instantcards converts your MTN MoMo, Orange Money, or M-Pesa balance into a real Visa or Mastercard — accepted everywhere online, instantly. No bank account. No paperwork. No waiting.
From opening the app to paying on Amazon in under a minute. No branch visit. No form to fill.
Sign up with your phone number and a PIN. Your wallet is created automatically — no documents needed for basic use.
Choose MTN MoMo, Orange Money, or any supported provider. Enter your amount, confirm the USSD prompt. Done.
Your wallet is credited in seconds. Every transaction is verified independently against the payment provider's records.
Tap "New Card". Choose Visa or Mastercard. Receive your virtual card number, CVV, and expiry instantly. Shop anywhere online.
From tapping "New Card" to a live Visa or Mastercard in your wallet — no waiting, no approval process.
Your instantcards virtual card works wherever Visa or Mastercard is accepted online — that's over 100 million merchants globally.
Your card number and CVV are encrypted before they ever touch our database. They only exist in plain text for 60 seconds after PIN authentication.
Freeze any card with one tap. Unfreeze instantly. Set spending limits. Terminate permanently. You are always in control.
All you need is a mobile money account. No employer letter, no credit history, no branch visit, no waiting weeks.
Fund your wallet from any major mobile money network across 12 African countries. One app, every provider.
We support every major mobile money provider across anglophone and francophone Africa.
Card numbers (PAN) and CVV codes are encrypted with AES-256-CBC before storage. They are never logged or transmitted in plain text — ever.
Card details are visible for only 60 seconds after PIN authentication. After that, they are auto-masked. The decrypted values are never persisted after reveal.
Your PIN is hashed with bcrypt (cost factor 12). Never stored in plain text. Never logged. All sensitive operations require PIN verification.
Our settlement engine verifies every payment independently via Flutterwave's verification API before crediting your wallet. Duplicate webhooks cannot double-credit your account.
Operates under COBAC R-2019/02 as a technology aggregation layer. MTN and Orange hold the required e-money licences.
Three-tier KYC aligned with COBAC thresholds. Basic use requires phone verification only (inherited from MoMo KYC). Higher limits require ID.
Velocity limits, threshold monitoring, wallet locking for suspicious activity, and Flutterwave's built-in AML screening on all transactions.
Card data handled exclusively by Sudo Africa, a PCI-compliant Visa/Mastercard programme manager. Lowest PCI scope category.
User data on MongoDB Atlas Frankfurt — EU-equivalent data protection. Financial data never stored on in-country servers.
Download instantcards and get your first virtual Visa or Mastercard in under a minute. Free to download, free to register.
instantcards exists to solve one of Africa's most persistent digital divides: hundreds of millions of people have mobile money but cannot make a single purchase online. We build the bridge between Africa's thriving mobile money ecosystem and the global internet economy.
Our platform converts Mobile Money balances — MTN MoMo, Orange Money, M-Pesa, Wave, and others — into real, globally accepted virtual Visa and Mastercard payment cards in under 10 seconds. No bank account. No branch visit. No paperwork.
The website you're reading is operated by Sanaga Digital (sanagadigital.app). The product advertised is instantcards, accessible at instantcards.app.
Sub-Saharan Africa now has more mobile money accounts than bank accounts. MTN MoMo, Orange Money, M-Pesa, and Wave collectively process hundreds of billions of dollars per year. Yet the moment a user tries to pay for anything online — a Netflix subscription, a Coursera course, cloud hosting, or an international flight — they hit a wall. Mobile money has no card number, no CVV, and is not accepted by any international payment gateway.
instantcards is the missing layer. We convert what Africans already have into the instrument the global internet requires.
| Partner | Role | Type |
|---|---|---|
| Flutterwave | Mobile money collection — anglophone Africa (11 markets) | Licensed payment aggregator |
| CinetPay | Mobile money collection — XOF francophone belt | Licensed payment aggregator |
| Sudo Africa | Virtual Visa and Mastercard card issuance | Visa/Mastercard programme manager |
| Smile Identity | KYC document verification (Tier 2) | Identity verification provider |
General enquiries: hello@instantcards.app
Support: support@instantcards.app
Legal & compliance: legal@instantcards.app
This Privacy Policy ("Policy") explains how instantcards, a product of Sanaga Digital operating at instantcards.app and sanagadigital.app ("we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use our mobile application, website, and payment services (collectively, the "Service"). We are committed to handling your data lawfully, transparently, and in accordance with applicable data protection and financial services legislation across all markets in which we operate.
