Admin Login Vendor Login
Data Protection & Privacy

Privacy Policy

Effective: 1 January 2025
Last Revised: March 2025
Regulation: NDPR 2019 & FCCPA 2018
Jurisdiction: Federal Republic of Nigeria
NDPR 2019 Compliant
NITDA Registered
SSL Encrypted
No Data Selling
Right to Erasure

This Privacy Policy explains how Ajaro Limited ("we", "us", "the Company") collects, uses, stores, and protects the personal data of vendors, customers, and visitors who interact with the Ajaro platform at www.ajaro.com.ng and any associated mobile applications. We are committed to handling personal data responsibly, transparently, and in full compliance with the Nigerian Data Protection Regulation (NDPR) 2019 and all other applicable Nigerian data protection laws.

1

Who We Are

Ajaro Limited is the data controller responsible for the personal data collected and processed through the Platform. Our registered details are:

Company NameAjaro Limited
RC NumberRC 00000000
Registered Address14 Broad Street, Victoria Island, Lagos State, Nigeria
Data Protection Officerprivacy@ajaro.com.ng
NITDA Registration No.NITDA/DPR/2025/000000

As a data controller, we determine the purposes for which and the means by which personal data is processed. Where we engage third-party service providers to process data on our behalf, they act as data processors under our instructions and are bound by appropriate data processing agreements.

2

Data We Collect

We collect the following categories of personal data depending on your relationship with the Platform:

2.1 Vendor Account Data
  • Full legal name or business name, trading name, and CAC registration number (where applicable)
  • Email address, phone number(s), and business address
  • Bank account name, number, and bank name for payout purposes
  • Government-issued identification (National ID, International Passport, or Driver's Licence)
  • Profile photograph or business logo
  • Tax Identification Number (TIN) where required by law
2.2 Transaction & Financial Data
  • Order details, product descriptions, quantities, and transaction amounts
  • Payment method metadata (we do not store full card numbers — these are handled by our PCI-DSS compliant payment processors)
  • Payout history, withdrawal requests, and revenue summaries
  • Subscription billing history and invoices
2.3 Store & Product Data
  • Store name, slug, description, logo, and banner images
  • Product listings including titles, descriptions, prices, categories, and product images
  • Promotional campaign details and advertisement content
2.4 Technical & Usage Data
  • IP address, browser type and version, and operating system
  • Device identifiers and screen resolution
  • Pages visited, time spent on pages, and navigation paths within the Platform
  • Login timestamps, session duration, and access logs
  • Error logs and crash reports
2.5 Communication Data
  • Support ticket content, emails, and live chat transcripts
  • Feedback, survey responses, and review submissions
  • Notification preferences and marketing communication opt-in/out records
Sensitive Personal Data
We do not intentionally collect sensitive personal data such as health information, biometric data, or political opinions. If you voluntarily provide such information in a support message or profile field, we will handle it with additional care and will not process it beyond what is strictly necessary to respond to your enquiry.
3

How We Collect Data

We collect personal data through the following channels:

3.1 Directly From You
  • When you register a vendor account or complete the onboarding process
  • When you set up or update your store, list products, or manage orders
  • When you submit bank account or payout details
  • When you contact our support team via email, phone, WhatsApp, or the contact form
  • When you respond to a survey or participate in a promotion
3.2 Automatically

When you use the Platform, we automatically collect certain technical data through cookies, web beacons, log files, and similar technologies. This includes your IP address, browser data, and behavioural data about how you interact with the Dashboard. See Section 7 for full details on cookies.

3.3 From Third Parties
  • Payment processors (Paystack, Flutterwave) — transaction status and payment metadata
  • Identity verification services — verification results for KYC compliance
  • Fraud detection services — risk signals associated with account or transaction activity
  • Government databases — CAC and TIN verification where applicable
4

Why We Use Your Data

We use personal data for the following purposes:

PurposeData UsedLegal Basis
Creating and managing your vendor accountAccount data, identity documentsContract performance
Processing orders, payments, and payoutsTransaction data, bank detailsContract performance
Verifying your identity and preventing fraudAccount data, ID documents, technical dataLegal obligation; Legitimate interest
Providing customer supportCommunication data, account dataContract performance; Legitimate interest
Sending service notifications (order alerts, expiry reminders)Email, phone numberContract performance
Sending marketing communications (where opted in)Email, phone number, preferencesConsent
Improving Platform features and user experienceUsage data, error logsLegitimate interest
Complying with legal and regulatory obligationsAll applicable data categoriesLegal obligation
Enforcing our Terms & ConditionsAccount data, transaction dataLegitimate interest; Legal obligation
Analytics and Platform performance monitoringTechnical data, usage dataLegitimate interest
5

Legal Basis for Processing

Under the NDPR 2019, we rely on one or more of the following legal bases when processing your personal data:

5.1 Contract Performance

The majority of data processing on the Platform is necessary to perform our contract with you as a vendor. This includes account management, order processing, payout disbursement, and subscription management. Without this processing, we cannot provide the Platform services to you.

