This Data Policy describes, in practical detail, the categories of data Nina Wallet processes, why we process them, who processes them on our behalf, how long we keep them, and the safeguards we apply. It complements our Privacy Policy.

As a wallet that moves money and verifies identity, Nina Wallet processes financial and identity data. We follow the principles of data minimisation (collect only what we need), purpose limitation (use it only for stated purposes), and storage limitation (keep it no longer than necessary).

1. Data Categories & Purpose

CategoryExamplesWhy we process it
IdentityName, email, phone, account numberCreate your account; authenticate you; enable transfers
KYC / verificationID photo, residential address, streetVerify identity; comply with anti-fraud and regulatory rules
Authentication secretsPassword hash, PIN hash, session/refresh tokens, OTP codesSecure sign-in and money-out authorisation
FinancialWallet balance, ledger entries, transfers, top-ups, ticket purchasesOperate the wallet; keep balances accurate and auditable
Payment instrumentsCard token & metadata (brand, last4), bank/virtual-account referencesLet you fund your wallet; we never store full card numbers or CVV
Device & technicalDevice ID, push token, IP-derived country/cityDeliver notifications; security and fraud monitoring

2. Lawful Basis for Processing

3. Processors & Third Parties

We use a small set of vetted service providers ("processors") that handle data only on our instructions:

ProcessorPurposeData shared
StripeCard payments (top-ups)Email, amount, card token/metadata
PaystackCard charges, dedicated virtual accounts, customer recordsName, email, phone, amount, authorization reference
CIMPayESPEES payments & bank-transfer notificationsEmail, amount, transaction reference
Google Firebase (FCM)Push notificationsDevice push token, message title/body
Email/SMTP providerOTP codes & receiptsEmail address, code/receipt content

We do not sell personal data and do not share it with advertisers.

4. International Transfers

Some processors (e.g. Stripe, Google) operate outside Nigeria. Where data is transferred across borders, we rely on the provider's contractual and technical safeguards to protect it to a standard consistent with applicable data-protection law.

5. Data Retention

DataRetention
Account & profileWhile your account is active; deleted or anonymised on closure, subject to legal holds
Transaction & ledger recordsRetained for the period required by financial/regulatory record-keeping rules
KYC images & detailsRetained while required for verification and compliance, then deleted
OTP & reset codesShort-lived (typically 10 minutes); expired/used codes are invalidated
Session & refresh tokensExpire automatically; revoked on logout; periodically pruned
Push tokens / device dataUntil you log out, remove the device, or the token becomes invalid

6. Security Controls

7. Your Controls

8. Data Breach Handling

If a breach affecting your personal data occurs, we will investigate, take steps to contain and remediate it, and notify affected users and the relevant authorities where required by law and within the applicable timeframes.

9. Updates

We may update this Data Policy as our processing or providers change. The "Last updated" date above reflects the current version.

10. Contact

For data requests or questions, contact our data team at privacy@ninawallet.com.


For a plain-language overview of your privacy, see our Privacy Policy.