Privacy Policy
At ZePay, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the zepay data mobile application and associated services.
1. Information We Collect
We collect only the information necessary to provide and secure our services. We collect information in the following ways:
Information you provide to us:
- Your phone number (used as your unique account identifier)
- A 4-digit PIN which is stored in encrypted form on your device using platform-level secure storage — we never store your raw PIN on our servers
- Transaction history (airtime purchases, data purchases, bill payments, and wallet top-ups)
- Beneficiary phone numbers you save for quick recharge
Information we collect automatically:
- Device type and operating system version (for compatibility and fraud detection)
- App usage patterns and transaction timestamps (for service improvement)
- Session tokens stored securely on-device to keep you logged in
Biometric Data:
If you enable biometric login (fingerprint or face recognition), authentication is handled entirely by your device's operating system (Android BiometricPrompt). We do not access, store, or transmit any biometric data. Biometric credentials never leave your device.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Process and complete your payment transactions
- Verify your identity and prevent fraud
- Provide customer support and respond to your inquiries
- Improve our services and develop new features
- Send you important updates about your account and transactions
- Comply with legal obligations and regulatory requirements
- Analyze usage patterns to enhance user experience
3. Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:
Service Providers:
We may share information with trusted third-party service providers who assist us in operating our services. This includes Paystack (our payment processor for wallet top-ups via card or bank transfer), network data/airtime APIs, cable TV and electricity bill payment providers, and cloud infrastructure services. Each provider is bound by its own privacy and security standards.
Legal Requirements:
We may disclose your information if required by law, court order, or government regulation, or if we believe such disclosure is necessary to protect our rights, prevent fraud, or ensure public safety.
Business Transfers:
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
We ensure that any third parties we share information with maintain appropriate security measures and are bound by confidentiality agreements.
4. Data Security
We implement comprehensive security measures to protect your personal information:
- All data transmitted between the app and our servers uses HTTPS/TLS encryption
- Your PIN is stored only on your device using flutter_secure_storage, which uses Android Keystore — it is never sent to or stored on our servers in any form
- Session tokens are stored in encrypted device storage and expire automatically
- Biometric authentication (if enabled) is handled exclusively by your device OS — no biometric data is collected by us
- Wallet balance and transaction records are stored in our secured backend database
- Regular security reviews of our backend infrastructure
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.
5. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal requirements)
- Portability: Request transfer of your data in a structured format
- Restriction: Request limitation of how we process your information
- Objection: Object to processing based on legitimate interests
To exercise these rights, please contact us using the information provided below.
6. On-Device Storage
The zepay data app is a mobile application and does not use browser cookies. Instead, we use the following on-device storage mechanisms:
- Secure Storage (Android Keystore): Used to store your encrypted PIN and session tokens — accessible only by the zepay data app on your specific device
- Local Database: Used to cache recent transaction history for offline viewing
- Shared Preferences: Used to store non-sensitive app settings such as your preferred theme and notification preferences
You can clear all locally stored app data at any time via your device's App Settings → zepay data → Clear Data. This will log you out and require re-registration.
7. International Data Transfers
Your information may be transferred to and processed in countries other than Nigeria. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards, including standard contractual clauses and adequacy decisions.
8. Children's Privacy
Our services are not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically.
10. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: info@zepayng.com
Phone: +234 814 841 6242
Address: Lagos, Nigeria
Data Protection Officer: info@zepayng.com
We will respond to your inquiries within 30 days of receipt.
Need Help?
If you have questions about your privacy or data protection rights, our team is here to help.
Support Hours: 24/7
Response Time: Within 24 hours