Version: 1.0 · Effective date: 25 September 2026 · Last updated: 25 September 2026
1. Who we are and what this policy covers
This policy explains how Ayamaz Ventures LTD ("Ayamaz", "we", "us"), trading as Ayamaz Data, collects, uses, shares and protects personal data when you use the Ayamaz Data mobile app (currently Android; iOS when it is released), our website at https://ayamaz.com.ng and our related services (together, the "Services"). Ayamaz Data provides a wallet-based service for buying airtime, mobile data, electricity, cable TV and exam PINs in Nigeria.
- Registered address: Gombe, Nigeria
- Privacy contact: support@ayamaz.com.ng
For the personal data described here, Ayamaz is the data controller. We handle personal data in line with the Nigeria Data Protection Act 2023 and applicable guidance from the Nigeria Data Protection Commission (NDPC).
2. Information we collect
a. Account and contact information (required to create an account). Your full name (stored as first and last name), phone number, email address, and password. You may add a referral code. If you sign in with Google or Apple, we receive the identifier and email/name they provide. We store your password only as a one-way cryptographic hash; we never store it in readable form.
b. Security credentials. Your transaction PIN (stored as a one-way hash), sign-in and PIN-attempt records, and session tokens. If you enable biometric unlock, your fingerprint/face is handled by your device's operating system; we do not receive or store your biometric data. To support the biometric shortcut, the app keeps your PIN in your phone's secure storage.
c. Identity verification (KYC) information (optional, needed for higher limits/features). Your BVN, NIN and/or virtual NIN, and, where you submit them, identity documents such as a passport photograph, proof of address and business registration documents. Sensitive identifiers are stored encrypted. We use an identity-verification provider to check them (see section 4).
d. Wallet, payment and transaction information. Wallet balances (main, commission/cashback and reserved amounts), transaction history, receipts, funding records, your dedicated virtual account number(s) and the bank that issues them, payment and provider references, and referral rewards. We do not collect debit/credit card numbers. You fund your wallet by bank transfer to your virtual account.
e. Service information. For each purchase: the recipient's phone number (which may be another person's), network, plan and amount; electricity meter numbers; TV smartcard/IUC numbers; and exam-PIN order details. If you upload a spreadsheet/text file of recipients, the phone numbers in it are used to place bulk orders.
f. Contacts (optional). If you tap "pick from contacts", the app asks for permission to read contacts, shows your device's contact picker, and uses only the number you choose as the recipient. We do not upload your address book.
g. Device and technical information. An app-generated device identifier, push-notification token (Firebase Cloud Messaging / Apple Push Notification service), platform, app version, device model, operating-system version, language, network type, IP address, crash reports, diagnostic and performance data (including request timing), and app-usage events (for example screens viewed, sign-in, purchase and top-up events with amounts, network and plan). Analytics and crash reports are associated with your internal Ayamaz user ID. The app also includes the Meta (Facebook) App Events SDK, which may collect device and advertising identifiers and app-install/usage events for attribution.
h. Communications. Emails and push notifications we send you, your notification preferences, and messages you send us. Support conversations that you start through WhatsApp or by phone take place on those third-party services.
i. Website. Our website currently does not use analytics or advertising cookies and does not store information in your browser. If you use links to WhatsApp or other services, or if you enter information into a form that we later add, that will be described here first. Our web hosting provider (Google Firebase Hosting) processes standard server logs such as IP address and browser type to deliver the site.
j. What we do not collect. We do not collect your location, camera or microphone data, SMS or call logs, or health data.
k. Referral leaderboard. If you take part in referrals, other users can see your first name and last initial and your referral ranking and totals on the leaderboard.
3. How and why we use your information
| Purpose | Data | Basis |
|---|---|---|
| Create and secure your account; sign you in; verify it is you | a, b, g | Contract; legitimate interest |
| Provide the service: top up your wallet, process purchases, deliver airtime/data/electricity/cable/exam PINs, show history and receipts | a, d, e, f | Contract |
| Verify your identity and apply account limits | c | Legal obligation / legitimate interest |
| Prevent fraud, abuse and duplicate transactions; keep audit records; reconcile with providers | b, d, e, g | Legitimate interest; legal obligation |
| Send transaction confirmations, security alerts, reset codes and service notices; optional marketing notifications you can switch off in settings | a, d, g, h | Contract; consent for marketing |
| Operate referral rewards and the leaderboard | a, d, k | Contract; legitimate interest |
| Diagnose crashes, measure performance and understand how the app is used | g | Consent / legitimate interest |
| Attribute app installs and measure marketing (where the app uses an install-attribution SDK) | g | Consent |
| Customer support and dispute handling | a, d, e, h | Contract; legitimate interest |
| Comply with law, respond to lawful requests, protect our rights | any | Legal obligation; legitimate interest |
We do not sell your personal data.
