Zuato's Privacy Policy

1. Introduction

Zuato Financial Services ("Zuato," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website www.zuato.com (the "Website"), use our payment services, or interact with us in any other way.

As a licensed payment acquirer operating in the United Arab Emirates, we are committed to complying with applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection and other relevant regulations.

By accessing or using our Website and services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our Website or services.

Our Commitment
We process your personal data lawfully, fairly, and transparently. We only collect data that is necessary for our legitimate business purposes and ensure appropriate security measures are in place to protect your information.

2. Information We Collect

We collect various types of information depending on how you interact with us. This includes information you provide directly, information collected automatically, and information from third parties.

2.1 Information You Provide

When you use our Website or services, you may provide us with the following information:

Personal Identification Information

  • Full name, date of birth, and nationality
  • Emirates ID number and passport details
  • Email address and telephone number
  • Residential or business address
  • Photographs and identity documents

Business Information

  • Company name and trade license details
  • Business registration and tax registration numbers
  • Shareholder and beneficial owner information
  • Bank account and financial information
  • Business address and contact details

Transaction Information

  • Payment card details (processed securely, not stored)
  • Transaction history and amounts
  • Merchant and customer transaction data
  • Refund and chargeback information

2.2 Information Collected Automatically

When you visit our Website, we automatically collect certain information about your device and usage:

Data Type Examples
Device Information IP address, browser type, operating system, device identifiers
Usage Data Pages visited, time spent, click patterns, navigation paths
Location Data General geographic location based on IP address
Referral Data Website or source that referred you to us

2.3 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Identity verification and fraud prevention services
  • Credit reference and risk assessment agencies
  • Payment networks (Visa, Mastercard, etc.)
  • Business partners and referral sources
  • Publicly available sources and government databases

3. How We Use Your Information

We use the information we collect for various purposes related to providing and improving our services:

3.1 Service Provision

  • Processing payment transactions and settlements
  • Creating and managing your merchant account
  • Providing customer support and responding to inquiries
  • Sending service-related communications and notifications
  • Processing refunds, chargebacks, and disputes

3.2 Compliance & Security

  • Verifying your identity and conducting KYC/KYB checks
  • Preventing fraud, money laundering, and other illegal activities
  • Complying with legal and regulatory requirements
  • Responding to lawful requests from authorities
  • Enforcing our terms of service and policies

3.3 Business Operations

  • Analyzing usage patterns to improve our services
  • Developing new products and features
  • Conducting research and statistical analysis
  • Managing our business relationships
  • Training our staff and improving processes

3.4 Marketing & Communications

  • Sending promotional materials and newsletters (with your consent)
  • Informing you about new services and features
  • Personalizing your experience on our Website
  • Conducting surveys and gathering feedback

Marketing Preferences
You can opt out of marketing communications at any time by clicking the "unsubscribe" link in our emails or by contacting us directly. Opting out will not affect service-related communications.

5. Information Sharing & Disclosure

We do not sell, rent, or trade your personal information. However, we may share your information with the following categories of recipients:

5.1 Service Providers

We engage trusted third-party companies to perform functions on our behalf, including:

  • Payment processing and settlement partners
  • Cloud hosting and data storage providers
  • Identity verification and fraud prevention services
  • Customer support and communication platforms
  • Analytics and performance monitoring tools

5.2 Payment Network Partners

To process transactions, we share necessary information with:

  • Card networks (Visa, Mastercard, American Express, etc.)
  • Issuing and acquiring banks
  • Payment processors and gateways

5.3 Regulatory & Legal Authorities

We may disclose your information when required by law or to:

  • Comply with legal processes or government requests
  • Protect our rights, property, or safety
  • Prevent fraud, money laundering, or other crimes
  • Report to the UAE Central Bank or other regulators

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

Important
All third parties with whom we share data are contractually obligated to protect your information and use it only for the purposes for which it was shared.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and regulatory requirements.

6.1 Retention Periods

Data Category Retention Period
Transaction Records Minimum 5 years after transaction date
KYC/KYB Documents Minimum 5 years after account closure
Account Information Duration of relationship + 5 years
Marketing Preferences Until you withdraw consent
Website Analytics 26 months from collection

6.2 Deletion

When personal data is no longer required, we will securely delete or anonymize it. Some data may be retained in backup systems for a limited period or as required by law.

