Top
Legal

Privacy Policy

Privacy Policy — ZovoPay

Effective Date: 4 July 2026
Last Updated: 4 July 2026

Operating Entity: EHSAN FALCON HOLDING LIMITED ("EFH LTD")
Registered in the United Kingdom
Company Registration Number (Companies House): 17091849
Registered Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Introduction

EHSAN FALCON HOLDING LIMITED ("EFH LTD"), registered in the United Kingdom, operates the ZovoPay digital wallet and financial solutions platform, including the User App, the unified Business App (Merchant/Agent/Company), and the website zovopay.com (collectively, the "Services"). EFH LTD provides financial services to customers across the Middle East, Turkey, and the United Kingdom. EFH LTD is referred to hereinafter as "we," "us," or "the Company."

We understand that money demands a higher standard of trust. This policy honestly and transparently explains: what data we collect, why we collect it, how we protect it, with whom we share it, and what your rights are.

By using the Services, you agree to the privacy practices described in this policy.

1. Data We Collect

1-A. Account and Identity Data

At registration we collect:

  • First and last name
  • Email address
  • Mobile phone number (with country code)
  • Username
  • Password (encrypted; we never store or access the plaintext)
  • Date of birth (for eligibility verification and compliance)
  • Nationality and country of residence

1-B. Identity Verification (KYC) Data

To comply with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations, we collect:

  • A copy of a valid government-issued identity document (national ID card, passport, or equivalent)
  • A selfie photograph for identity matching
  • Additional documents may be requested in accordance with applicable verification requirements
  • For merchants and agents: business licence documents, commercial registration records, and beneficial owner information

1-C. Financial Transaction Data

For every financial operation conducted on our platform we retain:

  • Incoming and outgoing transfers (sender, recipient, amount, currency, date/time)
  • Cash deposit and cash withdrawal operations via agents
  • Bill payments and mobile top-ups
  • Gift card purchases
  • QR code payments and payment link transactions
  • International remittance requests
  • Currency exchange transactions
  • Savings vault transactions

1-D. Virtual Card Data

  • Card creation, funding, and withdrawal data
  • Card transaction history
  • Note: Full card numbers and CVV codes are not stored on our servers; they are processed directly through our certified virtual card issuer (Airwallex).

1-E. Device and Usage Data

  • Device type, operating system, and version
  • Unique device identifier (for security purposes)
  • FCM push-notification token
  • Login logs: IP address, date/time, device type
  • Performance and crash data (technical diagnostics)

1-F. Device Permissions

  • Camera: Used only to scan QR codes for payments and for KYC identity verification. No content is captured without an explicit action on your part.

1-G. Communications Data

  • Support messages you send us through our support channels
  • Support chat logs

1-H. Voluntarily Provided Data

Any information you voluntarily provide, such as a profile photo or saved recipient contact details.

2. How We Use Your Data

We use the data we collect solely for the following purposes:

PurposeLegal Basis
Providing financial services and executing transactionsContractual necessity
Identity verification (KYC/AML) and legal complianceLegal obligation
Fraud prevention, AML, and counter-terrorism financingLegitimate interest + Legal obligation
Sending financial notifications (money received, transaction completed)Contractual necessity
Customer support and dispute resolutionContractual necessity + Legitimate interest
Service improvement and technical performanceLegitimate interest
Compliance with legal and regulatory requestsLegal obligation
Marketing communications (with your consent)Explicit consent

We do not use your data for third-party advertising. We do not sell your data.

3. Third-Party Sharing

We share your data only in the following circumstances:

3-A. Payment Processors

We share the minimum data necessary to complete your transactions with:

  • Stripe, Inc. — Processes automatic wallet top-ups via payment cards. Governed by its privacy policy at stripe.com/privacy.
  • PayPal Holdings, Inc. — Processes automatic wallet top-ups electronically. Governed by its privacy policy at paypal.com/privacy.
  • Airwallex Pty Ltd — Virtual card issuance (sole issuer). Governed by its privacy policy at airwallex.com/privacy.

Manual deposit and withdrawal methods (bank transfer and local cash channels) do not transmit your data automatically through the app; they are executed outside the app and reconciled based on a reference or receipt you provide.

