1.Who we are and what this policy covers
DataGrid (“DataGrid”, “we”, “us”, or “our”) provides digital airtime, data, bill-payment, wallet, reseller, scheduling, support, and receipt services in Nigeria. This Privacy Policy explains how we process personal information when you visit our website, use our progressive web application, create an account, sign in with Google, fund a wallet, purchase a service, use our reseller tools, or contact support.
DataGrid is responsible for the personal information described in this policy. Privacy questions and data-rights requests may be sent to privacy@datagrid.ng.
2.Google sign-in data
When you choose “Continue with Google”, Google authenticates you and provides DataGrid with the minimum account information needed to identify and sign you in.
DataGrid requests only the OpenID Connect scopes openid, email, and profile. We use this information solely to authenticate you, link your Google identity to the DataGrid account secured by your verified Nigerian phone number, display basic profile information, prevent account abuse, and support account recovery.
- Information received: your stable Google account identifier (sub), verified email address, display name, and profile image when Google supplies one.
- Information not requested: your Google password, Gmail messages, Google Drive files, contacts, calendar, photos, payment data, or other Google product content.
- DataGrid does not sell Google user data, use it for advertising, or permit humans to read private Google product content. We do not request access to such content.
- OAuth state, nonce, and PKCE verification values are short-lived security data and expire after approximately ten minutes.
- You may stop using Google sign-in through your Google Account’s third-party connections page. Revoking Google access prevents future Google authentication but does not itself delete records DataGrid must retain; use the deletion process below for that.
3.Other information we collect
The information we process depends on the features you use. We limit collection to information reasonably needed to operate, secure, and improve the service.
- Account and authentication data: Nigerian phone number, OTP verification records, encrypted or hashed PIN credentials, name, email, role, referral relationship, account status, and session information.
- Transaction and wallet data: service purchased, recipient number, network or biller, amount, wallet movements, provider references, order status, receipts, refund records, beneficiaries, and scheduled top-ups.
- Payment and compliance data: funding method, payment-provider references, virtual-account details, and optional identity or KYC information when required for a feature or by law.
- Support and communications data: messages, disputes, notifications, support tickets, and information you choose to provide when requesting help.
- Technical and security data: IP address, device or browser information, timestamps, diagnostics, audit events, and fraud-prevention signals.
4.How and why we use information
We process information to perform our contract with you, comply with legal obligations, protect legitimate security and operational interests, and obtain consent where required.
- Create, authenticate, secure, and maintain your account.
- Process wallet funding, airtime, data, electricity, cable, exam PIN, transfer, reseller, and scheduled transactions.
- Detect fraud, prevent abuse, enforce limits, investigate disputes, and maintain reliable audit trails.
- Provide receipts, notifications, customer support, service status, refunds, and account recovery.
- Meet accounting, tax, telecommunications, anti-fraud, consumer-protection, data-protection, and other lawful requirements.
- Measure reliability and improve user-facing functionality without selling personal information.
6.Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described here, including service delivery, security, fraud prevention, dispute resolution, accounting, regulatory obligations, and the establishment or defence of legal claims.
Google profile and linking information is retained while your Google identity remains linked to an active DataGrid account. Session cookies ordinarily expire after fourteen days; OAuth verification cookies expire after approximately ten minutes. Transaction, wallet, receipt, KYC, dispute, and audit records may be retained after account closure when law, fraud controls, financial reconciliation, or legitimate claims require it.
To request account deletion or removal of your Google link, email privacy@datagrid.ng from your registered email address or contact support from your authenticated account. Include your registered phone number and state whether you want Google unlinked or the entire account deleted. We may verify your identity before acting. We will delete or anonymise information that is no longer required and explain any lawful retention that applies.
7.Your privacy rights
Subject to the Nigeria Data Protection Act 2023 and other applicable law, you may have rights concerning your personal information.
- Be informed about processing and request access to personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion, restriction, objection, or data portability where the relevant legal conditions apply.
- Withdraw consent where processing depends on consent, without affecting earlier lawful processing.
- Request human review where a significant decision is made solely through automated processing.
- Complain to DataGrid or lodge a complaint with the Nigeria Data Protection Commission.
8.Security
We use administrative, technical, and organisational safeguards designed to protect personal information. These include encrypted session cookies, server-side OAuth processing, signed Google-token verification, hashed PINs and OTPs, access controls, security headers, audit records, and restricted administrative access.
No internet service can guarantee absolute security. Keep your phone, OTPs, PIN, recovery access, API keys, and transaction tokens private, and notify support promptly if you suspect unauthorised activity.
10.Service providers and international transfers
Some providers may process information outside Nigeria. Where personal information is transferred internationally, we use applicable contractual, legal, and organisational safeguards and limit transfers to what is necessary for the stated purpose.
11.Children
DataGrid is not directed to children who cannot lawfully agree to these services. If you are below the age of legal capacity, use DataGrid only with the involvement and permission of a parent or legal guardian. Contact us if you believe a child’s information was provided without appropriate authority.
12.Changes and contact
We may update this policy to reflect changes in the service, law, providers, or security practices. The revised policy will be posted at this permanent URL with a new effective date. Material changes may also be communicated in the application. Questions, complaints, access requests, and deletion requests may be sent to privacy@datagrid.ng.