5.2 Legal Obligation

We are required by Nigerian law to process certain personal data for compliance purposes, including KYC/AML obligations under the Money Laundering (Prohibition) Act, tax reporting requirements, and responses to lawful requests from regulatory authorities such as FIRS, the CBN, and EFCC.

5.3 Legitimate Interest

We process certain data where we have a legitimate business interest in doing so, provided that interest is not overridden by your rights and freedoms. This includes fraud prevention, platform security, service analytics, and improving user experience. You have the right to object to processing based on legitimate interest — see Section 11.

5.4 Consent

Where we rely on your consent — such as for marketing emails or optional analytics cookies — we will ask for it explicitly and you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal.

6

Sharing Your Data

We do not sell your personal data to third parties. We share data only in the limited circumstances described below:

6.1 Service Providers (Data Processors)

We share data with trusted third-party service providers who process it on our behalf under binding data processing agreements. These include:

Provider CategoryPurposeData Shared
Payment processors (Paystack, Flutterwave)Transaction processing and payout disbursementName, bank details, transaction amounts
Cloud hosting providerPlatform infrastructure and data storageAll Platform data (encrypted at rest)
Email delivery providerTransactional and marketing email deliveryEmail address, name, message content
SMS/notification providerOrder and account SMS notificationsPhone number, message content
Identity verification serviceKYC document verification during onboardingName, ID document images, date of birth
Analytics providerPlatform usage analytics (anonymised)Anonymised usage and technical data
Fraud detection serviceTransaction risk assessmentIP address, device data, transaction metadata
6.2 Regulatory & Law Enforcement

We may disclose personal data to government agencies, regulatory bodies, or law enforcement authorities where we are required to do so by law, court order, or lawful regulatory direction. We will notify you of any such disclosure where we are legally permitted to do so.

6.3 Business Transfers

In the event of a merger, acquisition, sale of assets, or restructuring of the Company, your personal data may be transferred to the successor entity as part of the business assets. You will be notified in advance of any such transfer, and the successor entity will be bound by privacy obligations no less protective than those in this Policy.

We Never Sell Your Data
Ajaro does not sell, rent, or trade your personal data to advertisers, data brokers, or any other third party for commercial gain. Our business model is based on Platform subscription fees and transaction commissions — not data monetisation.
7

Cookies & Tracking Technologies

We use cookies and similar tracking technologies on the Platform. A cookie is a small text file placed on your device when you visit our website. Full details are available in our Cookie Policy. Below is a summary of the types of cookies we use:

Cookie TypePurposeCan Be Disabled?
Strictly NecessaryEssential for logging in, maintaining your session, and basic Platform security. Cannot be turned off.No
FunctionalRemember your preferences such as language, layout, and sidebar state.Yes
AnalyticsCollect anonymised data about how users interact with the Platform to help us improve it.Yes
MarketingUsed to show relevant advertisements if you have opted in to marketing communications.Yes

You can manage your cookie preferences at any time through your browser settings or via the Cookie Preferences panel accessible from the footer of the Platform. Note that disabling certain cookies may affect the functionality of the Platform.

8

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our standard retention periods are as follows:

Data CategoryRetention PeriodReason
Active vendor account dataFor the duration of account activityContract performance
Financial and transaction records7 years after transaction dateTax law (FIRS requirements)
KYC and identity documents7 years after account closureAML regulatory obligation
Closed account data6 years after closureLegal claims and dispute resolution
Support communications3 years after last interactionQuality assurance; dispute resolution
Marketing opt-in recordsUntil withdrawal of consent + 1 yearProof of consent
Server and access logs12 monthsSecurity monitoring
Analytics data24 months (anonymised)Platform improvement

When data is no longer required, we securely delete or anonymise it. Where complete deletion is not technically feasible within normal operations (e.g. backup archives), we isolate the data from further active processing until deletion is possible.

