Privacy Policy
Effective date: July 11, 2026 · Last updated: July 11, 2026
PAYVORA Technologies Ltd. ("PAYVORA", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have. It applies to your use of the PAYVORA mobile application, website at www.payvora.org, and all related services (collectively, the "Services").
By using our Services you agree to the terms of this Privacy Policy. If you do not agree, please do not use our Services. For our full user agreement, please review our Terms of Service.
1. Who We Are
PAYVORA Technologies Ltd. is a financial technology company registered in Nigeria and operating under the oversight of the Central Bank of Nigeria (CBN). We provide digital financial services including virtual dollar cards, gift card trading, bill payments, airtime and data top-ups, and wallet management through our mobile application and website.
Our registered address and Data Protection Officer contact:
PAYVORA Technologies Ltd.
Lagos, Nigeria
Email: privacy@payvora.org
Support: hello@payvora.org
Website: www.payvora.org
2. Data We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
- Account Information: Full name, email address, phone number, date of birth, and password (stored as a secure hash).
- KYC / Identity Verification: Bank Verification Number (BVN), National Identification Number (NIN), international passport, driver's licence, and facial/biometric verification data required by CBN regulations.
- Financial Information: Linked bank account details, transaction amounts, recipient information, gift card details, and wallet funding data.
- Communication Data: Messages sent to our support team, survey responses, and feedback forms.
2.2 Information Collected Automatically
- Device Data: Device model, operating system version, unique device identifiers, and mobile network information.
- Usage Data: Pages visited, features used, tap/click interactions, session duration, and in-app navigation paths.
- Log Data: IP address, browser type, timestamps, referring URLs, and error reports.
- Location Data: Approximate location derived from IP address. We do not request or store precise GPS location.
2.3 Information from Third Parties
- Google Sign-In: If you choose to sign in with Google, we receive your name, email address, and profile photo from Google's API. We do not receive or store your Google password. See Section 6 for more details.
- Apple Sign-In: If you choose to sign in with Apple, we receive a unique Apple user identifier and, if permitted, your name and email address.
- Identity Verification Partners: Results of BVN and NIN lookups conducted through NIBSS or licensed identity verification providers.
- Payment Partners: Transaction status and confirmation data from partner banks and payment processors.
3. How We Use Your Data
We use your personal data for the following purposes:
Account Creation and Management
To register your account, verify your identity, set up your wallet, and manage your profile settings.
Transaction Processing
To execute bill payments, airtime top-ups, gift card trades, fund transfers, and virtual card issuance.
Identity Verification and Compliance
To verify your identity under CBN KYC requirements and comply with Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) obligations.
Fraud Prevention and Security
To detect, investigate, and prevent fraudulent transactions, unauthorized account access, and other security incidents.
Customer Support
To respond to your inquiries, troubleshoot issues, and process refund or dispute requests.
Service Improvement
To analyze usage patterns, fix bugs, develop new features, and improve the overall performance of our Services.
Communications
To send transactional emails (e.g., payment confirmations, security alerts) and, with your consent, marketing communications about new features or promotions.
Legal Obligations
To comply with applicable Nigerian laws, CBN directives, court orders, and regulatory requirements.
4. Legal Basis for Processing
We process your personal data under the following legal bases as required by the Nigerian Data Protection Regulation (NDPR) and, where applicable, the EU General Data Protection Regulation (GDPR):
- Contract Performance: Processing necessary to provide the Services you have signed up for (e.g., executing your transactions, creating your virtual card).
- Legal Obligation: Processing required to comply with CBN regulations, AML/CTF laws, and other applicable Nigerian statutes.
- Legitimate Interests: Processing for fraud prevention, security monitoring, and service analytics, where these interests are not overridden by your data protection rights.
- Consent: For marketing communications and non-essential cookies, we will ask for your explicit consent and you may withdraw it at any time.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share information only in the following circumstances:
- Service Providers: Trusted third-party vendors who help us operate our Services (cloud hosting, database management, push notifications, email delivery, customer support tools). All vendors are contractually required to protect your data and process it only for the purposes we specify.
- Payment and Banking Partners: Banks, card networks, and payment processors necessary to execute your financial transactions and issue virtual cards.
- Identity Verification Partners: Providers licensed to verify BVN, NIN, and other KYC documents as required by CBN regulations.
