This Data Policy describes, in practical detail, the categories of data Nina Wallet processes, why we process them, who processes them on our behalf, how long we keep them, and the safeguards we apply. It complements our Privacy Policy.
1. Data Categories & Purpose
| Category | Examples | Why we process it |
|---|---|---|
| Identity | Name, email, phone, account number | Create your account; authenticate you; enable transfers |
| KYC / verification | ID photo, residential address, street | Verify identity; comply with anti-fraud and regulatory rules |
| Authentication secrets | Password hash, PIN hash, session/refresh tokens, OTP codes | Secure sign-in and money-out authorisation |
| Financial | Wallet balance, ledger entries, transfers, top-ups, ticket purchases | Operate the wallet; keep balances accurate and auditable |
| Payment instruments | Card token & metadata (brand, last4), bank/virtual-account references | Let you fund your wallet; we never store full card numbers or CVV |
| Device & technical | Device ID, push token, IP-derived country/city | Deliver notifications; security and fraud monitoring |
2. Lawful Basis for Processing
- Performance of a contract — to provide the wallet, transfers, and ticketing you sign up for.
- Legal obligation — identity verification (KYC), record-keeping, and fraud prevention.
- Legitimate interests — securing accounts, preventing abuse, and improving the Service.
- Consent — for example, enabling push notifications on your device (which you can withdraw at any time).
3. Processors & Third Parties
We use a small set of vetted service providers ("processors") that handle data only on our instructions:
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe | Card payments (top-ups) | Email, amount, card token/metadata |
| Paystack | Card charges, dedicated virtual accounts, customer records | Name, email, phone, amount, authorization reference |
| CIMPay | ESPEES payments & bank-transfer notifications | Email, amount, transaction reference |
| Google Firebase (FCM) | Push notifications | Device push token, message title/body |
| Email/SMTP provider | OTP codes & receipts | Email address, code/receipt content |
We do not sell personal data and do not share it with advertisers.
4. International Transfers
Some processors (e.g. Stripe, Google) operate outside Nigeria. Where data is transferred across borders, we rely on the provider's contractual and technical safeguards to protect it to a standard consistent with applicable data-protection law.
5. Data Retention
| Data | Retention |
|---|---|
| Account & profile | While your account is active; deleted or anonymised on closure, subject to legal holds |
| Transaction & ledger records | Retained for the period required by financial/regulatory record-keeping rules |
| KYC images & details | Retained while required for verification and compliance, then deleted |
| OTP & reset codes | Short-lived (typically 10 minutes); expired/used codes are invalidated |
| Session & refresh tokens | Expire automatically; revoked on logout; periodically pruned |
| Push tokens / device data | Until you log out, remove the device, or the token becomes invalid |
6. Security Controls
- Passwords and transaction PINs are stored as bcrypt hashes; OTPs are stored hashed and expire quickly.
- Money movements run as atomic, idempotent ledger operations to prevent double-spends and keep balances consistent.
- Short-lived access tokens with rotating refresh tokens; reuse of a rotated token revokes the whole session.
- PIN lockout after repeated failures; automatic idle and absolute session timeouts on the web wallet.
- Administrative access is separated from user accounts, protected by a second factor, and audit-logged.
7. Your Controls
- View & edit your profile and resubmit unverified KYC fields in the app.
- Manage payment methods — add or remove saved cards/accounts at any time.
- Manage notifications through your device settings.
- Request export or deletion of your data by contacting us (subject to legal retention).
8. Data Breach Handling
If a breach affecting your personal data occurs, we will investigate, take steps to contain and remediate it, and notify affected users and the relevant authorities where required by law and within the applicable timeframes.
9. Updates
We may update this Data Policy as our processing or providers change. The "Last updated" date above reflects the current version.
10. Contact
For data requests or questions, contact our data team at privacy@ninawallet.com.
For a plain-language overview of your privacy, see our Privacy Policy.