Legal
Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how ZuZu Corporation, trading as ZuZu (“ZuZu,” “we,” “us,” or “our”), collects, uses, discloses, stores, retains, and protects personal data when you access or use zuzuwallet.com, our Android application, and any websites, products, features, communications, integrations, and related services that we operate (collectively, the “Services”).
ZuZu provides digital wallet and financial technology functionality that may allow eligible users to deposit, hold, transfer, convert, earn on, and withdraw supported digital assets; transfer value to other ZuZu users; and convert or cash out supported balances to Philippine peso (“PHP”) through available payout methods.
This Privacy Policy should be read together with our Terms of Service and any additional privacy notices or consent forms presented when particular information is collected.
By accessing or using the Services, you acknowledge that your personal data will be handled as described in this Privacy Policy.
1. Who We Are
The Services are operated by:
ZuZu Corporation
Trading as ZuZu
For privacy-related questions, requests, or concerns:
ZuZu Privacy / Data Protection Contact
Email: privacy@zuzuwallet.com
You may also contact us through Help while signed in to your ZuZu account or through the official support channels published on zuzuwallet.com.
Where required by applicable law, additional information concerning our Data Protection Officer, registered business address, or local representative will be made available through our official website or privacy contact.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data we process when you:
- visit zuzuwallet.com or another official ZuZu website;
- create, access, or maintain a ZuZu account;
- use the ZuZu Android application;
- create or edit a ZuZu profile or username;
- deposit or withdraw supported digital assets;
- convert between supported digital assets or currencies;
- use ZuZu Earn features;
- send or receive internal ZuZu transfers;
- create, receive, or respond to money requests;
- create or use payment links or payment QR codes;
- request a PHP withdrawal or cash out;
- save payout destinations or cryptocurrency addresses;
- complete identity, account, or transaction verification;
- enable passkeys, authenticator verification, app lock, or other security features;
- enable push notifications or other communications;
- contact customer support;
- interact with ZuZu through an available third-party integration such as Telegram; or
- otherwise use or interact with the Services.
This Privacy Policy does not govern third-party websites, applications, wallets, exchanges, blockchains, banks, payment providers, or other services that operate independently of ZuZu.
3. Our Privacy Principles
We aim to process personal data in a manner that is appropriate to the nature of our Services. Our approach includes the following principles:
Purpose limitation: We process personal data for legitimate and disclosed purposes related to operating, securing, supporting, and improving ZuZu.
Data minimization: We seek to collect information that is reasonably necessary for the relevant feature, transaction, security control, or legal obligation.
Accuracy: We take reasonable steps to maintain accurate account and transaction records and provide users with appropriate methods to correct certain information.
Security: We use technical, organizational, and administrative safeguards appropriate to the sensitivity of the information and the risks involved.
Retention limitation: We do not intend to retain personal data indefinitely when there is no legitimate business, security, contractual, or legal reason to retain it.
Transparency: We aim to explain what we collect, why we process it, and the circumstances in which it may be disclosed.
4. Personal Data We Collect
The personal data we collect depends on how you use ZuZu and which Services are available to you.
4.1 Account and Profile Information
When you create or maintain an account, we may collect:
- email address;
- username;
- display name;
- profile photograph or avatar, if provided;
- password credentials, which are stored using cryptographic password hashing rather than as a plain-text password;
- email verification status;
- account creation information;
- account status;
- account settings;
- notification and communication preferences; and
- other profile information you voluntarily provide.
Your sign-in email is not intended to be publicly displayed merely because you create a ZuZu username.
4.2 Public Profile and Payment Information
Certain ZuZu features allow you to make limited information available to other people.
Depending on how you configure and use the Services, this may include:
- username;
- display name;
- profile photograph;
- public profile URL;
- payment QR code;
- payment link;
- information included in a money request; and
- other information you intentionally share for a payment or transfer.
For example, if you create a public payment link or share a profile QR code, people who receive that link or QR code may be able to view the information necessary to identify your ZuZu profile and initiate a payment.
Do not include information in a public profile, payment request, note, or payment link that you do not want the intended recipient to see.
