Privacy Policy

This Privacy Policy explains how Beamline Systems ("Beamline," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with the Beamline mobile application, website, and related services (the "Service"). By using the Service, you acknowledge the practices described in this Policy. This Policy is incorporated into, and should be read together with, our Terms of Service.

1. Information We Collect

1.1 Information you provide. When you create an account, we collect your name, email address, phone number, and a hashed (never plaintext) copy of your password. When you add a contact or send a Beam, we collect the recipient's name, phone number, and (if provided) country/carrier — including for people who are not themselves Beamline users. When you contact support, we collect the content of your communications.

1.2 Transaction information. We collect records of your wallet top-ups, balance, and every Beam you send (type, amount, recipient, product, status, and timestamps), which we retain as an append-only ledger for accounting, fraud prevention, and dispute-resolution purposes.

1.3 Payment information. Card and payment details you provide for wallet top-ups are collected and processed directly by our payment processor, Stripe, Inc. Beamline does not store your full card number, CVV, or equivalent card credentials on its own servers.

1.4 Verification information. To verify your phone number, we (or our SMS provider, Twilio) send a one-time code to that number and record whether and when it was successfully verified.

1.5 Call data. If you place a call through the Service, we collect the recipient number, call duration, and cost. Depending on how a call is connected, our voice infrastructure provider (LiveKit) and, for calls to non-Beamline numbers, our telecom partner (IDT Express) process call-routing data necessary to connect the call; Beamline does not record call audio.

1.6 Device and usage information. We may automatically collect technical information such as IP address, device identifiers, operating system, app version, and general usage/diagnostic data, to operate, secure, and improve the Service.

2. How We Use Information

We use the information described above to: provide, operate, and maintain the Service; process wallet top-ups and fulfill Beams (including sharing recipient phone numbers and transaction amounts with the fulfillment providers named in Section 3, as necessary to complete your request); verify your identity and phone number; detect, investigate, and prevent fraud, money laundering, and other prohibited or unlawful activity; enforce our Terms of Service; comply with legal and regulatory obligations; communicate with you about your account and transactions; and, where you have not opted out, send you service updates or promotional communications.

3. Automated Decision-Making and AI

We may use artificial intelligence, machine learning, or other automated tools to help detect fraud or suspicious transaction patterns, to assist customer support, and to help build and operate the Service. These tools process the information described in Section 1 (for example, transaction and device information) to generate a recommendation or flag; a resulting account restriction may be applied automatically or reviewed by a person depending on the circumstances. This automated processing does not, by itself, produce a legal or similarly significant decision about you without an avenue for review — you may request human review of a decision that materially affects your account by contacting us at the email in Section 10. We do not use your personal information to train third-party general-purpose AI models.

4. How We Share Information

We do not sell your personal information. We share information only as described below:

4.1 Service providers. We share the minimum information necessary with the following categories of third-party service providers so they can perform services on our behalf: payment processing (Stripe, Inc.); airtime, mobile data, and prepaid fulfillment (Zendit, an IDT Corporation company, which in turn works with local telecom operators such as Ethio Telecom); SMS/phone verification (Twilio Inc.); and voice calling infrastructure (LiveKit, and, for calls to non-Beamline phone numbers, IDT Express). Each of these providers is authorized to use your information only as necessary to provide their service to us and is contractually or otherwise obligated to protect it.

4.2 Recipients. When you send a Beam, the recipient's telecom provider necessarily receives the recipient's phone number and the value/product being delivered, in order to complete delivery.

4.3 Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to investigate or prevent fraud, protect the safety of any person, protect Beamline's rights or property, or as part of a merger, acquisition, financing, or sale of assets.

4.4 With your direction. We may share information with other parties when you direct us to do so.

5. International Data Transfers

Beamline is based in the United States, and information about you (and about the contacts you send Beams to) is processed and stored in the United States. Because the Service is designed to deliver airtime, data, cash, or calls to recipients in Ethiopia and elsewhere, information necessary to complete those transactions — including a recipient's phone number and the value being sent — is transmitted to service providers and telecom operators located outside the United States, including in Ethiopia. By using the Service, you consent to this transfer and processing.

6. Data Retention

We retain account and transaction information for as long as your account is active and for a reasonable period afterward as necessary to comply with legal, tax, accounting, or regulatory requirements, resolve disputes, enforce our agreements, and prevent fraud. Our wallet ledger is append-only and retained indefinitely as a financial and audit record, consistent with standard practice for financial services.

When you delete your account (Section 8.1), we immediately remove or irreversibly de-identify the personal information that could otherwise identify you — your name, email address, and phone number are permanently replaced with a random, non-identifying placeholder, and the account is disabled such that it can no longer be logged into. We do not delete the underlying transaction and ledger records associated with the de-identified account: financial institutions and payment services are generally required to retain transaction records for a period of years for anti-money-laundering, tax, accounting, and dispute-resolution purposes, and we retain that data in de-identified form rather than deleting it outright. This is the same limited exception recognized by every US state comprehensive privacy law's deletion right (see Section 8.2) for information needed to comply with a legal obligation.

7. Data Security

We use administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, alteration, or disclosure, including hashing of passwords, encryption of data in transit, and access controls on internal systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of certain personal information we hold about you, or to object to or restrict certain processing. You can update your name, email, and phone number directly in the app. We may retain certain information as required by law or for legitimate business purposes described in Section 6 even after an account is closed.

8.1 Deleting your account, right in the app. You can permanently delete your account yourself, at any time, from Profile → Delete my account — no need to email us or wait on a request. After you confirm your password, deletion is immediate: your account is disabled so it can no longer be used, and your name, email, and phone number are permanently removed from our active systems as described in Section 6. You may also request deletion by contacting us at the email in Section 11 if you are unable to access the app; we will verify your identity before completing such a request and will respond within the time required by applicable law (see Section 8.2).

8.2 State privacy law rights. Beamline does not sell or "share" (as those terms are defined under state privacy laws, e.g. for cross-context behavioral advertising) your personal information. Depending on your state of residence, you may have rights to know/access, delete, correct, and obtain a portable copy of your personal information, to opt out of certain processing (including targeted advertising, sale/sharing, and certain profiling), and to non-discrimination for exercising these rights. This Policy is designed to honor these rights for residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive consumer privacy laws in effect from time to time. You may exercise any of these rights by using the in-app controls described above or by contacting us at the email in Section 11; we may need to verify your identity before completing certain requests, and where applicable law provides an appeal process for a denied request, we will describe how to appeal in our response. We do not charge a fee for exercising these rights and will not discriminate against you for doing so.

8.3 Financial information. Because Beamline facilitates money transfers, we apply safeguards to your financial and transaction information consistent with the privacy and safeguarding principles of the Gramm-Leach-Bliley Act, in addition to the state-law rights above.

8.4 Communications. You may opt out of promotional communications at any time using the instructions in those messages or by contacting us; you cannot opt out of transactional or account-related messages (such as verification codes or transaction confirmations) necessary to operate the Service.

9. Children's Privacy

The Service is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time; the "Effective date" above reflects the date of the latest revision. Material changes will be notified through the Service or by other reasonable means. Your continued use of the Service after a revised Policy takes effect constitutes your acceptance of it.

11. Contact Us

Questions or requests regarding this Privacy Policy or your information can be sent to contact@beamlinesystems.com.