may affect some features of our Service.

10. Children's Privacy

Our Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. International Data Transfers

Your data may be transferred to and processed in countries other than Ghana. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: [email protected]

By using Harpoon, you acknowledge that you have read and understood this Privacy Policy.