4.3 Identity Verification and Compliance Information
Where identity verification, account limits, transaction review, risk assessment, or legal or compliance requirements apply, we may collect or process information such as:
- full legal name;
- date of birth;
- residential address;
- nationality;
- country of residence;
- occupation or similar identifying information where required;
- government-issued identification type or number;
- photographs or copies of identity documents;
- photographs, selfies, or other verification materials;
- information used to confirm document authenticity;
- verification results and status;
- review notes;
- transaction-related information;
- information concerning the source, destination, or purpose of funds where required;
- sanctions, fraud, risk, or compliance-related information where lawfully obtained; and
- other information reasonably necessary for identity verification, fraud prevention, risk management, or compliance.
Not every user will be required to provide every category of information listed above.
Identity and verification information may constitute sensitive personal information under applicable law and is subject to heightened access restrictions and security controls where required.
4.4 Wallet, Balance, and Transaction Information
When you use wallet or money-movement features, we may process information such as:
- supported asset balances;
- available and reserved balances;
- asset and blockchain-network selections;
- blockchain deposit addresses;
- withdrawal addresses and other destinations;
- transaction hashes;
- blockchain transaction identifiers;
- deposit amounts;
- withdrawal amounts;
- transaction fees;
- transaction status;
- blockchain confirmation information;
- conversion requests;
- quoted and completed conversion rates;
- amounts sent and received in conversions;
- internal ZuZu transfers;
- transfer sender and recipient information;
- money requests;
- payment links;
- transaction or payment notes;
- Earn deposits;
- Earn positions;
- applicable Earn rates;
- Earn withdrawals or maturity information;
- timestamps;
- transaction and ledger references;
- idempotency or operational transaction identifiers;
- transaction history; and
- other records needed to operate, reconcile, support, or secure the Services.
We maintain transaction records for operational, security, financial, accounting, dispute-resolution, fraud-prevention, and legal purposes.
4.5 PHP Withdrawal and Payout Information
When you request a PHP withdrawal or cash out through a supported payout method, we may collect and process information necessary to execute, review, reconcile, and support the payout.
Depending on the payout method, this may include:
- payout channel;
- bank or financial institution;
- account holder or recipient name;
- bank account number or other account identifier;
- mobile number;
- GCash destination information;
- Maya destination information;
- other supported e-wallet details;
- saved payout destination information;
- payout amount;
- transaction fees where applicable;
- payout status;
- payout reference or confirmation number;
- timestamps; and
- related operational, compliance, or support information.
To complete a payout, we may disclose the information necessary to the relevant bank, payment network, e-wallet provider, payout operator, or other service provider involved in processing the transaction.
4.6 Security, Authentication, and Session Information
To authenticate users and protect ZuZu accounts, we may process:
- sign-in events;
- sign-out events;
- session identifiers;
- session creation and expiration times;
- IP addresses;
- device information;
- browser information;
- application information;
- password-change events;
- password-reset events;
- email-verification events;
- authenticator-app or time-based one-time password (“TOTP”) enrollment and verification information;
- passkey and WebAuthn credential information;
- authentication challenges;
- step-up verification events;
- application-lock settings;
- security preferences;
- account-lock or restriction events;
- suspected unauthorized-access information;
- records of active or historical sessions and devices;
- session revocation events; and
- other information reasonably necessary to secure accounts and transactions.
4.7 Passkeys and Biometrics
ZuZu may allow you to use passkeys and device authentication mechanisms supported by Android.
Passkey functionality may involve cryptographic credentials created and managed by your device, operating system, credential provider, or compatible account.
Where biometric authentication is used to unlock ZuZu or approve use of a device credential, biometric matching is generally performed by the device operating system.
ZuZu does not receive or store your raw fingerprint, facial image, or biometric template merely because you use fingerprint or facial authentication through your Android device.
Your device manufacturer, operating-system provider, or credential provider may independently process information relating to its biometric or credential services under its own privacy terms.