Key principle: We collect only what we need to provide the Service, protect it with industry-leading encryption, never sell it to third parties, and give you meaningful control over it at all times.
Data Controller: Sanaga Digital (trading as instantcards)
Product: instantcards.app
Website: sanagadigital.app
Data Protection Contact: legal@instantcards.app
For data protection enquiries, identity verification, or to exercise your rights, please contact us at the address above. We will respond within 30 calendar days.
This Policy applies to all personal data we collect and process in connection with:
| Category | Specific data | When collected |
|---|---|---|
| Identity data | First name, last name, date of birth (Tier 2 KYC) | Registration / KYC |
| Contact data | Phone number, email address (optional) | Registration |
| Credential data | PIN — stored exclusively as a bcrypt hash (cost 12); never in plain text | Registration / PIN change |
| KYC documents | National ID number, passport number, document photograph, selfie (Tier 1 / 2) | KYC verification |
| Country of residence | Two-letter ISO country code | Registration |
| Category | Specific data | Purpose |
|---|---|---|
| Wallet data | Balance, currency denomination, transaction history | Service delivery |
| Transaction data | Amount, timestamp, provider reference, Flutterwave/CinetPay transaction ID, status, fee charged | Settlement, audit, support |
| Card data (encrypted) | Masked PAN (last 4 digits visible); full PAN and CVV stored AES-256-CBC encrypted; expiry date; card network; card status | Card management |
| Device data | Expo push notification token; operating system type (iOS/Android) | Push notifications |
| Authentication data | JWT token (device-side only); token expiry; last login timestamp | Security, session management |
| KYC status | Tier (0/1/2), verification status (none/pending/verified/rejected), rejection reason | Limit enforcement, compliance |
| Processing activity | Legal basis | Details |
|---|---|---|
| Creating and managing your account | Performance of contract | Necessary to provide the Service you have contracted for |
| Processing mobile money top-ups | Performance of contract | Core service delivery |
| Issuing and managing virtual cards | Performance of contract | Core service delivery |
| KYC identity verification | Legal obligation | Required under COBAC R-2019/02, FATF Recommendations, and applicable AML/CFT law |
| AML transaction monitoring and fraud prevention | Legal obligation / Legitimate interest | Required by financial crime regulations; necessary to protect users and the platform |
| Sanctions screening | Legal obligation | Required under OFAC, UN, EU, and African Union sanctions regimes |
| Retaining financial records | Legal obligation | 7-year minimum retention under financial audit regulations |
| Sending push notifications (wallet credits, card spend) | Consent | You grant permission when you enable notifications in-app |
| Customer support | Legitimate interest | Necessary to resolve queries and disputes |
| Service security and fraud detection | Legitimate interest | Protecting the platform and all users from fraud and cyberattack |
| Anonymised service improvement analytics | Legitimate interest | Improving the product; data anonymised before use |
<iv_hex>:<ciphertext_hex>. Encryption key held exclusively in server-side environment variables, never in source code or version control.GET /cards endpoint returns only the masked PAN (last 4 digits).POST /cards/:id/reveal endpoint, which is rate-limited and audited.crypto.timingSafeEqual() to prevent timing attacks.npm audit) run in CI/CD. High and critical vulnerabilities block deployment.User data is stored on MongoDB Atlas, hosted in the Frankfurt, Germany region. This region operates under EU-equivalent data protection standards. No sensitive financial data is stored on servers physically located within any user's country of residence unless specifically required by applicable local law.
