One Ziko – Privacy & Data Policy
Last updated: 7 June, 2026
Applicable to: One Ziko website, mobile applications, OneZiko Identity (SSO platform), e‑Mpiya OMPS (payment platform), and all related services (collectively, “Services”)
Contact: info@oneziko.com
This Privacy & Data Policy explains what personal data we collect, why we collect it, how we use and share it, and your rights over your information. It applies to all users of our Services, whether you register via social login, OneZiko Identity, email, mobile number, or use our apps anonymously.
By using our Services, you confirm that you have read and understood this policy.
1. What Personal Data We Collect
We collect only the data necessary to provide and improve our Services. We do not collect sensitive data (e.g., health, biometrics, political opinions, banking passwords).
1.1 Data you provide directly (via Social Login or registration)
When you register or log in using Facebook Login, Google Sign-In, or Log in with Twitter, we collect:
| Data field | Why we collect it |
|---|---|
| Unique User ID (from the social platform) | To identify your account and link it to your profile. |
| User Name | To create your profile username and profile URL. |
| Email Address | To communicate with you (service updates, password reset, account verification). |
| Avatar (profile picture) | To display as your default profile picture (you can change or remove it). |
Legal basis: Performance of a contract (providing you with an account) and your consent.
1.2 Automatically collected information (when you use our apps or website)
We automatically receive certain technical data from your device:
| Data type | Example | Legal basis |
|---|---|---|
| Device identifiers | Mobile device unique ID, advertising ID (if consented) | Legitimate interest (security, fraud prevention) |
| IP address | 192.168.1.1 (anonymised after 30 days) | Legitimate interest (analytics, security) |
| Operating system & browser | iOS 17.5, Chrome 124 | Legitimate interest (compatibility, debugging) |
| Usage data | Time spent in app, features clicked, error logs | Legitimate interest (improving our Services) |
| Navigation & referral URL | Which page you came from or go to | Legitimate interest (analytics) |
Note: Automatically collected information is linked to your user account if you are logged in. If you use our Services without logging in, it is stored anonymously and cannot be traced back to you.
1.3 Location information
We do not use GPS to track your precise location. However, we may infer your approximate location (city or region level) from your IP address or network traffic. This is used only to aggregate anonymous demographic insights (e.g., “30% of our users are in Lusaka”).
Legal basis: Legitimate interest (understanding our user base). You can opt out by disabling cookies or contacting us.
1.4 Information from third‑party analytics providers
We use trusted third‑party analytics and performance monitoring platforms to help us understand how users interact with our Services, diagnose errors, and improve user experience. These providers may collect data according to their own policies, but they are contractually bound to process data only on our behalf and not for their own purposes.
Current service providers (as of this policy date):
| Provider | Purpose | Privacy policy link |
|---|---|---|
| Google Analytics 4 | Website & app usage analytics | https://policies.google.com/privacy |
| Google Search Console | Search performance monitoring | https://policies.google.com/privacy |
| Sentry | Error tracking and crash reporting | https://sentry.io/privacy/ |
| Mixpanel | Product analytics | https://mixpanel.com/legal/privacy-policy/ |
| Microsoft Clarity | Session recording and heatmaps | https://clarity.microsoft.com/terms |
We will update this list when we change providers. If you do not want your data shared with these providers, you may stop using our Services or disable non‑essential cookies / tracking via our cookie consent banner.
1.5 OneZiko Identity – Our Single Sign‑On (SSO) Identity Platform
We operate OneZiko Identity (accessible at https://identity.oneziko.com/), which provides a unified login experience across all One Ziko services. When you choose to log in using OneZiko Identity instead of third‑party social logins (Facebook/Google/Twitter), we collect:
| Data field | Why we collect it |
|---|---|
| Email address or mobile phone number (MSISDN) – you choose which to provide. | To uniquely identify you, send verification codes, and enable secure authentication. This mobile number is stored as a core credential for as long as your account exists. |
| Authentication logs (timestamp, success/failure, IP address) | For security, fraud detection, and to help you troubleshoot login issues. |
Legal basis: Performance of a contract (providing you with an SSO account) and legitimate interest (security).
