Privacy Policy
What we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
Last updated: 9 September 2026 · Version 1.0
We collect what a payment needs: your name and email, the numbers you top up, and the transactions on your wallet. We never see your card details — those go straight to Paystack. We do not sell your personal data, and there is no advertising network in the app.
1. Who we are
SA Data Sub Global Resources operates the SA Data Sub app and this website, and is the data controller for the personal data described here. This policy is written to meet our obligations under the Nigeria Data Protection Act 2023 (NDPA) and the guidance of the Nigeria Data Protection Commission (NDPC).
Contact us about anything in this policy at sadatasubglobalresources@gmail.com.
2. What we collect
Information you give us
- Account details — your full name, email address, and a password (stored only as a cryptographic hash, never in readable form).
- Transaction details — the phone numbers, meter numbers and smartcard/IUC numbers you top up, the plans and amounts you choose, and any contact phone number you supply for an order.
- Security settings — that you have set a transaction PIN or enabled app lock. The PIN is stored as a hash; your fingerprint and face data never leave your device (see section 11).
- Support correspondence — what you send us by email or through the contact form, including any transaction reference and details of the problem.
- Referral information — your referral code and the link between an account and the code it signed up with.
Information created by your use of the Service
- Wallet and ledger records — every funding, purchase, reversal and reward, with amounts, timestamps and references. We are required to keep accurate financial records.
- Order records — the request reference, provider response and delivery outcome for each purchase, including electricity tokens and PINs issued to you.
- Technical and log data — device type and operating system, app version, IP address, and timestamped records of requests, sign-ins and errors. We use these to operate the Service, diagnose faults and detect fraud.
Information from third parties
- Payment confirmations from Paystack — the payment reference, amount, status, channel, and the masked details (such as the last four digits of a card or a bank name) they return to us.
- Customer validation from providers — when you enter a meter or smartcard number, the provider returns the registered name and account status so you can confirm you are paying the right account.
3. What we do not collect
To be unambiguous, we do not collect or store:
- your card number, expiry date, CVV, card PIN or online banking credentials — these are entered on Paystack’s own PCI‑DSS certified checkout and are never transmitted to us;
- your fingerprint, face scan or any other biometric template — these are matched by your device and never shared with us;
- your contacts, photos, messages, call logs or precise location;
- any data for advertising profiles — we operate no advertising network and run no third-party ad or social tracking SDKs in the app.
4. Why we use it
- To provide the Service — create and secure your account, hold your wallet balance, fulfil purchases with the relevant provider, and deliver tokens, PINs and receipts.
- To keep money accurate — maintain the ledger, verify payments, reverse failed orders, and reconcile with our payment and fulfilment partners.
- To keep accounts secure — authenticate you, detect and prevent fraud, unauthorised access, promotion abuse and money laundering, and enforce our Terms.
- To support you — investigate a transaction, answer a question, and trace an order with a provider.
- To operate and improve — diagnose crashes and errors, understand which flows fail, and make the app more reliable. We use aggregated, non-identifying figures for this wherever it is sufficient.
- To meet legal obligations — financial record-keeping, tax, regulatory requests and lawful orders.
- To administer referrals — check whether a referral qualifies and credit the reward.
We do not use your personal data to make solely automated decisions that have a legal or similarly significant effect on you. Automated checks may flag a transaction or account for review, but a person makes the decision on any restriction.
5. Our lawful bases
Under the NDPA we rely on:
- Performance of a contract — to give you the Service you signed up for: your account, wallet and purchases.
- Legal obligation — to keep financial records and to respond to lawful requests.
- Legitimate interests — to secure the Service, prevent fraud and abuse, and improve reliability, where doing so does not override your rights.
- Consent — for anything optional, such as marketing emails or push notifications. You can withdraw consent at any time without affecting your use of the Service.
6. Who we share it with
We do not sell your personal data, and we do not share it for third-party advertising. We share only what a specific purpose requires, with:
- Paystack — our payment processor. They receive what is needed to process a funding payment and return the confirmation.
- Our fulfilment partner and the service providers — the mobile networks, electricity distribution companies and pay-TV operators. To deliver a purchase we must pass on the recipient detail for that order: the phone number, meter number or smartcard number, and the plan or amount.
- Infrastructure providers — the hosting, database and edge-computing services that run our backend under contract, and cloud messaging services if you enable push notifications.
- Professional advisers and auditors — where confidentiality obligations apply and there is a genuine need.
- Authorities and regulators — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, or to prevent serious harm or fraud.
- A successor — if the business is reorganised, merged or acquired, subject to this policy continuing to protect your data.
Processors acting on our behalf may use your data only for the purpose we set, under a written contract, and are required to protect it.