3-B. International Remittance Partners

To execute international remittances, the minimum necessary data may be shared with our licensed and approved remittance partners.

3-C. Regulatory and Legal Authorities

We may disclose data when:

  • Required by a court order or formal request from a competent regulatory authority
  • There is suspicion of money laundering, terrorism financing, or financial fraud
  • Required by applicable legal obligations

3-D. Technical Service Providers

We engage trusted service providers to operate our infrastructure (hosting, push notifications, performance analytics). These providers are contractually bound to process data solely for the purpose of the service.

3-E. Agents (Customer Data Only)

In the context of cash-in operations, the agent accesses the minimum data necessary to execute the transaction (customer name and phone number) pursuant to compliance requirements, and is not permitted to retain or use that data for any other purpose.

4. Data Security

We implement serious technical and organisational measures to protect your data, including:

  • Encryption in transit: HTTPS/TLS for all data transmitted
  • Encryption at rest for sensitive data: KYC documents and sensitive card data are encrypted
  • Two-factor authentication (2FA): Available and encouraged for all accounts
  • Fraud monitoring: Continuous systems to detect suspicious activity
  • Access control: Internal access rights governed by the principle of least privilege

Despite our commitment to high security standards, no method of internet transmission is 100% guaranteed. In the event of a security breach affecting your data, we will notify you in accordance with applicable legal requirements.

5. Data Retention

Data TypeRetention Period
Account data and KYC recordsFive (5) years after account closure, in accordance with applicable anti-money laundering standards
Financial transaction recordsFive (5) years, in accordance with applicable regulatory requirements in operating jurisdictions
Technical support logsTwo (2) years
Technical performance data / crash logs90 days
Marketing data (with your consent)Until consent is withdrawn

Upon expiry of the applicable retention period, data is securely deleted or anonymised.

6. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your data where no legal obligation prevents us from doing so
  • Objection: Object to the processing of your data for direct marketing purposes
  • Withdrawal of Consent: Withdraw consent for consent-based processing at any time
  • Restriction of Processing: Request restriction of processing in certain circumstances

To exercise these rights, contact us at: support@zovopay.com

We will respond to privacy requests within thirty (30) days of receipt.

Account Deletion

You may request deletion of your account at any time through any of the following:

  • In-app: Settings → Account → Delete Account
  • Web: zovopay.com/account-deletion
  • Email: support@zovopay.com

What happens when you request deletion:

  • Your account is deactivated immediately upon identity verification, once your balance is cleared and pending transactions are resolved
  • Personal data is deleted or anonymised after the legally required retention period expires
  • Financial transaction records are retained for the period required by law (anti-money laundering)
  • Deletion cannot proceed while the account holds a balance or has pending transactions

7. Cookies and Tracking

On the website (zovopay.com):
We use technically necessary cookies to operate the website and maintain secure sessions. We will update this policy if additional analytics tools are adopted.

On the app:
We do not use cookies in the app. We use anonymised device identifiers for security and push-notification purposes.

8. Children and Eligibility

ZovoPay services are directed to persons aged 18 years or older (or the legal age for financial eligibility in your country of residence if higher). We do not knowingly collect data from persons under the age of 18. If we discover that a minor has opened an account, we will suspend the account, contact the guardian, and delete the data in accordance with applicable legal procedures. If you are a guardian and believe your child has submitted data to us, please contact us immediately.

9. International Data Transfers

Our data is hosted on secure servers with reputable hosting providers. Your data may be transferred to and processed in countries other than your country of residence; in all cases, the protections described in this Policy apply.

10. Changes to This Privacy Policy

We may update this policy periodically. Where material changes are made, we will notify you by registered email or in-app notification at least 30 days before the change takes effect. Your continued use of the Services after the change takes effect constitutes your acceptance of the updated policy.

11. Contact Us

For any privacy-related enquiry or request:

  • Customer Support Email: support@zovopay.com
  • Corporate / Legal Email: info@efhlimited.com
  • Postal Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
  • For data-protection and privacy inquiries: info@efhlimited.com

If you are not satisfied with our response, you have the right to lodge a complaint with the data-protection authority in your country of residence; in the United Kingdom, the Information Commissioner's Office (ICO).