NairaCheck

Privacy

Privacy Policy

This policy explains what personal data NairaCheck handles, why we use it, when it may be shared, and the choices and rights available to you.

Last updated 28 August 2026

Scope and who we are

This Privacy Policy explains how NairaCheck collects, uses, discloses, stores, and protects personal data when you visit our website, contact us, create an account, use an application programming interface, or use another NairaCheck service (together, the Services).

NairaCheck is the controller of personal data used for our own purposes. Where a business customer submits personal data to a verification service and determines why it is processed, that customer is normally the controller and NairaCheck acts as its processor under separate data-processing terms. Contact us at hello@nairacheck.com with privacy questions.

This Policy is intended to address the Nigeria Data Protection Act 2023 and other privacy requirements that apply to our processing. Specific rights and obligations may vary according to the service, the people involved, and applicable law.

Personal data we collect

The data we collect depends on how you use the Services and may include:

  • Contact and correspondence data: your name, email address, organisation, and the content of messages or support requests.
  • Account and business data: login details, profile information, role, organisation, phone number, bank name, account number, subscription or service records, and authorised-user details where an account-based service requires them.
  • Verification data: identity or account details a customer submits for a permitted verification, such as a name, date of birth, phone number, photograph, bank-account detail, NIN, BVN, and the resulting match or audit information. We will provide or require an additional notice before a live service collects this data.
  • Technical and usage data: IP address, browser and device type, operating system, timestamps, requested pages, referring page, approximate location derived from IP, request identifiers, and diagnostic or security events.
  • Preference data: choices you make in the interface. For example, the current rate-card display preference is kept in your browser’s session storage.
  • Data from other sources: information from customers, identity and financial-data providers, public sources, security providers, and other partners where lawful and relevant to a Service.

Please do not send sensitive personal data unless we specifically request it through a secure channel for a stated purpose.

How we collect data

We collect personal data:

  • directly from you when you contact us, register, configure, or use a Service;
  • automatically from your browser, device, and interaction with the Services;
  • from a business customer when it submits an authorised verification request;
  • from service providers that help us prevent abuse and operate the Services; and
  • from lawful public, identity, banking, market-data, or verification sources where needed to provide a requested Service.

Why we use personal data

We use personal data to:

  • provide market information, accounts, APIs, verification results, and support;
  • authenticate users, manage credentials, and administer our customer relationships;
  • respond to messages, requests, complaints, and data-subject enquiries;
  • maintain, troubleshoot, measure, and improve the performance and accessibility of the Services;
  • protect users, data subjects, and the Services against fraud, misuse, security threats, and unlawful activity;
  • keep appropriate records and comply with legal, regulatory, tax, accounting, and contractual obligations; and
  • send service notices and, only where lawfully permitted, relevant product communications that you can opt out of.

We do not sell personal data or use it for third-party targeted advertising. We do not use verification data to build advertising profiles.

Lawful bases

Depending on the context, we rely on one or more of these lawful bases:

  • Contract: processing needed to provide a Service you request or to take steps before entering a contract.
  • Legitimate interests: operating, securing, supporting, and improving NairaCheck, preventing misuse, and managing business relationships, where those interests are not overridden by your rights.
  • Consent: where you freely give specific, informed consent, which you may withdraw at any time.
  • Legal obligation: processing necessary to comply with applicable law or a binding request.
  • Vital or public interests: only where applicable law permits and the circumstances require it.

When we process sensitive personal data, we also identify an additional condition permitted by law and apply safeguards appropriate to the risk.

Cookies and browser storage

NairaCheck may use cookies or similar browser storage that is strictly necessary for security, authentication, network delivery, and user-requested preferences. The current exchange-rate display preference uses session storage, which remains in your browser for the browser session and is not designed to identify you.

We do not currently use advertising cookies. If we introduce optional analytics, advertising, or similar technologies, we will update this Policy and provide a consent or choice mechanism where required. You can also control browser storage through your browser settings, although blocking necessary storage may affect a feature.

