Last updated July 2026
We collect your name, email, phone number, and business details when you sign up. Invoice and payment data you create in Payvex is stored securely in our database. Bank connections (Mono) use read-only tokens. We never see your credentials.
When someone opens one of your invoices on the public payment page and accepts or disputes it, we record the IP address and browser (user agent) they used, and the time they did it. We keep this to hold an accurate, non-repudiable record of who acknowledged or contested an invoice — our legitimate interest in resolving disputes and preventing fraud. We keep these records for 12 months, then delete them.
We use your data to deliver the Payvex service: invoice generation, payment collection, WhatsApp reconciliation, and FIRS compliance. We do not sell your data to third parties.
All data is stored in Neon PostgreSQL (EU region). Bank statement CSVs sent via WhatsApp are processed in memory and not persisted after reconciliation.
When you reconcile a bank account through Mono, the description (narration) of a transaction we match to one of your invoices is stored with the payment record we create, so the match stays auditable. We keep the narration, never your full transaction history.
When an owner changes the business's settlement bank details, we keep an audit record of the change: the old and new bank name and code, the last four digits of the account number (never the full number), the resulting Paystack subaccount, who made the change, and the IP address it came from. This guards against unauthorized redirection of your settlement money.
Questions? Email hello@payvex.com.ng