7. International transfers
Some of the infrastructure and payment services we use operate outside Nigeria, so your data may be processed abroad. Where we transfer personal data internationally, we do so under the NDPA’s conditions for cross-border transfer — meaning an adequate destination, or contractual safeguards that require the recipient to protect the data to a standard comparable to Nigerian law.
8. How long we keep it
- Account details — while your account is open, then deleted or anonymised after closure, subject to the record-keeping below.
- Transaction and ledger records — retained for at least the period required by Nigerian financial record-keeping and tax law (generally six years from the transaction), because we must be able to evidence money movements.
- Support correspondence — up to two years after a matter is resolved.
- Technical and security logs — typically up to 12 months, and longer where a specific log is needed for a fraud or security investigation.
- Tokens and PINs on receipts — retained with the transaction record so you can retrieve a receipt.
When a retention period ends, we delete the data or irreversibly anonymise it.
9. How we protect it
- All traffic between the app and our servers is encrypted in transit with TLS.
- Passwords and transaction PINs are stored only as cryptographic hashes — we cannot read them, and neither can an attacker who obtains the stored value.
- Session credentials on your device are held in the platform’s secure storage — the Android Keystore or the iOS Keychain — not in ordinary app files.
- Card data is out of scope by design: it goes to Paystack’s certified checkout and never reaches our systems.
- Every request is authorised server-side, and administrative rights are re-derived on each request rather than trusted from the client.
- Wallet movements are written to a double-entry ledger, which makes discrepancies detectable rather than silent.
- Access to production data is limited to the people who need it, and payment notifications are verified by signature before being acted on.
No system is perfectly secure. Protect your side too: use a password you do not reuse elsewhere, enable app lock, and never share your PIN or an OTP with anyone — including anyone claiming to be us.
10. Your rights
Under the NDPA you have the right to:
- Be informed — about how your data is used, which is what this policy is for.
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your data where we have no lawful ground to keep it. Note that we must retain transaction records for the statutory period even after account closure.
- Restriction — ask us to limit processing while a dispute about accuracy or lawfulness is resolved.
- Object — object to processing based on our legitimate interests.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent — at any time, where we relied on consent.
- Complain — to us, and to the Nigeria Data Protection Commission.
To exercise any of these, email sadatasubglobalresources@gmail.com from the address on your account, with “Data request” in the subject. We will respond within 30 days. We may need to verify your identity first — that protects you from someone else requesting your data. Exercising these rights is free; we may charge a reasonable fee only for a manifestly excessive or repetitive request.
11. App permissions
The app asks for a permission only when a feature needs it, and each one is optional in the sense that declining it disables just that feature:
- Biometrics — to unlock the app with your fingerprint or face. The match happens inside your device’s secure hardware; we receive only a yes or no, never the biometric itself.
- Camera — to scan a meter, smartcard or referral QR code so you do not have to type it. Images are used for the scan and are not uploaded or retained by us.
- Photos — only if you choose to pick an image, for example to attach evidence to a support request.
- Notifications — to tell you when a purchase is delivered or a funding is credited. You can turn these off at any time.
- Network state — to detect that you are offline and say so, instead of failing silently.
You can change or revoke any of these in your device settings at any time. The app does not request access to your contacts, messages or precise location.
12. Cookies and this website
This website does not use tracking or advertising cookies and carries no analytics or social media trackers. It stores one item in your browser’s local storage: your light or dark theme choice, so the site opens the way you left it. That stays on your device and is never sent to us.
The site loads its typeface from Google Fonts, which means your browser makes a request to Google’s servers, and the contact form hands your message to your own email application rather than posting it to a server here. Nothing you type into that form is transmitted by this website.
13. Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it and the associated data.
14. Marketing
We send transactional messages — receipts, delivery confirmations, security alerts and essential service notices — as part of providing the Service. Any promotional email or push message is sent only with your consent, and every one carries a way to opt out. Opting out of marketing does not stop transactional messages, which you need in order to use a wallet safely.
15. Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Nigeria Data Protection Commission within the timeframe the NDPA requires, and inform affected users without undue delay, describing what happened, what data was involved, and what we and you should do about it.
16. Changes to this policy
We will update this policy when our practices, partners or the law change. The current version always sits on this page with its “last updated” date. Where a change materially affects how we use your data, we will give notice in the app or by email before it takes effect.
17. Contact and complaints
SA Data Sub Global Resources
Email:
sadatasubglobalresources@gmail.com
Support: sadatasub.app/contact
If you are not satisfied with how we have handled your data or your request, you may complain to the Nigeria Data Protection Commission (NDPC). We would appreciate the chance to put it right first.
Related: Terms & Conditions