Zipa
Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how Zipa handles personal data when you visit our website, use the Zipa application, or use related services. Zipa is currently a beta product operating primarily on test networks.
1. Who is responsible for your data
Zipa is operated by OneDev Studioo, Nigeria (CAC BN 9704508), which acts as the data controller for personal data it determines the purposes and means of processing.
For privacy questions or data-rights requests, contact musa@usezipa.xyz.
This policy is intended to operate consistently with the Nigeria Data Protection Act, 2023 and applicable guidance of the Nigeria Data Protection Commission (NDPC).
2. What information we collect
- Account information: email, phone number or social-login details, @username, display name, optional avatar and profile information.
- Service activity: transfers, swaps, conversions, invoices, pay pages, referrals, bill orders, timestamps, notes and public wallet addresses associated with your account.
- Verification information: verification status and limited verification results when identity verification is used. Zipa does not store the ID images or biometric material submitted through the verification provider's flow.
- Bill information: recipient identifiers you enter for airtime, data, electricity or TV services, together with order and delivery status.
- Technical information: IP address, browser/device information, security logs and basic product preferences.
- Communications: messages, support requests, feedback and correspondence you send to us.
3. Identity verification and biometric data
Identity verification is performed through our specialist verification partner, Didit. Documents, selfie video and biometric facial information are submitted within Didit's verification flow and are handled according to the applicable provider terms and privacy notices.
Zipa receives the verification outcome and limited information needed to operate the account and meet applicable compliance or risk requirements. We do not intentionally store the underlying ID images or biometric templates on Zipa's application database.
Where consent is required for biometric processing, the verification flow obtains the relevant consent before collection. Some verification records may need to be retained where required by law.
4. How we use information
- to create and operate your account and provide Zipa features;
- to process transfers, swaps, invoices, pay pages and bill orders;
- to authenticate users and protect accounts and infrastructure;
- to conduct identity, fraud and abuse checks where applicable;
- to send transactional messages, receipts, security notices and product communications you can opt out of where applicable;
- to understand product usage and improve Zipa;
- to comply with legal, regulatory, security and dispute-resolution obligations.
Depending on the processing, our lawful bases may include performance of a contract, legitimate interests, consent and compliance with legal obligations.
5. Service providers and sharing
We use service providers to operate Zipa, including Privy for authentication and wallet infrastructure, Supabase for database services, Vercel for hosting, Didit for identity verification, Flutterwave for supported bill/payment rails, Helius for blockchain infrastructure, Resend for email delivery and CoinGecko for market-price information.
We share only the information reasonably necessary for the relevant service. We may also disclose information to professional advisers, regulators, law-enforcement authorities or other parties where required or permitted by law.
We do not sell personal data and do not use advertising networks for cross-site behavioural advertising.
6. International and cross-border processing
Some Zipa providers process information outside Nigeria. Where personal data is transferred across borders, Zipa seeks to use the safeguards and lawful transfer mechanisms required by applicable Nigerian data-protection law.
Because providers may update their infrastructure, the countries and locations used to process information can change. We will update this policy when a material change requires notice.
7. Blockchain data
Transactions that settle on public blockchain networks are public, pseudonymous and generally irreversible. Wallet addresses and on-chain activity may be visible to anyone and cannot be deleted from the blockchain by Zipa.
Do not treat a public blockchain address as private information simply because Zipa displays it inside your account.
8. Retention and deletion
We keep personal data for as long as reasonably necessary for the purposes described here, including account operation, security, dispute handling and legal obligations. Retention periods can differ by data type.
You may request account deletion by contacting us. We will delete or anonymise personal data that we are not required to retain, subject to legal obligations, legitimate security needs and the permanent nature of public blockchain records.
9. Your data rights
Subject to applicable law and any lawful limitations, you may have rights including the right to be informed, access, rectification, objection, restriction, portability, erasure and withdrawal of consent where consent is the lawful basis.
To exercise a right, email musa@usezipa.xyz. You may also have the right to lodge a complaint with the NDPC.
10. Cookies and local storage
The marketing website and application may use functional browser storage for preferences such as theme, language or session state. We do not use advertising cookies for cross-site tracking.
11. Security
We use technical and organisational safeguards appropriate to the nature of the information, including encrypted transport, access controls, row-level database controls, rate limiting and least-privilege infrastructure access. No online system can be guaranteed completely secure.
Zipa does not hold your blockchain private keys. Wallet infrastructure is provided through Privy.
12. Children
Zipa is intended for people aged 18 and over. We do not knowingly provide accounts to children. If you believe a person under 18 has provided personal data to Zipa, contact us so we can review and take appropriate action.
13. Changes to this policy
We may update this policy as Zipa, our services or applicable requirements change. Material changes will be communicated through the website, application or email where appropriate. The date at the top of this page shows when the current version took effect.
14. Contact
OneDev Studioo · Nigeria
Privacy contact: musa@usezipa.xyz