About this policy
GramCheck (“we”, “our”, or “us”) provides a mobile application for verifying Ethiopian bank and mobile-money payment receipts (Commercial Bank of Ethiopia, Bank of Abyssinia, Awash Bank, Telebirr, and M-PESA). This policy explains what personal data we collect, why we collect it, how we use it, and the choices you have.
By creating an account or using GramCheck, you agree to this policy. If you do not agree, please stop using the app and delete your account.
Data we collect
Account information — When you sign up we collect your name, email address, and password (stored as a one-way hash). You may optionally provide a phone number, which is used only for phone-number login and password reset.
Telegram identity — If you link your Telegram account, we store your Telegram user ID and username so you can log in through the GramCheck Telegram bot.
Business and employee data — Business-account owners may add branches (name, address) and employees (name, phone number, email). This data is stored on our servers and is visible only to the owner of that business account.
Payment receipt data — When you scan or type a payment reference, we query the relevant bank or mobile-money provider and store the verified receipt: bank name, transaction reference, date, amount, sender name, and receiver account name or number. We also store the raw scan input so you can trace how a reference was submitted. Receipts you save are associated with your account and, for business users, with the branch and employee that made the scan.
Wallet and billing data — We maintain an in-app credit balance (denominated in Ethiopian Birr cents). When you top up your wallet we record the payment reference number you submit for verification, the amount, and a manual note you may provide. We do not process payments directly; top-ups are verified manually.
Device and session data — We log IP addresses and standard HTTP headers with each API request. Session tokens are stored in your device's secure storage (iOS Keychain / Android Keystore equivalent via Expo SecureStore).
Device permissions
The app requests the following device permissions:
- Camera — Required to scan payment QR codes in real time. Frames are processed locally on your device; no camera feed is transmitted to our servers.
- Photo library (read-only) — Optional. Lets you pick a saved screenshot containing a payment QR code instead of scanning live. The selected image is decoded locally; the raw image is not uploaded to our servers.
We do not request access to your contacts, location, microphone, notifications, or any other device resource.
How we use your data
We use the data described above to:
- Authenticate you and maintain your session.
- Verify payment receipts by querying bank or mobile-money provider APIs on your behalf.
- Cache receipt results in Redis to reduce latency and API load on bank servers.
- Match a verified receipt's receiver account against the saved accounts in your profile (to show whether the payment was directed at you).
- Maintain your transaction history so you can review scans made today, this week, or this month.
- Manage your in-app wallet balance and verify top-up payments.
- Allow business owners to monitor branch- and employee-level verification activity.
- Detect and notify you when a bank's service is down.
- Send you password-reset and account-activation messages via Telegram (if linked).
- Operate and improve the GramCheck service.
We do not use your data to serve advertising, build marketing profiles, or sell to third parties.
Third-party services
Verifying a receipt requires us to contact the relevant bank or mobile-money provider. The following external services receive the reference number or receipt URL you submit:
- Commercial Bank of Ethiopia (CBE) — for CBE reference lookups.
- Bank of Abyssinia (BOA) — for BOA reference lookups.
- Awash Bank — for Awash reference lookups.
- Ethio Telecom (transactioninfo.ethiotelecom.et) — for Telebirr receipt lookups.
- Safaricom Ethiopia (m-pesabusiness.safaricom.et) — for M-PESA receipt lookups.
For Telebirr and M-PESA, network conditions on our server sometimes require the app to fetch the receipt page directly from your device and forward the raw page content to our server for parsing. In that case your device temporarily contacts the provider's servers directly.
We do not share your account information, personal data, or transaction history with any of these providers.
Our infrastructure runs on a Virtual Private Server in a managed data-centre. The server hosts MongoDB (database), Redis (cache), and the GramCheck API. No third-party cloud analytics, crash-reporting, or advertising SDKs are embedded in the app or the API.
Data retention
We retain your account data for as long as your account exists. Verified receipts and wallet records are kept until you delete them or delete your account, so you can access your history.
Deleting your account
You can delete your account at any time, without contacting us:
- In the app — open the Profile tab, tap Delete next to “Delete account”, and confirm.
- On the web — go to https://gramcheck.et/delete-account and confirm with your phone number and password.
Deletion is immediate and permanent. We delete your profile (name, phone number, email, password, and Telegram link), your sign-in sessions, the payment receipts you saved, your saved bank accounts, and your wallet. Any remaining wallet balance is forfeited and is not refunded.
Business owners — deleting an owner account also deletes the business, its branches, every employee login, all receipts saved by the business and its employees, and the business wallet.
Employees — deleting an employee account removes your login and personal details. Receipts you scanned for your employer belong to the business and stay in its history, no longer linked to your name.
What we keep — for accounting and audit purposes we retain top-up payment records (amount, reference number, date, and the payer name and phone number shown on the payment receipt), wallet ledger entries, and promo code redemptions (amounts and dates). These records are no longer linked to a profile.
Security
Passwords are stored as bcrypt hashes and are never stored or transmitted in plain text. Session tokens are signed and stored in your device's secure enclave. All communication between the app and our API uses HTTPS (TLS 1.2 or higher).
No security measure is perfect. If you discover a vulnerability, please report it to [email protected].
Children
GramCheck is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
Your rights
You may at any time:
- Access the personal data we hold about you.
- Correct inaccurate data from within the app (profile settings).
- Delete your account and personal data yourself, in the app or at https://gramcheck.et/delete-account.
- Delete saved bank accounts, and remove individual receipts from your history, from within the app. Removed receipts are hidden straight away and permanently erased when you delete your account.
- Export your saved transaction history.
For anything you cannot do yourself in the app, contact us at [email protected].
Changes to this policy
We may update this policy as the service evolves. We will post the revised policy at https://gramcheck.et/privacy and update the effective date above. Continued use of GramCheck after a change constitutes acceptance of the updated policy.
Contact us
Gram Labs — makers of GramCheck
Email: [email protected]
Website: https://gramcheck.et