Privacy Policy
First Bank Connect · Last updated May 15, 2026
Contents
- Introduction
- Data We Collect
- Financial Data
- Biometric Authentication
- Camera & QR Scanning
- Device Fingerprinting
- How We Use Your Data
- How We Share Your Data
- Data Retention
- Security Measures
- Your Rights
- Children’s Privacy
- Policy Changes
- Contact Us
1. Introduction
Afriland First Bank South Sudan (« the Bank », « we », « us », or « our ») operates the First Bank Connect mobile banking application (the « App ») available on Google Play and the Apple App Store. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the App.
By downloading, installing, or using First Bank Connect, you agree to the practices described in this policy. If you do not agree, please do not use the App.
This policy applies to:
- All registered customers of Afriland First Bank South Sudan using the App
- Visitors who browse the App without creating an account
- All devices (Android and iOS) on which the App is installed
This policy is compliant with applicable data protection regulations including the General Data Protection Regulation (GDPR), Google Play Data Safety requirements, and the data protection guidelines of the Bank of South Sudan.
2. Data We Collect
We collect the following categories of information when you use First Bank Connect:
2.1 Account & Identity Information
- Full name, phone number, and email address
- Account number(s) and bank account details
- Date of birth and national ID (collected during registration)
- Profile photo (if provided)
2.2 Financial Information
- Account balances and transaction history
- Payment details (amounts, dates, recipients, references)
- Bill payment records (electricity, merchants, etc.)
- Transfer beneficiaries you save
2.3 Technical & Device Information
- Device model, manufacturer, and operating system version
- App version and session activity logs
- IP address and network type (Wi-Fi / mobile data)
- Device identifiers used for security (see Section 6)
- Crash reports and performance diagnostics
2.4 Usage Data
- Features and screens accessed within the App
- Timestamps of logins and logouts
- Error logs and failed authentication attempts
Data you choose NOT to provide: Some features may be unavailable if you decline to provide certain data (e.g., camera access disables QR scanning; declining biometric setup means PIN-only login). Core banking functions are always available via PIN authentication.
3. Financial Data Handling
As a mobile banking application, First Bank Connect processes sensitive financial information. We treat this data with the highest level of security and discretion.
3.1 What Financial Data We Process
- Account balances retrieved in real time from Afriland First Bank South Sudan’s servers
- Transaction records: amount, currency, date, time, description, and counterparty details
- Payment instructions you initiate (transfers, bill payments, merchant payments)
- OTP (one-time password) codes used for transaction authorization — never stored after use
3.2 How We Protect Financial Data
- All data is transmitted over TLS 1.2+ encrypted connections
- Every API request is signed with HMAC-SHA256 to prevent tampering
- Access tokens are stored in the device’s secure hardware enclave (iOS Keychain / Android Keystore) — never in plain storage
- Access tokens expire after 60 minutes and are refreshed securely
- Financial data at rest is encrypted using AES-256
3.3 Currency & Multi-Account Support
The App supports multiple currencies (including SSP, USD, and others held at Afriland First Bank South Sudan). Each account’s currency is used as-is for payments and transfers — we do not silently convert or substitute currencies.
3.4 Regulatory Compliance
Financial transaction records are retained for a minimum of 7 years as required by financial regulations applicable to Afriland First Bank South Sudan. Transaction data may be disclosed to regulatory authorities (Bank of South Sudan, law enforcement) when legally required.
4. Biometric Authentication
Key commitment: Your biometric data (fingerprint or face scan) is processed entirely on your device. We never collect, transmit, or store your raw biometric data on our servers.
4.1 How Biometric Login Works
If you choose to enable biometric login, the App uses your device’s operating system APIs (Face ID / Touch ID on iOS, BiometricPrompt on Android) to verify your identity. The biometric template is stored exclusively in the device’s Secure Enclave or StrongBox hardware — a tamper-resistant chip isolated from the main processor.
4.2 What We Do NOT Do
- We do not receive, store, or process your fingerprint or face image
- We do not transmit biometric data over the network
- We do not use biometric data for any purpose other than unlocking the App
- We do not use biometrics for advertising, profiling, or analytics
4.3 Consent & Opt-Out
Biometric login is entirely optional. You can disable it at any time in the App settings or in your device’s system settings. Disabling biometric login reverts you to PIN-based authentication; all other features remain available.
