Privacy & Data Protection

Your trust is the core of MograPay. This page explains how we collect, use, protect, and respect your data across our orchestration and intelligence platform.

Our Privacy Commitment

MograPay is designed for financial institutions, fintechs, and payment innovators. We handle sensitive transaction data, logs, and analytics with strict controls, industry-standard security, and a privacy-first mindset. We never sell your personal data and we only process information necessary to deliver and improve our services.

Scope of this Privacy Notice

This Privacy Notice applies to the MograPay .NET Core Web Application and related services, including:

  • Web-based dashboards, simulators, and configuration tools for acquirers, issuers, and routing.
  • Transaction simulation environments for ISO 8583 and ISO 20022 messages.
  • Intelligence and analytics modules, including fraud scoring, behavioral analytics, and routing intelligence.

If you access MograPay through your organization (e.g., a bank, fintech, or processor), your organization may have its own privacy policies and agreements that work together with this notice.

Account & Profile Information

When you create or use an account on MograPay, we may collect:

  • Name, email address, organization, and role.
  • Authentication details (e.g., username, hashed passwords, identity provider IDs).
  • Preferences such as language, notification settings, and UI configuration.
Usage & Device Information

When you interact with the WebApp, we may automatically collect:

  • Browser type, operating system, and device identifiers.
  • IP address, approximate location (based on IP), and connection metadata.
  • Pages visited, actions performed, timestamps, and error logs.
Payment & Transaction Simulation Data

MograPay is a simulator and orchestration platform. Depending on configuration, we may process:

  • ISO 8583 and ISO 20022 message fields (e.g., PAN tokens, amounts, merchant IDs, timestamps).
  • Routing decisions, authorization outcomes, and issuer/acquirer responses.
  • Test data, synthetic datasets, and anonymized production-like data provided by your organization.

We encourage and support tokenization, anonymization, and masking of sensitive fields wherever possible. Your organization controls what data is sent into the platform.

Support & Communication Data

When you contact us or use in-app messaging, we may collect:

  • Email content, support tickets, and attachments you provide.
  • Notes from support interactions, troubleshooting steps, and resolutions.
  • Feedback, feature requests, and survey responses.
How We Use Your Data

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the MograPay WebApp and related services.
  • To authenticate users, manage access, and enforce security policies.
  • To simulate, route, and analyze payment transactions as configured by your organization.
  • To monitor performance, detect errors, and improve reliability.
  • To develop and refine fraud scoring, behavioral analytics, and routing intelligence models.
  • To respond to support requests and communicate about updates, security, and service changes.
  • To comply with legal, regulatory, and contractual obligations.
  • To generate aggregated, anonymized insights that do not identify individual users.

We do not use your personal data for unrelated marketing without your consent, and we do not sell your personal information.

Cookies & Similar Technologies

MograPay uses cookies and similar technologies to provide a secure and user-friendly experience:

  • Essential cookies: Required for login, session management, and core functionality.
  • Preference cookies: Store UI settings, language, and other personalization options.
  • Analytics cookies: Help us understand usage patterns and improve performance.

You can control cookies through your browser settings. Disabling essential cookies may impact your ability to use the WebApp.

Transaction Logs, Wire-Level Data & ISO Messages

A core feature of MograPay is detailed logging of simulated and orchestrated transactions, including:

  • Wire-level request and response messages for ISO 8583 and ISO 20022 flows.
  • Routing paths, decision points, and rule evaluations.
  • Replayable transaction histories for debugging, analysis, and audit trails.

These logs may contain sensitive fields depending on your configuration. We provide options to:

  • Mask or tokenize PANs and other cardholder data.
  • Restrict access to logs based on roles and permissions.
  • Configure retention periods and automated deletion policies.

Your organization is responsible for ensuring that data sent to MograPay complies with applicable data protection and payment security standards (e.g., PCI DSS).

Analytics, Fraud Scoring & Intelligence Layer

MograPay includes analytics and intelligence capabilities that may use transaction and behavioral data to:

  • Score transactions for potential fraud or anomalies.
  • Optimize routing decisions based on performance, cost, or risk.
  • Train and evaluate machine learning models using curated datasets.

Where possible, we use anonymized or pseudonymized data for model training and analytics. Access to raw datasets is restricted to authorized personnel and governed by strict controls.

We do not use analytics to make automated decisions that produce legal or similarly significant effects on individuals without appropriate safeguards and, where required, human review.

Data Sharing & Third Parties

We may share data with carefully selected third parties in the following situations:

  • Service providers: Cloud hosting, monitoring, logging, and support tools that help us operate the platform.
  • Integration partners: Optional connectors to external systems (e.g., data lakes, CRM, or fraud tools) configured by your organization.
  • Legal & compliance: When required by law or to protect our rights, users, or the public.

We require third parties to handle data in accordance with applicable privacy and security standards and only for the purposes we specify.

We do not sell your personal data to advertisers or data brokers.

Security Measures

We implement technical and organizational measures designed to protect your data against unauthorized access, loss, or misuse, including:

  • Encryption in transit (e.g., TLS) and, where applicable, encryption at rest.
  • Role-based access control, strong authentication, and audit logging.
  • Hardened infrastructure, regular updates, and security monitoring.
  • Policies, training, and procedures for staff handling sensitive information.

No system can be guaranteed 100% secure, but we continuously review and improve our controls to align with industry best practices.

Your Privacy Rights

Depending on your jurisdiction and relationship with MograPay, you may have rights such as:

  • Access: Request a copy of personal data we hold about you.
  • Correction: Ask us to correct inaccurate or incomplete information.
  • Deletion: Request deletion of certain data, subject to legal and contractual obligations.
  • Restriction & objection: Limit or object to certain types of processing.
  • Portability: Receive data in a structured, commonly used format where applicable.

If we process your data based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise your rights, please contact us using the details below. If you access MograPay through your employer or organization, we may redirect certain requests to them.

Data Retention

We retain data only for as long as necessary to fulfill the purposes described in this notice or as required by law, contract, or legitimate business needs. In particular:

  • Account and profile data are retained while your account is active and for a reasonable period thereafter.
  • Transaction logs and simulation data follow retention policies configured by your organization.
  • Aggregated, anonymized analytics may be retained for longer periods as they do not identify individuals.

When data is no longer needed, we may delete it, anonymize it, or securely archive it in accordance with our policies.

Children’s Privacy

MograPay is a professional platform intended for use by organizations and adult professionals in the financial and technology sectors. We do not knowingly collect personal data from children.

If you believe that a child has provided us with personal information, please contact us so we can investigate and take appropriate action.

Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our services, legal requirements, or best practices.

When we make material changes, we will provide appropriate notice, such as updating the date at the top of this page, sending in-app notifications, or emailing registered users.

Your continued use of MograPay after changes become effective indicates that you have read and understood the updated notice.

Contact & Data Protection Queries

If you have questions, concerns, or requests related to privacy or data protection, you can contact us at:

When you contact us, please include enough detail to help us understand your request (e.g., the environment you use, your organization, and any relevant context). We may need to verify your identity before fulfilling certain requests.

If you are located in a region with a data protection authority (e.g., EU/EEA), you also have the right to lodge a complaint with your local authority. We encourage you to contact us first so we can address your concerns directly.