Privacy Policy for EpassCard

Last Updated: 15/1/2026
Company Name: Epasscard
App Name: Epasscard EpassCard | SmartPass Wallet

1. Introduction

EpassCard (“we”, “our”, or “us”) operates the EpassCard | SmartPass Wallet mobile application (the “App”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our App.

By using the App, you agree to the collection and processing of your data in accordance with this Privacy Policy. If you do not agree, please discontinue use of the App.

2. Data We Collect

We collect the following categories of data:

a) Personal Data
  • Login information (email, username, password)
  • Card details (gift card or membership card information for verification and claiming)
  • Device information (IP address, device model, operating system version)
  • Usage data (app interactions, timestamps, feature usage)
b) Location Data (Including Background Location)

The App collects precise location data, including background location access, to enable geofence-based notifications.

This means the App may access location data even when the App is closed or not actively in use, for the following purposes:

 

Detect when a user enters or exits a specific shop or merchant location

Notify the user if they hold a valid card that can be used at that specific place

Location data collected may include:

Precise GPS location

Location updates required for geofencing

Location access is requested only with the user’s explicit consent and can be disabled at any time through the device’s system settings.

 

c) Non-Personal Data

Aggregated and anonymized usage statistics for analytics and service improvement

3. How We Use Your Data

We use collected data for the following purposes:

User authentication and account management

Card verification, claiming, and wallet functionality

Geofence-based notifications when users are near participating shops or locations

Background location processing to trigger location-aware alerts

Customer support and communication

Security, fraud prevention, and misuse detection

App performance monitoring and improvement

Compliance with legal and regulatory obligations

4. Legal Basis for Processing (GDPR Compliance)

Under Article 6 of the GDPR, we process personal data based on:

  • Contractual Necessity (to provide App services)
  • Legitimate Interest (fraud prevention, analytics)
  • App Functionality (processing gift card transactions)
  • User Consent (where required by law)

5. Data Sharing and Disclosure

We may share data with:

  • Payment processors (for card verification and transactions)
  • Cloud service providers (secure hosting and data storage)
  • Analytics and security service providers
  • Legal or regulatory authorities when required by law

We do not sell personal data, including location data, to third parties.

6. Data Retention

We retain your data only as long as necessary:

  • Login data: until account deletion
  • Card details: until the related transaction is completed or as required by law
  • Location data: processed in real time and not permanently stored
  • Analytics data: anonymized after 12 months

7. Data Security

We apply appropriate technical and organizational security measures, including encryption (SSL/TLS), secure authentication, and restricted access controls. However, no method of transmission or storage is completely secure, and users are responsible for safeguarding their login credentials.

8. Your Rights

Depending on applicable law, you have the right to:

  • Access, correct, or delete your personal data

    Withdraw consent, including consent for location access

    Restrict or object to processing

    Request data portability

    Lodge a complaint with a relevant data protection authority

To exercise these rights, please contact us using the details below.

9. International Data Transfers

If personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards, such as Standard Contractual Clauses (SCCs), in compliance with GDPR requirements.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated through the App or via email.

11. Contact Us

For privacy-related questions or requests, please contact:
Company Name: EpassCard

Email: hello@epasscard.com

Address: House No: 1/c, Road No 2, Sector 3, Uttara, Dhaka, Bangladesh.