How we collect, use, store, share, and protect your personal information when you use ZWAP. Your privacy is not a feature — it is a right.
usezwap Ltd ("ZWAP," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, store, share, and protect your personal information when you use our website at usezwap.com (the "Website"), our mobile applications (the "App"), and our crypto and fiat payments platform (collectively, the "Service").
This Policy applies to all users of the Service, including registered account holders, visitors to our Website, and individuals who interact with us through any other channel.
By accessing or using the Service, you consent to the practices described in this Policy. If you do not agree with this Policy, please do not use the Service.
This Policy should be read alongside our Terms of Use and AML Policy, which contain additional information about how we handle your data in the context of our services.
We collect information that you provide directly to us, information that is collected automatically when you use the Service, and information that we receive from third parties.
A. Information You Provide Directly
B. Information Collected Automatically
C. Information Received from Third Parties
D. Sensitive Personal Data
In the course of providing the Service, we process the following categories of sensitive personal data as defined by the Nigeria Data Protection Act (NDPA) 2023:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| BVN / NIN | Identity verification | Contractual necessity + Legal obligation |
| Government ID photo | Identity verification | Contractual necessity + Legal obligation |
| Live selfie | Facial matching / Liveness check | Contractual necessity |
| Bank account number | Deposit / Withdrawal | Contractual necessity |
| Financial transaction data | Service delivery | Contractual necessity + Legal obligation |
| Blockchain wallet addresses | Crypto deposit / purchase | Contractual necessity |
We use your personal information for the following purposes:
A. To Provide and Operate the Service
B. For Security and Fraud Prevention
C. For Legal and Regulatory Compliance
D. For Product Improvement
E. For Communications
We process your personal data only when we have a lawful basis to do so. Under the Nigeria Data Protection Act (NDPA) 2023, our legal bases include:
| Legal Basis | When We Rely On It |
|---|---|
| Consent | Marketing communications, optional analytics cookies, optional device location access. |
| Contractual Necessity | Processing transactions, maintaining account balances, providing customer support — data processing necessary to perform our contract with you. |
| Legal Obligation | KYC verification, AML screening, STR filing, record retention, responding to court orders or regulatory requests. |
| Legitimate Interest | Security monitoring, fraud prevention, product improvement (where your rights do not override our interests), and network performance optimization. |
| Vital Interest | Not applicable to our services — we do not process data to protect anyone's life. |
When we rely on consent, you may withdraw it at any time by contacting us at privacy@usezwap.com or through your account settings. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
We do not sell your personal data to any third party. We share your information only in the circumstances described below.
A. Licensed Financial Partners
We share necessary information with licensed Nigerian banks and financial institutions to process deposits, withdrawals, and card transactions. This includes your name, account details, and transaction instructions. These partners are bound by confidentiality obligations under their licensing terms and applicable banking regulations.
B. Card Issuer Partner
We share your name, delivery address, and naira balance status with our licensed Visa card issuer partner for the purpose of issuing and managing your ZWAP debit card. Card transaction data is shared back to us for display in your transaction history.
C. KYC and Compliance Vendors
We share your identity documents (government ID, selfie) with vetted third-party KYC vendors who perform document verification, facial matching, and liveness checks on our behalf. These vendors are contractually obligated to delete your documents after verification and are prohibited from using them for any other purpose.
D. Government and Regulatory Authorities
E. Service Providers
All service providers are contractually bound to process data only as instructed by us, maintain appropriate security measures, and not use the data for their own purposes.
F. Counterparties on the ZWAP Platform
When you send or receive funds to/from another ZWAP user, they see your ZWAP ID (ZID) — not your legal name, phone number, or other personal information. See our Terms of Use, Section 11, for full details on ZID privacy.
G. Corporate Transactions
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you via email at least 30 days before any such transfer and provide you with the opportunity to exercise your data rights.
Data Storage Location
Your data is stored on secure servers located in data centers operated by reputable cloud infrastructure providers. Primary data storage is within jurisdictions that provide adequate data protection. In some cases, data may be replicated across geographic regions for redundancy and disaster recovery.
Security Measures
We implement industry-standard technical and organizational security measures to protect your personal data:
What We Do Not Store
No system is perfectly secure. While we implement robust security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. In the event of a data breach, we will follow our incident response plan and notify affected individuals and regulators as required by law.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, as described below:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 5 years | Contractual + Legal requirement |
| KYC documents (ID, selfie) | Duration of account + 5 years | Legal requirement (CBN/NFIA) |
| Transaction records | Minimum 5 years | Legal requirement (AML) |
| Card transaction data | Minimum 5 years | Legal requirement (CBN) |
| Server logs | 90 days | Security + Operational need |
| Analytics data (anonymized) | 26 months | Legitimate interest |
| Job applications | 12 months (unsuccessful) / Duration of employment + 5 years (successful) | Legitimate interest + Legal requirement |
When retention periods expire, personal data is securely deleted or anonymized in accordance with our data disposal procedures. We may retain certain data in anonymized or aggregated form which cannot be attributed to any individual.
We use cookies and similar tracking technologies for the purposes described below. A cookie is a small text file stored on your device when you visit our Website.
A. Strictly Necessary Cookies
These cookies are essential for the Service to function and cannot be disabled:
B. Analytics Cookies (Optional)
These cookies help us understand how visitors interact with our Website by collecting anonymized information. We use this data to improve the user experience.