4.8 Device, Application, and Technical Information
When you access our websites or applications, we may automatically receive technical information such as:
- IP address;
- device type;
- operating system;
- operating-system version;
- browser type and version;
- Android application version;
- network and connectivity information;
- device or application identifiers where applicable;
- timestamps;
- requested pages, screens, or API endpoints;
- security events;
- application events;
- crash information;
- error reports;
- performance or diagnostic information; and
- information reasonably necessary to detect abuse, troubleshoot problems, or maintain the Services.
We may derive an approximate geographic area from your IP address for security, fraud-prevention, or operational purposes. An approximate location derived from an IP address is different from precise GPS location.
4.9 Push Notifications
If you enable push notifications, we may process:
- device push tokens;
- device platform information;
- notification preferences;
- notification delivery information; and
- routing information necessary to open the appropriate ZuZu screen when you interact with a notification.
The ZuZu Android application may use Firebase Cloud Messaging, provided by Google, to deliver push notifications.
Google may process certain device or technical information in connection with Firebase Cloud Messaging under Google's own applicable privacy terms.
You may control notification permissions through Android settings and, where available, through your ZuZu notification preferences.
Disabling push notifications does not necessarily disable required account, transaction, or security communications delivered through other channels.
4.10 Camera Access
The ZuZu Android application may request access to your device's camera for features such as:
- scanning payment QR codes;
- scanning blockchain addresses;
- capturing supported verification information; or
- other functionality clearly presented to you before camera access occurs.
Camera access is subject to the permission controls provided by Android.
You may revoke camera permission through your device settings, although doing so may prevent camera-dependent features from working.
4.11 Customer Support and Communications
When you contact ZuZu, we may collect:
- your contact information;
- support-request subject and category;
- support messages;
- email correspondence;
- support-ticket history;
- attachments you submit;
- screenshots or documents you provide;
- transaction or account information relevant to your request;
- records of our responses; and
- other information reasonably necessary to investigate and resolve the matter.
Support communications may be retained where reasonably necessary for customer service, security, fraud prevention, quality assurance, dispute resolution, legal compliance, and operational purposes.
4.12 Telegram and Other Integrations
Where ZuZu offers functionality through Telegram or another third-party integration, we may receive information provided through that service that is necessary to authenticate, connect, or operate the integration.
For Telegram, this may include information such as:
- Telegram user identifier;
- username or profile information made available to the integration;
- authentication information provided through the Telegram integration; and
- information necessary to associate your Telegram interaction with a ZuZu account where you choose to connect them.
Telegram and other third parties independently process information under their own privacy policies and terms.
5. Information We Receive From Other Sources
We may receive personal data or transaction-related information from sources other than you, including:
- public blockchain networks;
- blockchain nodes and RPC providers;
- financial institutions;
- banks and payment providers;
- payout operators;
- e-wallet providers;
- identity-verification providers;
- fraud-prevention providers;
- security providers;
- communications providers;
- cloud and infrastructure providers;
- counterparties involved in transactions;
- public records or publicly available sources where permitted by law;
- professional advisers;
- government authorities;
- regulators;
- courts; and
- law-enforcement agencies.
We may combine information received from these sources with information associated with your ZuZu account when necessary for the purposes described in this Privacy Policy.
6. Public Blockchain Information
Public blockchains operate differently from private databases.
When you send or receive a blockchain transaction, information may be permanently recorded on a public blockchain, including:
- sending and receiving blockchain addresses;
- cryptocurrency or token amounts;
- transaction hashes;
- transaction timestamps;
- network fees;
- smart-contract interactions; and
- other blockchain transaction data.
Public blockchain information:
- may be visible to anyone;
- may remain available indefinitely;
- may be copied, indexed, analyzed, or redistributed by third parties;
- may allow transaction relationships to be inferred when combined with other information; and
- generally cannot be changed or deleted by ZuZu after a transaction is confirmed.
ZuZu does not control the continued availability of information independently recorded on public blockchain networks.
You should understand these characteristics before using blockchain-based features.
7. How We Use Personal Data
We may use personal data to:
Provide and Operate ZuZu
- create and administer accounts;
- provide wallet functionality;
- maintain balances;
- assign or display deposit addresses;
- process deposits;
- process withdrawals;
- process PHP cash-outs;
- process transfers;
- process money requests and payment links;
- provide conversion quotes;
- execute conversions;
- administer Earn features;
- display activity and transaction history;
- provide saved payout destinations or cryptocurrency addresses; and
- otherwise perform Services you request.
