Data Collection Scope
Stated the same way in this policy and in our account terms — only identity, contact, and transaction data.
At up77, we want you to understand exactly what personal data we collect when you open an account or use our platform in supported Pakistan regions, how we...
This policy applies to all personal data we process when you access up77 in supported regions where local law permits. We collect only what is necessary: your name, contact details, account credentials, and transaction records linked to payment methods such as JazzCash, Easypaisa, SadaPay, and Raast. We do not sell your data to third parties. Retention periods align with our legal obligations,
and we apply industry-standard encryption to data both in transit and at rest. You may request a copy of your stored data or ask us to delete it at any time through your account settings or via our support team.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Our data practices are built around transparency and security rather than compliance checkboxes. Every measure below is active on your account the moment you create it, and we review these controls regularly...
All data you send to up77 — login credentials, payment details, account documents — travels over TLS-encrypted connections so nothing is readable in transit between your device and our servers.
We collect only what we actually need to run your account and process transactions via JazzCash, Easypaisa, SadaPay, and Raast. Data we do not need is never requested and never stored.
Your personal data is accessible only to staff with a direct operational need. Internal access is logged, audited regularly, and revoked immediately when no longer required.
You can ask us to delete your personal data at any time. We process deletion requests within 30 days, confirm completion in writing, and retain only what law specifically requires us to keep.
Every marketing preference and data-sharing consent you give is logged with a timestamp. You can review or withdraw these consents from your account settings page without contacting support.
We conduct periodic internal audits of our data storage and access systems. Any vulnerability found during an audit is patched before it reaches production, keeping your account data protected.
Our privacy approach is consistent whether you are reading this page, our cookie policy, or our account terms. The table below shows how key data commitments appear uniformly across our policy documents...
Stated the same way in this policy and in our account terms — only identity, contact, and transaction data.
Consistent across this policy and our cookie policy: transaction records kept per legal requirement, marketing data deleted on request.
No sale of personal data to third parties is stated uniformly here and in our terms — no exceptions for analytics partners.
Supported-region language appears in this policy, our terms, and our cookie notice so you always know where access applies.
Rights to access, correct, and delete data are described with identical scope in this policy and in our account help section.
JazzCash, Easypaisa, SadaPay, and Raast transaction data handling is documented consistently here and in our payment terms.
Encryption and access-control commitments mirror the technical standards referenced in our account security page exactly.
Our privacy framework is structured so you can find what you need quickly and understand how every part of your account data is handled. The six...
Every clause is written in clear English so you do not need legal training to understand what we collect, why we collect it, and how long we keep it on file.
This policy moves from broad principles to specific data types, so you can stop reading at the level of detail that answers your question without scrolling through irrelevant sections.
Marketing emails, data-sharing preferences, and cookie categories each have their own toggle in your account settings rather than a single all-or-nothing consent button.
Account holders can request a full log of when their data was accessed internally, by whom, and for what operational purpose — downloadable directly from account settings.
Every time we update this policy, the previous version is archived and accessible. You can compare the current text against any prior version to see exactly what changed and when.
If you disagree with how we have handled a data request, this policy sets out a clear escalation route to our senior privacy contact before any external complaint process is needed.