Cred Data Sub Back to Home

Contents

  • 1. Information We Collect
  • 2. How We Use Your Information
  • 3. Legal Basis for Processing
  • 4. Third Parties We Share Your Data With
  • 5. Data Security
  • 6. Data Retention
  • 7. Your Rights Under the NDPR and NDPA
  • 8. Cookies and Device Identifiers
  • 9. Children's Privacy
  • 10. Changes to This Policy
  • 11. How to Contact Us

Legal

Privacy Policy

How Cred Data Sub collects, uses, shares, and protects your personal information.

Last updated: July 14, 2026
Effective date: June 24, 2026

This Privacy Policy describes how Cred Data Sub ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our platform to purchase airtime, data bundles, electricity tokens, cable TV subscriptions, exam pins, and other digital utility services.

By registering for or using Cred Data Sub, you agree to the practices described in this Policy. This Policy is written in compliance with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023.

1.

Information We Collect

When you register and use Cred Data Sub, we collect the following categories of personal information.

Account and Identity Information
- Full name (first and last name)
- Email address — your primary login credential
- Phone number — used as an alternate login credential and for WhatsApp OTP delivery
- Date of birth — required for KYC verification
- Gender (optional)
- Profile photograph (optional)

KYC (Know Your Customer) Documents
- National Identity Number (NIN)
- Bank Verification Number (BVN)
- International Passport
- Driver's License
- Voter's Card
- Images and scans of submitted identity documents

Financial and Transaction Data
- Wallet balance and full transaction history (credits, debits, refunds, reversals)
- Virtual bank account details assigned to your wallet for funding
- Cashback balance and transaction history
- Referral bonus balance and commission history
- Funding method details (card details are processed by our payment gateways — we do not store your card number)

Service Delivery Data
- Phone numbers, meter numbers, and smart card numbers you provide for each transaction
- Auto-renewal schedules and preferences you configure
- Favourite numbers you save in the platform

Device and Technical Data
- IP address, logged on every login and authentication event
- Browser type and device user agent, logged for security purposes
- Firebase device push notification token, used to deliver transaction alerts
- Login timestamps and session information

Support and Communication Data
- Messages you send to our AI-powered support assistant
- Support tickets you raise and replies exchanged with our human agents
- Satisfaction ratings you provide on resolved support interactions


2.

How We Use Your Information

We use your personal information only for purposes directly connected to delivering and improving our services:

  • Account creation and authentication — registering your account, verifying your email and phone number via OTP, and enabling secure login
  • Processing your purchases — delivering airtime, data bundles, electricity tokens, cable TV subscriptions, and exam pins to the phone numbers and meter/smart card numbers you specify
  • Wallet management — accurately crediting and debiting your wallet for every transaction, funding deposit, cashback reward, and reversal
  • KYC verification — validating your identity documents to unlock higher service tiers and generate dedicated virtual bank accounts for wallet funding
  • Sending OTPs and notifications — delivering one-time passwords via email and WhatsApp (through Termii) for login, email verification, phone verification, and password resets; sending push notifications via Firebase about transaction outcomes, auto-renewals, and account events
  • Auto-renewal execution — executing your scheduled repeat purchases for airtime, data, electricity, and cable TV on your chosen schedule and on your behalf
  • Referral and cashback programmes — tracking referral relationships, calculating commission payments, crediting bonus wallets, and managing cashback credits and 90-day expiry cycles
  • AI-powered customer support — routing your support enquiries to our AI assistant and, where needed, escalating to a human support agent
  • Fraud prevention and security — detecting unusual activity, logging authentication events, enforcing daily spending limits, managing wallet freeze capability, and maintaining a phone number blacklist
  • Legal and regulatory compliance — meeting our obligations under CBN anti-money laundering (AML) directives, the NDPR, the NDPA, and other applicable Nigerian laws
  • Platform improvement — analysing aggregated, anonymised transaction patterns and support data to improve service reliability and user experience

3.

Legal Basis for Processing

Under the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, we process your personal data on the following legal bases:

  • Contractual necessity — processing is required to deliver the services you registered for, including airtime, data, electricity, cable TV, exam pins, wallet funding, auto-renewal, and referral programmes
  • Legitimate interests — fraud detection, security audit logging, and anonymised platform analytics, where our interests do not override your rights
  • Legal obligation — compliance with CBN anti-money laundering requirements, KYC obligations, and financial record-keeping mandated by Nigerian law
  • Consent — for optional features such as marketing communications and optional profile fields such as gender and avatar photograph. You may withdraw consent at any time without affecting the lawfulness of processing already carried out

4.

Third Parties We Share Your Data With

We share personal information only where necessary to deliver our services. We do not sell your data to any third party.

Service Delivery
- VTpass — our primary VTU provider. Your phone number, meter number, or smart card number is transmitted to VTpass to fulfil every airtime, data, electricity, cable TV, and exam pin purchase.

Payment and Wallet Funding
- Paystack and Flutterwave — payment gateways used to process card and bank transfer wallet funding. These providers handle your payment card details under their own PCI-DSS-compliant controls; we do not receive or store card numbers.
- PaymentPoint (Palmpay, Opay) and Monnify — providers that generate dedicated virtual bank accounts for your wallet. Your name and, for higher KYC tiers, your BVN or NIN are shared as required for virtual account creation.

Communication
- Termii — our OTP and WhatsApp message delivery provider. Your phone number is transmitted to Termii solely to deliver one-time passwords. Termii does not use your data for any other purpose.
- Firebase (Google) — used to deliver push notifications to your mobile device. Your device notification token is shared with Firebase for this purpose only.