Authenticate and Protect Users
- authenticate sign-ins;
- maintain and manage sessions;
- support passkeys and authenticator verification;
- perform additional verification for sensitive transactions;
- prevent unauthorized account access;
- investigate suspicious activity;
- detect account takeover;
- manage device and session security; and
- provide security alerts.
Process and Reconcile Transactions
- validate requests;
- calculate amounts, rates, and fees;
- track blockchain confirmations;
- reconcile deposits and withdrawals;
- maintain transaction records;
- resolve failed or delayed transactions; and
- investigate disputes or transaction discrepancies.
Prevent Fraud, Abuse, and Security Incidents
- detect suspicious or prohibited activity;
- investigate attempted fraud;
- identify abusive use;
- enforce risk controls;
- prevent duplicate or unauthorized transactions;
- protect ZuZu infrastructure; and
- respond to actual or suspected security incidents.
Verify Identity and Meet Compliance Requirements
Where applicable, we may use information to:
- verify identity;
- review account activity;
- administer transaction or account limits;
- perform compliance or risk reviews;
- investigate unusual activity;
- respond to lawful requests;
- comply with legal or regulatory recordkeeping requirements; and
- otherwise meet obligations imposed on us by applicable law.
Communicate With You
We may use contact information to send:
- email-verification messages;
- security notifications;
- password or authentication notices;
- deposit notifications;
- withdrawal notifications;
- transfer notifications;
- conversion notifications;
- Earn notifications;
- verification updates;
- support replies;
- material Service notices;
- push notifications you enable; and
- optional product communications where you have not opted out or where consent has been provided if required.
Provide Customer Support
We may use account, transaction, and communication information to:
- respond to questions;
- investigate support requests;
- troubleshoot account or transaction problems;
- resolve complaints;
- verify account ownership where necessary; and
- maintain support records.
Maintain and Improve the Services
We may process technical and usage information to:
- monitor availability and reliability;
- troubleshoot errors;
- diagnose crashes;
- improve application performance;
- test features;
- understand how Services are used;
- improve user experience;
- maintain system integrity; and
- develop or improve ZuZu functionality.
Protect Our Rights and Meet Legal Obligations
We may use information to:
- enforce our Terms of Service;
- protect users and the public;
- protect ZuZu's rights and property;
- maintain records;
- respond to disputes;
- comply with lawful legal process;
- establish, exercise, or defend legal claims; and
- satisfy applicable tax, accounting, regulatory, security, or legal obligations.
8. Account, Transaction, and Security Communications
Certain communications are necessary to provide or protect your account.
These may include communications about:
- account creation or verification;
- sign-in activity;
- password changes;
- passkeys or authentication changes;
- security events;
- suspicious activity;
- deposits;
- withdrawals;
- conversions;
- transfers;
- Earn activity;
- identity verification;
- support requests;
- changes affecting your account; and
- material changes to the Services.
These communications are operational or security-related rather than marketing communications.
Accordingly, some account and security communications cannot be disabled while maintaining an active ZuZu account.
Where ZuZu allows you to disable optional money, account, product, or promotional emails, important security communications may continue to be sent.
You may manage available notification preferences through your ZuZu account.
9. How We Disclose Personal Data
We do not sell your personal data for money.
We disclose personal data only where reasonably necessary for the purposes described in this Privacy Policy, including in the circumstances below.
9.1 Service Providers
We may disclose information to vendors and service providers that assist us with:
- cloud hosting;
- application infrastructure;
- data storage;
- database services;
- blockchain nodes and RPC infrastructure;
- email delivery;
- push notifications;
- identity verification;
- compliance services;
- fraud prevention;
- security monitoring;
- customer support;
- diagnostics;
- operational monitoring; and
- other technology necessary to provide the Services.
Service providers are expected to process personal data only for authorized purposes and subject to applicable contractual and legal obligations.
