Back to Home

Privacy Policy

Last updated: May 2026

This Privacy Policy describes how Ziyo ("we", "us", "our") collects, uses, discloses, and protects your personal data when you use our platform at ziyo.in, our API, dashboard, and all related services (the "Service"). We are committed to protecting your privacy in compliance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDPA), and where applicable, the EU General Data Protection Regulation (GDPR).

1. Data Controller

The data controller for your personal data is Ziyo, a sole proprietorship registered in Bangalore, Karnataka, India. For data protection inquiries, contact us at support@ziyo.in.

2. Information We Collect

2.1 Information You Provide

  • Identity Data: Name, email address, phone number, and Google OAuth profile information when you sign in.
  • Payment Data: UPI ID, bank account number, IFSC code, bank holder name for processing payouts. We do not store full bank credentials.
  • Business Data: Brand name, GSTIN, industry, website, logo, and product information (for Brands).
  • Communication Data: Support tickets, feedback, and correspondence.

2.2 Information Collected Automatically

  • Device Data: Browser type, operating system, device identifiers for security and fraud prevention.
  • Usage Data: Pages visited, features used, timestamps, and interaction patterns.
  • Location Data: Approximate location (city-level) when you scan a reward code, used for fraud detection and analytics.
  • Cookies: See our Cookie Policy for details.

2.3 Information from Third Parties

  • Google OAuth: When you sign in with Google, we receive your name, email, and profile picture.
  • Razorpay: Payment confirmation and transaction status (we do not receive your full card or bank details from Razorpay).

3. How We Use Your Data

We process your personal data for the following lawful purposes:

3.1 For Consumers

  • To authenticate you and provide access to your rewards.
  • To process reward claims and send payouts to your UPI/bank account.
  • To prevent fraud, duplicate claims, and abuse of the reward system.
  • To send notifications about your rewards, payouts, and account activity.

3.2 For Brands

  • To provide the reward management dashboard and API access.
  • To generate and track reward codes and program analytics.
  • To process credit purchases and subscription payments.
  • To provide aggregated, anonymized analytics about consumer behavior.

3.3 For All Users

  • To comply with legal obligations (tax records, fraud reporting, court orders).
  • To maintain the security and integrity of the platform.
  • To communicate important service updates and policy changes.

4. Legal Basis for Processing (GDPR)

For users protected by the GDPR, we process your data on the following legal bases:

  • Contractual Necessity: Processing required to provide the Service you signed up for (e.g., account creation, reward processing, payouts).
  • Legitimate Interest: Fraud prevention, security, platform improvement, and analytics (with appropriate safeguards).
  • Legal Obligation: Compliance with Indian tax laws, financial record-keeping requirements, and court orders.
  • Consent: For non-essential communications and optional data collection (e.g., marketing emails), which you can withdraw at any time.

5. Data Processing Context

Ziyo processes workspace and personal data to operate reward programs, reporting, fraud checks, payouts, support, and approved integrations.

  • Brands: When you claim a reward, the relevant Brand receives your name and claim details so they can fulfill the reward. Brands do not receive full payout details by default in standard views.
  • Payment Providers: To process subscription payments and consumer payouts through configured provider workflows.
  • Cloud Infrastructure (Neon, Cloudflare): For database hosting and application delivery. These providers are bound by Data Processing Agreements.
  • Law Enforcement: When required by law, court order, or government regulation.

6. Infrastructure Regions

Our primary infrastructure is hosted in India and Singapore. If you access the Service from outside India, your data may be processed in these regions under applicable safeguards and contractual controls where required.

7. Data Retention

  • Active Accounts: Data is retained for as long as your account is active.
  • Deleted Accounts: Upon account deletion, your personal data is anonymized (email replaced, name removed, payment details cleared). The anonymized record is retained for financial audit purposes as required by Indian law (6-8 years).
  • Financial Records: Transaction records, payout histories, and credit purchases are retained for 8 years from the date of transaction, as required by the Income Tax Act, 1961 and GST laws.
  • Fraud Records: Data related to flagged or fraudulent activity is retained for 5 years after resolution.

8. Your Rights

You have significant rights over your personal data. Here's what you can do:

8.1 Under DPDPA (India)

  • Right to Access: Request a copy of your personal data.
  • Right to Correction: Request correction of inaccurate data.
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements).
  • Right to Nominate: Nominate another individual to exercise your rights in case of death or incapacity.

8.2 Under GDPR (EU/EEA)

  • Right to Access (Art. 15): Obtain confirmation and a copy of your personal data.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON). You can export your data from your dashboard settings.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Restrict (Art. 18): Request restriction of processing in certain circumstances.

8.3 How to Exercise Your Rights

  • Data Export: Go to your dashboard Settings → Export My Data to download a copy of all your personal data in a machine-readable format.
  • Account Deletion: Go to your dashboard Settings → Delete Account to permanently remove your account and anonymize your personal data.
  • Email: support@ziyo.in — we will respond within 30 days (15 days for DPDPA requests).

9. Data Security

  • All data in transit is encrypted using TLS 1.3.
  • All data at rest is encrypted using AES-256 (via our cloud providers).
  • Authentication tokens are cryptographically signed and have configurable expiry.
  • CSRF protection is enforced on all mutating API requests.
  • Access to production systems is restricted to authorized personnel with MFA.
  • We conduct regular security reviews and vulnerability assessments.

While we implement industry-standard security measures, no system is completely immune to breaches. In the event of a data breach affecting your rights, we will notify you and the relevant authorities within 72 hours as required by the GDPR and DPDPA.

10. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at support@ziyo.in.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or platform notification at least 15 days before they take effect. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

12. Contact & Supervisory Authority

For privacy-related inquiries, data access requests, or complaints:

Ziyo — Data Protection

Email: support@ziyo.in

Website: ziyo.in

EU/EEA users also have the right to lodge a complaint with their local supervisory authority. Indian users may lodge complaints with the Data Protection Board of India as established under the DPDPA.