1. Purpose and scope
This policy sets out how MonCashConnect, a service operated by Haipay LLC, a company registered in the United States of America, verifies the identity of its users, what we ask for, what we keep, for how long, and what rights you have. It supplements our privacy policy and terms of service; on any question of identity verification or compliance, this document prevails.
It applies to two categories of user:
- Merchants, who open an account and collect or send money through our APIs.
- Cardholders, whether individuals or merchants, to whom a MonCashConnect virtual card is issued. The card-specific provisions are in sections 7 to 10 and apply to every card issued under the programme.
It does not apply to our merchants' own customers. Someone paying a merchant through MonCash is not verified by MonCashConnect and never has to send us identity documents. Their identification, where required, is a matter for Digicel/MonCash and for the merchant.
2. Why we verify
MonCashConnect moves real money and, under the card programme, gives access to an international means of payment. Identity verification exists to:
- meet applicable anti-money-laundering and counter-terrorist-financing (AML/CFT) obligations;
- know who owns an account before allowing it to collect funds belonging to third parties;
- satisfy the requirements of our banking partners, issuing institutions and card networks, all of which require every cardholder to be fully identified;
- prevent identity theft, account takeover, and accounts opened for the purpose of fraud;
- allow us to respond to a legitimate request from a competent authority.
The fact that MonCashConnect charges no commission on its merchants' transactions changes none of this: these obligations attach to the movement of funds, not to our pricing model.
3. Who must verify, and when
Every user must be verified before handling real money. Verification is not required to explore and integrate the service.
3.1 Open without verification
- creating an account and signing in;
- creating a project and generating test keys (
sk_test_proj_…); - integrating and testing the entire API in sandbox, webhooks included;
- reading the documentation and using the dashboard and simulator.
3.2 Requires approved verification
- any API call made with a live key (
sk_proj_…): creating a payment, checking a status, checking a balance; - any payout to a MonCash number;
- any transfer between accounts;
- any withdrawal of your balance;
- requesting, issuing, loading or using a virtual card.
Until verification is approved, these operations are refused with an explicit kyc_required error. Your test integration keeps working normally in the meantime.
4. What we ask for
Verification rests on three things:
- A valid government-issued identity document, photographed front and back (national identity card, passport, or driver's licence).
- A selfie with a liveness check, to confirm that the person present is the person on the document, and that they are a real person rather than a replayed photo or video.
- The account details we already hold (name, email, phone), used to cross-check what is read from the document.
The process then reads the following from your document: given and family names, date of birth, document number, dates of issue and expiry, document type, issuing country or authority, nationality, and depending on the document, address and machine-readable zone (MRZ).
We may request additional information where the profile or the activity warrants it: proof of address, source of funds, nature of the business activity, incorporation documents for a legal entity, or a second identity document. Refusing to provide a requested item results in refusal or withdrawal of access to the functions concerned.
We will never ask for your password, your MonCash PIN, or a payment in order to carry out a verification. No member of our team will contact you to request them.
5. How verification works
- You open the verification page from your dashboard.
- We open a session with our provider and redirect you to it. The session stays valid for roughly 23 hours; after that you simply start a new one.
- You photograph your document and take a selfie directly inside the provider's interface.
- The check is automated and usually completes within minutes. The result is returned to us in a cryptographically signed notification, which we reject if the signature is missing or invalid.
- Your status becomes approved or refused, and on approval the relevant functions unlock immediately.
A session may also stay in progress if the provider requires further review, expire if you do not finish it, or be cancelled if you interrupt it. None of these states is final: you can always start again.
6. Our providers
Document and biometric checks are carried out by Didit(didit.me), an identity verification specialist acting as a processor for Haipay LLC.
To open a session we send it only an internal account identifier and a return address. Your photographs and document data are submitted by you directly to the provider: they do not pass through our servers. Images and video remain hosted with the provider; we keep no copy, only time-limited access links and the result of the analysis (section 13).
Virtual cards are issued by a licensed issuing institution and distributed over an international network. MonCashConnect acts as programme distributor: we identify the cardholder, apply this policy, and pass the issuer the identification data it requires. The issuer applies its own controls and may refuse or revoke a card independently of our decision.
7. Virtual cards: programme scope
The MonCashConnect virtual card is a prepaid payment method denominated in US dollars, intended for online purchases with merchants accepting the network. It exists in digital form only.
- Prepaid, never credit. No spending is possible beyond the loaded balance. We grant no overdraft, no deferred payment and no credit of any kind.
