Cookie & Privacy Policy
Last updated: 21 April 2026
Your privacy matters to us. This policy explains exactly what data we collect, why we collect it, how we use it, and your rights under the Zambia Data Protection Act No. 3 of 2021(the “Act”).
1. Data Controller
Tupane Payments (“we”, “us”) is the Data Controller for personal data you provide when using our website and services. We are registered as a data controller with the Zambia Information & Communications Technology Authority (ZICTA) under the Act.
Chamomile Street, Salama Park, Lusaka, Zambia
founders@usetupane.com
2. What Personal Data We Collect
We collect only what is necessary to provide our service:
| Data | Why we collect it | Legal basis |
|---|---|---|
| Full name | Identity verification & account creation | Contract performance |
| Mobile number (MTN / Airtel) | Account access, payment collection, SMS notifications | Contract performance |
| Transaction history | Affordability & eligibility assessment; repayment scheduling | Contract performance / Legitimate interest |
| Device / browser data | Fraud prevention; website analytics | Legitimate interest |
| Marketing preferences | Only if you opt in to promotional messages | Consent |
We do not collect biometric data, national identity numbers, or financial account credentials (bank account numbers, mobile money PINs).
3. How We Use Your Data
- To process your application and run automated eligibility checks;
- To collect repayments and send you payment reminders and confirmations via SMS;
- To detect and prevent fraud and money-laundering in compliance with the Prohibition and Prevention of Money Laundering Act (Cap. 08:06);
- To comply with reporting obligations to the Bank of Zambia under the Sandbox framework;
- To improve and operate our website and service;
- To send you marketing communications — only if you have separately opted in.
4. Cookies & Website Tracking
Our website uses the following categories of cookies:
| Category | Purpose | Can you opt out? |
|---|---|---|
| Strictly necessary | Session management, security, modal state | No — required for the site to function |
| Analytics | Google Analytics (anonymised IP) — page views, user journeys | Yes — see below |
| Preference | Remembering your consent choices | Managed automatically |
We use Google Analytics 4 with IP anonymisation enabled and ad personalisation disabled. No advertising cookies or third-party tracking pixels are placed on this site.
To opt out of analytics cookies, you can use the Google Analytics Opt-out Browser Add-on or clear your browser cookies.
5. Sharing Your Data
We never sell your personal data. We share data only with:
- MTN Zambia / Airtel Zambia — to initiate and confirm mobile money transactions;
- Bank of Zambia — as required under our Sandbox participation obligations;
- Google LLC — anonymised analytics data only, under a Data Processing Agreement;
- Credit reference bureaus — only in the event of default, as permitted by Zambian law;
- Law enforcement / courts — where required by a valid legal order under Zambian law.
6. Data Retention
We retain your personal data for as long as your account is active and for 7 years thereafter, as required by financial record-keeping regulations in Zambia. Transaction records may be retained longer if required by a regulatory order.
You may request deletion of data not required for legal or regulatory compliance at any time.
7. Your Rights Under the Data Protection Act No. 3 of 2021
You have the right to:
- Access — request a copy of all personal data we hold about you;
- Correction — request that inaccurate data be corrected;
- Deletion — request erasure of data we are not legally required to retain;
- Restriction — ask us to limit how we process your data while a dispute is resolved;
- Objection — object to processing based on legitimate interests;
- Withdraw consent — where we rely on your consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at founders@usetupane.com. We will respond within 30 days.
If you are unsatisfied with our response, you may lodge a complaint with ZICTA, the Zambian data protection supervisory authority.
8. Data Security
We implement technical and organisational measures to protect your data including:
- TLS encryption for all data in transit;
- Access controls limiting data to authorised personnel only;
- Regular security reviews of our systems;
- Incident response procedures in line with the Act.
In the event of a data breach that poses a risk to your rights, we will notify you and ZICTA within the timeframes prescribed by the Act.
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. For material changes, we will notify you by SMS or in-app notice at least 14 days in advance.