Privacy Policy
Effective 29 July 2026. This policy explains what personal data we handle, why, on what legal basis, and what you can ask us to do about it.
src/lib/company.js completed, before this page is published.1. Who controls your data
This website is operated by Otaro Pay Ltd, FINTRAC M23150730, registered at Suite 250 - #1585 997 Seymour St, Vancouver BC V6B 3M1 ("Zen Card", "we", "us").
Where you hold a card issued by a licensed financial institution through a Zen Card programme, that institution is generally the data controller for your account and card data, and Zen Card acts as a processor on its instructions. For data you provide directly through this website, Zen Card is the controller. Your issuing institution's own privacy notice applies alongside this one.
Data protection enquiries: info@otaropay.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, date of birth, nationality, identity document details | You, and your issuing institution |
| Contact data | Email address, telephone number, postal address for card delivery | You |
| Account data | Account identifiers, card identifiers, balances, product settings | Generated in use |
| Transaction data | Authorisations, settlements, merchant, amount, currency, timestamp | Generated in use |
| Funding data | On-ramp and off-ramp records, wallet addresses used to fund a balance | Generated in use |
| Device and technical data | IP address, device identifiers, browser type, session and login history | Automatically |
| Usage data | Pages viewed, features used, interaction events | Automatically |
| Support data | Correspondence, tickets, dispute evidence you supply | You |
We do not intentionally collect special category data. Where an identity document incidentally reveals such data, it is handled only as necessary to verify identity.
3. Why we use it, and on what basis
| Purpose | Legal basis |
|---|---|
| Providing and operating the card and account | Performance of a contract |
| Identity verification, KYC and customer due diligence | Legal obligation |
| Anti-money-laundering, sanctions screening and fraud prevention | Legal obligation; legitimate interests |
| Transaction monitoring and risk controls | Legal obligation; legitimate interests |
| Processing disputes and chargebacks | Performance of a contract; scheme rules |
| Customer support | Performance of a contract |
| Service security, availability and abuse prevention | Legitimate interests |
| Product analytics and improvement | Legitimate interests; consent where required |
| Marketing communications | Consent, withdrawable at any time |
| Regulatory reporting and responding to lawful requests | Legal obligation |
4. Who we share it with
We share personal data only where there is a reason to. Recipients fall into defined categories: the licensed institution issuing your card; card schemes and processors, including Visa, as required to authorise and settle transactions; card production, personalisation and fulfilment providers; identity verification, sanctions screening and fraud prevention providers; cloud infrastructure, hosting and communications providers acting as processors under contract; professional advisers such as auditors and lawyers; and regulators, law enforcement and other authorities where we are legally required to disclose.
We do not sell personal data, and we do not share it with advertisers.
5. International transfers
Card programmes operate across multiple jurisdictions, so personal data may be transferred outside the country in which it was collected. Where it is, we rely on an adequacy decision where one exists, or on appropriate safeguards such as standard contractual clauses together with supplementary measures where required.
6. How long we keep it
Retention is driven principally by financial-services record-keeping obligations rather than by our preference. Identity, transaction and due-diligence records are typically retained for the statutory period applicable in the relevant jurisdiction following the end of the customer relationship, commonly five years and in some jurisdictions longer. Support correspondence, device and usage data are kept for shorter periods proportionate to their purpose. Data no longer required is deleted or irreversibly anonymised.
7. Your rights
Subject to the law that applies to you, you may have the right to access the personal data we hold about you, to have inaccurate data corrected, to request erasure, to restrict or object to certain processing, to receive your data in a portable format, to withdraw consent where processing relies on it, and to complain to your supervisory authority.
Some rights are limited where we are legally required to retain data, for example anti-money-laundering records. Where we cannot action a request in full, we will explain why. Requests go to info@otaropay.com and we aim to respond within one month.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls on a least-privilege basis, multi-factor authentication, device management, logging and monitoring. No system is perfectly secure, and we do not claim otherwise. See our security page for detail on the controls available to you.
9. Children
The service is not directed at, and must not be used by, anyone under the age at which they can lawfully hold a payment account in their jurisdiction. We do not knowingly collect data from children, and will delete it if we discover we have.
10. Changes
We will update this policy as the service changes or as the law requires. Material changes will be notified in advance where required. The effective date at the top of this page reflects the current version.