AI Support
- OpenAI, Google (Gemini), and Anthropic (Claude) — our support assistant may transmit the content of your support messages to one or more of these AI providers to generate a response. We do not transmit personally identifiable information such as your full name, NIN, BVN, or financial data to AI providers.

Legal and Regulatory Authorities
- We may disclose your information where required by Nigerian law, court order, or at the lawful request of authorised regulatory or law enforcement bodies.

We contractually require all third-party service providers to handle your data securely, to use it only for the purposes we specify, and to comply with applicable data protection law.


5.

Data Security

We implement multiple layers of security to protect your personal information:

  • OTP codes — one-time passwords are never stored in plaintext. Only the SHA-256 hash of each OTP is persisted; the raw code is discarded immediately after delivery and cannot be recovered.
  • Transaction PIN — your 4-digit transaction PIN is hashed using PBKDF2-SHA256 (Django's industry-standard password hasher) and is never stored, displayed, or recoverable in its original form.
  • KYC identifiers — sensitive identifiers (BVN, NIN) stored in connection with virtual account creation are encrypted at rest.
  • Rate limiting — OTP delivery is rate-limited to prevent brute-force attacks: a maximum of 5 codes per hour per user per purpose, with a 60-second cooldown between each request.
  • Authentication event logging — every login, logout, password change, password reset, and OTP event is logged with IP address and device user agent for security auditing and fraud investigation.
  • Wallet freeze — we can immediately freeze a wallet suspected of unauthorised use, preventing any further debits until the matter is resolved.
  • Phone number blacklisting — numbers identified as fraudulent are immediately blocked across the entire platform.
  • Daily spending limits — configurable daily airtime purchase limits reduce exposure in the event of a compromised account.
  • HTTPS — all data transmitted between your device and our servers is encrypted using TLS.

Despite these measures, no system is perfectly secure. We cannot guarantee the absolute security of information transmitted to or stored on our platform, and we encourage you to use a strong, unique password and to keep your transaction PIN confidential.


6.

Data Retention

We retain your personal information for as long as your account is active and for such additional period as is required by law:

  • Account and identity data — retained for the duration of your account and for up to 7 years after account closure, as required for financial record-keeping under Nigerian law.
  • Transaction records — retained indefinitely, as required by CBN anti-money laundering regulations.
  • OTP records — expired and used OTP codes are automatically purged by a scheduled background task; security logs of OTP events (without the code itself) are retained for 12 months.
  • Authentication event logs — retained for 12 months for security auditing and fraud investigation.
  • KYC documents — retained for the duration of the account plus 7 years, as mandated by Nigerian financial regulations.
  • Support conversations and tickets — retained for 12 months after resolution.
  • Cashback and bonus wallet records — retained permanently as part of the transaction ledger; cashback credits that are not redeemed expire automatically after 90 days and the balance is written off, but the ledger record is retained for auditing.

7.

Your Rights Under the NDPR and NDPA

As a data subject under the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, you have the following rights:

  • Right to access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may request correction of personal data that is inaccurate or incomplete.
  • Right to erasure — you may request deletion of your account and personal data. Deletion is request-based only: it cannot be performed instantly by yourself, but you can submit a deletion request at any time from within the app (Settings) or by emailing us at hello@creddatasub.com. Once we receive a valid request, we will delete your account and associated personal data within 90 days, subject to our legal retention obligations (we cannot delete data we are required by law to keep, such as transaction and KYC records — see Section 6, Data Retention).
  • Right to data portability — you may request your transaction history and core account data in a structured, machine-readable format.
  • Right to object — you may object to processing that relies on our legitimate interests, unless we can demonstrate compelling grounds that override your rights.
  • Right to withdraw consent — for any processing based on your consent (such as marketing), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint — if you believe your data protection rights have been violated, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

To exercise any of these rights, please contact us using the details in Section 11. We will respond within 30 days. We may require identity verification before processing your request.


8.

Cookies and Device Identifiers

Our web platform uses the following cookies and similar technologies:

  • Session cookies — required to keep you logged in during a browsing session. These are deleted when you close your browser.
  • CSRF cookies — protect against cross-site request forgery attacks. These are a mandatory security control and cannot be disabled.
  • Analytics — we may use anonymised, aggregated analytics to understand how users navigate the platform and to identify areas for improvement. These analytics do not identify you personally.

Our mobile application uses your device's push notification identifier (Firebase token) to deliver transaction confirmations, auto-renewal updates, and account notifications directly to your device. You may disable push notifications through your device settings at any time; doing so will not affect your ability to use the platform but will mean you no longer receive real-time transaction alerts.


9.

Children's Privacy

Cred Data Sub is a financial technology platform intended exclusively for persons who are 18 years of age or older. We do not knowingly collect, process, or store personal information from children under the age of 18.

If you believe that a minor has registered on our platform or that we hold personal information about a child, please contact us immediately at hello@creddatasub.com. Upon receiving such a report, we will investigate and, where confirmed, delete the relevant account and data without undue delay.


10.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify you via the email address associated with your account or via an in-app notification, where the change is significant

Your continued use of the platform after the effective date of any update constitutes your acceptance of the revised Policy. If you do not agree with any change, you should discontinue use of the platform and contact us to close your account.


11.

How to Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact us:

Cred Data Sub
Email: hello@creddatasub.com
Phone: +234 800 000 0000

You also have the right to escalate a complaint to the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng if you believe your rights under the NDPR or NDPA have been violated after raising the matter with us first.

© 2026 Cred Data Sub. All rights reserved.

Privacy Policy Terms of Service Home