Push notification delivery is facilitated by Expo Push Notification Service, which uses Apple Push Notification Service (APNs) for iOS and Firebase Cloud Messaging (FCM) for Android. Notification payloads are minimised and do not contain card numbers, CVV codes, or account balances.
| Data type | Retention period | Reason |
|---|---|---|
| Account identity data | Account lifetime + 5 years after closure | Regulatory and AML/CFT requirements |
| Transaction records | 7 years minimum | Financial audit obligations; AML/CFT record-keeping requirements |
| Encrypted PAN and CVV | Card lifetime + 7 years | Payment dispute resolution; regulatory audit |
| KYC documents | As per Smile Identity policy (typically 5–7 years) | Financial services regulatory requirement |
| Push notification device tokens | Until removed by user or device change | Service delivery |
| Application error logs | 90 days | Operational troubleshooting |
| Authentication tokens | 7-day access token; 30-day refresh token | Session management |
| Customer support records | 3 years after last interaction | Dispute resolution; regulatory audit |
We do not sell, rent, or trade your personal data. We share your data only as follows:
| Recipient | Data shared | Purpose | Legal basis |
|---|---|---|---|
| Flutterwave | Normalised phone number, transaction reference (tx_ref), amount, currency | Initiating mobile money charge via USSD | Contract performance |
| CinetPay | Normalised phone number, transaction reference, amount, currency | Mobile money collection for XOF-belt markets | Contract performance |
| Sudo Africa | Minimal data required to create a card customer profile and issue a card | Virtual Visa/Mastercard issuance and management | Contract performance |
| Smile Identity | Name, date of birth, ID document details, document photograph | Tier 2 KYC identity verification | Legal obligation / consent |
| Expo / Apple / Google | Device push token; notification content (no card data) | Delivery of push notifications | Consent |
| Legal authorities | As required by law, court order, or regulatory request | Compliance with legal obligations; fraud prevention | Legal obligation |
| Business acquirer | All user data (in the event of merger/acquisition) | Business continuity | Legitimate interest; user notification provided |
All third-party processors are contractually bound to process your data only for the specified purposes, under equivalent confidentiality and security obligations, and in compliance with applicable data protection law.
Flutterwave is incorporated in the United States and operates across multiple African jurisdictions. CinetPay operates from Côte d'Ivoire. Sudo Africa operates from Nigeria. Smile Identity operates from the United States. Data transfers to these recipients are governed by their respective data processing agreements and applicable international transfer mechanisms. We perform due diligence on all processors prior to engagement to ensure adequate data protection standards are in place.
The instantcards mobile application does not use cookies. Our website (sanagadigital.app / instantcards.app) uses only strictly necessary cookies required for basic functionality (e.g. session state). We do not use:
We use automated systems for:
Where a significant automated decision affects you (e.g. account freeze or transaction refusal), you have the right to request human review. Contact legal@instantcards.app.
Depending on your country of residence, you may have the following rights under applicable data protection law. We will honour these rights to the fullest extent permitted:
| Right | Description | Limitations |
|---|---|---|
| Right of access | Request a copy of all personal data we hold about you | Identity verification required |
| Right of rectification | Correct inaccurate or incomplete personal data | May not apply to immutable audit records |
| Right of erasure ("right to be forgotten") | Request deletion of your personal data | Subject to our legal retention obligations (7-year financial records) |
| Right to restrict processing | Request we limit how we use your data while a dispute is resolved | May temporarily suspend service |
| Right to data portability | Receive your data in a structured, machine-readable format (JSON) | Applies to data you provided; not derived data |
| Right to object | Object to processing based on legitimate interest | We will balance your interests against ours |
| Right to withdraw consent | Withdraw consent for push notifications at any time (in-app or by contacting us) | Does not affect processing before withdrawal |
| Right not to be subject to automated decisions | Request human review of significant automated decisions | See Section 11 |
To exercise any right, contact legal@instantcards.app with your name, phone number, and a clear description of your request. We will respond within 30 calendar days. We may request identity verification before processing sensitive requests.
instantcards is not directed to, and does not knowingly collect personal data from, individuals under the age of 18. The Service requires a mobile money account, which itself requires minimum age verification by the mobile network operator. If we become aware that a minor has registered, we will immediately delete their account and associated data. If you believe a minor has registered, contact legal@instantcards.app.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and in any case within 72 hours of becoming aware of the breach. Notification will include: the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address the breach.
