Privacy Policy
VultPay operates a naira-only escrow service that holds a buyer's payment securely until they confirm they have received what they paid for, then releases it to the seller. This Privacy Policy explains what personal data we collect, why, the lawful basis for using it, who we share it with, how long we keep it, how we protect it, and the rights you have over it. It applies to sellers, to buyers (including guest buyers who pay without an account), and to visitors to our websites and apps. Please read it together with our Cookie Policy and the Buyer Terms / Seller Agreement.
We handle personal data under the Nigeria Data Protection Act, 2023 (NDPA) and its subsidiary regulations. For visitors in the European Economic Area or the United Kingdom, we also apply the GDPR where it is relevant.
1. Who we are and how to contact us
VultPay is the data controller responsible for the personal data described in this policy. Because we are a financial-sector business that holds fiduciary custody of customer funds, we are a controller of major importance under the NDPA: we are registered with the Nigeria Data Protection Commission (NDPC) and have appointed a Data Protection Officer (DPO).
You can reach our DPO about anything in this policy, or to exercise your rights, at support@vultpay.co. VultPay is operated by Vult Technologies Ltd (RC 9724145), 2A Oshonaike by Coates, Yaba, Ijora, Lagos State.
2. The data we collect
We collect only the data we need to run the escrow service, verify identity, meet our legal obligations, prevent fraud, and support you. We collect it directly from you, automatically as you use the service, and from third parties such as our identity-verification and screening providers and our payment processor.
- Account data - your email, password (stored only as a secure hash), business or display name, account type, and phone number.
- Identity / KYC data - your NIN or BVN, name, and date of birth, used to verify who you are.
- Financial and transaction data - transaction amounts and references, escrow and ledger entries, payout bank-account details, and refund / payout records.
- Dispute and evidence data - photos, delivery / tracking references, and the narratives you and your counterparty submit when a transaction is disputed.
- Risk and fraud-screening data - sanctions and politically-exposed-person screening results, device and technical signals, and risk flags used to detect and prevent fraud and abuse.
- Communications data - the email address and phone number we use for transactional notices, records of your support messages, and (only if you opt in) product updates.
- Technical and usage data - IP address, device and browser information, log data, and, with your consent, aggregate analytics about how the product is used (see the Cookie Policy).
3. How we use your data and our lawful basis
We use your data for the purposes below. For each purpose the NDPA requires a lawful basis, shown alongside it. Where we rely on legal obligation for regulated activities such as KYC, that is the primary basis and any consent we capture is additional good practice.
- Operating the escrow service - creating transactions, holding and releasing funds, and processing payouts and refunds. Basis: performance of the contract with you.
- Verifying your identity (KYC) and meeting anti-money-laundering / counter-terrorist-financing and CBN requirements. Basis: legal obligation, with consent for anything beyond the regulatory minimum.
- Preventing, detecting, and investigating fraud, abuse, and financial crime. Basis: legal obligation (AML/CFT) and our legitimate interest in keeping the platform safe.
- Resolving disputes fairly between buyers and sellers. Basis: performance of the contract and our legitimate interest in fair resolution.
- Sending transactional notices you need to use the service (for example, payment and delivery updates) by email and SMS. Basis: performance of the contract.
- Keeping financial, transaction, and compliance records. Basis: legal obligation and our legitimate interest in record-keeping.
- Improving and securing the product, including error monitoring and, with your consent, analytics. Basis: legitimate interest for security / reliability, and consent for analytics.
- Sending optional product or marketing updates. Basis: your consent, given separately and withdrawable at any time.
4. Sensitive (restricted) data
Your NIN, BVN, and full financial account details are treated as restricted, sensitive personal data and handled to a higher standard. They are encrypted at rest, access to them is limited to the few staff and systems that genuinely need it and is logged, and they are never shown on general screens or shared beyond what a transaction or the law strictly requires.
5. Consent and how we manage it
Where we rely on consent, we ask for it by a clear, affirmative action, separately for each purpose - we never bundle optional marketing consent with the acceptance needed to use the core service, and we do not use pre-ticked boxes. We keep an auditable record of what you consented to, when, and against which version of this policy. You can withdraw any consent as easily as you gave it, and doing so does not affect the lawfulness of what we did before you withdrew it.
6. Automated decision-making
Some risk assessments and some dispute outcomes are decided or assisted by automated systems that can affect whether funds are released, held, or refunded. We assess these systems for data-protection risk before they go live. Where a decision that significantly affects you is made in this way, you have the right to an explanation, to express your view, and to appeal to a human reviewer within the stated window.