When we share personal data

We may disclose relevant personal data to:

  • Service providers: hosting, cloud infrastructure, communications, customer support, security, monitoring, and professional advisers that act under appropriate obligations.
  • Data and verification partners: where needed to complete an authorised request or provide a data source, subject to applicable law and product terms.
  • Customers: the business customer that submitted a verification request and is authorised to receive the result.
  • Authorities and other parties: where disclosure is required by law, legal process, or reasonably necessary to protect rights, safety, security, and the integrity of the Services.
  • Transaction parties: advisers and a prospective buyer, investor, or successor in connection with a genuine financing, reorganisation, sale, or transfer, subject to confidentiality and applicable law.

We require processors to handle personal data only for documented purposes and with appropriate confidentiality and security. We do not allow a customer to use verification data for an unlawful purpose.

International transfers

Some providers may process personal data outside Nigeria. Before making a restricted transfer, we use a mechanism recognised by applicable law and assess whether the data will receive an adequate level of protection. Depending on the transfer, this may include an adequacy decision, an approved contractual or transfer instrument, your informed consent where appropriate, or another ground allowed by law.

You may contact us for more information about the safeguards relevant to your personal data.

How long we keep data

We keep personal data only for as long as needed for the stated purpose, to protect the Services, resolve disputes, and meet legal, regulatory, accounting, or reporting duties. Our normal starting points are:

  • browser session preferences: until the session ends or you clear them;
  • keyed IP hash and security events: 90 days;
  • aggregated, non-identifying trends: up to 12 months;
  • periodically roated HMAC key; and
  • verification data: for the shortest period needed to return and evidence the authorised result, as further stated in the relevant service notice or contract.

A different period may apply where law requires it, a dispute or investigation makes it necessary, or a shorter period is appropriate. We then delete, de-identify, or securely isolate the data. Backup copies expire on their normal protected cycle.

Security

We use technical and organisational measures intended to protect personal data in a manner appropriate to its nature and risk. These may include access controls, encryption in transit, credential controls, logging, minimisation, vendor review, backups, and incident procedures.

No system is completely secure. You should protect your account and credentials and tell us promptly if you suspect misuse. If a personal-data breach occurs, we will investigate, reduce harm, and notify affected people and regulators when required by law.

Your privacy rights

Subject to applicable law and any permitted exception, you may have the right to:

  • be informed about our processing and access or obtain a copy of your personal data;
  • correct inaccurate or incomplete personal data;
  • ask us to erase, restrict, or stop certain processing;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • receive data you provided in a structured, commonly used, machine-readable format where portability applies;
  • request human review of a decision based solely on automated processing that has a legal or similarly significant effect; and
  • complain to the Nigeria Data Protection Commission or another competent authority.

Send a request to hello@nairacheck.com. We may ask for information needed to verify your identity and protect other people’s data. We aim to respond within the period required by law, normally 30 days. You will not be treated unfairly for exercising a privacy right.

You can also learn about complaints directly from the Nigeria Data Protection Commission.

Automated decisions

NairaCheck does not currently make decisions about website visitors based solely on automated processing that produce legal or similarly significant effects. A verification result may use automated matching, but the customer receiving it is required to apply appropriate review and is responsible for its final decision.

If this changes, we will provide the information and safeguards required by law, including a way to request human intervention where applicable.

Children’s privacy

The public Services are not directed to children under 18, and children may not create an account or submit personal data directly to us. If we learn that a child provided personal data without appropriate authority, we will take reasonable steps to delete it.

Where a legitimate verification service involves a child’s data, the customer must have a lawful basis and any required parent or guardian authorisation. We will apply age-appropriate safeguards, data minimisation, and any additional notice required by law.

Third-party sites

The Services may link to websites or services that NairaCheck does not control. Their privacy practices are governed by their own notices, not this Policy. Review those notices before giving them personal data.

Changes to this policy

We may update this Policy as the Services, providers, or legal requirements change. We will post the revised version and change the date above. If a change materially affects how we use personal data, we will take reasonable steps to provide more prominent notice and obtain consent where required.

Contact us

For a privacy request, concern, or complaint, email hello@nairacheck.com with the subject “Privacy request”. Please do not email identity documents, NINs, BVNs, bank details, passwords, or API secrets unless we ask you to use an approved secure channel.