We will also notify the relevant data protection authority or financial services regulator as required by applicable law.
We may update this Policy to reflect changes in our practices, our Service, or applicable law. Material changes will be communicated via push notification and/or email (if provided) at least 14 days before they take effect. The "Last updated" date at the top of this Policy will be revised accordingly. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not accept material changes, you must stop using the Service and contact us to close your account.
For all privacy matters: legal@instantcards.app
You also have the right to lodge a complaint with the relevant data protection supervisory authority or financial regulator in your country of residence. In Cameroon, this is the Commission Nationale de l'Informatique et des Libertés (CNIL Cameroun) or the COBAC for financial services matters.
These Terms and Conditions of Service ("Terms") constitute a legally binding agreement between you ("User", "you") and Sanaga Digital (trading as instantcards), the operator of the instantcards mobile application and the websites instantcards.app and sanagadigital.app (collectively, the "Service"). By downloading, installing, registering for, or using the Service in any way, you confirm that you have read, understood, and agree to be bound by these Terms and all policies incorporated by reference (including our Privacy Policy and AML/CFT Policy).
If you do not agree to these Terms, you must not use the Service. These Terms contain important provisions on fees, liability limitations, dispute resolution, and your obligations as a user. Please read them carefully.
instantcards is a financial technology platform that enables users to convert mobile money balances into virtual Visa and Mastercard payment cards for use in online transactions. instantcards is a product of Sanaga Digital. The Service is available at instantcards.app and advertised at sanagadigital.app.
instantcards operates as a technology aggregation layer. It is not a bank, an e-money institution, or a card issuer. Mobile money collection is provided by licensed payment aggregators (Flutterwave and CinetPay). Card issuance is provided by Sudo Africa, a licensed Visa and Mastercard programme manager. instantcards does not hold client funds in its own accounts.
To register for and use the Service, you must:
By registering, you represent and warrant that you meet all of the above requirements and will continue to do so throughout your use of the Service. We reserve the right to verify your eligibility at any time and to suspend or terminate your account if eligibility requirements are not met.
You must provide accurate, complete, and current information at registration, including your legal name, phone number, and country of residence. You agree to update your information promptly if it changes. Providing false registration information is a ground for immediate account termination and may constitute a criminal offence.
Your account is secured by a 4–6 digit PIN. You are solely responsible for keeping your PIN confidential. You must not:
You must notify us immediately at support@instantcards.app if you become aware or suspect that your PIN or account has been compromised. You accept responsibility for all transactions and activities that occur under your account credentials, whether or not authorised by you, until you have notified us and we have taken remedial action. We will not be liable for losses arising from your failure to keep your credentials secure.
You may hold only one instantcards account. Creating multiple accounts to circumvent transaction limits, KYC thresholds, or any other restriction is a material breach of these Terms and grounds for permanent suspension of all associated accounts.
You may fund your instantcards wallet by initiating a mobile money transfer from a supported provider in your country. Upon initiating a top-up:
A service fee of 1.5% of the top-up amount is charged on every successful top-up. This fee is clearly displayed before you confirm any transaction. The fee is non-refundable once the transaction has settled.
Your wallet is denominated in the local currency of your country of residence (e.g. XAF for Cameroon, GHS for Ghana, KES for Kenya). The currency is fixed at registration and cannot be changed. Wallet balances cannot be converted between currencies within the platform.
Minimum and maximum top-up amounts are determined by your KYC tier, your mobile money provider's own limits, and our platform limits. These limits are displayed in-app and may be updated from time to time. We reserve the right to reject any top-up that falls outside permitted limits without liability.
If a mobile money deduction is confirmed by your provider but your wallet is not credited within 10 minutes, contact support@instantcards.app with your transaction reference number. We will investigate within 3 business days. In confirmed cases of failed settlement due to our error, the full amount (including fee) will be refunded to your mobile money account within 5 business days.