Important: You are never required to use OneZiko Identity; you may continue using social login or register directly on each service.
How it relates to our other policies: OneZiko Identity acts as a data controller for authentication data, but we share relevant identifiers (User ID, email/mobile number) with other One Ziko services when you log in. Those services then process that data according to this unified policy.
1.6 e-Mpiya OMPS – Mobile Money Payment Processing
We use e-Mpiya OMPS (http://e-mpiya.oneziko.com/) to accept mobile money payments (Airtel Money, MTN MoMo, Zamtel ZamKwacha). This platform relies on third‑party payment aggregators, primarily PawaPay, to process transactions.
Important note: The mobile money account number (MSISDN) is the same as the mobile number you provide for authentication via OneZiko Identity. We already store this number as part of your account credentials (see section 1.5). For payment processing, we do not store it a second time; we simply use the existing stored number at the moment of payment.
When you make a payment via e-Mpiya OMPS, the following data is processed:
| Data field | Collected by whom | Purpose |
|---|---|---|
| Mobile money account number (your stored mobile number) | One Ziko (already stored) → shared with PawaPay → mobile operator | To debit the correct account. |
| Transaction amount, currency, timestamp | e-Mpiya OMPS & PawaPay | To complete and reconcile the payment. |
| Payment status (success, failed, pending) | e-Mpiya OMPS | To update your order and trigger fulfilment. |
| IP address and device information (for fraud scoring) | PawaPay (as a processor) | To prevent fraudulent transactions. |
Legal basis: Performance of a contract (processing your payment) and compliance with legal obligations (anti‑fraud, record‑keeping).
What we do NOT do:
- We do not create a separate copy of your mobile number for payment purposes; we use the one already stored for authentication.
- We do not retain payment-specific copies of your mobile number beyond the transaction log (which references your user ID, not the raw number, after 7 days).
- The payment aggregator (PawaPay) and mobile operators may store your mobile number as part of their transaction records according to their own policies. We encourage you to read their privacy policies:
- PawaPay Privacy Policy
- Airtel Money / MTN MoMo / Zamtel ZamKwacha (links on their websites)
Refunds: Any refunds processed via e-Mpiya OMPS will use the same stored mobile number – you do not need to provide it again.
2. How We Use Your Personal Data
We use your data for the following purposes only:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Social login data or OneZiko Identity data (email/mobile number) | Contract performance |
| Authenticating users via OneZiko Identity | Mobile number / email, authentication logs | Contract performance / legitimate interest |
| Processing mobile money payments (e-Mpiya OMPS) | Stored mobile number, transaction data, IP address | Contract performance / legal obligation |
| Providing customer support | Email address, mobile number, usage logs | Contract performance / legitimate interest |
| Improving our apps (debugging, feature usage analysis) | Automatically collected info (anonymised where possible) | Legitimate interest |
| Security and fraud prevention | IP address, device ID, authentication logs | Legitimate interest / legal obligation |
| Sending service-related emails or SMS (not marketing) | Email address, mobile number | Contract performance |
| Aggregated analytics (market research) | Location, usage data (anonymised) | Legitimate interest |
| Legal compliance or responding to lawful requests | Any relevant data | Legal obligation |
We do NOT sell your personal data to third parties. We do NOT use your data for automated decision-making or profiling that has legal or significant effects on you.
3. Cookies and Similar Technologies
Our website and apps use cookies, local storage, and similar tracking technologies to:
- Keep you logged in (essential cookies)
- Remember your preferences (functional cookies)
- Collect analytics and performance data (non‑essential – including those used by Google Analytics, Mixpanel, Clarity, etc.)
Your consent is required for non‑essential cookies (e.g., analytics, session recording). When you first visit our website or open our app, a cookie consent banner will appear, allowing you to:
- Accept all cookies
- Reject non‑essential cookies (only essential cookies will be set)
- Customise your preferences
You can change your cookie settings at any time via the “Cookie Preferences” link in the footer of our website or app settings.
