lomi. logo

Privacy Policy

This Privacy Policy explains how lomi. Technologies Africa S.A. (lomi., we, us), registered office at Cocody, Les Perles, Rue 01012 L82/375, Abidjan, Côte d'Ivoire, collects, uses, shares and protects personal data when you visit lomi.africa, create or use a lomi. account, pay a business that uses lomi., or otherwise interact with us. It applies to the businesses that use our payment services and their representatives (Merchants), to the people who pay them (Customers), and to visitors of our websites and documentation.
We process personal data in accordance with Côte d'Ivoire Law No. 2013-450 of 19 June 2013 on the protection of personal data, the ECOWAS Supplementary Act on personal data protection, and, where it applies to a data subject, the EU General Data Protection Regulation (GDPR). This Policy is part of our Terms and Conditions. It is drafted in French; the English, Spanish and Chinese versions are convenience translations and the French version prevails in case of conflict.

1. Who we are and our roles

Controller or processor, depending on the data

lomi. is a payment processor. We provide payment collection, checkout, payment-link, subscription and disbursement services to Merchants through licensed partner banks, electronic-money issuers, card acquirers and mobile-money operators (Payment Channel Partners). We are not a party to the sale between a Merchant and its Customers. lomi. Technologies Africa S.A. has applied to the BCEAO for authorisation as a payment institution; the application is under review.
lomi. as controller. We decide how and why personal data is processed, and are therefore the controller, when we: verify the identity of Merchants, their owners and representatives (KYC and KYB); process payments, refunds, Chargebacks and Payouts; prevent and detect fraud; comply with anti-money-laundering, counter-terrorist-financing, sanctions, tax and Card Network obligations; operate and secure our websites, dashboard, API and support channels; and send our own communications. For Customer data needed to complete a payment (for example name, email, phone number, payment instrument and transaction details), we act as an independent controller alongside the Merchant.
lomi. as processor. When a Merchant configures our services to collect or store additional Customer data on its behalf (for example custom checkout fields, delivery addresses, customer notes or catalog data), we process that data as the Merchant's processor, only on its documented instructions. The Merchant is the controller of that data and is responsible for informing its Customers and for answering their requests; we assist it as described in our Terms.
Merchants' own obligations. Each Merchant is responsible for its own compliance with data-protection law in its relationship with its Customers, including telling them that payments are processed by lomi. and its Payment Channel Partners.

2. Personal data we collect

What we collect, from whom, and where it comes from

Personal data means any information that identifies, or could reasonably be used to identify, a natural person. Data that has been aggregated or anonymized so that it can no longer be associated with a person is not personal data. What we collect depends on how you interact with us.

2.1 Merchants and their representatives

  • Account and identity data: name, email address, phone number, role, login credentials, language and preferences.
  • Business verification (KYC and KYB): legal and trade name, registration number (such as RCCM), tax identification (such as NINEA or DFE), address, business description and websites, identity documents of owners, directors and signatories (including document number, date and place of birth, nationality and photograph), proof of address, beneficial-ownership information, bank account or mobile-money details for Payouts, and the results of sanctions, politically-exposed-person and registry checks.
  • Financial and transaction data: Balance, Payouts, Fees, invoices, refunds, Chargebacks, Reserves and Holds, and the transactions you process.
  • Usage and technical data: dashboard actions, API calls and keys, webhook endpoints, connected applications and AI agents authorized through OAuth, IP address, device and browser information, and security logs.
  • Communications: support requests, emails, WhatsApp or SMS messages, survey answers and feedback.
  • lomi. Pos and in-person payments: device model, operating-system version, app version, device integrity and attestation results and, where the Tap to Pay provider or the device platform requires it for fraud prevention, the approximate location of the device at the time of a transaction; staff user profiles and hashed PINs; and the in-person transactions you process.

2.2 Customers who pay a Merchant

  • Payment data: name, email address, phone number, mobile-money number, card details (processed through our PCI DSS compliant partners; we do not store full card numbers or CVV on our own systems), bank account or instant-payment identifiers, billing and, where the Merchant requests it, delivery address.
  • Transaction data: amount, currency, date, payment method, Merchant, product or service description, status, refunds and disputes.
  • Fraud and device data: IP address, device and browser fingerprint, approximate location derived from IP, authentication results (for example 3-D Secure or mobile-money confirmation) and risk signals from our Payment Channel Partners.
  • Additional data configured by the Merchant, which we process as the Merchant's processor.

2.3 Website and documentation visitors

Technical data such as IP address, browser and device type, pages viewed, referrer and approximate country, collected through essential cookies and our cookieless analytics (see Section 9), and any information you send us through a contact form, a newsletter sign-up or an email.

2.4 Sources

We receive personal data directly from you, from the Merchant you pay or work for, from our Payment Channel Partners (for example authorization results, dispute notices and account details), from identity-verification and fraud-prevention providers, from public registries (including a greffe, RCCM or NINEA records), from sanctions and PEP lists, and from your interactions with our websites, dashboard and API.