4. How we share information
We share personal data only as needed to run the Services, with service providers acting on our behalf, and as required by law. Based on our current systems, these include:
| Recipient | Why | What |
|---|---|---|
| Google (Google Cloud hosting; Firebase Analytics, Crashlytics, Performance Monitoring and Cloud Messaging; Google Sign-In; Gmail email delivery) | Hosting and running the Services; analytics, crash reporting and push; sign-in; emailing you | Account and transaction data held on our servers; usage/diagnostic data and your user ID; push token; email address and message content |
| Apple | Sign in with Apple; iOS push notifications | Identifier/email you authorise; push token |
| Meta Platforms (Facebook App Events SDK) — if kept | Install attribution and measurement | Device/advertising identifiers and app events |
| BillStack and the bank(s) that issue your virtual account | Create your dedicated virtual account and notify us of incoming transfers | Information needed to open the account; deposit details |
| Airtime, data, electricity, cable and exam-PIN providers | Fulfil your order | Recipient number/meter/smartcard, product, amount, our order reference |
| Dojah | Verify your BVN/NIN | The identifiers you submit |
| Professional advisers, auditors, insurers, and regulators or law-enforcement authorities | Legal, audit and compliance needs; lawful requests | As required |
| A buyer or successor | If our business is restructured or sold | As required, subject to this policy |
When you message us on WhatsApp or open other links, that provider's own terms and privacy notices apply. Where we rely on processors, we take steps to require appropriate confidentiality and security.
5. International transfers
Our servers are hosted on Google Cloud in the United States (region "us-central1"), and other providers listed above may process data outside Nigeria. Where personal data is transferred outside Nigeria we will do so only as permitted by the Nigeria Data Protection Act and NDPC requirements.
6. Security
We use measures designed to protect personal data, including: encrypted (HTTPS/TLS) connections between the app and our servers; passwords and PINs stored only as salted one-way hashes; encryption of BVN/NIN and identity-document references in our database; keeping session tokens in the device's secure storage; automatic locking after repeated wrong PIN or password attempts; rate limiting; role-based access, multi-factor step-up checks and audit logging for staff; and log redaction of sensitive fields. No system is completely secure, and we cannot guarantee absolute security. Keep your PIN, password and device safe and tell us immediately if you suspect unauthorised use. If a personal data breach occurs that is likely to harm you, we will notify you and the NDPC as required by law.
7. How long we keep information
We keep personal data only as long as needed for the purposes above and to meet legal, tax, financial and audit obligations. Our retention periods are:
| Category | Retention |
|---|---|
| Account and profile data | 30 days after account closure, apart from the records listed below |
| Transaction, ledger and reconciliation records | 6 years |
| Identity-verification (KYC) data and documents | 5 years after the account is closed |
| Security, fraud-prevention and audit logs | 12 months |
| Support records | 2 years |
| Analytics, crash and diagnostic data | Up to 14 months, under the provider's retention settings |
| One-time codes and session tokens | Short-lived; expire automatically (access tokens ~15 minutes; refresh tokens up to 30 days unless you sign out) |
8. Account and data deletion
How to request deletion
- In the app: Profile → Delete account. Give an optional reason and confirm. You can withdraw the request before we complete it.
- Without the app: follow the steps at https://ayamaz.com.ng/legal/delete-account, or contact support@ayamaz.com.ng.
What happens. Our team reviews each request and tells you the outcome within 48 hours. We can only complete closure when your wallet balance is zero and you have no pending orders; if you have a balance, contact support to settle it first. When we approve the request we remove or replace your name, phone number and email in your profile, and stop notifications.
What we may keep, and why. Some records are not erased when you close your account because we need them for legitimate legal, financial, security or fraud-prevention reasons:
- transaction, ledger, payment and reconciliation records and audit logs (for accounting, dispute and regulatory purposes);
- identity-verification records where the law or our partners require us to keep them;
- one-way fingerprints ("hashes") of your phone number and email, kept permanently to prevent a closed account from being re-registered.
We will delete or anonymise other personal data that we no longer need. Data held by third parties (for example Google analytics) is handled under their retention settings.
9. Your rights
Under the Nigeria Data Protection Act 2023 you have rights that include: to be informed about how we use your data; to access your data; to have inaccurate data corrected; to request deletion; to restrict or object to certain processing, including direct marketing; to data portability; to withdraw consent at any time (without affecting earlier processing); and not to be subject to decisions based solely on automated processing that significantly affect you, in the circumstances the law provides. These rights are subject to legal limits (for example we may need to retain financial records). To exercise them, contact support@ayamaz.com.ng; we may need to verify your identity. You may also complain to the Nigeria Data Protection Commission (https://ndpc.gov.ng).
10. Children
Our Services are for people aged 16 and over. If you are under 18, you confirm that a parent or guardian agrees to you using them. We do not knowingly collect data from anyone under 16. If you believe a child has registered, contact us and we will take appropriate steps.
11. Cookies and similar technologies (website)
- Our website does not currently set cookies or use analytics/advertising trackers. If we add them, we will ask for your consent where the law requires it and update this policy first.
- The Ayamaz Data mobile app uses analytics, crash-reporting and performance SDKs — see sections 2(g) and 4.
12. Third-party links
The Services link to services such as WhatsApp, Google and Apple. We are not responsible for their privacy practices.
13. Changes to this policy
We may update this policy from time to time. We will change the version and effective date above and, for material changes, notify you in the app or by email before they take effect where practicable.
14. Contact us
Ayamaz Ventures LTD · Gombe, Nigeria Privacy / DPO: support@ayamaz.com.ng · Support: support@ayamaz.com.ng · +234 813 076 2880