- Regulatory Authorities: The Central Bank of Nigeria (CBN), NFIU, EFCC, or other government bodies when required by law, regulation, or a valid court order.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to the same privacy protections described here.
- With Your Consent: We will share your data with any other party when you have given us explicit consent to do so.
6. Google Services and Third-Party SDKs
PAYVORA integrates with several Google and third-party services. This section explains what data each service receives and how it is used.
Google Sign-In (OAuth 2.0)
When you use "Sign in with Google," we access your Google Account profile using OAuth 2.0. The data received is limited to: your name, email address, and profile photo. We use this data solely to create or authenticate your PAYVORA account. We do not access your Google Drive, Gmail, contacts, or any other Google services. Your use of Google Sign-In is also governed by Google's Privacy Policy.
Google Analytics
We use Google Analytics to understand how users interact with our website. Google Analytics collects anonymized data including page views, session duration, device type, and approximate geographic location. IP addresses are anonymized before storage. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
Firebase (Google)
We may use Firebase services (Crashlytics, Cloud Messaging) to monitor app stability and send push notifications. Firebase may collect device identifiers and crash logs. This data is used solely for improving app performance and is governed by Firebase's Privacy and Security terms.
Other Third-Party SDKs
Our application may incorporate additional third-party SDKs for features such as in-app customer support, analytics, and security. Each SDK is subject to its own privacy policy. We review all third-party integrations for compliance with NDPR requirements before deployment.
Important — Limited Use Disclosure: PAYVORA's use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, profile users for non-service purposes, or transfer data to third parties except as required to provide our Services.
8. International Data Transfers
Your data is primarily processed and stored in Nigeria. To provide certain Services, your data may be transferred to and processed in other countries (for example, our cloud infrastructure hosted in the EU or US). Wherever we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by applicable data protection authorities.
- Data processing agreements requiring recipient parties to maintain NDPR-equivalent protections.
- Technical measures including end-to-end encryption in transit and at rest.
9. Data Retention
We retain your personal data for as long as necessary to provide the Services and to comply with our legal obligations:
- Active Accounts: We retain your data for the duration your account is active.
- Closed Accounts: Upon account closure, we delete or anonymize your personal data within 90 days, except as required by law.
- Transaction Records and KYC Data: CBN regulations require us to retain transaction history, KYC documents, and AML records for a minimum of five (5) years after account closure.
- Marketing Data: Retained until you withdraw consent or we determine it is no longer needed.
- Support Communications: Retained for up to 3 years to support dispute resolution.
10. Your Privacy Rights
Under the Nigerian Data Protection Regulation (NDPR) and, where applicable, the GDPR, you have the following rights:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of any inaccurate or incomplete data.
Right to Erasure
Request deletion of your data, subject to legal retention requirements.
Right to Portability
Request a machine-readable export of your personal data.
Right to Object
Object to processing based on legitimate interests, including direct marketing.
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
Right to Withdraw Consent
Withdraw consent for marketing or non-essential cookies at any time.
Right to Lodge a Complaint
File a complaint with the Nigerian Data Protection Commission (NDPC) at ndpc.gov.ng.
To exercise any of these rights, contact our Data Protection Officer at privacy@payvora.org. We will respond within 30 days.
11. Children's Privacy
PAYVORA's Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18 without parental consent, we will promptly delete that information. If you believe a minor has registered for our Services, please contact us at privacy@payvora.org.
12. Security Measures
We implement industry-standard technical and organisational measures to protect your data, including:
- AES-256 encryption for data at rest.
- TLS 1.3 encryption for all data in transit (HTTPS only).
- Multi-factor authentication for account access and high-value transactions.
- Continuous fraud monitoring and anomaly detection.
- Role-based access controls limiting employee access to personal data.
- Regular security audits and penetration testing.
No security system is impenetrable. If you suspect unauthorized access to your account, contact us immediately at security@payvora.org or visit our Security page.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will notify you by email or through a prominent notice in the app at least 14 days before the changes take effect. The updated policy will always be accessible at www.payvora.org/privacy-policy. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
14. Contact Us
For questions, data subject requests, or privacy concerns, contact our Data Protection Officer:
Data Protection Officer — PAYVORA Technologies Ltd.
Email: privacy@payvora.org
General Support: hello@payvora.org
Security Issues: security@payvora.org
Website: www.payvora.org
Related Legal Documents
Review our other legal policies that govern your use of PAYVORA.