9.2 Banks, E-Wallets, and Payout Providers
When you request a PHP cash out or another supported payout, we may disclose the information necessary to execute, review, reconcile, or support the transaction to:
- banks;
- payment networks;
- GCash or Maya, where applicable;
- other e-wallet providers;
- payment processors;
- payout operators; or
- other financial service providers involved in the transaction.
Those entities may independently process information in accordance with their own legal obligations and privacy notices.
9.3 Blockchain Networks and Infrastructure Providers
To generate, monitor, verify, sign, broadcast, or otherwise support blockchain transactions, information may be transmitted to or received from:
- blockchain networks;
- blockchain nodes;
- RPC providers;
- blockchain infrastructure providers; and
- other technical providers supporting the relevant network.
Information written to public blockchains is public as described in Section 6.
9.4 Other ZuZu Users and Payment Recipients
Certain ZuZu features necessarily disclose limited information to another user.
For example, a transfer, money request, username-based payment, payment link, or profile QR code may display information necessary to identify the sender or intended recipient.
Information you intentionally include in a transfer note, request, profile, or payment link may also be visible to the intended recipient or anyone with whom you share the relevant link.
9.5 Professional Advisers
We may disclose information where reasonably necessary to:
- lawyers;
- accountants;
- auditors;
- insurers;
- compliance professionals;
- consultants; and
other professional advisers,
subject to appropriate professional, legal, or contractual confidentiality obligations.
9.6 Legal, Regulatory, and Safety Disclosures
We may disclose information where we reasonably believe disclosure is necessary or appropriate to:
- comply with applicable law or regulation;
- comply with a court order, subpoena, warrant, or lawful governmental request;
- cooperate with a regulator or supervisory authority;
- investigate fraud or unlawful conduct;
- investigate or respond to a security incident;
- enforce our Terms of Service or other agreements;
- protect the rights, property, or security of ZuZu;
- protect users or other persons;
- prevent harm; or
- establish, exercise, or defend legal claims.
9.7 Corporate Transactions
If ZuZu or ZuZu Corporation is involved in a:
- merger;
- acquisition;
- financing;
- investment;
- reorganization;
- restructuring;
- sale of assets;
- insolvency proceeding; or
similar corporate transaction,
personal data may be disclosed to relevant parties or transferred as part of that transaction, subject to applicable law and appropriate safeguards.
10. We Do Not Sell Personal Data
ZuZu does not sell personal data in exchange for money.
We also do not use account, KYC, wallet, or transaction information for third-party behavioral advertising.
If our practices materially change in the future, we will update this Privacy Policy and provide any choices or notices required by applicable law.
11. Cookies, Local Storage, and Similar Technologies
Our websites may use cookies, browser storage, local storage, session technologies, or similar mechanisms.
These technologies may be used to:
- maintain sign-in sessions;
- authenticate users;
- remember preferences;
- maintain security state;
- protect against unauthorized requests;
- prevent abuse;
- maintain website functionality;
- troubleshoot problems; and
- detect security or operational issues.
Some technologies are necessary for authenticated ZuZu functionality and cannot be disabled without affecting the operation of the Services.
If we introduce non-essential analytics, advertising, or behavioral-tracking technologies that require consent, we will provide any notice or consent controls required by applicable law.
12. Legal Bases for Processing
The legal basis on which we process personal data depends on the information, purpose, Service, and law applicable to the processing.
Where applicable law requires a legal basis, processing may be based on one or more of the following:
Contract or Requested Service
Processing may be necessary to:
- create and administer your account;
- authenticate you;
- process transactions;
- provide wallet functionality;
- provide support; or
- otherwise perform a Service you request.
Legal or Regulatory Obligation
We may process information where necessary to comply with:
- applicable laws;
- regulatory requirements;
- lawful governmental demands;
- accounting obligations;
- tax requirements;
- recordkeeping obligations; or
- other legal duties.
Legitimate or Lawful Interests
Where recognized by applicable law, we may process information where reasonably necessary for interests such as:
- protecting users;
- preventing fraud;
- maintaining account security;
- securing networks and systems;
- preventing abuse;
- maintaining the reliability of the Services;
- improving our products;
- providing support; and
protecting or enforcing legal rights,
provided the relevant interests and rights are appropriately considered.
