1. Scope and controller
This policy applies to the SpenVest Nepal website, Nepal merchant portal, Nepal customer surfaces and Nepal administration services.
[LEGAL REVIEW REQUIRED] Insert the full legal name and registered details of the entity responsible for Nepal personal information.
2. Information we collect
Depending on the service used, information may include merchant business details, staff names and usernames, phone numbers, email addresses, product and inventory data, order and transaction records, customer contact details, support messages, device and browser information, IP address, security events and audit records.
Customer wallet and account-linked history access is currently paused while verified phone authentication is completed. We do not ask customers to treat a wallet code as a password.
3. How information is used
We use information to operate requested services, authenticate users, process merchant-managed orders, record merchant-confirmed payments, maintain catalogs and inventory, provide support, detect abuse, investigate incidents, improve reliability and meet documented legal obligations.
SpenVest does not currently initiate, hold or settle eSewa, Khalti, Fonepay, card or bank funds through the Nepal platform.
4. Sharing and service providers
Information may be handled by infrastructure, hosting, communications, security and professional service providers only where needed to operate or protect the service. We may also disclose information where lawfully required or during a properly structured business transaction.
[LEGAL REVIEW REQUIRED] Confirm all processors, data locations, cross-border transfer wording and any mandatory Nepal disclosures before launch.
5. Security
We use access controls, scoped merchant permissions, encrypted network transport, password hashing, audit records, backups and operational monitoring appropriate to the service stage. No system can guarantee absolute security.
Users should keep credentials confidential, use unique passwords and report suspected access promptly.
6. Retention
We retain information only for operational, security, dispute, accounting and legal needs, then delete or de-identify it where reasonably possible.
[LEGAL REVIEW REQUIRED] Approve a record-specific retention schedule for customer, merchant, transaction, audit, support and backup data.
7. Your choices and requests
You may ask about, correct or request deletion of personal information, subject to identity verification and legal or operational retention requirements. Marketing communications should include an opt-out where applicable.
Send a request through the contact page. [LEGAL REVIEW REQUIRED] Add the final privacy email and response process.
8. Children
The business and merchant tools are not designed for children. Customer eligibility and age requirements must be confirmed before public account access is launched.
9. Changes and contact
We may update this policy as services or legal requirements change. Material changes will be communicated through an appropriate product or website notice.
Privacy contact: [TO BE CONFIRMED].