4. Data Sharing and Third‑Party Disclosures
We share your personal data only in the following limited circumstances:
4.1 With your consent
If you ask us to share your data with another user or platform, we will do so only with your explicit permission.
4.2 With our service providers (processors)
We share data with companies that help us operate our Services, such as hosting providers, analytics platforms, and crash reporting tools. All processors sign a Data Processing Agreement (DPA) that requires them to protect your data and use it only for the purposes we specify.
Categories of processors: Cloud hosting (e.g., AWS, Google Cloud), analytics (Google Analytics, Mixpanel, Clarity, Google Search Console), error tracking (Sentry), customer support tools.
4.3 For legal reasons
We may disclose your data if required by law, such as to comply with a subpoena, court order, or lawful request from Zambian or other competent authorities. We will notify you unless prohibited by law.
4.4 Business transfers
If One Ziko is involved in a merger, acquisition, or sale of assets, your data may be transferred to the new owner. We will notify you via email and/or a prominent notice in our app at least 30 days before any such transfer, and you may delete your account before the transfer takes effect.
4.5 With your explicit consent for other cases
Any other sharing will be clearly explained to you, and you will have the opportunity to refuse.
4.6 Payment aggregators and mobile money operators (e-Mpiya OMPS)
When you make a payment, we share your stored mobile number (MSISDN) , transaction amount, and timestamp with PawaPay and the respective mobile network operator (Airtel, MTN, Zamtel) solely to execute the transaction. These third parties act as independent data controllers for the data they receive and may retain transaction records according to their own legal obligations. We do not share your mobile number with them for any other purpose.
We do not share your data with “our clients” in any manner that identifies you personally. Any aggregated insights shared with business partners are fully anonymised.
5. International Data Transfers
One Ziko is based in Zambia, but we use service providers located in other countries, including the United States (Google, Microsoft, Mixpanel, Sentry, Amazon Web Services, PawaPay) and the European Union.
When we transfer your personal data outside of Zambia or outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission, or
- Data Privacy Framework certification (for transfers to the US, where applicable)
By using our Services, you acknowledge that your data may be transferred, stored, and processed in countries with different data protection laws than your own. We take all reasonable steps to ensure your data is treated securely and in accordance with this policy.
To obtain a copy of the safeguard mechanisms (e.g., SCCs), please contact us at info@oneziko.com.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law.
| Type of data | Retention period |
|---|---|
| Social login data (name, email, avatar, user ID) | While your account is active + deleted within 30 days after you delete your account. |
| OneZiko Identity mobile number and/or email (authentication credential) | While your account is active + deleted within 30 days after account deletion. |
| OneZiko Identity authentication logs | 12 months (for security auditing). |
| Mobile money transaction logs (reference to user ID, amount, date, status – not the raw mobile number after processing) | 7 years (for tax and audit compliance). The mobile number itself is not retained in these logs beyond the initial transaction window; it is replaced by a user reference. |
| Automatically collected information (non‑personal, anonymous) | Up to 24 months in identifiable form, then permanently anonymised or aggregated. |
| IP addresses | Raw IP addresses are kept for 30 days for security purposes, then anonymised. |
| Cookies and tracking data | As set in your cookie preferences (typically up to 13 months for analytics cookies). |
| Customer support emails and logs | 2 years after the last support interaction. |
| Backups and disaster recovery | Up to 90 days, after which data is permanently deleted. |
After the retention period expires, data is either deleted, anonymised, or aggregated in a way that can no longer identify you.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the UK, you have the following rights under the General Data Protection Regulation (GDPR). We extend these rights to all users worldwide as a matter of good practice, where feasible.