9

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. Our security measures include:

  • 256-bit TLS/SSL encryption for all data transmitted between your device and our servers
  • AES-256 encryption for data stored at rest in our databases
  • Role-based access controls ensuring staff can only access data required for their specific function
  • Multi-factor authentication for all internal administrative systems
  • Regular security audits and penetration testing by independent third-party firms
  • Secure PIN lockscreen and session timeout controls on the Vendor Dashboard
  • PCI-DSS compliant payment processing through Paystack and Flutterwave — we never store full card numbers
  • 24/7 automated monitoring for suspicious access patterns and anomalous activity
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the Nigeria Data Protection Bureau (NDPB) without undue delay and within 72 hours of becoming aware of the breach, as required by the NDPR. Notification will include the nature of the breach, the data affected, and the steps we are taking to mitigate it.
10

International Data Transfers

Our primary servers are located in Nigeria. However, some of the third-party service providers we use (such as cloud hosting and analytics providers) may process your data outside Nigeria. Where this occurs, we take steps to ensure that your data receives an equivalent level of protection to that afforded under Nigerian law.

These steps include:

  • Entering into Standard Contractual Clauses or equivalent contractual safeguards with the receiving entity;
  • Transferring data only to countries that the NITDA has assessed as providing adequate protection; or
  • Obtaining your explicit consent to the transfer where required.

You may request details of the safeguards in place for any specific international transfer by contacting our Data Protection Officer at privacy@ajaro.com.ng.

11

Your Rights

Under the NDPR 2019 and applicable Nigerian data protection law, you have the following rights in relation to your personal data. You may exercise any of these rights by contacting our Data Protection Officer at privacy@ajaro.com.ng. We will respond to all valid requests within thirty (30) days.

Right to Access
Request a copy of the personal data we hold about you, including information on how it is being used.
Right to Rectification
Request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data where there is no compelling reason for continued processing.
Right to Object
Object to processing based on our legitimate interests, including direct marketing at any time.
Right to Restriction
Request that we restrict processing of your data in certain circumstances, such as while you contest accuracy.
Right to Portability
Receive your personal data in a structured, commonly used format to transfer to another service.
Right to Withdraw Consent
Withdraw consent to marketing or optional processing at any time without affecting past processing.
Right to Lodge a Complaint
Lodge a complaint with the Nigeria Data Protection Bureau (NDPB) if you believe your rights have been infringed.
How to Exercise Your Rights
Email privacy@ajaro.com.ng with the subject line "Data Subject Request" and describe the right you wish to exercise. We will verify your identity and respond within 30 days. Most requests can be fulfilled at no cost. We may charge a reasonable administrative fee for manifestly excessive or repetitive requests.
12

Children's Privacy

The Ajaro Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. Vendor account registration requires confirmation that the applicant is at least 18 years of age.

If we become aware that we have inadvertently collected personal data from a person under 18 without appropriate parental or guardian consent, we will take immediate steps to delete that data from our systems. If you believe we may have collected data from a minor, please contact us immediately at privacy@ajaro.com.ng.

13

Third-Party Links

The Platform may contain links to third-party websites, payment portals, or partner services. This Privacy Policy applies only to Ajaro and does not extend to any third-party website or service, even where accessed through a link on our Platform. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies before providing any personal data.

Third-party payment pages operated by Paystack and Flutterwave are governed by their own privacy policies. When you are redirected to a payment page, you are leaving the Ajaro Platform.

14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Where changes are material, we will notify you by email to your registered address and/or by a prominent notice on the Platform Dashboard at least fourteen (14) days before the changes take effect.

We encourage you to review this Policy periodically. The date at the top of the Policy indicates when it was last revised. Your continued use of the Platform after the revised Policy takes effect constitutes your acceptance of the changes. A version archive of past policies is available on request from our Data Protection Officer.

15

Contact & Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact our Data Protection Officer:

Data Protection OfficerAjaro Data Protection Office
Emailprivacy@ajaro.com.ng
PostData Protection Officer, Ajaro Limited, 14 Broad Street, Victoria Island, Lagos State, Nigeria
Phone+234 901 234 5678 (Mon – Fri, 8am – 6pm WAT)
Response TimeWithin 30 days of receipt of your request

If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Bureau (NDPB) at ndpb.gov.ng or by post to: Nigeria Data Protection Bureau, No. 5 Ogunyemi Street, Wuse 2, Abuja, FCT.

This Privacy Policy was last reviewed and updated in March 2025. Document reference: DBM-PP-V2.1-2025. This policy supersedes all previously published versions.

Questions about your privacy?

Our Data Protection Officer is here to help. Reach out at any time and we'll respond within 30 business days.