4.4 Retention
Biometric authentication keys are automatically removed when you uninstall the App, disable biometric login in settings, or perform a factory reset of your device.
5. Camera & QR Code Scanning
Key commitment: Camera access is used exclusively for real-time QR code scanning. We do not record, save, or transmit any images or video from your camera.
5.1 Purpose
The App requests camera permission only when you choose to use the Scan & Pay feature to scan merchant QR codes. The camera processes each frame locally on your device to detect and decode QR codes. No image data leaves your device.
5.2 What the QR Scanner Reads
QR codes used with First Bank Connect follow the format afbss-mba://merchant/<TILL_NUMBER>. The App extracts only the merchant till number from this code to pre-fill the payment form. No other QR content is stored or transmitted beyond what is needed to complete your payment.
5.3 Your Control
- Camera permission is requested only when you open the QR scanner
- You can decline the permission — manual entry of the till number is always available
- You can revoke camera permission at any time in your device settings
5.4 No Third-Party Access
No third parties have access to your camera or to any camera data. The QR scanning library (mobile_scanner) operates entirely offline on your device.
6. Device Fingerprinting
For the security of your account and to comply with financial fraud prevention regulations, First Bank Connect collects a set of device-level identifiers to create a device fingerprint. This is a standard practice in mobile banking.
6.1 What We Collect for Fingerprinting
- Device model and manufacturer
- Operating system name and version
- App version and build number
- Screen resolution and density
- Network connection type
- A unique device installation ID (generated at first launch, not tied to hardware)
We do not collect your phone number’s SIM serial (IMSI), IMEI, MAC address, or any hardware identifier that uniquely identifies your physical device across apps.
6.2 Why We Collect This
- Fraud detection: Detect logins from unknown or suspicious devices
- Device registration: Validate that new devices are authorized by you via OTP
- Security audit trails: Identify the device used in each session for dispute resolution
- Regulatory compliance: Meet KYC/AML requirements applicable to digital banking
6.3 How It Is Transmitted
Device fingerprint data is sent with every authenticated API request via encrypted HTTP headers (X-Device-*, X-OS-*, X-App-*) over TLS 1.2+. It is also signed as part of the HMAC-SHA256 request signature.
6.4 Legal Basis
Device fingerprinting is processed on the basis of our legitimate interest in preventing fraud and protecting your account, and our legal obligation to comply with financial sector security regulations. This processing is necessary for the core security of the App and cannot be disabled while using the service.
7. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Process banking transactions (transfers, payments) | Account info, financial data | Performance of contract |
| Authenticate your identity (PIN, biometric) | Device ID, biometric (local) | Performance of contract |
| Prevent fraud and unauthorized access | Device fingerprint, IP, usage logs | Legitimate interest / Legal obligation |
| Send you transaction notifications and alerts | Phone number, email | Performance of contract |
| Provide customer support | Account info, transaction history | Performance of contract |
| Comply with AML/KYC regulations | Identity info, transaction data | Legal obligation |
| Generate receipts & PDF documents | Transaction data | Performance of contract |
| Improve App performance and fix bugs | Crash logs, usage data | Legitimate interest |
We do not use your data for targeted advertising, sell your data to third parties, or use your data to build profiles for marketing purposes.
8How We Share Your Data
We do not sell or rent your personal information. We may share your data only in the following limited circumstances:
8.1 Afriland First Bank South Sudan
First Bank Connect is the official mobile interface for Afriland First Bank South Sudan. Your data is shared with the Bank’s core banking system to process all financial operations. This sharing is necessary to provide the service.
8.2 Service Providers & Technology Partners
We use carefully vetted third-party service providers who process data on our behalf and are bound by data processing agreements. These include:
- Payment processors: to settle transfers and bill payments
- SMS/OTP gateway: to deliver one-time passwords to your phone
- Hosting and infrastructure providers: to run the API servers securely
These providers are not permitted to use your data for their own purposes.
8.3 Regulatory & Legal Disclosures
We may disclose your information to government authorities, regulators, or law enforcement when legally required to do so, including:
- The Bank of South Sudan (regulatory oversight)
- Tax authorities, financial intelligence units (AML/CFT compliance)
- Courts or law enforcement (when subject to a valid legal order)
8.4 With Your Explicit Consent
In situations not covered above, we will ask for your explicit consent before sharing your personal information with any third party.
