Privacy Policy

How Sagira Wallet collects, uses, and protects your data. Last updated: August 21, 2026.

Service Operator

"Sagira", "Sagira Wallet", and "Sagira Ecosystem Wallet" are product and brand names. The service is operated by the following registered legal entity, responsible for the app and your data:

  • Legal entity: Sagira Halal Food Eatery
  • Registered address: San Lucas Street
  • Registration no.: 7858608
  • Privacy contact: privacy@sagira.store
  • Governing law: Republic of the Philippines

This policy explains what personal data the Sagira Wallet application collects, why, and the choices you have. Sagira is not a bank, electronic-money issuer, payment institution, crypto exchange, or card issuer. Payment and identity services are provided by the third parties named below.

1. Information We Collect

  • Account: full name, email address, mobile number, and a role (customer, merchant, rider, or admin).
  • Identity verification (KYC): government-issued ID images, a selfie, and (when applicable) proof of address. Required only when using remittance, large-value transfer, or merchant features.
  • Wallet & payments: transaction history, wallet top-up and cash-out records, QR-pay receipts, and bill-payment references.
  • SGR rewards (Coming Soon): the planned loyalty token architecture will, where available, optionally link to a user-controlled Solana wallet address. SGR token trading, transfers, and Solana Pay are not currently available in the public app.
  • Location: approximate device location, collected only when you choose to share it — used to find nearby merchants, manage active deliveries, and pin store addresses. Foreground only; no background location.
  • Device & usage: device fingerprint for trusted-device recognition, app activity logs, and crash/performance data used to keep the app stable.
  • Communications: in-app messages, support conversations, and notification log entries you generate.

2. How We Use Your Information

  • To create and maintain your account, verify your identity, and grant role-based access.
  • To process wallet top-ups, food orders, QR payments, bill payments, and remittance send/claim flows.
  • To show you nearby merchants, route deliveries, and award loyalty and referral rewards.
  • To send order, payment, and booking notifications and to communicate support and policy updates.
  • To detect and prevent fraud, abuse, and violations of our terms.
  • To comply with legal obligations and regulatory requirements applicable to a non-bank stored-value wallet operator.

3. Permissions

  • Camera: used for QR scanning, merchant product barcodes, and KYC document/selfie capture.
  • Location (foreground only): used for nearby merchant search, delivery routing, and store-address pinning. We do not collect background location.
  • Notifications: used for order, payment, and travel alerts; you can disable them in your device settings.
  • Storage/photos: used to upload KYC documents and proof-of-delivery captures.

4. Payments, Wallet & Stored Value

Sagira is a stored-value wallet, not a bank and not a licensed e-money issuer. Wallet balances reflect stored value held within the Sagira ecosystem and are not insured bank deposits.

Inbound top-ups are processed by Maya and PayMongo (third-party payment providers) and the resulting credit is recorded in your Sagira wallet ledger. Other payment flows you may use (Send Money, Bills, Remittance) are currently recorded as internal Sagira ledger entries; where applicable law requires external disbursement, Sagira coordinates the external leg with the relevant service partner and you will be informed of the partner at the time of the transaction. Sagira is not itself a payment institution or electronic-money issuer.

Google Play Billing is used only where a digital-content purchase is required by Google's policy and is processed through Google Play Billing at that point. Today Google Play Billing is not used for the wallet, the food order, or the travel booking flows described above.

5. Sagira Rewards (SGR) — Coming Soon

SGR is planned as a loyalty reward token and is currently not available in the public app. SGR trading, exchange, swap, spot, liquidity, staking, launchpad, OTC, and P2P transfer are not enabled and have no live balance in your account. When this feature is published it will be described in an updated policy. SGR is not a security, currency, or regulated financial instrument; on-chain Solana activity (where applicable in the future) is public and cannot be erased. We do not store your private keys.

6. Third-Party Service Providers

  • Base44 — backend-as-a-service platform hosting all Sagira data, files, and authentication. Sagira user data is stored on Base44-managed infrastructure.
  • Maya — payment provider used for inbound wallet top-ups and order checkout. Maya receives transaction amount, customer identifier, and a Sagira reference.
  • PayMongo — payment provider used for inbound wallet top-ups and QR Ph (QR Ph host-to-host) flows. PayMongo receives transaction amount and reference.
  • Resend — outbound email delivery used for verification codes and transactional notifications. Receives the recipient email address and message body.
  • SMS providers — incorporated pluggable SMS gateway used for OTP and campaign messages. Receives phone number and message body.
  • Google (Sign-In) — OAuth sign-in provider. Receives your Google profile (email, name) at sign-in only.
  • Google AdSense — advertising network used to display ads on the public Landing page. Receives page URL and ad-context signals; never receives your wallet, KYC, or transaction data.
  • OpenStreetMap / Nominatim — map tiles and forward-geocoding of addresses. Receives address text for routing only.
  • Base44 Core LLM — AI text generation used by the in-app assistant, concierge, and AI Writer. Receives the prompt text you submit and the conversation context.
  • Identity Verification provider — where applicable, processes KYC ID + selfie + liveness submissions. Receives your uploaded documents for verification.
  • Travelopro — for the optional flight/hotel search flow. Receives search queries and passenger/contact details only when you complete a booking search.
  • Webhook / payment-provider endpoints — called by the providers above to settle transactions. Receive webhook payloads verified by stored signatures.

7. Sharing & Disclosure

  • With the merchant or rider involved in your order, delivery, or booking (only the details needed to fulfill it).
  • With the payment, identity-verification, SMS, email, AI, map, and travel providers listed above, only when you initiate a flow they support.
  • When required by law, regulation, or to protect rights, safety, or property.

8. Data Retention

We keep your data only as long as your account is active or as needed to provide services, resolve disputes, and meet legal obligations.

Financial and audit records (wallet ledger entries, orders, settlements, remittances, bill-payments, and platform-revenue entries) are retained for the period required by applicable financial law in the Philippines. KYC documents are retained per regulatory minimums and then securely deleted through an admin retention sweep.

Approximate location is currently held until you delete your account. Foreground-only rider GPS for active delivery is not persisted beyond the active delivery page.

9. Security

We protect data using encryption in transit, role-based access controls, field-level security on sensitive user fields, audit logging, and signed payment-provider webhooks. KYC and remittance flows require identity verification before funds can be sent or claimed. No method is fully secure; we implement safeguards appropriate to the sensitivity of the information.

10. Your Rights & Account Deletion

  • Access, correct, or request deletion of your personal data via your Profile or by contacting us.
  • Withdraw consent for optional permissions (camera, location, notifications) in your device settings at any time.
  • Delete your account from Profile → Delete Account. Account deletion disables sign-in, anonymizes your personal information, and preserves immutable financial/audit records (wallet ledger, orders, settlements, remittances, bill payments) per applicable law. Uploaded KYC document files are marked for the admin retention sweep and purged after the regulatory hold window.
  • Object to or restrict certain processing of your data.

11. Children's Privacy

Sagira Wallet is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to This Policy

We may update this policy to reflect changes in our services or the law. Material changes will be announced in-app or by notification. Continued use after changes takes effect constitutes acceptance.

13. Contact Us

Questions about this policy or your data? Contact Sagira Support:

© 2026 Sagira Wallet. This privacy policy is provided for use with the Sagira Wallet application on Google Play and the App Store.