4. Automated decisions, fraud scoring and AI-assisted review

How automation is used and how you can contest it

We use automated tools to keep payments safe and to meet our compliance obligations: transaction risk scoring (including tools provided by our Payment Channel Partners such as Stripe Radar), velocity and pattern checks, sanctions and PEP screening, document authenticity checks, and AI-assisted review of onboarding files and support requests.
These tools may block or delay a payment, place a Hold or Reserve, or flag an account for review. In line with Article 25 of Law 2013-450 and Article 22 of the GDPR, no decision that produces legal effects or similarly significantly affects you (for example refusing an account, terminating a Merchant, or reporting to an authority) is based solely on automated processing: such decisions are reviewed by a trained member of our team, who considers the documents and explanations you provide.
You have the right to obtain meaningful information about the logic involved, to express your point of view, and to contest an automated decision by writing to hello@lomi.africa. We will review it and answer within thirty (30) days. We may not disclose details that would reveal a Payment Channel Partner's confidential risk criteria or compromise an investigation.

5. Who we share personal data with

Partners, service providers and authorities

We do not sell or rent personal data. We share it only as described here, under contracts that require recipients to protect it and to use it only for the stated purpose.
  • Payment Channel Partners needed to process your payment or Payout and to comply with their rules: card acquirers and card networks (including Stripe, Visa, Mastercard and GIM-UEMOA), partner banks and electronic-money issuers, mobile-money operators (for example Orange Money, MTN MoMo, Moov Money and Wave) and instant-payment schemes (PI-SPI). These partners are independent controllers for their own compliance and fraud-prevention processing, described in their own privacy policies.
  • Merchants: we share with the Merchant you pay the data needed to fulfil your order, manage refunds and disputes and reconcile its accounts.
  • Service providers (sub-processors) acting on our instructions, in the following categories: cloud hosting and databases, identity verification and document checks, fraud prevention, email, SMS and WhatsApp delivery, customer support tooling, cookieless product analytics, error monitoring, AI model providers used for document review and support assistance, and professional advisers. Sub-processors are bound by written data-processing terms; a current list of categories and of named payment partners is available on request.
  • Authorities and legal requirements: regulators (including the BCEAO, the Commission Bancaire de l'UMOA and the ARTCI), the CENTIF, tax authorities, courts and law-enforcement agencies, in Côte d'Ivoire or abroad, where the law requires it or to protect our rights, Merchants or Customers.
  • Corporate transactions: a buyer or successor in a merger, acquisition, financing or sale of assets, under confidentiality obligations, with notice to you where required.
  • With your direction: connected applications, e-commerce platforms, marketplaces or AI agents that you authorize to access your account, within the permissions you grant.

6. International transfers

Where personal data is stored and processed

We are established in Côte d'Ivoire and our Payment Channel Partners are mainly in the UEMOA zone. Some of our service providers and partners, including cloud hosting, analytics, email delivery, identity verification and card acquiring (for example Stripe), process data in the United States or in the European Union.
Transfers within the ECOWAS area are permitted under Law 2013-450 and the ECOWAS Supplementary Act. Transfers to countries outside ECOWAS are made only where the destination provides an adequate level of protection or with appropriate safeguards, including contractual data-protection clauses with the recipient, the recipient's binding security and confidentiality commitments, and, where required, the prior authorization of the ARTCI. We limit transferred data to what is necessary for the purpose. You may ask us for information about the safeguards that apply to a specific transfer.
Authorities of the countries where data is processed may, in some cases, be entitled to access it under their own laws.

7. How long we keep personal data

Retention periods

We keep personal data only for as long as needed for the purposes described in this Policy and to meet our legal obligations, then delete or anonymize it. The main periods are:
  • Identity, KYC, KYB and transaction records: ten (10) years after the end of the business relationship or the date of the transaction, as required by the anti-money-laundering and counter-terrorist-financing law applicable in Côte d'Ivoire and the UEMOA (uniform law implemented by Ordinance No. 2023-875) and by our Payment Channel Partners.
  • Dispute, refund and fraud evidence (including Payment Link descriptions, receipts and Customer communications): for the applicable card-scheme dispute window and any ongoing investigation, and in any case within the ten-year period above.
  • Accounting and tax records: ten (10) years under OHADA accounting law and the Ivorian tax code.
  • Account, usage and security logs: for the life of the account and up to two (2) years after closure, unless needed longer for security investigations or legal claims.
  • Marketing data and cookies: until you opt out or, for prospects, three (3) years after your last interaction; analytics data is aggregated and does not identify you.
  • Support communications: three (3) years after the last exchange.
When a Merchant closes its account we stop active processing but keep the records above for the periods indicated. Residual copies may remain in encrypted backups for a limited time before they are overwritten. Anonymized data may be kept indefinitely.

8. Security and breach notification

How we protect personal data

We apply organizational, technical and physical measures appropriate to the risk, including encryption of data in transit and at rest, network and application access controls, least-privilege and multi-factor authentication for our staff, segregation of environments, logging and monitoring, secure development practices, vulnerability management, vendor due diligence and staff training. Card data is handled through PCI DSS compliant Payment Channel Partners and never stored in full on our systems. Secret API keys are shown once and stored hashed.
No system is perfectly secure. Merchants remain responsible for protecting their own credentials, API keys and systems, and Customers for their payment instruments and devices.
If we become aware of a personal-data breach likely to result in a risk to your rights, we will notify the ARTCI and, where required, the affected persons and Merchants without undue delay and in any case within seventy-two (72) hours of becoming aware of it, with the information available at that time, and we will cooperate with the Merchant in its own notifications. If you believe your data or account is no longer secure, contact us immediately at hello@lomi.africa.