PDF Receipts: When you use the « Share » button on a receipt, the PDF is generated on your device and passed directly to your device’s native share sheet. We do not receive or store the shared file. Sharing is fully under your control.
9. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Financial transaction records | 7 years after transaction | Regulatory/legal requirement |
| Account information | Duration of account + 3 years after closure | Legal obligation, dispute resolution |
| Authentication & session logs | 90 days | Security audit trail |
| Device fingerprint records | Duration of account + 1 year | Fraud prevention, compliance |
| OTP codes | Deleted immediately after use or expiry | Security (single-use) |
| Camera / QR data | Not stored — processed in memory only | Privacy by design |
| Biometric data | Stored locally on device only; deleted on uninstall | Privacy by design |
| Crash & diagnostic logs | 30 days | App stability improvements |
After the applicable retention period, data is securely deleted or anonymised so that it can no longer be linked to you personally.
10. Security Measures
We implement industry-standard and banking-grade security controls to protect your personal and financial information:
- Encryption in transit: All API communications use TLS 1.2+
- Request signing: Every API request is signed with HMAC-SHA256 using a secret key; unsigned requests are rejected
- Secure token storage: Authentication tokens are stored in the device’s hardware-backed secure storage (iOS Keychain / Android Keystore)
- Short-lived tokens: Access tokens expire after 60 minutes; refresh tokens are rotated on each use
- Device registration: New devices must be verified with an OTP before accessing your account
- Rate limiting & retry protection: API endpoints are rate-limited to prevent brute-force attacks
- PIN protection: Your PIN is never stored on device or transmitted in plaintext
- Biometric isolation: Biometric data never leaves the device’s secure hardware
- Production certificate pinning: The App validates the server’s TLS certificate in production builds
In the event of a security incident: If we become aware of a data breach that affects your personal information, we will notify you and the relevant authorities within the timeframe required by applicable law.
11. Your Rights
Depending on your country of residence, you may have the following rights regarding your personal data:
11.1 Right of Access
You can request a copy of the personal data we hold about you. We will respond within 30 days.
11.2 Right to Rectification
You can request correction of inaccurate personal data. For account details linked to your bank profile, please visit a branch or contact customer support.
11.3 Right to Erasure
You can request deletion of your personal data. Note that some data (financial transaction records) must be retained to meet legal and regulatory obligations and cannot be deleted on request.
11.4 Right to Data Portability
You can request an export of your transaction history and account data in a machine-readable format (CSV or JSON).
11.5 Right to Object
You can object to processing of your data for purposes based on legitimate interest (e.g., analytics). You cannot object to processing that is necessary for the performance of your banking contract or for legal compliance.
11.6 Account Deletion
You can request full account deletion by contacting us at quality@afrilandfirstbankss.com. Account deletion removes your access to First Bank Connect and initiates the data retention/deletion process as described in Section 9.
To exercise any of these rights, contact us at quality@afrilandfirstbankss.com or in writing at our Head Office. We will verify your identity before processing any request.
12. Children’s Privacy
First Bank Connect is intended for users who are at least 18 years of age and hold a valid Afriland First Bank South Sudan account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
13. Policy Changes
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the « Last updated » date at the top of this page
- Display an in-app notification on your next login
- For significant changes affecting your rights, we may send an email or SMS notice
Continued use of the App after a policy update constitutes acceptance of the revised terms. We encourage you to review this policy periodically.
14. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Afriland First Bank South Sudan
📍 Hai Cinema, PO BOX 640, Juba, South Sudan
📧 quality@afrilandfirstbankss.com
📧 firstbank_ss@afrilandfirstbankss.com
📞 +211 922 442 446
This Privacy Policy is governed by the laws of the Republic of South Sudan and applicable international data protection regulations. Any disputes arising from this policy shall be subject to the jurisdiction of South Sudanese courts.
First Bank Connect — Official mobile banking app of Afriland First Bank South Sudan
privacy@afrilandfirstbankss.com · Licensed by the Bank of South Sudan
Privacy Policy · Version 1.0 · Last updated May 15, 2026
