Privacy Policy
What personal information SharpPoint collects when you use our app and this website, why we collect it, who we share it with, and the choices you have.
1. Who we are
SharpPoint Corporation (“SharpPoint”, “we”, “us”) is a company based in Monrovia, Liberia. We run the SharpPoint mobile app and this website, and we are responsible for the personal information described in this policy. You can reach us at support@sharppointcorp.com.
2. Information we collect
When you create an account
- To sign in: your email address and password.
- For a personal profile: your first, middle and last name, date of birth, gender, county of origin, and phone numbers (a main number and, if you add one, a second number).
- For a business profile: the business name, industry and category, a short description, its location and county, opening days and hours, and its phone numbers. If the business chooses, the details it asks people paying it to give.
- A public contact email and a profile picture, if you choose to add them. If you add more than one profile, each extra profile has its own password.
We never store your password itself — only a one-way scrambled version of it, which cannot be turned back into the password.
Your date of birth needs your separate consent. Liberia’s Personal Data Protection and Privacy Act treats age as sensitive personal information (section 4(m)) and allows it to be processed with consent specific to the purpose (section 13(a)). So when you enter your date of birth, we ask you to agree to SharpPoint using it to confirm you are 18 or older and keeping it as part of your identity record, and we record when you agreed and to which wording. If you signed up before we asked, the app asks you; if you choose not to agree, you are signed out and asked again the next time you sign in.
When you sign in with Google (not available yet)
Sign in with Google is not available yet. When it is, and you choose “Continue with Google”, Google will share with us your Google account identifier, your name, your email address and whether Google has verified it, and your profile picture if you have one. We will not receive your Google password, and we will not ask for access to your contacts, email, files or any other Google data. See section 10.
When you link a wallet or bank account
The mobile money number and network (or, when bank linking becomes available, the bank account details) you link, the name on the account as the operator reports it, the last balance we read from the operator, and the result of the one-time code check that proves it is yours. When you approve a payment with your wallet PIN, the PIN goes to the operator to approve it; we never store it.
When you pay or get paid
- The amount, currency, date and time, the accounts involved, the other person’s or business’s name and SharpPoint ID, the payment’s status and reference, its purpose, and any note you add.
- The items in an order or checkout when you buy from a business, and any note you or the business add to the order.
- If you pay on behalf of someone else, the details you enter about that person. We store these encrypted, except the one reference number a business uses to match payments (such as a student ID), which the business you pay can see.
When you run a business on SharpPoint
Details you enter about the people you work with: team members you invite (their SharpPoint ID, name and role), staff and payroll information, collection agents, payout lists you upload as spreadsheet (CSV) files, and your product catalogue, product photos and orders.
To keep your account secure
- Your phone’s operating system and version, your app’s or browser’s user-agent, an identifier the app creates for your device, your IP address, and when you sign in.
- A record of activity on your account — sign-ins (including failed attempts), payments you make, and changes to your password, two-factor settings, linked wallets, profiles, team and plan — with the time, IP address and device involved. Security alert emails we send you show the time, device and IP address of a sign-in.
- Our app servers keep standard request logs, such as your IP address and the time and address of each request, for security and to fix problems. To limit repeated attempts we briefly hold your IP address and account identifier in a short-lived cache.
- Your two-factor settings. The key for your authenticator app is stored encrypted, and recovery codes only in one-way scrambled form.
- Passkeys, when that feature is available: we store only the public half. The private key stays on your device or in your password manager and is never sent to us.
Notifications, camera and photos
- A push notification token, so we can send alerts to your phone. Notifications can include an amount, the other person’s first name or a business name, and an order reference; they pass through Expo and Google or Apple to reach your phone. We also keep a list of the notifications we send you in the app.
- The camera is used to scan QR codes. The code is read on your phone; no picture is taken or sent to us.
- We access your photos only when you choose a picture to upload (a profile picture, business logo or product photo), and save an image to your gallery only when you ask to save your QR code. Payout spreadsheets you pick are read on your phone. Pictures you upload are stored with our provider Supabase at a web address that other SharpPoint users are shown.
- The app keeps an encrypted copy of your recent account information on your phone so it works offline, and deletes it when you sign out.
