PRIVACY POLICY
Last Updated: November 2025
This Privacy Policy ("Policy") governs the manner in which Pincode ("Company", "we", "our", "us") collects, processes, uses, stores, shares, and protects information relating to individuals and merchants ("User", "you", "your") who access or use our website, mobile application, APIs, or any related services ("Services").
This Policy is prepared in accordance with:
- The Prevention of Electronic Crimes Act (PECA), 2016
- The Personal Data Protection Bill of Pakistan (where applicable)
- SECP AML/CFT Guidelines
- Applicable data protection and privacy regulations
By using the Services, you expressly consent to the processing of your personal data in accordance with this Policy.
1. Introduction
This Policy explains what information we collect, why we collect it, how we use it, and the choices you have about your information.
2. Categories of Data Collected
2.1 Personal Identification Data
- Full name
- CNIC/NICOP number
- Date of birth
- Contact number
- Email address
- Residential or business address
2.2 Business Information
- Business name and registration details
- NTN/Tax information
- Nature of business
- Business documentation (if applicable)
- Bank account details
2.3 KYC/Verification Documents
- CNIC front and back
- Live selfie (for biometric verification)
- Proof of business (SECP certificate, bank letter, tax certificate, etc.)
- Signature or corporate stamp (if required)
2.4 Transaction & Financial Data
- Payment requests
- Wallet balances
- Settlement history
- Payout details
- Third-party wallet identifiers (Easypaisa, JazzCash, Zindigi, etc.)
2.5 Technical & Behavioral Data
- IP address
- Device identifiers
- Browser information
- Access logs
- Usage patterns
- Geo-location (if permitted by device)
3. Legal Basis for Processing
We process your data under the following lawful bases:
- Performance of Contract: To provide payment and wallet services
- Legal Obligation: AML, KYC, SECP reporting compliance
- Legitimate Interest: Fraud prevention, service enhancement
- Consent: Marketing communications, optional features
4. Purpose of Processing
Your data is used for:
- Identity and business verification (KYC/CDD)
- Activation and maintenance of your merchant wallet
- Payment processing, settlements, and payouts
- Risk assessment, anti-fraud, AML/CFT compliance
- Customer support and dispute resolution
- Providing analytics, insights, and dashboard features
- Regulatory reporting
- System security, performance enhancement, and audits
We do not sell or trade your personal data to any unaffiliated third party.
5. Data Sharing and Disclosure
We may share your information with:
5.1 Payment Networks & Financial Institutions
- Easypaisa
- JazzCash
- Zindigi
- Banks and settlement partners
For the purpose of executing payments, settlements, and verifications.
5.2 Regulatory Bodies
Upon lawful request:
- SECP
- SBP (if required through partner banks)
- FIA Cyber Crime Wing
- Law enforcement agencies
5.3 Third-Party Service Providers
For:
- Cloud hosting
- Fraud detection
- KYC verification
- Analytics
- Customer support
All such providers act under strict confidentiality obligations.
6. Data Retention
- KYC data for minimum 5 years post-termination
- Transaction data for 7 years (regulatory requirement)
- Account information until legally permissible or upon closure
Data may be retained longer in case of legal disputes or investigations.
7. Data Security
We implement:
- End-to-end encryption
- Secure socket layer (SSL)
- Multi-factor authentication
- Role-based access control
- Continuous monitoring
- Audit logging
- Tokenization of sensitive data
Despite our efforts, no system is fully immune from risks.
8. User Rights
You may:
- Request access to your data
- Request rectification
- Request deletion subject to regulatory obligations
- Request restriction on processing
- Withdraw consent for non-essential processing
- Lodge a complaint with the relevant authority
9. International Data Transfer
If your data is processed outside Pakistan, it is done only in jurisdictions with adequate data protection standards.
10. Changes to Policy
We reserve the right to amend this Policy at any time. Continued use of Services constitutes acceptance of modifications.
11. Contact
Email: support@pincode.pk