| Right | What it means | How to exercise |
|---|---|---|
| Right to access (Art. 15) | You can request a copy of all personal data we hold about you. | Email info@oneziko.com with subject “GDPR Access Request”. |
| Right to rectification (Art. 16) | You can correct inaccurate or incomplete data (e.g., your mobile number). | Edit your profile in the app, or contact us. |
| Right to erasure (“right to be forgotten”) (Art. 17) | You can request deletion of your data. | Use the “Delete Account” button in your profile settings. Note: Transaction history may need to be retained for 7 years in anonymised form (no mobile number). |
| Right to restriction of processing (Art. 18) | You can ask us to stop processing your data temporarily. | Email info@oneziko.com with subject “Restrict Processing”. |
| Right to data portability (Art. 20) | You can request a machine‑readable copy of your data to transfer to another service. | Email info@oneziko.com – we will provide JSON or CSV format. |
| Right to object (Art. 21) | You can object to processing based on legitimate interests (e.g., analytics). | Adjust cookie settings or email us. |
| Right to withdraw consent (Art. 7(3)) | If processing is based on your consent, you can withdraw it at any time. | Withdraw via cookie banner or email. |
| Right to lodge a complaint | You can complain to your local data protection authority. | For EU users: https://edpb.europa.eu/about-edpb/board/members_en |
We will respond to all valid requests within 30 days (or 60 days for complex requests, with notification). There is no fee for exercising your rights, except for manifestly unfounded or excessive requests.
8. Children’s Privacy
Our Services are not intended for children under the age of 16 (or the age of digital consent in your country, if higher).
OneZiko Identity and e‑Mpiya OMPS are not available to users under 16, as they require a mobile money account or email address that must be held by a person of legal age.
We do not knowingly collect personal data from children under 16. If we discover that we have inadvertently done so, we will delete that information immediately.
If you are a parent or guardian and believe your child under 16 has provided us with personal data, please contact us at info@oneziko.com.
For users in the EU, the GDPR sets the default age of consent at 16. Some member states have lowered it to 13, but we choose to apply 16 as a uniform standard.
9. Security Measures
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES‑256).
- Access controls – only authorised employees on a need‑to‑know basis can access personal data.
- Regular security reviews and vulnerability scanning.
- Data minimisation – we collect only what is necessary.
However, no system is 100% secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.
10. Data Breach Notification (GDPR Article 33)
We have an internal data breach response plan. In the event of a personal data breach (e.g., unauthorised access, loss, or disclosure), we will:
- Contain and assess the breach within 24 hours.
- Notify the Zambian Data Protection Authority (or lead EU authority) within 72 hours, unless the breach is unlikely to result in a risk.
- Notify affected users directly if the breach poses a high risk to their rights (e.g., financial or identity theft).
You will be informed via email or in‑app notification.
11. How to Delete Your Account
You can delete your account at any time:
- In the app: Go to “Edit Profile” → scroll to bottom → click “DELETE ACCOUNT” (red button).
- On the website: Log in → Profile settings → Delete Account.
- By email: Send a request to info@oneziko.com from the email address or mobile number associated with your account.
What happens after deletion:
- Your profile, username, email, mobile number, avatar, and all content you posted will be permanently deleted within 30 days.
- OneZiko Identity authentication logs will be deleted after 12 months (or earlier upon request, if not needed for security).
- Some automatically collected information may remain in anonymised, aggregated form for analytics purposes (no link to you).
- Transaction history (without mobile number) may be retained for up to 7 years to comply with tax and audit laws.
- Backup copies will be destroyed within 90 days.
You cannot recover a deleted account. Please be certain before proceeding.
12. Changes to This Policy
We may update this Privacy & Data Policy from time to time to reflect changes in our practices or legal requirements.
- Minor changes (e.g., adding a new analytics provider) – we will update the “Last updated” date and notify you via in‑app notice.
- Material changes (e.g., new data sharing, different legal basis) – we will notify you by email or SMS (to the contact details you provided) and seek renewed consent where required.
Your continued use of our Services after the effective date of changes constitutes acceptance of the revised policy. If you do not agree, you must delete your account before the changes take effect.
13. Contact Information
For any questions, requests, or complaints regarding this policy or your data, please contact us:
One Ziko
Email: info@oneziko.com
Address: AfricaWorks @Agora Village, Lusaka, Zambia 10101
For GDPR-related matters – if you are in the EU and wish to raise a concern, you may also contact your local data protection authority. We will cooperate fully.
© One Ziko 2025 – All Rights Reserved