You may use your wallet balance to generate a virtual Visa or Mastercard payment card. Each card is issued by Sudo Africa, a licensed Visa and Mastercard programme manager. A flat card generation fee (displayed at the time of generation) is deducted from your wallet balance. You must have sufficient wallet balance to cover the generation fee plus any minimum card load amount required by Sudo Africa.
Upon issuance, you will receive a virtual card number (PAN), CVV code, and expiry date. These details are:
You are responsible for keeping your card details confidential. Do not share your PAN, CVV, or expiry date with any party you do not trust to process a legitimate payment.
Your virtual card may be used for:
Your virtual card must not be used for:
Violation of these prohibited uses may result in immediate card termination, account suspension, freezing of wallet funds pending investigation, and reporting to relevant authorities.
| Operation | Effect | Reversible? | Fee |
|---|---|---|---|
| Freeze card | All transactions declined immediately; card cannot be used until unfrozen | Yes | Free |
| Unfreeze card | Card restored to active status; transactions permitted again immediately | Yes | Free |
| Terminate card | Card permanently deactivated; cannot be restored; any unspent card balance may be lost | No — permanent | Free |
| Reveal PAN/CVV | Decrypted card details displayed for 60 seconds; PIN verification required | N/A | Free |
Virtual cards are denominated in USD (Sudo Africa requirement). When you generate a card with a spending limit set in your local currency, a foreign exchange conversion is applied. instantcards applies a 2% markup over the interbank rate on this conversion. This FX markup is a revenue stream for instantcards and is displayed before you confirm card generation. For XAF (Central African CFA Franc), note that XAF is pegged to EUR at a fixed rate, which affects the EUR/XAF leg of the XAF/USD conversion.
If you identify a transaction on your virtual card that you did not authorise:
Failure to report within 30 days may limit our ability to pursue a chargeback on your behalf. We cannot guarantee a successful chargeback outcome as this is determined by Visa/Mastercard rules and the merchant's bank.
| Service | Fee | When charged | Refundable? |
|---|---|---|---|
| Mobile money top-up | 1.5% of top-up amount | On successful settlement | No (except in cases of our error) |
| Virtual card generation | Flat fee (displayed at generation; varies by market) | On card issuance | No |
| FX conversion (card spend in non-local currency) | 2% markup over interbank rate | At card generation / spend event | No |
| Card freeze / unfreeze | Free | N/A | N/A |
| Card termination | Free | N/A | N/A |
| Card reveal (PAN/CVV) | Free | N/A | N/A |
| Account registration | Free | N/A | N/A |
| Account maintenance | Free | N/A | N/A |
We reserve the right to modify our fee schedule with 30 days' written notice to users via push notification and/or email. Continued use of the Service after the notice period constitutes acceptance of the revised fees.
We are required by applicable financial services legislation, including COBAC Regulation R-2019/02 and the FATF Recommendations, to verify the identity of our users. Our KYC programme is tiered:
| Tier | Verification required | Monthly top-up limit | How to achieve |
|---|---|---|---|
| Tier 0 (default) | Phone number only (inherited from mobile money KYC performed by your MNO) | XAF 150,000 / GHS 500 / KES 5,000 or local equivalent | Automatic at registration |
| Tier 1 (standard) | National ID number or passport number (self-declared) | 3× Tier 0 limit | Submit in Profile → KYC |
| Tier 2 (enhanced) | Document photograph + biometric verification via Smile Identity | 10× Tier 0 limit | Submit in Profile → KYC |
You agree to provide accurate, genuine KYC information. Providing false documents is a criminal offence. We reserve the right to request additional information at any time for Enhanced Due Diligence (EDD) purposes, including for Politically Exposed Persons (PEPs) or users transacting at elevated volumes. Failure to complete required KYC may result in transaction limits being enforced or your account being suspended.
In addition to the card-specific prohibitions in Section 5.4, you must not:
We may immediately and without prior notice suspend, restrict, or terminate your account if:
In cases of account suspension for investigation, we will communicate the suspension and expected timeline to you unless prohibited from doing so by law (e.g. due to the AML tipping-off prohibition).
