Skip to main content
Legal

Privacy Policy

Last updated: 03 November 2025 · Experience Zeno Pte. Ltd.

1. Purpose

Experience Zeno Pte. Ltd. ("Zeno", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Zeno platform.

We comply with Singapore's Personal Data Protection Act 2012 ("PDPA") and handle all personal data responsibly and transparently.

2. Scope

This Policy applies to all users who:

  • Download and use the Zeno mobile application
  • Register for a Zeno account
  • Participate in merchant loyalty or rewards programmes via the platform
  • Access any Zeno web services or APIs

This Policy does not apply to data collected directly by merchants or payment service providers, who operate under their own independent privacy policies. We encourage you to review those policies separately.

3. Personal Data We Collect

Information you provide directly:

  • Account details: name, email address, contact number, and date of birth
  • Login credentials (passwords are securely hashed and never stored in plaintext)
  • Transaction references and descriptions
  • Communications submitted via support or feedback channels

Information collected automatically:

  • Device information: model, operating system, device ID, and IP address
  • Usage analytics: pages visited, features used, and time spent in the app
  • Cookies and similar tracking technologies for session management

Information from third parties:

  • Transaction confirmations from payment service providers
  • Identity verification results from authentication services
  • Social login profile data (when you choose to log in via Google or Apple)

Zeno does not collect or store payment card numbers, bank account details, or other sensitive financial credentials. All payment data is handled exclusively by our licensed payment service providers.

4. How We Use Your Data

We use your personal data for the following purposes:

  • Account creation, management, and authentication
  • Processing wallet top-ups, transactions, and loyalty rewards
  • Providing customer support and resolving disputes
  • Improving platform features, performance, and user experience
  • Sending service notifications, transaction confirmations, and security alerts
  • Sending marketing communications (only with your explicit consent)
  • Complying with legal and regulatory obligations

We do not engage in automated profiling or decision-making that produces legal effects without your consent.

5. Disclosure of Personal Data

We may share your personal data with:

  • Participating merchants — to facilitate transactions and loyalty rewards on their platforms
  • Payment service providers — to process top-ups and transactions
  • Technology service providers — cloud infrastructure, analytics, and communication services that help us operate the platform
  • Regulatory authorities — when required by law, court order, or government directive

All third-party recipients are required to maintain a standard of data protection equivalent to or greater than the requirements of the PDPA.

6. Cross-Border Data Transfers

Your personal data may be transferred to and processed in countries outside Singapore. Where such transfers occur, we ensure that:

  • The recipient country provides a comparable standard of protection under the PDPA
  • Appropriate contractual safeguards (such as standard contractual clauses) are in place
  • Technical safeguards including encryption and access controls are applied

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. When personal data is no longer required, it is securely deleted or anonymised in accordance with our data lifecycle policies.

Transaction records may be retained for longer periods to comply with financial record-keeping requirements under applicable Singapore law.

8. Security Measures

We implement industry-standard technical and organisational safeguards to protect your personal data:

  • End-to-end encryption for data in transit (TLS/HTTPS)
  • Encrypted storage for sensitive data at rest
  • Role-based access controls and multi-factor authentication for staff
  • Regular security audits and penetration testing
  • Staff training on data protection and security awareness
  • Incident response procedures for data breach detection and notification

While we take all reasonable precautions, no system is completely immune to security risks. We encourage you to use strong passwords and report any suspicious activity promptly.

9. Your Rights Under the PDPA

As a data subject under the PDPA, you have the following rights:

📋

Access

Request a copy of personal data we hold about you

✏️

Correction

Request correction of inaccurate or incomplete data

🚫

Withdrawal

Withdraw consent for processing at any time

🗑️

Deletion

Request deletion when data is no longer necessary

To exercise any of these rights, please contact us at dpo@expzeno.com. We will respond within 30 days.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to maintain your session, remember your preferences, and improve platform performance. You can manage cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.

11. Children's Privacy

The Zeno platform is not intended for children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will take prompt steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Where changes are material, we will notify you via the app or by email. Continued use of the platform after such changes constitutes acceptance of the updated Policy.

13. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact our Data Protection Officer:

Experience Zeno Pte. Ltd.
Email: dpo@expzeno.com

We are committed to addressing your concerns and will respond within 30 days of receipt.