DCB V1 pilot
Privacy notice
V1 pilot update · October 6, 2026
This notice describes the information used to run and protect DCB's invited pilot accounts and test transactions.
Information we collect
- Account and onboarding details: email address, name, phone, address, date of birth, primary language, account type, and optional gender. Business and sponsor accounts also have account names and access roles.
- Wallet and activity records: DCB account identifiers and balances, transfer parties and amounts, optional transfer notes, payment requests and references, receipts, merchant inventory requests and review records, refunds and reasons, statuses, and timestamps.
- Recruiter workspace details: recruiter account information and merchant leads entered there, including business and contact names, contact email and phone, status, notes, and timestamps.
- Security records: sign-in and account events, the network address seen by the server, browser User-Agent information, and event times. A proxy may be the network peer recorded by the server.
- Support messages and information you choose to send to DCB.
How we use information
We use this information to create and manage accounts, check access permissions, process pilot DCB activity, display balances and receipts, review merchant activity, investigate errors or abuse, deliver account-recovery messages, and support pilot users.
Browser and camera
Account workspaces use session cookies for sign-in. Browser storage can hold a pending transfer operation key so an uncertain payment can be checked before another attempt, and a local sign-out lock flag. The merchant terminal keeps its lock flag across app restarts until server sign-out is confirmed. Installed app files may be cached by the browser. With your permission, the Wallet can use the camera to scan a payment QR code; you can enter the reference instead.
Service providers
The V1 pilot uses application hosting, a PostgreSQL database, a public web gateway, and configured email delivery for account recovery. V1 application infrastructure runs on DigitalOcean. The Merchant Terminal also uses a Render web gateway. Other provider details can change as the pilot is deployed.
Storage and security
Passwords are stored as salted Argon2id hashes, rather than reversible encrypted passwords. Session tokens and password-reset codes are stored as hashes. KALE receipts are signed with a server-managed key. No online service can promise perfect security; protect your password, reset codes, and devices.
Your choices
You may contact DCB to request access to, correction of, or deletion of account information. Some transaction and security records may need to be retained for dispute, security, or legal reasons.
Contact
Email security@dcbsend.com with privacy questions. Do not email your password or reset code.