LEGAL REFERENCE

How up77 Handles Your Personal Data

At up77, we want you to understand exactly what personal data we collect when you open an account or use our platform in supported Pakistan regions, how we...

Encrypted Data StorageAccount Privacy ControlsPakistan-Region PolicyRight to Access Your DataSecure Data Transmission
up77 How up77 Handles Your Personal Data

What This Privacy Policy Covers

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

PRIVACY CONTACT PATHS

Reach Our Privacy Team Directly

If you have questions about how your data is handled, want to exercise your data rights, or need to report a privacy...

Live Chat Connect with our privacy support team instantly through...
Email Support Send your data request or privacy query to...
Help Centre Our account help section carries step-by-step directions for...
HOW WE PROTECT YOU

Six Ways We Keep Your Data Safe

Our data practices are built around transparency and security rather than compliance checkboxes. Every measure below is active on your account the moment you create it, and we review these controls regularly...

End-to-End Encryption

All data you send to up77 — login credentials, payment details, account documents — travels over TLS-encrypted connections so nothing is readable in transit between your device and our servers.

Minimal Data Collection

We collect only what we actually need to run your account and process transactions via JazzCash, Easypaisa, SadaPay, and Raast. Data we do not need is never requested and never stored.

Access Controls

Your personal data is accessible only to staff with a direct operational need. Internal access is logged, audited regularly, and revoked immediately when no longer required.

Data Deletion Rights

You can ask us to delete your personal data at any time. We process deletion requests within 30 days, confirm completion in writing, and retain only what law specifically requires us to keep.

Consent Records

Every marketing preference and data-sharing consent you give is logged with a timestamp. You can review or withdraw these consents from your account settings page without contacting support.

Regular Security Audits

We conduct periodic internal audits of our data storage and access systems. Any vulnerability found during an audit is patched before it reaches production, keeping your account data protected.

POLICY CONSISTENCY

How This Policy Aligns Across Our Site

Our privacy approach is consistent whether you are reading this page, our cookie policy, or our account terms. The table below shows how key data commitments appear uniformly across our policy documents...

01

Data Collection Scope

Stated the same way in this policy and in our account terms — only identity, contact, and transaction data.

02

Retention Periods

Consistent across this policy and our cookie policy: transaction records kept per legal requirement, marketing data deleted on request.

03

Third-Party Sharing

No sale of personal data to third parties is stated uniformly here and in our terms — no exceptions for analytics partners.

04

Pakistan Region Scope

Supported-region language appears in this policy, our terms, and our cookie notice so you always know where access applies.

05

Your Data Rights

Rights to access, correct, and delete data are described with identical scope in this policy and in our account help section.

06

Payment Data Handling

JazzCash, Easypaisa, SadaPay, and Raast transaction data handling is documented consistently here and in our payment terms.

07

Security Standards

Encryption and access-control commitments mirror the technical standards referenced in our account security page exactly.

Key Elements of Our Privacy Framework

Our privacy framework is structured so you can find what you need quickly and understand how every part of your account data is handled. The six...

Plain-Language Drafting

Every clause is written in clear English so you do not need legal training to understand what we collect, why we collect it, and how long we keep it on file.

Layered Structure

This policy moves from broad principles to specific data types, so you can stop reading at the level of detail that answers your question without scrolling through irrelevant sections.

Granular Consent Controls

Marketing emails, data-sharing preferences, and cookie categories each have their own toggle in your account settings rather than a single all-or-nothing consent button.

Audit Trail Access

Account holders can request a full log of when their data was accessed internally, by whom, and for what operational purpose — downloadable directly from account settings.

Version History

Every time we update this policy, the previous version is archived and accessible. You can compare the current text against any prior version to see exactly what changed and when.

Direct Escalation Path

If you disagree with how we have handled a data request, this policy sets out a clear escalation route to our senior privacy contact before any external complaint process is needed.

Common Questions About Your Data on up77

We collect your name, email address, phone number, date of birth, and the identity document you use for verification. We also record transaction data linked to your chosen payment method — JazzCash, Easypaisa, SadaPay, or Raast — and session data such as device type and login timestamps.

We do not sell your personal data. We share data only with payment processors required to clear your JazzCash, Easypaisa, SadaPay, or Raast transactions, and with service providers bound by strict data processing agreements that prohibit them from using your data for their own purposes.

Account data is retained while your account is active and for the period required by applicable law after closure. Marketing preferences are deleted as soon as you withdraw consent. Transaction records tied to JazzCash and Easypaisa payments are kept for the minimum period required by financial regulations.

Log into your account and visit the privacy settings section to request a data export. We prepare the file within 30 days and notify you by email when it is ready to download. The export covers account details, transaction records, and stored consent logs.

Yes. Submit a deletion request through your account settings or by emailing our privacy team. We complete verified deletion within 30 days and confirm it in writing. We retain only what law requires us to keep, such as transaction records for a defined statutory period.

All data in transit uses TLS encryption. Stored data uses encryption at rest. Internal access is role-based and logged. We run regular access audits and revoke permissions the moment a staff member no longer needs them. Your account password is hashed and never stored in plain text.

Contact our privacy team via live chat or email with the details of your concern. We will investigate and respond within 72 hours. If you remain unsatisfied after our response, this policy sets out the escalation route to our senior privacy contact for further review.