LEGAL REFERENCE

How 999ha Handles Your Personal Information

At 999ha, your privacy is built into how we operate, not added as an afterthought. This policy sets out exactly what data we collect when you open an...

Transparent Data UseSecure Account StorageYour Rights, Clearly StatedPakistani Payment PrivacyNo Data Sold to Third Parties
999ha How 999ha Handles Your Personal Information

What This Privacy Policy Covers and Why

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

PRIVACY CONTACT PATHS

How to Reach Our Privacy Team at 999ha

If you have questions about how we handle your personal data, or you want to exercise any of your data rights, our support team is ready to help. Reach us through the channel that works for you — we respond to privacy queries within 48 hours on business days.

Team online

Live Chat

Start a live chat directly from your 999ha account dashboard. Our agents handle data access requests, correction queries, and deletion submissions in real time during operational hours for Pakistan.

Email Support

Send your privacy query or formal data request to our dedicated support email address. Attach your account details so we can locate your record and respond within the required timeframe.

Help Centre

Our Help Centre contains step-by-step guidance on submitting data requests, understanding what we store, and managing your account privacy settings without waiting for a live agent.

POLICY TRUST SIGNALS

Why You Can Count on Our Data Practices

We designed our privacy practices around the expectations of Pakistani account holders who manage funds through local payment rails. Every layer of our data handling reflects that commitment — from how we...

Encrypted Storage

All account data, including payment method details and personal identifiers, is encrypted at rest using industry-standard protocols so unauthorised parties cannot read stored records even if infrastructure is ever compromised.

Access Controls

Only verified 999ha staff with a specific operational need can access your account data. Access events are logged and regularly audited so any unusual internal activity is flagged and reviewed promptly.

Payment Data Isolation

JazzCash, Easypaisa, SadaPay, and Raast transaction data is stored in isolated environments, separate from general account logs, reducing the risk that a single breach exposes your full payment history.

Data Minimisation

We collect only the personal details required to run your account and process your transactions. We do not ask for information beyond what is necessary, and we do not retain data longer than operationally justified.

Regular Policy Reviews

Our privacy policy is reviewed internally on a scheduled basis. When practices change, we update this page and notify active account holders through their registered contact method before changes take effect.

Breach Notification

In the unlikely event of a data incident affecting your account, we commit to notifying you through your registered email or phone number promptly, with a clear explanation of what occurred and what steps we are taking.

POLICY CONSISTENCY CHECK

How This Policy Aligns Across 999ha Pages

Our privacy commitments are consistent across every section of the 999ha platform. Whether you are reading this page, our terms of service, or our cookie notice, the same principles apply — no...

01

Terms of Service

Our terms reference this privacy policy directly. The data handling described there matches what is written here — there are no hidden clauses in the terms that override your data rights.

02

Cookie Notice

Our cookie notice details the specific tracking technologies we use. It aligns with this policy's description of device data collection and gives you clear opt-out options for non-essential cookies.

03

Account Registration Flow

The data fields you complete when opening an account correspond exactly to the categories listed in this policy. Nothing collected at registration falls outside the scope described on this page.

04

Payment Processing Pages

The privacy handling described on our deposit and withdrawal pages is consistent with the payment data isolation principles outlined here. JazzCash, Easypaisa, SadaPay, and Raast data is treated identically across all pages.

05

Security Settings Page

Account security options, including two-factor authentication and session management, are described in terms that match this policy's explanation of how we protect access to your stored information.

06

Support Interactions

When you contact our support team, the conversation log is handled under the same data retention rules described here. Support agents do not have access to data categories beyond what is needed to resolve your query.

07

Email and SMS Notifications

Any communication we send to your registered contact details falls within the use-case categories listed in this policy. We do not use your contact details for purposes outside those described here.

Key Elements of Our Privacy Framework

Our privacy framework is structured to give you a clear picture of your data at every stage of your account lifecycle — from first sign-up through...

Data Collection Scope

We document every category of personal data we collect, including identity details, contact information, and transaction records, so you always know what is held on file and why it was gathered in the first place.

Retention Schedules

Each data category has a defined retention period. Payment records are held only as long as required for dispute resolution, and identity documents are removed once verification is confirmed and the retention period expires.

Third-Party Sharing Rules

We name the categories of third parties who may receive your data — licensed payment processors, fraud prevention services — and specify that sharing is limited strictly to what those parties need to perform their function.

Your Data Rights

You can request a copy of your data, ask us to correct inaccurate records, or submit a deletion request. Each right is explained in plain language with the exact contact path you need to exercise it.

Cookie and Tracking Scope

We explain which cookies are essential for the account to function and which are optional. You can manage optional tracking preferences from your account settings without affecting core platform access.

Policy Update Process

When we revise this policy, we publish the updated version here and send a notification to your registered contact. The effective date at the top of the page always reflects when the current version came into force.

Answers to Your Data and Privacy Questions

We collect your name, email address, phone number, date of birth, and the payment method details you add, such as your JazzCash or Easypaisa account reference. We also log device and IP data for security purposes.

No. We do not sell, rent, or trade your personal data to advertisers or unrelated third parties. Data is shared only with licensed payment processors and fraud prevention services strictly needed to run your account.

Certain records, including transaction history and identity verification documents, are retained for a period required under applicable financial regulations. After that period expires, data is securely deleted from our systems.

Yes. Submit a data access request through our support email or live chat. We will compile and send you a summary of the personal information held on your account within the timeframe required under applicable rules.

Payment transaction references linked to JazzCash, Easypaisa, SadaPay, and Raast are stored in isolated environments with restricted access. They are encrypted at rest and accessible only to staff with a specific operational need.

We will notify you through your registered email or phone number as promptly as practicable, explaining what data was affected and what steps we are taking to contain the incident and prevent recurrence.

Contact our support team via live chat or email with your account details and a deletion request. We will process it in line with our retention obligations and confirm once the deletion has been completed on our systems.