Privacy Policy & Acceptable Use
Version 1.0
1. Information We Collect
When you apply for access or use the platform, we collect information you provide directly, such as your name, email address, phone number, address, password, and (depending on your applicant type) business or agent/certificate details, along with the reason you've given for wanting access. If you submit a supporting document with your application, we collect that document. Once you have an account, we collect the details of the verification, modification, printing, and other requests you make through your dashboard, since those are necessary to provide the corresponding service and to maintain your wallet/transaction history.
2. Applications Are Reviewed, Not Automatic
If you submit a signup application, submitting the form does not create an account and does not guarantee approval. Every application is reviewed by an administrator, who may approve or reject it. If your application is rejected, we will tell you why by email. If approved, an account is created for you with standard access — the type of applicant you say you are (individual, agent, or business) does not by itself grant any special or elevated permissions.
3. How Supporting Documents Are Handled
A document submitted with an application is stored outside the public web folder, under a randomly generated filename rather than the name of your original file, and is not reachable by any direct or guessable web address. It can only be opened through an administrator-only review screen, and every time it is opened, that access is logged (who viewed it and when). Reviewing a document is a manual step performed by an administrator as part of deciding on your application — we do not run any automated verification or authentication process against documents you submit.
4. Acceptable Use
Access to this platform, and to any identity-related or lookup-style information it provides, is for your own legitimate, authorized use only. You agree not to:
- Search for, look up, or retrieve information about any individual without proper authorization to do so on their behalf;
- Scrape, bulk-extract, or systematically harvest data from the platform;
- Resell, redistribute, or share access to information obtained through the platform with anyone not authorized to receive it;
- Share your login credentials, API key, or any self-service/account credentials linked through the platform with anyone else;
- Impersonate another person, or misrepresent your authority to act on someone else's behalf;
- Use the platform to harass, stalk, defraud, or otherwise cause harm to any person.
5. Data Retention
We keep account, application, and transaction records for as long as necessary to provide the service, maintain accurate records, and meet our own legal and operational obligations. One category of record is deleted automatically: request/response logs for our own outbound API calls are removed after roughly a month. Beyond that, we do not currently promise automatic deletion timelines for other categories of data, and any such claim would only be added here once it reflects how the system actually behaves.
6. Security
We do not claim the platform is 100% secure — no system is — but we do apply a number of concrete controls, including:
- Passwords are never stored in plain text; they are hashed before being saved;
- Application supporting documents are stored outside the public web folder under randomly generated filenames, and are only accessible through an admin-only, access-logged review screen;
- Access to both user and admin areas requires an authenticated session;
- Sensitive administrative actions on applications (approvals, rejections, notes, document views) are recorded in an audit trail, including which admin performed the action and when;
- Actions like approving or rejecting an application are processed so that a duplicate click, or two administrators acting at the same time, cannot both process the same application;
- Outbound calls we make to identity-verification and similar service providers are logged so we can monitor for failures or misuse.
7. Third-Party & Upstream Providers
Some services on this platform are fulfilled with the help of third-party identity-verification, communications, and payment providers. We share only the information necessary for those providers to carry out the specific request you've made, and we do not sell your information to third parties. We are not able to make specific claims here about the internal policies, certifications, or licensing of any individual provider we work with; if you have a service-specific question, please contact us.
8. Service-Specific Agreements
Certain requests you submit through your dashboard — for example, NIN modification requests — come with their own, more detailed consent and authorization agreement shown to you at the time you make that request. That agreement governs the specifics of that service; this policy is not a substitute for it and does not repeat its terms here.
9. Your Responsibilities
- Provide accurate, truthful information when applying for access and when submitting requests;
- Keep your login credentials and any linked account credentials confidential;
- Use the platform only for lawful, authorized purposes and in line with this policy;
- Comply with all applicable laws and regulations governing the information you access or submit;
- Notify us if you believe your account has been compromised.
10. Suspension & Termination
We may block, suspend, or deactivate your account — including while we look into a concern — if we believe you have violated this policy, misused the platform or any information it provides, or provided false information in your application. A suspended or blocked account will be told to contact an administrator to discuss recovery.
11. Contact Us
Questions about this policy or your data can be sent to us via WhatsApp/phone at US WHEN LOGGED IN.
This policy may be updated from time to time as the platform's services and controls change.