7. Who we share your data with
We share personal data only as needed to run the service, and each provider acts for us under a written data-processing agreement that restricts what they may do with it. We do not sell your personal data or share it for others' advertising.
- Payment processing - Paystack, to collect card and bank payments and to make payouts.
- Safeguarding of funds - our safeguarding bank / microfinance partner, which holds customer funds.
- Identity verification - Dojah, to verify your NIN / BVN and identity.
- Notifications - our email provider (Resend) and SMS providers (Termii / Twilio) to deliver transactional messages and one-time codes.
- Product reliability and analytics - our error-monitoring provider (Sentry) and, with your consent, our analytics provider (Google), as described in the Cookie Policy.
- Infrastructure - our cloud hosting and database providers that run the service.
- Legal and regulatory - courts, regulators (including the NDPC and financial regulators), and law-enforcement bodies, where we are legally required to disclose data or need to establish, exercise, or defend legal claims.
8. International transfers
Some of our providers may process data outside Nigeria. The NDPA permits this only where the destination offers an adequate level of protection, where appropriate contractual safeguards are in place, or under a specific exception such as your explicit consent for a particular transfer. Before onboarding any provider that may process data abroad we confirm and document where the data is handled and which safeguard applies, and we prefer Nigeria-region storage for restricted data where technically feasible.
9. How we keep your data secure
We protect personal data with technical and organisational measures appropriate to its sensitivity: encryption in transit and encryption at rest for restricted data, least-privilege access with logging, network and application controls, and continuous monitoring. No system is perfectly secure, but we work to reduce risk and to respond quickly if something goes wrong (see Data breaches below).
10. How long we keep your data
We keep data only as long as needed for the purpose we collected it, or as the law requires - never indefinitely by default. Retention is enforced by scheduled deletion and anonymisation processes rather than manual clean-up.
- Financial, transaction, ledger, KYC, and risk / fraud records - retained for a minimum of 6 years consistent with financial record-keeping and AML/CFT obligations, and for KYC, for the account relationship plus that post-closure period.
- Marketing consent and communications data - kept only while your consent is active and purged promptly after withdrawal, subject to a short operational grace period.
- Consent and acceptance records - retained as long as needed to demonstrate compliance.
11. Your rights
Under the NDPA (and the GDPR where it applies) you have the right to access your data, to have it rectified, to have it erased, to restrict or object to its processing, to data portability (we provide an export of your own records in a structured, commonly-used format), to withdraw consent, and not to be subject to a solely automated decision that significantly affects you without human review.
Some rights are limited by our legal retention obligations - for example, we cannot erase records we are legally required to keep, but where full erasure is not possible we will de-identify what we can and stop using the rest. We verify your identity before acting on a request, to protect your data from impersonation, and we respond within the timeframe the law allows and without charge in ordinary cases. To make a request, contact us at support@vultpay.co.
12. Children
VultPay is intended for adults and is not directed to anyone under 18. Our KYC flow is age-gated by design, and buyer-side account creation includes an age affirmation. We do not knowingly process the personal data of a minor as an account holder; if you believe a minor has provided us data, contact our DPO and we will take appropriate steps.
13. Marketing communications
Transactional messages that are necessary to operate the service (such as payment, delivery, and dispute notices, and security codes) are part of the service and are not marketing. We send optional product or promotional updates only if you have opted in, and you can opt out at any time using the unsubscribe link or the in-product setting, without affecting the transactional messages you need.
14. Cookies and similar technologies
We use strictly necessary and functional cookies and storage to run the service and, only with your consent, analytics cookies. We do not use advertising or cross-site tracking cookies. See the Cookie Policy for the full details, our position on third-party cookies, and how to change your choice.
15. Data breaches
We maintain a breach register and a response process. If a personal-data breach is likely to put your rights at risk, we notify the NDPC within 72 hours of becoming aware of it, and where the risk to you is high we notify you without undue delay, in plain language, with clear guidance on what to do. If a breach happens at one of our providers, our contracts require them to tell us promptly so we can still meet these obligations.
16. Changes to this policy
We may update this policy as our service, providers, or legal obligations change. We show the version and effective date at the top, and where a change is material we bring it to your attention and, where the law requires, ask you to accept the updated terms. Please review this page from time to time.
17. Contact and complaints
For any question, request, or complaint about your data, contact our DPO at support@vultpay.co. If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).