Consent
Where required, we may ask for your consent to a particular processing activity.
Where processing is based on consent, you may withdraw that consent as permitted by applicable law. Withdrawal does not affect the lawfulness of processing that occurred before consent was withdrawn.
13. International Processing and Data Transfers
ZuZu, its infrastructure, and its service providers may process personal data in countries other than the country in which you reside.
Those countries may have privacy and data-protection laws that differ from the laws in your country.
Where applicable law requires safeguards for an international transfer, we will use appropriate measures intended to protect transferred personal data.
Depending on the circumstances and applicable law, these may include:
- contractual data-protection obligations;
- approved transfer mechanisms;
- security safeguards;
- vendor assessments; and
- other legally recognized transfer protections.
14. Data Retention
We retain personal data for only as long as reasonably necessary for the purposes for which it is processed, subject to legal, regulatory, security, financial, and operational requirements.
Factors we consider when determining retention include:
- how long your account remains active;
- the nature of the information;
- the sensitivity of the information;
- transaction and financial recordkeeping requirements;
- security and fraud-prevention needs;
- dispute and complaint periods;
- applicable statutes of limitation;
- tax and accounting requirements;
- contractual obligations;
- regulatory requirements; and
- legal holds or investigations.
We may retain information after an account is closed or deleted where retention is reasonably necessary or required for:
- transaction records;
- financial reconciliation;
- fraud prevention;
- account-security history;
- dispute resolution;
- compliance obligations;
- audits;
- legal claims; or
- other lawful purposes.
Account deletion therefore does not necessarily result in the immediate deletion of all personal data.
When personal data is no longer required, we may delete, anonymize, de-identify, or otherwise securely dispose of it in accordance with our retention procedures and applicable law.
Public Blockchain Records
Information independently recorded on a public blockchain is not controlled solely by ZuZu and may remain publicly available indefinitely.
ZuZu cannot erase or modify confirmed public blockchain records.
Backups
Deleted information may remain temporarily in encrypted or protected backup systems until those backups are overwritten, rotated, or otherwise deleted in accordance with our backup and retention procedures, unless longer retention is legally required.
15. Security
We use administrative, organizational, and technical safeguards designed to protect personal data against unauthorized access, acquisition, alteration, disclosure, destruction, loss, or misuse.
Depending on the system or feature, safeguards may include:
- encrypted transmission using HTTPS/TLS;
- cryptographic password hashing;
- authentication controls;
- session management;
- session revocation;
- authenticator-app verification;
- passkeys and WebAuthn;
- additional authentication for sensitive actions;
- device-level application locking;
- access controls;
- role-based administrative permissions;
- security logging;
- monitoring and audit mechanisms;
- transaction validation;
- network validation;
- fraud and abuse controls;
- infrastructure security measures; and
- internal operational procedures.
Access to sensitive account and identity information is restricted to personnel, systems, and service providers with an appropriate need for access.
Security Incidents
We maintain processes designed to detect, investigate, contain, and respond to security incidents.
Where an incident involving personal data requires notification under applicable law, we will notify affected individuals and/or the appropriate authority in accordance with the requirements that apply to us.
Your Responsibilities
No website, application, blockchain, network, or storage system can be guaranteed to be completely secure.
You are responsible for taking reasonable steps to protect:
- your ZuZu password;
- your email account;
- your passkeys;
- your authenticator application;
- your device credentials;
- your mobile device; and
- any other account-recovery or authentication method associated with your account.
Do not share passwords, authentication codes, or other security credentials with another person.
If you believe your account, email, authentication method, or device has been compromised, contact ZuZu support promptly and secure the affected accounts or devices.
16. Your Privacy Rights
Your privacy rights depend on the laws that apply to you and may be subject to exceptions.
Depending on applicable law, you may have the right to:
- be informed about the processing of your personal data;
- request access to personal data we maintain about you;
- request correction or rectification of inaccurate or incomplete data;
- object to certain processing;
- request restriction of certain processing;
- request erasure, deletion, or blocking of certain data;
- withdraw consent where processing is based on consent;
- request portability of eligible personal data;
- request information concerning recipients or categories of recipients;
- lodge a complaint with an applicable privacy or data-protection authority;
- seek compensation or damages where provided by applicable law; and
- exercise other rights provided by applicable privacy law.