On this website
- If you use the contact form: your name, email address, topic and message, delivered to our support mailbox. The form uses Cloudflare Turnstile, which receives your IP address, to check that you are not an automated program.
- Your theme and animation choices are saved in your own browser, not sent to us. The website uses no advertising or analytics trackers. Its icons are loaded from Google Fonts, which receives your IP address when your browser fetches them.
- Like any website, our hosting provider keeps standard server logs, such as IP addresses and the time of each request, for security.
3. How we use your information
- To create your account and let you sign in.
- To move money when you ask us to, and to give you receipts and a payment history.
- To confirm who you are and to meet our legal duties, including anti-money-laundering and counter-terrorist-financing rules.
- To protect your account and prevent fraud: recognising new devices, sending security alerts, limiting repeated attempts, and keeping a record of sensitive changes.
- To contact you with sign-in codes, receipts, security alerts and messages about the service. We will not send you marketing unless you have agreed to it.
- To answer your questions and help when something goes wrong.
- To keep the service reliable and to fix problems.
We do not sell your personal information, and we do not use it for advertising.
5. Where your information is stored
Our servers and service providers are located outside Liberia, including in the European Union and the United States. We choose providers that protect personal information to recognised industry standards, and the information is encrypted when it travels between your phone and our servers.
6. How long we keep it
We keep your information for as long as your account is open. When you ask us to delete your account (see section 9), we wait 30 days before deleting anything, so you can change your mind. The 30 days are our own choice; no law sets them. After that we delete your personal details, except the records below.
What we keep, and why
Liberia’s Personal Data Protection and Privacy Act lets personal information be kept for as long as it is needed, or “as provided by law” (section 11(e)), and allows processing that is needed to meet a legal obligation (section 12(c)).
The Central Bank of Liberia sets how long financial institutions and mobile money providers must keep records. SharpPoint is not yet licensed by the Central Bank, but we already keep records to these rules, so that nothing is deleted that a licensed payment provider must keep:
- Records of your payments and orders — for at least five years from the date of each payment (Regulation No. CBL/RSD/002/2017, section 2.7.1, and Regulation No. CBL/RSD/003/2014, section 19, item iv). They include your name and SharpPoint ID as they were at the time, and any notes on orders.
- The identity details we verified — your name, date of birth, gender, county of origin, phone numbers, email addresses, business name and location, SharpPoint IDs, and linked wallet numbers and account names — for five years after your account is deleted, which is when our relationship with you ends (Regulation No. CBL/RSD/002/2017, section 2.7.2). We then delete them, except your name and SharpPoint ID as they appear on payment records.
- Security and audit records of activity on your account, including IP addresses and devices. No regulation sets a period for these; our choice is to keep them with your payment records, for at least five years, to prevent fraud and protect accounts.
We have not yet set a date after which payment, order and security records are deleted; when we do, we will update this policy. The identity details are kept sealed with encryption. Payment and security records are kept in our systems with access restricted, and all of these records are used only for legal, regulatory, fraud-prevention and security purposes.
Businesses you dealt with keep their own records of payments and payroll that involved you.
If you start signing up but never confirm your email address, we delete that unfinished account within about a day.
7. How we protect it
All traffic between the app and our servers is encrypted. Sensitive details, such as authenticator keys and the details of people you pay for, are also encrypted where they are stored. Passwords and recovery codes are kept only in one-way scrambled form. You can protect your account further with two-factor sign-in, and the app can lock itself behind your phone’s fingerprint, face or screen lock. Access inside SharpPoint is limited to the people who need it.
No system is completely secure. If information that could be used against you — for example to commit identity fraud — is reasonably believed to have been taken, and that puts you at real risk of serious harm, we will tell you promptly: what happened, what information was involved and what we are doing about it, as the Personal Data Protection and Privacy Act requires (section 20(f)).
If you believe your account or our service has been compromised, email support@sharppointcorp.com straight away.
8. Your choices and rights
- See and correct your information. Most of it is in the app, where you can update it. To change your sign-in email address or main phone number, email us.