9. Cookies and analytics

What runs in your browser

Essential cookies and storage. Our websites, dashboard and checkout use strictly necessary cookies and local storage to keep you signed in, remember your language and theme, protect against cross-site request forgery, route your session and complete payments. These cannot be switched off without breaking the service and do not require consent.
Analytics. We measure how our websites and documentation are used with Vercel Analytics and a cookieless configuration of PostHog. These tools do not set tracking cookies, do not build cross-site profiles and do not use advertising identifiers; data is aggregated and we do not use it to identify you. Session recording is not enabled. We do not use third-party advertising trackers on our websites.
Merchant sites. When you pay on a Merchant's site or app, that Merchant's own cookies and analytics apply and are governed by its policy. Our embedded checkout only uses the essential storage described above.
You can control cookies through your browser settings; blocking essential cookies may prevent you from signing in or paying. The former cookies page in our documentation now redirects here.

10. Marketing communications

What we send and how to opt out

If you are a Merchant or have asked to hear from us, we may send you product news, changelog updates, educational content and event invitations by email and, where you have given us the number for that purpose, by WhatsApp or SMS. We do not send marketing to Customers based on the payments they make to Merchants, and we do not share your contact details with third parties for their own marketing.
You can opt out at any time through the unsubscribe link in each email, by replying STOP to a WhatsApp or SMS message, in your dashboard notification settings, or by writing to hello@lomi.africa. We will act on your request within ten (10) business days. Opting out of marketing does not stop transactional and service messages (receipts, security alerts, dispute notices, changes to our Terms), which we must send to operate your account.

11. Your rights

What you can ask and how we answer

Subject to the conditions and exceptions set by applicable law, you have the right to:
  • Information and access: know whether we process your personal data and obtain a copy of it and of the related information.
  • Rectification: have inaccurate or incomplete data corrected or completed.
  • Erasure: have your data deleted where it is no longer necessary, where you withdraw consent, or where it was processed unlawfully. Records we must keep by law (Section 7) are exempt.
  • Objection and restriction: object to processing based on legitimate interests, object at any time to direct marketing, and ask us to restrict processing while a request is being examined.
  • Portability: receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another provider where technically feasible.
  • Automated decisions: not be subject to a decision based solely on automated processing, and obtain human review (Section 4).
  • Withdraw consent at any time where processing is based on consent.
To exercise a right, write to hello@lomi.africa from the email address linked to your account, or by post to the address in Section 15, stating which right you exercise and which data is concerned. We may ask for information to verify your identity. We answer within thirty (30) days, extendable by a further sixty (60) days for complex requests with notice to you. Requests are free unless manifestly unfounded or excessive. If you are a Customer and your request concerns data controlled by a Merchant, we will direct you to the Merchant and assist it where we act as its processor.
Complaints. You may lodge a complaint with the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), the Ivorian data-protection authority (artci.ci), or with the competent authority of your country of residence. We would appreciate the chance to address your concern first.

12. Children

Our services are for adults and businesses

Our services are intended for businesses and for adults aged eighteen (18) or over. We do not knowingly collect personal data from children under eighteen (18). Merchants selling to minors must comply with the law applicable to them and may not submit a minor's personal data to us beyond what a payment requires. If you believe a child has provided us with personal data, contact us at hello@lomi.africa and we will delete it.

13. If you pay a business that uses lomi.

What Customers should know

When you pay a Merchant through a lomi. checkout, Payment Link or plugin, the Merchant is responsible for your order and for its own privacy policy. We process your payment data as described in this Policy to complete the payment, prevent fraud, handle refunds and disputes and meet our legal obligations, and we share with the Merchant what it needs to fulfil your order.
We may show you a receipt, save your email or phone number to send it, and, if you choose, remember your payment method for future payments to Merchants using lomi. You can ask us to forget a saved method at any time. For questions about an order, contact the Merchant first; for questions about how lomi. processes your data, contact us at hello@lomi.africa.

14. Changes to this Policy

How we tell you about updates

We may update this Policy when our services, partners or legal obligations change. The Last updated date at the bottom of this page shows the latest revision. For material changes in how we use personal data, we will give Merchants at least two (2) months' notice by email and in the dashboard before the change takes effect, and will inform Customers through the checkout or our website where appropriate. Changes required by law may take effect on the date the law requires. Continued use of our services after the effective date means you have read the updated Policy.

15. Contact

How to reach us about privacy

For any question, request or complaint about this Policy or about your personal data, contact our privacy team at hello@lomi.africa or by post at lomi. Technologies Africa S.A., Privacy, Cocody, Les Perles, Rue 01012 L82/375, Abidjan, Côte d'Ivoire. We acknowledge requests within five (5) business days.

Last updated: September 8, 2026