These rights are not absolute.
For example, we may be unable or not required to delete information that must be retained for:
- completing transactions;
- financial recordkeeping;
- fraud prevention;
- security purposes;
- legal compliance;
- regulatory obligations;
- resolving disputes;
- exercising or defending legal claims; or
- other lawful purposes.
Public blockchain information may also be impossible for ZuZu to erase.
Exercising Your Rights
You may manage certain information directly through your account, including available:
- profile settings;
- security settings;
- active sessions;
- notification preferences; and
- account settings.
For other privacy requests, contact:
We may need to verify your identity and account ownership before acting on a request in order to prevent unauthorized access to personal data.
We may request additional information where reasonably necessary to verify or process a request.
We will respond within the period required by applicable law.
17. Additional Information for Users in the Philippines
Where the Republic Act No. 10173, the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission (“NPC”) apply to our processing of your personal data, you may have rights provided under Philippine data-protection law.
These may include the:
- right to be informed;
- right to object;
- right of access;
- right to rectification;
- right to erasure or blocking;
- right to data portability;
- right to file a complaint; and
- right to damages where provided by law.
Requests may be subject to the conditions, limitations, exemptions, verification requirements, and other provisions of applicable Philippine law.
If you believe your rights under Philippine data-protection law have been violated, you may contact ZuZu first at:
You may also have the right to lodge a complaint with the National Privacy Commission of the Philippines.
Nothing in this Privacy Policy is intended to limit rights granted to you by applicable law.
18. Account Deletion
Where account deletion is available, you may initiate a request through the available account settings, Help functionality, or other deletion method made available by ZuZu.
Before deleting an account, we may require additional verification to protect against unauthorized deletion.
Deleting your account may result in loss of access to certain Services and information associated with the active account interface.
Account deletion does not necessarily delete:
- transaction records we are required or permitted to retain;
- blockchain records;
- security records;
- fraud-prevention information;
- dispute records;
- compliance records;
- financial or accounting records; or
- information subject to a legal hold.
Where information can lawfully and reasonably be deleted following account closure, we will process it in accordance with our applicable retention procedures.
19. Children's Privacy
ZuZu is intended for adults who are legally eligible to use the Services.
The Services are not intended for persons under 18 years of age.
We do not knowingly permit persons under 18 to create ZuZu accounts or knowingly collect their personal data for use of the Services.
If you believe that a person under 18 has provided personal data to ZuZu in violation of this requirement, contact privacy@zuzuwallet.com so that we can investigate and take appropriate action.
20. Third-Party Services and Links
The Services may contain links to, integrate with, or rely upon third parties, including:
- blockchain networks;
- banks;
- payment networks;
- e-wallet providers;
- payout providers;
- infrastructure providers;
- credential providers;
- Telegram;
- Google services;
- identity-verification services; and
- other websites or applications.
Third parties may independently collect or process information under their own privacy notices, terms, and legal obligations.
ZuZu does not control the independent privacy practices of third parties.
You should review the applicable third party's privacy information before providing personal data directly to that party.
21. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to:
- the Services;
- available features;
- technology;
- security practices;
- privacy practices;
- service providers;
- applicable laws or regulations; or
- our business and operational requirements.
When this Privacy Policy is updated, we will revise the “Last updated” date at the top.
Where a change is material, we may provide additional notice where appropriate or required, including through:
- an in-app notice;
- our website;
- email;
- account notifications; or
- another appropriate communication method.
If consent to a new or materially different processing activity is required by applicable law, we will seek that consent where required.
22. Contact Us
If you have a question, concern, complaint, or request relating to privacy or personal data, contact:
ZuZu Privacy / Data Protection Contact
ZuZu Corporation
Email: privacy@zuzuwallet.com
For account-specific questions, you may also contact us through Help after signing in to your ZuZu account.
Please do not send passwords, authenticator codes, passkey secrets, private keys, seed phrases, or other authentication secrets by email.