- Funded exclusively from your MonCashConnect balance, which itself consists of funds already traced by the MonCash network and by our ledger. No third-party loading, external transfer or cash loading is accepted.
- Named and personal. A card is attached to one verified person and may not be lent, transferred, or used by anyone else, including a family member.
- No cash access. The card allows no ATM withdrawal and no quasi-cash transaction.
Structural control. Because a card can only be loaded from a MonCashConnect balance, every amount reaching a card has already been identified on the way in, recorded in our ledger, and attached to a verified person. There is no anonymous, third-party or cash funding path.
8. Virtual cards: issuance conditions
No card is issued unless all of the following are satisfied:
- an approved identity verification under sections 4 and 5, current and unexpired;
- sanctions and politically exposed person screening with no unresolved match (section 12);
- an account that is not suspended and has no open compliance matter;
- a holder who is at least 18 years old, checked against the date of birth read from the document;
- acceptance of the card programme terms and, where applicable, those of the issuing institution.
A card is issued in the name of the verified holder only. We do not issue anonymous cards, bearer cards, cards in the name of a third party, or cards to anyone whose identity has not been confirmed by the means described in this policy.
We may refuse a card request without affecting the rest of your account, and we may limit the number of active cards per holder.
9. Virtual cards: source of funds and limits
A card can only be loaded from funds already sitting in your MonCashConnect balance. Those funds come either from payments collected through our APIs or from a MonCash top-up in your name. This constraint is deliberate: it guarantees that any amount reaching a card has already been identified, recorded in our ledger, and attached to a verified person.
We may ask you to evidence the source of funds where amounts, frequency or patterns do not match the declared activity, and may suspend loading while we review.
Cards are subject to limits: maximum amount per transaction, per day and per month, maximum balance held, and number of cards per holder. These limits are shown in your dashboard, are applied proportionately to the risk of the profile, and may be raised after further verification or lowered where an anomaly appears.
10. Virtual cards: prohibited uses
The following are prohibited and result in immediate blocking of the card, without prejudice to a report where the law requires one:
- any unlawful activity, and the purchase of illegal goods or services, weapons, narcotics, or child sexual abuse material;
- use by anyone other than the holder, sharing of the card details, or use on behalf of a third party;
- gambling and betting, where the network or the issuer prohibit them for this card type;
- buying, selling or exchanging virtual assets, where the network or the issuer prohibit them;
- transactions with any person, entity or country subject to applicable sanctions;
- deliberately splitting transactions to stay under a limit or evade a control;
- any transaction designed to convert the card into cash or to effect a disguised money transfer.
11. Ongoing monitoring
Initial verification is not a one-off check. Throughout the relationship:
- we monitor collection, payout, loading and spending activity for patterns that are unusual against the declared profile;
- we periodically re-screen holders against sanctions and politically exposed person lists, since a match can appear after issuance;
- we require re-verification when the identity document used reaches expiry, when the information we hold becomes stale, or after a security incident on the account;
- we apply enhanced due diligence where activity is unrelated to the declared use, where volumes are disproportionate, where a list match occurs, where there is a link to a high-risk jurisdiction, or where we receive a report from a partner or an authority.
These measures can lead to a request for information, reduced limits, temporary suspension of a card or an account, or termination of the relationship.
12. Sanctions and politically exposed person screening
Every holder is screened automatically against sanctions and politically exposed person lists at onboarding, before any card is issued, and periodically thereafter.
A match is not an accusation: it suspends the operation concerned and triggers a manual review by an authorised person. Depending on the outcome, the match is cleared, or it leads to a request for further information, enhanced due diligence, refusal to issue, or, where the law requires it, freezing of funds and closure of the account.
We do not open accounts or issue cards to any person or entity subject to applicable sanctions, nor to a person resident in an embargoed jurisdiction.
13. What we keep in our systems
We keep the full verification result, so that we can demonstrate our obligations were met and can re-examine a contested decision. Specifically:
- the verification status and its dated history;
- the provider's session identifier;
- the data read from your document: name, date of birth, document number and type, dates of issue and expiry, issuing authority, nationality, and where applicable address and MRZ;
- the technical indicators of the check: face match score, liveness result, image quality indicators, any warnings;
- the result of the provider's supplementary checks (phone, email, list screening);
- time-limited links to the images hosted with the provider;
- the reason, in the event of refusal;
- for cards: the card identifier at the issuer, its status, its limits, the history of loads and transactions, and any compliance decisions taken about it.