You may close your account at any time by contacting support@instantcards.app. Before closure:
Upon termination, all licences granted to you under these Terms are immediately revoked. Data is retained for the periods set out in our Privacy Policy. Termination does not affect any rights or obligations that accrued before termination.
We target 99.5% monthly uptime for the API. The Service may be temporarily unavailable due to:
We are not liable for losses arising from service interruptions beyond our reasonable control. We will use commercially reasonable efforts to restore service as promptly as possible.
All intellectual property rights in the instantcards application, brand, website, source code, algorithms, designs, trademarks, documentation, and all other proprietary materials are owned exclusively by Sanaga Digital or its licensors. Nothing in these Terms grants you any right, title, or interest in our intellectual property. You may not:
The Service is provided "as is" and "as available" without warranties of any kind, express or implied, to the maximum extent permitted by applicable law. We do not warrant that:
To the maximum extent permitted by applicable law:
Nothing in these Terms limits our liability for death or personal injury caused by our gross negligence, fraud, or any other matter that cannot be excluded by law.
You agree to indemnify, defend, and hold harmless Sanaga Digital, its officers, directors, employees, agents, and partners from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from or related to: (a) your use of the Service in violation of these Terms; (b) your violation of any applicable law; (c) your provision of false, misleading, or inaccurate information; (d) any third-party claim arising from your actions on the platform.
These Terms shall be governed by and construed in accordance with the laws of Cameroon, without regard to its conflict of laws principles.
Before commencing formal proceedings, you agree to contact us at legal@instantcards.app and attempt to resolve the dispute informally. We will use good faith efforts to resolve the dispute within 30 calendar days.
If informal resolution fails, any dispute, controversy, or claim arising from or relating to these Terms or the Service shall be submitted to the exclusive jurisdiction of the competent courts of Douala, Cameroon. Each party irrevocably submits to the personal jurisdiction of those courts.
Nothing in these Terms prevents either party from seeking urgent injunctive, interim, or emergency relief before any court of competent jurisdiction anywhere in the world, including to protect intellectual property rights or prevent irreparable harm.
We shall not be liable for any failure or delay in performing our obligations under these Terms to the extent that such failure or delay is caused by circumstances beyond our reasonable control, including but not limited to: acts of God, natural disasters, pandemic or epidemic, war, civil unrest, government action, regulatory changes, telecommunication network failures, power outages, or actions of mobile network operators. We will notify you of such circumstances promptly and use commercially reasonable efforts to minimise their impact and resume normal service.
We may update these Terms at any time. We will provide at least 14 days' advance notice of material changes via push notification and/or email (if provided). The updated Terms will be posted on our website with a revised "Last updated" date. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms. If you do not accept material changes, you must stop using the Service and request account closure before the effective date.
If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision shall be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible, and the remaining provisions shall continue in full force and effect.
Our failure to enforce any provision of these Terms on any occasion does not constitute a waiver of that provision or our right to enforce it in the future.
These Terms, together with our Privacy Policy and AML/CFT Policy (each incorporated by reference), constitute the entire agreement between you and instantcards with respect to the Service and supersede all prior negotiations, representations, agreements, or understandings, whether oral or written.
Legal enquiries: legal@instantcards.app
Support: support@instantcards.app
instantcards — a product of Sanaga Digital — sanagadigital.app
instantcards (Sanaga Digital) is committed to the highest standards of anti-money laundering (AML) and counter-terrorism financing (CFT) compliance. We recognise that financial technology platforms can be misused for financial crime, and we take our obligations and responsibilities in this regard with the utmost seriousness. This Policy sets out the framework we apply to prevent, detect, and report financial crime across all markets in which we operate.
Zero tolerance: instantcards has zero tolerance for money laundering, terrorist financing, sanctions evasion, or any other financial crime. Any user found to be using the platform for such purposes will have their account immediately frozen, funds held pending investigation, and the matter reported to the relevant authorities.
