How personal information is handled across the PayGap website, support channels and relevant app services, and the choices available to you.
01
Who is responsible
PayGap is an application and product name. UNIVERSO MAGNÂNIMO, UNIPESSOAL LDA (Universo) develops and provides its technology services. Universo is registered in Portugal under number 516839462, with its registered office at Praceta Sebastião da Gama, nº 3, 3º ESQ, Massamá, 2745-837 Queluz, Portugal. Shanchie FX Corp is the app publisher, a Montana corporation registered under file D1564175. The companies are affiliated under common ownership. Each company remains responsible for its own services and legal obligations. Common ownership does not transfer financial-service permissions or give unrestricted access to personal information. Use the Contact form for website or app questions.
Financial services are supplied by the providers identified for your selected service, under their own applicable terms. Shanchie FX Corp has a developer agreement with Bridge. Where a service is provided by Bridge, Bridge contracts separately with the customer for that service. This relationship does not mean every PayGap route is supplied by Bridge or that Universo holds Bridge's permissions. Review the provider, account or custody structure, fees, protections and terms for your selected route before proceeding. PayGap is not a bank; no deposit protection or regulatory endorsement is implied by the product name.
Universo is responsible for personal information it processes to operate the PayGap website and handle its own support enquiries. Shanchie is responsible for information it processes in its app-publishing activities. Financial providers may act as independent controllers for their onboarding, transaction processing and legal records. For a service supplied by Bridge, its own privacy notice explains its onboarding, identity verification and financial-service processing. Their own privacy notices explain that processing. Use the Contact form with the subject “Privacy request” to ask about your information or our role.
02
Information collected through this website
The Contact form collects your name, reply email address, subject and message. The Complaints form also asks for the outcome you seek and allows an optional payment reference. The Data deletion form asks what information you want deleted and allows an optional PayGap account email if it differs from your reply email. Required fields are identified on each form. We use this information to understand your enquiry, investigate an issue and reply to you.
Please avoid including identity documents, full bank or card details, passwords, verification codes or unnecessary sensitive information. The forms do not offer document uploads. If a matter requires additional protected evidence, request an appropriate channel before sending it. We may receive information about another person where you describe a payment or act with that person’s authority; provide only what is relevant.
03
Technical information and device storage
Hosting and delivery services process connection and request information needed to serve the website and protect it against misuse. This can include an IP address, browser information, request time and the page requested. The website’s form handler checks the submission origin, field lengths and a hidden anti-spam field.
The current website does not include an advertising tracker or an optional analytics service in its application code. The Featurebase support integration uses browser storage for workspace configuration. Hosting or sign-in infrastructure may use essential storage for delivery, security or access. Your browser also caches website files. If optional tracking is introduced, the relevant notice and consent choices must be provided before it operates where consent is required.
04
Why information is processed
We process information to answer a request you make, provide website and app support, investigate complaints, protect the service and meet applicable legal obligations. Depending on the purpose and relationship, the legal basis may be steps taken at your request before a contract, performance of a contract, a specific legal obligation or legitimate interests in operating and defending the service.
Where legitimate interests apply, the processing must be necessary and balanced against your rights. Information supplied for a support request is not automatically permission for marketing. Where processing relies on consent, withdrawing that consent does not affect the lawfulness of processing carried out before withdrawal.
05
FormSubmit, Featurebase and support delivery
Support chat is provided through Featurebase. Information you choose to provide in chat, including your message and any contact or account details you supply, is processed to handle your enquiry. The Featurebase integration loads its support workspace and uses browser storage for its workspace configuration. Where a conversation uses Featurebase’s Fibi AI, automated assistance processes the conversation to generate a response. You can request help from the support team. Do not send identity documents, passwords, verification codes or full bank and card details through chat.
Website form submissions are sent through the PayGap server to FormSubmit for delivery to the support team. The destination inbox is held privately on the server and is not included in the website’s public form code. FormSubmit processes the submission content and states that it retains submissions for 30 days. A copy delivered to the support team may remain for the enquiry or complaint and any justified record-keeping period.
FormSubmit’s privacy information is linked next to each form. Do not assume that the provider’s 30-day submission period also deletes an email already delivered to a mailbox or a complaint record held by another responsible provider.
06
App, verification and payment information
An enabled app or financial service may require profile details, identity and address verification, funding references, recipient information, transaction amounts and status records. The collection notice for that service must explain what is requested, why it is needed and which entity is responsible. A provider’s legal obligation does not automatically become Universo’s legal basis.
Identity, biometric or automated eligibility processing is not performed by these website contact forms. Any such processing introduced within a verification or payment journey requires an appropriate notice identifying the provider, conditions and available rights. Do not submit biometric or identity evidence through an ordinary support message.
07
Recipients and international processing
Recipients include FormSubmit for form delivery and Featurebase for support chat, together with hosting and communications suppliers, the support team, the financial provider handling your selected service or investigating a payment, professional advisers and authorities where disclosure is legally required. For a Bridge service, Bridge receives the information required for its onboarding, identity checks and financial-service processing under its own notices. Sharing should be limited to what the recipient needs for its purpose. Membership of a wider company group does not itself give unrestricted access to personal information.
Providers may operate in different countries. Where applicable data-protection law requires a transfer mechanism, the responsible controller must use a valid mechanism and assess any required safeguards. You can ask through Contact which recipients and transfer arrangements apply to your enquiry or service. Route-specific notices must explain additional provider processing.
08
How long information is kept
Support information is retained while the request is being handled and for a justified period needed to address follow-up enquiries, complaints, legal obligations or disputes. The criteria include the type and seriousness of the issue, whether a payment provider is investigating it, applicable legal record-keeping requirements and the limitation period for a relevant claim. Information should then be deleted or anonymised when it is no longer needed.
A request to close an app profile does not necessarily require immediate deletion of records that a responsible controller must lawfully retain. Financial providers may have their own retention duties. Ask for the applicable retention period or criteria for the specific record through Contact. The same period does not apply to every financial and support record.
09
Your rights and requests
Depending on the applicable law and processing, you may request access, correction, deletion, restriction or portability of your information, object to processing, or withdraw consent. For deletion, use the Data deletion form and describe the information concerned without sending a password or identity document. Use the Contact form with the subject “Privacy request” for other privacy requests. Any identity check should be proportionate to the information requested.
For requests governed by the GDPR, the usual response period is one month. Where a permitted extension is necessary because of complexity or the number of requests, its reason must be explained within that first month. Requests are normally free, subject to the conditions and exceptions in applicable law. A refusal or limitation should be explained together with the available complaint route.
10
Complaints, children and changes
You may complain to Portugal’s Comissão Nacional de Proteção de Dados (CNPD) or another competent data-protection authority. Contacting the support team first can help resolve a concern but is not a condition for approaching an authority.
Financial-service eligibility is governed by the applicable customer agreement. If a child’s information is submitted through a support form in error, contact us so it can be assessed and handled appropriately. We will explain material changes to this notice and provide any additional notice or consent choice required before new processing begins.