Sensitive card data. The full card number, expiry date and security code are held by the issuing institution and shown to you through its secure interface. They are never written to any Haipay LLC database.
This data is stored with row-level isolation: a holder can read only their own verification sessions and their own cards.
14. Retention period
Verification data and card transaction records are kept for five (5) years from the end of the business relationship, in line with standard AML/CFT retention periods and consistent with our privacy policy.
A request to delete an account therefore does not delete these records immediately: they are isolated, stop being used for any other purpose, and are deleted at the end of the period. Abandoned, expired or cancelled sessions that never resulted in an approval are kept for a shorter time, as long as needed to detect abuse.
15. Who can access your verification data
- You, for your own sessions and your own cards.
- Authorised administrators, for compliance review, re-examination, or investigation of reported fraud. These accesses and any manual status change are logged.
- Our verification provider, solely to perform the check.
- The issuing institution and the card network, for the identification data they require and for their own compliance obligations.
- Competent authorities, on a valid legal request.
We do not sell this data, do not use it for advertising, and do not pass it to any other merchant.
16. Automated decisions and human review
The decision to approve or refuse is automated, based on the provider's document and biometric analysis. It has a concrete effect on you, since it governs access to live functions and to any card.
You have the right to request review by a person. Write to privacy@moncashconnect.com with your account email and the date of the attempt. An administrator can correct a status manually where review warrants it. Blocking decisions taken on sanctions grounds are always reviewed by a person before they become final.
17. Possible outcomes and what to do next
| Status | What it means | What you can do |
|---|---|---|
| Approved | Identity confirmed | Live keys and card requests available |
| In progress | Check unfinished or under further review | Wait; we notify you of the result |
| Refused | Document unreadable, expired, unrecognised, or face mismatch | Retry with a valid document, or request human review |
| Expired / cancelled | Session not completed in time, or interrupted | Start a new verification |
A refusal does not delete your account and does not cost you your test integration.
18. Refusal, suspension and closure
- Without approved verification your account stays open and your test environment stays fully usable, but live calls, payouts, transfers, withdrawals and any card remain refused.
- A card may be blocked immediately for prohibited use (section 10), suspected fraud, a sanctions list match, or at the request of an authority.
- No funds belonging to you are confiscated. If a balance or card balance is caught by a compliance review, it is frozen for the duration of that review and then returned, unless the law requires otherwise.
- In cases of proven fraud, persistent refusal to provide a required item, or legal obligation, the account and any associated cards may be closed.
19. Suspicious activity reporting
Where the law requires it, we report suspicious transactions to the competent financial intelligence authority, and we respond to requests from judicial and regulatory authorities.
Such a report is confidential: we can neither tell you it exists nor disclose its contents. A lack of detail in answer to a question about a block may have this cause, and is in no sense an accusation.
20. Your rights
- Access: obtain a copy of the verification data we hold about you.
- Rectification: correct inaccurate data, for example a name misread from the document.
- Erasure: request deletion, subject to the legal retention period in section 14.
- Objection and restriction: contest a processing activity, other than our legal compliance obligations.
- Human review of an automated decision, as set out in section 16.
- Complaint to the competent data protection authority.
We respond within one month. Proof of identity may be required to handle the request, precisely to stop a third party obtaining your data. Some rights yield to our retention and confidentiality obligations under AML/CFT rules.
21. Security
- Verification data is isolated per holder at the database level.
- Sensitive card data is not stored by us: it stays with the issuing institution.
- Result notifications are signed with HMAC-SHA256 and rejected if the signature is missing or invalid, so no third party can declare an account verified.
- Administrative access and manual status changes are logged with author and timestamp.
- Data is encrypted in transit.
To report a vulnerability: security@moncashconnect.com.
22. Minors
The service is restricted to people aged 18 and over, and no card is issued to a minor. A verification revealing a lower age results in refusal, and the account is closed.
23. Changes to this policy
This policy may change, in particular if we change verification provider or issuing institution, or if the applicable regulation changes. Substantial changes are notified by email and/or by a banner in the dashboard, with their effective date. The version in force is always the one published on this page.
24. Contact
- Verification and data questions: privacy@moncashconnect.com
- Security: security@moncashconnect.com
- General support: support@moncashconnect.com
MonCashConnect is a service of Haipay LLC, a limited liability company registered in the United States of America. Operations: Port-au-Prince, Haiti.