7. Data Security

We implement comprehensive security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.

7.1 Technical Measures

  • Encryption: All data transmitted to and from our Website is encrypted using TLS/SSL protocols
  • PCI-DSS Compliance: We maintain Payment Card Industry Data Security Standard compliance for handling card data
  • Access Controls: Strict authentication and authorization systems limit data access to authorized personnel only
  • Firewalls & Monitoring: Advanced firewalls and intrusion detection systems protect our infrastructure
  • Regular Audits: We conduct regular security assessments and penetration testing

7.2 Organizational Measures

  • Employee background checks and confidentiality agreements
  • Regular security awareness training for all staff
  • Incident response procedures and breach notification protocols
  • Data protection impact assessments for new processing activities

Your Role in Security
While we take extensive measures to protect your data, security is a shared responsibility. Please keep your login credentials confidential, use strong passwords, and notify us immediately if you suspect unauthorized access to your account.

8. Your Rights

Under applicable data protection laws, you have certain rights regarding your personal information. We are committed to honoring these rights and facilitating their exercise.

Right to Access

Request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data in certain circumstances (subject to legal obligations).

Right to Restrict Processing

Request limitation of processing in certain circumstances while we verify your concerns.

Right to Data Portability

Receive your data in a structured, machine-readable format and transfer it to another provider.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on your consent.

Right to Lodge a Complaint

Lodge a complaint with the relevant data protection authority if you believe your rights have been violated.

8.1 How to Exercise Your Rights

To exercise any of these rights, please contact us using the details provided in the Contact section below. We will respond to your request within 30 days. We may need to verify your identity before processing your request.

Please note that some rights may be limited in certain circumstances, such as when we have a legal obligation to retain data or when disclosure would adversely affect the rights of others.

9. Cookies & Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your experience, analyze traffic, and personalize content.

9.1 Types of Cookies We Use

Cookie Type Purpose
Essential Cookies Required for Website functionality (login sessions, security features)
Analytics Cookies Help us understand how visitors interact with our Website
Functional Cookies Remember your preferences and personalization choices
Marketing Cookies Track visitors to display relevant advertisements

9.2 Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to:

  • View and delete cookies
  • Block third-party cookies
  • Block all cookies from specific sites
  • Block all cookies entirely

Please note that blocking certain cookies may affect the functionality of our Website. For more detailed information, please visit our Cookie Policy.

10. International Data Transfers

As a global financial services provider, we may transfer your personal data to countries outside the United Arab Emirates. When we do so, we ensure appropriate safeguards are in place to protect your information.

10.1 Transfer Safeguards

  • Transfers to countries with adequate data protection laws recognized by the UAE
  • Standard contractual clauses approved by relevant authorities
  • Binding corporate rules for intra-group transfers
  • Your explicit consent for specific transfers

10.2 Payment Network Requirements

Processing payment transactions may require sharing data with international payment networks, banks, and processors. This is necessary to provide our services and is conducted in compliance with payment industry standards and regulations.

11. Third-Party Services & Links

Our Website may contain links to third-party websites, plugins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.

We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

11.1 Third-Party Services We Use

  • Google Analytics: Website traffic analysis
  • Intercom/Zendesk: Customer support chat
  • Social Media Platforms: Social sharing and login features
  • Cloud Service Providers: Data hosting and storage

12. Children's Privacy

Our Website and services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

If we become aware that we have collected personal data from a child without verification of parental consent, we will take immediate steps to delete that information. If you believe we may have collected information from a child, please contact us immediately.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • We will update the "Last Updated" date at the top of this page
  • For significant changes, we will provide prominent notice on our Website or notify you directly via email
  • We will obtain your consent where required by law

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Stay Informed
We recommend bookmarking this page and checking back regularly. Your continued use of our Website and services after changes are posted constitutes your acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection team:

Data Protection Office

We are committed to addressing your privacy concerns promptly and transparently.

Dubai, United Arab Emirates

For general inquiries not related to privacy, please visit our Contact page or email info@zuato.com.