You open your wallet app, scan a QR code, pay for your tea, and move on with your day. It takes four seconds. What you probably don't think about in those four seconds is that the transaction just created a small trail of data — what you bought, where you were standing, what phone you used, what time it happened — and that trail doesn't stay in one place. Nobody asks where it goes until something goes wrong: a data breach makes headlines, a targeted ad feels a little too accurate, or a loan offer arrives referencing spending habits you never explicitly shared. This is the question worth asking before that happens, not after.
What Data Fintech Apps Actually Collect
Every digital wallet or mobile banking app collects far more than the amount you sent and to whom. Most of it is collected quietly, through permissions you approved once during installation and never revisited. Broadly, it falls into three buckets.
Transaction history is the most obvious: every payment, transfer, top-up, and merchant scan, timestamped and tied to your account. Over months, this builds a surprisingly detailed picture — where you shop, how often, what you spend on food versus fuel versus subscriptions, and roughly how much disposable income you carry. It's less a ledger and more a behavioral diary.
Location data is collected in two ways: coarsely, through the IP address or cell tower your transaction pings from, and precisely, if the app has requested and been granted GPS access — often justified as "to find nearby merchants" or "to verify the transaction location for fraud checks." The second kind is far more revealing, since it can place you at a specific address, workplace, or route at a specific time.
Device and behavioral information rounds out the picture: your phone model, operating system version, unique device identifiers, installed app list in some cases, network type, and even typing or tap patterns used for fraud-scoring. None of this is unusual by industry standards — but stacked together, transaction history, location, and device fingerprinting can identify and profile a person more precisely than any single data point alone.
Your transaction data doesn't have one destination — it branches into required regulatory flows and optional, less visible ones.
Who Has Access: Provider, Banks, NRB, and Third Parties
As the diagram above shows, a single transaction rarely stays in just one system. Understanding each party's role is the first step to understanding your actual exposure.
The app provider — the company running eSewa, Khalti, or your bank's app — has the broadest access by default, since it operates the servers, the ledger, and the analytics behind the interface you use. Your partner or linked bank sees the settlement side of the transaction: the amount, the account, and the counterpart, because the money has to actually move through the banking system. Nepal Rastra Bank (NRB), as the central regulator, has reporting access relevant to anti-money-laundering monitoring, systemic risk oversight, and licensing compliance — not a live feed of your personal spending, but audit-level access when required. The least transparent category is third-party partners: analytics vendors, advertising networks, and merchant-integration tools that some apps quietly connect to in order to personalize offers, measure engagement, or run loyalty programs. This is the layer most users have never consciously agreed to in a specific, informed way.
| Party | Primary Purpose | Typical Data Shared | Your Control Level |
|---|---|---|---|
| App Provider | Runs the wallet/app and its ledger | Full transaction history, device data, location (if granted) | Low — governed by their terms of service |
| Partner / Linked Bank | Settles funds behind the transaction | Amount, account number, counterpart details | Low — required for the transfer to work |
| Nepal Rastra Bank | Regulatory oversight, AML monitoring | Audit-level records, reported on request or by law | None — legally mandated, not opt-out |
| Third-Party Partners | Analytics, advertising, merchant tools | Behavioral data, device IDs, sometimes location | Medium-high — often adjustable in app permissions |
Nepal's Current Data Protection Legal Framework
Nepal's legal protections around personal and financial data are real but still developing, and the gaps matter as much as the protections do. The Individual Privacy Act, 2018 (Privacy Act) establishes a general right to privacy and sets rules around the collection, use, and disclosure of personal information, including a requirement that data generally be collected and used with consent and for a stated purpose. Separately, banking-sector rules under Nepal Rastra Bank impose confidentiality obligations on banks and financial institutions regarding customer information, and payment-related directives govern how licensed PSPs like wallet operators must handle transaction records and security.
Where the framework falls short is in the specifics that matter most for fintech: there is no single, comprehensive data protection law equivalent to something like the GDPR that clearly defines data portability rights, mandatory breach-notification timelines, restrictions on cross-border data transfer, or a dedicated independent regulator solely focused on data protection enforcement. Enforcement mechanisms exist but are fragmented across different bodies — the Privacy Act's provisions, NRB's sector-specific directives, and general consumer protection law — rather than unified under one clear standard. In practice, this means an app can be broadly compliant with existing rules while still sharing more data with third parties than most users would expect, simply because the law hasn't caught up to define exactly where that line sits.
How to Check What Permissions Your Wallet App Has
Most people grant app permissions once, during install, under time pressure, and never look at them again. It takes about two minutes to audit any wallet or banking app properly, and it's worth doing quarterly.
On Android
- Open Settings → Apps, find your wallet or banking app, and tap into its detail page.
- Tap Permissions to see everything it can access — location, contacts, camera, storage, and more.
- For anything not essential to how you actually use the app (contacts and precise location are the most commonly over-granted), switch it to "Ask every time" or "Deny."
- Scroll to Data usage & permissions if available, and review any toggle related to "personalized ads" or "usage analytics" — these are usually opt-out, not opt-in.
On iOS
- Open Settings, scroll down to the app in the list of installed apps.
- Review each permission toggle: Location, Notifications, Cellular Data, and any others listed.
- Set Location to "While Using the App" at most — never "Always," unless you have a specific, ongoing reason.
- Go to Settings → Privacy & Security → Tracking and confirm the app isn't permitted to track you across other apps and websites.
Best Practices for Limiting Unnecessary Data Exposure
- Grant location access only "while using the app," and only if the feature you need (nearby merchant search, fraud verification) genuinely requires it.
- Turn off personalized ads and analytics sharing wherever the app exposes that toggle — it rarely affects core functionality.
- Use separate apps for separate purposes rather than linking every wallet, loyalty program, and merchant tool into one super-app account, which multiplies your data footprint unnecessarily.
- Review connected third-party services periodically — many wallets let you see and revoke merchant or partner integrations you approved once and forgot about.
- Read the specific data-sharing clause in the privacy policy, not the whole document — search for "third parties," "partners," or "affiliates" to jump straight to the relevant section.
- Keep the app updated, since security patches often close off exactly the kind of data leakage that older versions are vulnerable to.
What Stronger Data Protection Laws Could Look Like
The gap between Nepal's current framework and where fintech has already gone points to a few concrete improvements that would close it. A dedicated, comprehensive data protection act — separate from the general Privacy Act — could set fintech-specific standards the way banking-sector directives already do for money itself. Mandatory breach notification within a defined window (commonly 72 hours in comparable frameworks) would force transparency instead of leaving users to find out about a leak through the news. Clear rules on cross-border data transfer would matter increasingly as more fintech infrastructure runs on cloud services hosted outside Nepal. And a single, independent data protection authority — rather than enforcement split across sector regulators — would give users one clear place to file a complaint and expect a real investigation, instead of navigating which agency actually has jurisdiction over their specific issue.
The Bottom Line
Your transaction data was never going to just one place, and that's not necessarily sinister — some of that flow is exactly what keeps the system functional, regulated, and safe from fraud. The part worth your attention is the branch that goes to third parties for reasons that have nothing to do with moving your money: advertising, analytics, and merchant tools you never explicitly agreed to in plain language. You can't rewrite Nepal's data protection law from your phone, but you can spend two minutes checking what your own wallet app is allowed to access — and that's the part actually within your control today.
Discussion