Our AML/CFT programme is designed to comply with, and exceed where possible, the requirements of:
instantcards operates as a technology aggregation layer, not as a licensed e-money institution or card issuer. The AML/CFT obligations are shared across the following licensed entities in our value chain:
| Regulated function | Licence holder | instantcards role |
|---|---|---|
| Mobile money account holding and transfer | MTN, Orange, Safaricom, and other MNOs (each independently licensed) | Technology interface only — never holds MoMo float |
| Payment aggregation and USSD routing | Flutterwave (licensed across multiple jurisdictions) and CinetPay | API client — bound by their AML/CFT terms |
| Card issuance and card programme management | Sudo Africa (Visa/Mastercard programme manager licence) | API client — bound by Sudo Africa and card network AML requirements |
| KYC identity verification | Smile Identity (licensed identity verification provider) | API client for Tier 2 KYC |
Despite this structure, instantcards accepts that it has independent AML/CFT obligations as a financial technology intermediary and takes full responsibility for the controls described in this Policy.
All users must be identified and verified before they can transact above Tier 0 limits. Our KYC programme applies Customer Due Diligence (CDD) and, where appropriate, Enhanced Due Diligence (EDD):
| Tier | Due Diligence Level | Verification | Monthly Limit (XAF equivalent) |
|---|---|---|---|
| Tier 0 | Simplified CDD | Phone number (via MNO KYC) | XAF 150,000 |
| Tier 1 | Standard CDD | Self-declared national ID or passport number | XAF 450,000 |
| Tier 2 | Standard CDD + biometric | Document photo + Smile Identity biometric check | XAF 1,500,000 |
| EDD | Enhanced Due Diligence | Additional information required (source of funds, PEP declaration, etc.) | Case-by-case |
EDD is applied automatically or upon manual review trigger to any user who:
KYC is not a one-time event. We conduct ongoing due diligence including:
All transactions are monitored in real-time by our automated systems for the following patterns:
Flagged transactions and accounts are reviewed by a compliance officer within 2 business days. The compliance officer may: clear the flag and allow the transaction; request additional information from the user; suspend the account pending further investigation; or escalate to Suspicious Activity Reporting (SAR).
All transaction records are retained for a minimum of 7 years from the date of the transaction, in a format that can be retrieved and submitted to regulators on request within a reasonable timeframe. Records include: transaction amount, currency, timestamp, provider reference, settlement status, user ID, and the full Flutterwave/CinetPay verification response.
instantcards screens all users at registration and on an ongoing basis against the following sanctions lists:
A positive match or potential match triggers immediate account suspension and escalation to the compliance officer. Confirmed matches result in permanent account termination, freezing of all wallet funds pending regulatory direction, and mandatory reporting to the relevant Financial Intelligence Unit (FIU) or equivalent authority.
We also screen all transactions, not just accounts, to prevent routing of funds through sanctioned payment corridors.
Where instantcards, in the course of its compliance activities, knows or reasonably suspects that a user is involved in money laundering, terrorist financing, or sanctions evasion, it is legally required to file a Suspicious Activity Report (SAR) or equivalent report with the relevant Financial Intelligence Unit or authority in the applicable jurisdiction.
In Cameroon, this is the Agence Nationale d'Investigation Financière (ANIF), established under Law No. 2005/015.
Tipping-off prohibition: Once a SAR has been filed or is contemplated, we are legally prohibited from informing the subject user that a report has been or will be filed, or that an investigation is underway. This is a mandatory legal requirement and is not a matter of our discretion. Users whose accounts are frozen while a SAR is under consideration will be informed of the suspension but not of the reason beyond "regulatory compliance requirements."
instantcards will not knowingly onboard or provide services to:
The following governance structures support our AML/CFT programme:
If you have concerns about financial crime, suspicious activity, or a compliance matter related to instantcards, please contact:
AML/CFT Compliance: compliance@instantcards.app
All reports are treated in strict confidence. Reports from users in good faith are protected from any form of retaliation.
instantcards is a product of Sanaga Digital. By using this service you agree to our Terms & Conditions and Privacy Policy. We are committed to AML/CFT compliance across all operating markets.