Ping Prepay

Privacy Policy

Ping Prepay CRM · crm.pingprepay.com
Effective 31 August 2026

Scope

This Policy governs the Ping Prepay customer relationship management application located at crm.pingprepay.com (the “Application”), operated by Ping Prepay (“Ping Prepay”, “we”, “us”). The Application is an internal business system available only to authorised Ping Prepay personnel. It is not offered to consumers and does not accept public registration.

This Policy addresses information processed by the Application. Ping Prepay’s general privacy practices are set out in its corporate privacy policy. Where the two differ in respect of the Application, this Policy applies.

Eligibility and access

Accounts are provisioned by an administrator. Authentication is performed by Google; a sign-in attempt from an address that has not been provisioned is refused, including where the underlying Google account is valid and belongs to an approved domain (pingholdings.com, pingprepay.com or nexcomventures.com).

Information collected from personnel

The Application records the following in respect of each authorised user:

  • identity and contact information, being name, work email address, assigned role, and the Google account identifier used for authentication;
  • records of work performed, being the leads and retailer accounts assigned to the user, activities logged against those records (calls, text messages, emails, meetings and site visits), notes authored by the user, and the date and time of each; and
  • an audit record of changes to record ownership and record status, attributed to the user who made them.

The audit record referred to above is maintained so that questions of account ownership and record history can be determined from contemporaneous data.

Google user data

Authentication is performed through Google. Ping Prepay receives the user’s name, email address and Google account identifier. Ping Prepay does not receive, process or store Google account passwords.

Where calendar access has been granted for a user’s account, the Application creates and maintains calendar entries corresponding to work scheduled within the Application. In such cases:

  • the Application writes only calendar entries originating from the Application, and reads only subsequent modifications to those same entries. Other entries in a user’s calendar are not read into the Application;
  • the data retained is limited to the identifier of each calendar entry created by the Application, its scheduled time, and the Application record to which it relates;
  • calendar data is not sold, is not used for advertising or profiling, and is not disclosed to any party outside Ping Prepay; and
  • a user may withdraw calendar access at any time through their Google account settings, which terminates the synchronisation. Work previously scheduled remains recorded in the Application.

Ping Prepay’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Information relating to retailers

The Application records business information concerning retailers and prospective retailers, being business and contact name, business email address and telephone number, premises addresses, product applications and approvals, and transaction and activation activity as reported by the Ping POS platform. Such information is business contact information processed for the purpose of managing a commercial relationship.

Premises addresses are submitted to Google’s Address Validation service for standardisation, and premises may be displayed using Google Street View imagery.

Purposes of processing

Information is processed for the purposes of managing retailer relationships and onboarding, allocating and recording work, identifying duplicate records, reporting on commercial performance, and maintaining an accurate record of account ownership. Information held in the Application is not sold, and is not used for advertising.

Disclosure

Access within Ping Prepay is determined by role. Users may access records assigned to them; managers and administrators may access all records. No party outside Ping Prepay is granted access to the Application.

The Application relies on the following service providers, which process information solely to provide their services and are not permitted to use it for their own purposes: Vercel Inc. (application hosting), Supabase Inc. (database hosting), Google LLC (authentication, address validation and mapping), and the Ping POS platform (retailer data).

Information may additionally be disclosed where required by law or where necessary to establish, exercise or defend legal claims.

Security

Authentication is delegated to Google and no passwords are stored by the Application. Access to records is enforced at the data layer rather than by interface restriction. Changes to record ownership and status are logged and attributed. Data in transit is encrypted. Administrative credentials and service keys are held as server-side configuration and are not exposed to client applications.

Retention

Records are retained for the duration of the commercial relationship and for such further period as Ping Prepay’s record-keeping and legal obligations require.

Where a user ceases to be authorised, the account is deactivated rather than deleted. Deletion would remove the attribution of work previously performed by that user and render the audit record inaccurate.

Rights of personnel

A user may request details of the information the Application holds concerning them and may require the correction of inaccuracies. Requests should be directed to the address set out in the Contact section below.

Amendments

Ping Prepay may amend this Policy. The effective date above will be revised accordingly, and material changes affecting personnel will be communicated to them.

Contact

Enquiries and requests under this Policy should be addressed to shahzeb@pingholdings.com.