You can opt out of analytics cookies through your browser settings or by using the opt-out mechanism below.
C. How to Manage Cookies
Disabling cookies may affect certain features of the Service. Strictly necessary cookies cannot be disabled as the Service will not function without them.
D. We Do NOT Use:
ZWAP ID (ZID) is a privacy feature that replaces your legal name with an alphanumeric alias (e.g., ZID-4X9RK2) on transaction records visible to other ZWAP users.
What ZID hides:
What ZID does NOT hide:
Technical implementation:
Cryptocurrency transactions are recorded on public blockchains. This has important privacy implications that you should understand:
What is publicly visible on the blockchain:
What is NOT publicly visible:
Immutability:
Once a transaction is confirmed on the blockchain, it cannot be altered or deleted — by us, by you, or by anyone. This is a fundamental property of blockchain technology. If you send crypto to the wrong address, the transaction is permanent. This is why we display clear warnings before every transaction and emphasize verifying the destination address and network.
Analytics services:
Blockchain analytics companies (e.g., Chainalysis, TRM Labs) may analyze public blockchain data and potentially associate deposit addresses with our service. This is beyond our control as we do not operate the blockchain networks. We do not share your personal identity with these services.
Under the Nigeria Data Protection Act (NDPA) 2023 and other applicable privacy laws, you have the following rights regarding your personal data:
A. Right of Access
You have the right to request a copy of the personal data we hold about you. To make a request, contact privacy@usezwap.com. We will respond within 30 days. For security reasons, we may verify your identity before fulfilling the request.
B. Right to Rectification
You have the right to correct inaccurate or incomplete personal data. You can update most information directly in your account settings. For changes to KYC data (name, ID documents), contact our support team as these require re-verification.
C. Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data, subject to certain exceptions:
To request account deletion, contact privacy@usezwap.com. Please note that account deletion is permanent and irreversible — you will lose access to your balance and all associated data. We will facilitate the withdrawal of any remaining funds before deletion, except where prohibited by law (e.g., active compliance hold).
D. Right to Restrict Processing
You have the right to request that we limit how we process your data in certain circumstances, such as when you contest the accuracy of the data or object to processing based on legitimate interest.
E. Right to Data Portability
You have the right to request your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV). Contact privacy@usezwap.com to make this request.
F. Right to Object
You have the right to object to processing of your personal data based on legitimate interest or for direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
G. Right to Withdraw Consent
Where we rely on consent as our legal basis, you may withdraw consent at any time through your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
H. Right to Lodge a Complaint
You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe our processing of your personal data violates the NDPA. You may also contact us first, and we will endeavor to resolve your complaint within 30 days.
How to Exercise Your Rights
Data Protection Officer
Email: privacy@usezwap.com
Nigeria Data Protection Commission (NDPC)
Website: ndpc.gov.ng
Response Timeline
We will acknowledge your request within 5 business days and respond substantively within 30 days. Complex requests may require additional time, in which case we will notify you of the extension and reason.
Your personal data may be transferred to and processed in countries other than Nigeria. This occurs when:
Safeguards for International Transfers:
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If we discover that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete that data from our systems. If you believe that a child under 18 has provided us with personal information, please contact privacy@usezwap.com.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
The notification to you will include, where feasible:
We may delay notification if doing so would impede a law enforcement investigation, in which case we will document the reason for the delay.
The Service may contain links to third-party websites, applications, or services (e.g., blockchain explorers, partner exchanges, regulatory websites) that are not operated or controlled by us.
This Privacy Policy does not apply to third-party websites or services. We are not responsible for the privacy practices of third parties. We encourage you to read the privacy policies of any third-party service you interact with.
The inclusion of a link on our Service does not imply our endorsement of the linked site or service.
We may update this Privacy Policy from time to time. Changes will be effective upon the earlier of:
Material changes (e.g., new data categories, new purposes of processing, changes to your rights) will be communicated at least 14 days before they take effect.
Non-material changes (e.g., clarifying language, updating contact details) may be made without advance notice.
Your continued use of the Service after changes are posted constitutes your acceptance of the revised Policy. We encourage you to review this page periodically.
| Term | Definition |
|---|---|
| BVN | Bank Verification Number — a unique identifier issued by NIBSS linked to an individual's bank account. |
| NIN | National Identification Number — an 11-digit unique identifier issued by NIMC to Nigerian citizens and legal residents. |
| NDPA | Nigeria Data Protection Act 2023 — the primary data protection legislation in Nigeria. |
| NDPC | Nigeria Data Protection Commission — the regulatory body enforcing the NDPA. |
| NFIU | Nigeria Financial Intelligence Unit — responsible for receiving and analyzing Suspicious Transaction Reports. |
| STR | Suspicious Transaction Report — filed with the NFIU when a transaction exhibits indicators of money laundering or terrorism financing. |
| KYC | Know Your Customer — the process of verifying identity to assess potential risks of illegal intentions. |
| AML/CFT | Anti-Money Laundering / Combating the Financing of Terrorism. |
| PEP | Politically Exposed Person — an individual who holds a prominent public function, posing higher risk for involvement in bribery or corruption. |
| ZID | ZWAP ID — a unique alphanumeric alias that replaces your legal name on transaction records. |