Let's Get your organization upgraded. Explore products
HomePrivacy policy

Legal

Privacy policy

Last updated: February 2026

Who we are

Stratigo Collectives Pvt. Ltd. ("Stratigo", "we", "us") is a technology company incorporated in Nepal, based in Lalitpur. We develop and provide software platforms, digital products, and technology solutions for businesses and institutions — including Qaventra for payment operations, Nexora for banking infrastructure, and Luma for loyalty and rewards.

For the purposes of this policy, Stratigo is the controller of information collected through our website, demo and contact forms, and account registration. Where our customers use our platforms to process their own end-user or employee data, the customer acts as the controller of that data and Stratigo processes it on the customer’s instructions under the applicable customer agreement.

Scope of this policy

This policy covers information handled when you browse stratigo websites, submit a demo or contact request, register for an account, or use our platforms as an authorized user of a customer. It does not cover data practices of third-party banks, payment networks, or other providers our products integrate with — those institutions apply their own privacy notices to the regulated services they provide.

Information we collect

Information you provide directly. When you book a demo, contact us, or register, we collect details such as your name, work email, company name, phone number, and the content of your message. Account registration also creates login credentials associated with your profile.

Customer and transaction data. To operate the platforms, our customers provide business data such as wallet activity, payment and payout records, vendor and expense details, member and rewards data, and onboarding and verification records. We process this data solely to provide the services to the relevant customer.

Technical and usage information. When you use our website or platforms, we automatically receive limited technical details such as device and browser type, pages or screens viewed, and diagnostic logs. We use this to keep services secure, prevent misuse, and improve reliability and performance.

Cookies and similar technologies

We use a limited set of cookies and local storage for essential purposes: keeping you signed in, remembering preferences such as filter selections, and protecting against fraud and abuse. These are required for the site and platforms to function.

We do not operate third-party advertising trackers on our marketing website. Where a platform embeds third-party components required for its operation (for example verification or payment providers), those components are governed by the relevant provider’s own notices.

How we use information

We use information to provide, maintain, and improve our website and platforms; to respond to demo requests, inquiries, and support tickets; to register and administer accounts; to onboard customers and configure their environments; to monitor security, prevent fraud and misuse, and generate audit trails; to meet legal and compliance obligations, including record-keeping; and to communicate operational updates about the services.

We do not sell personal information, and we do not use customer transaction or end-user data for advertising. Analytics we produce about platform usage are aggregated and used to improve reliability and product decisions.

How we share information

Service providers. We share information with infrastructure, hosting, communications, and analytics providers that help us operate, bound by confidentiality and data-protection obligations and limited to what is necessary for their function.

Financial and integration partners. Certain products integrate with banks, payment service providers, financial institutions, and other technology providers. Data required for those integrations is shared with the applicable institution so it can provide its services under its own terms and regulatory duties.

Legal and safety disclosures. We disclose information where required by law or legal process, to enforce our terms, or to protect the rights, safety, and integrity of Stratigo, our customers, and the public.

Business transfers. If Stratigo is involved in a merger, acquisition, or asset transfer, information may transfer as part of that transaction, subject to continued protection under this policy.

International transfers

Stratigo is based in Nepal and primarily serves customers in Nepal and the surrounding region. Infrastructure, support tooling, or integration partners may process information in other jurisdictions. Where information moves across borders, we apply contractual and technical safeguards appropriate to the sensitivity of the data, and integrations with regulated institutions remain subject to those institutions’ own cross-border obligations.

Security

We maintain administrative, technical, and organizational measures proportionate to what we handle — including access controls limited by role, encryption of sensitive data, and audit trails across platform operations. Our teams review these controls as the platforms evolve.

However, no software system or transmission of information can be guaranteed to be completely secure, uninterrupted, or error-free. You play a part too: safeguard your credentials, use access controls your administrator provides, and notify us promptly of suspected misuse through our contact page.

Retention

We keep website inquiry and demo records only as long as needed to respond and maintain business records. Account and platform data is retained for the life of the customer relationship plus any period required by law or legitimate business need — financial and compliance records, for example, must be preserved for statutory periods even after accounts close. When retention periods end, data is deleted or irreversibly anonymized.

Your choices and rights

You may request access to, correction of, or deletion of information you provided to us, object to certain processing, and opt out of non-essential communications at any time. Account holders can update profile details directly; for other requests, reach us through the contact page and we will respond within a reasonable time.

These choices operate alongside any rights available to you under applicable law, including Nepal’s Privacy Act, 2018. Some information cannot be deleted where retention is required — for instance, transaction and compliance records our customers or the law oblige us to keep — and we will explain when that applies.

Children

Our website and platforms are business products and are not directed at children. We do not knowingly collect information from children, and authorized users must meet the age of majority in their jurisdiction.

Changes and contact

We may update this policy as our products and practices evolve; material changes will be reflected on this page with a revised date. Continued use of the website or platforms after changes take effect constitutes acceptance of the updated policy.

For privacy questions or requests, contact Stratigo Collectives Pvt. Ltd., Lalitpur, Nepal, through our contact page.

© 2026 Stratigo Collectives Pvt. Ltd. All rights reserved.