- Download a copy of your data. In the app, go to Profile → Security & login → Download a copy of your data. You choose the format: a readable copy (PDF), laid out like a statement, or a technical file (JSON), a common electronic format you can give to another service. Both contain everything we hold for your whole sign-in: your account and profiles, linked wallets, payments and orders, team and agent agreements, devices, security activity and notifications. To protect you, it asks for your password (and your authenticator code if you use two-factor sign-in), gives one copy every 10 minutes in either format, is paused for 24 hours after a password reset made without your authenticator code, and we email you each time a copy is downloaded. We build the file when you ask and do not keep it; the app deletes its copy from your phone after about 2 minutes. It leaves out passwords, security codes and sign-in tokens; we record when your information was last changed but not when it was last looked at, so it cannot show that. For anything the file does not cover, email us.
- Delete your account. You can do it yourself in the app — see section 9.
- Remove Google sign-in (once Sign in with Google is available). You will be able to stop signing in with Google once you have another way to sign in, and to remove SharpPoint’s access at any time at myaccount.google.com/connections.
- Control permissions. You can turn off notifications, camera and photo access in your phone’s settings.
Liberia’s Personal Data Protection and Privacy Act gives you the right to see the information we hold about you and to have it corrected (section 16(c) and (d)), and to get a copy of it in a structured, commonly used electronic format (section 18). It also lets you ask us to remove information that is incomplete, outdated, false, unlawfully obtained, misused or no longer needed (section 16(e)), and lets your lawful heirs use these rights for you after your death or if you become unable to (section 17). Some records must still be kept even then — see section 6.
To make a request, email support@sharppointcorp.com. We will reply within 30 days, and may ask you to confirm your identity first so no one else can make a request about your account.
If you are not satisfied with our answer, you have the right to complain to the Independent Information Commissioner of Liberia, and after that to seek redress under the Freedom of Information Act of 2010 (Personal Data Protection and Privacy Act, section 16(b)(8)).
9. Deleting your account
Open the SharpPoint app and go to Profile → Security & login → Delete account (at the bottom of the page). To make sure it is really you, we ask for your password — and your authenticator code or a recovery code, if you use two-factor sign-in — then a code we email to you, and a final confirmation. Deleting covers your personal profile and every business profile under the same sign-in.
If you no longer have the app, see how to delete your account without the app.
What happens
- Straight away, your account closes: it can’t be used, no one can find or pay you, and you are signed out on every device. Your memberships of other businesses’ teams end.
- For 30 days, you can change your mind: sign in to the app and choose Restore account, and your profiles come back (places on other businesses’ teams do not — they can invite you again). Forgotten your password? Tap Forgot password on the sign-in screen to set a new one first. If you use two-factor sign-in, your authenticator app signs you in without email. Otherwise, signing in needs a code sent to your email; if you no longer have access to it, contact us — we can help only once we have confirmed it is you, which may take longer.
- After 30 days, we delete or erase your personal details: the names and details on your profiles, your contact details, photos, sign-in details, linked wallet numbers and account names, notifications, and your business’s catalogue, staff lists and saved recipients. This can’t be undone.
We keep only the records, and for the periods, set out in section 6. Payment records show your name and SharpPoint ID as they were at the time. After the 30 days, once your account is deleted, you can use the same email address to open a new one.
You can’t delete your account while a payment or payout is still being processed, an order is still being agreed, one of your businesses has an order paid in the last 14 days that isn’t marked delivered, or one of your businesses still has team members — or for 24 hours after a password reset made without your authenticator code. The app tells you what to finish first.
10. How we handle Google user data
Sign in with Google is not available yet. This section describes how we will handle Google user data once it is. When you choose Sign in with Google, we will receive only the basic profile information listed in section 2: your Google account identifier, name, email address, whether the email is verified, and your profile picture. We will use it only to create your SharpPoint account, to sign you in, and to fill in your profile so you do not have to type it again.
- We do not sell Google user data or use it for advertising.
- We do not use it to build profiles for any other purpose, or to train AI models.
- We share it only with the service providers listed in section 4 who need it to run SharpPoint, or when the law requires it.
SharpPoint’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
11. Children
SharpPoint is for people aged 18 and over. We do not knowingly collect information from anyone younger. If you believe a child has created an account, contact us and we will close it.
12. Changes to this policy
When we change this policy, we update the date at the top of this page. If a change affects how we use your information in a significant way, we will tell you in the app or by email before it takes effect.
13. Contact us
Questions or requests about your information: support@sharppointcorp.com, SharpPoint Corporation, Monrovia, Liberia.