FINTACLOUD PRIVACY POLICY
1Our Commitment to Privacy
FINTACLOUD is designed to provide trusted digital infrastructure for protected commerce. Trust requires more than protecting payments. It also requires protecting the information entrusted to us by Buyers, Sellers, Merchants, and other users. This Privacy Policy explains how FINTACLOUD (“FINTACLOUD,” “we,” “us,” or “our”) collects, uses, stores, shares, secures, tokenizes, and otherwise processes personal data when you use the FINTACLOUD website, applications and dashboards, protected transaction links, merchant services, identity-verification features, payment and settlement workflows, delivery and inspection functionality, dispute-resolution services, customer support, and other services that reference this Privacy Policy. We seek to process personal data lawfully, fairly, transparently, securely, and only to the extent reasonably necessary for legitimate business, contractual, security, and regulatory purposes.
2Data Protection Framework
FINTACLOUD processes personal data in accordance with applicable Nigerian data-protection requirements, including the Nigeria Data Protection Act 2023 and applicable regulations, directives, guidance, and requirements issued by the Nigeria Data Protection Commission (“NDPC”). Depending on the particular processing activity, FINTACLOUD may act as a data controller or may process information in connection with services provided by another controller or processor. Our data-protection approach is based on lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; confidentiality; integrity; availability; accountability; and appropriate protection of data-subject rights.
3Information We Collect
Information collected depends on how you interact with FINTACLOUD.
3.1 Account Information
full name email address telephone number username and account identifier account type and authentication information business name and registration information merchant profile information account preferences
FINTACLOUD Privacy Policy • August 30, 2026
FINTACLOUD does not seek to require more information than reasonably necessary for the applicable account or service.
4Identity Verification and KYC/KYB Data
FINTACLOUD may be required to verify the identity of Buyers, Sellers, Merchants, directors, beneficial owners, or other users. Depending on verification level and applicable requirements, verification may involve:
Bank Verification Number (BVN) National Identification Number (NIN) Virtual NIN (vNIN) government-issued identity information date of birth telephone number facial or biometric verification information where legally permitted bank-account information Corporate Affairs Commission (CAC) information company registration information directors or beneficial owners business address other information required for KYC, KYB, fraud prevention, AML, or regulatory compliance
FINTACLOUD may use approved third-party identity-verification providers to conduct some or all verification procedures.
5Tokenized Identity Data Handling
5.1 Our Tokenization Principle
FINTACLOUD seeks to reduce unnecessary exposure of sensitive identity information. Where supported by our verification architecture, sensitive identifiers are handled using tokenization, reference identifiers, or similar privacy-enhancing mechanisms. Tokenization means that a sensitive identifier can be replaced within FINTACLOUD’s operational systems by a non-sensitive reference value or token. Instead of repeatedly storing and transmitting a user’s raw NIN or BVN throughout FINTACLOUD’s application environment, an approved identity-verification service may verify the identifier and return a verification result, reference, token, identity-match status, selected verified attributes, or another non-raw identifier. FINTACLOUD can then use that reference for permitted operational purposes without repeatedly exposing the underlying identity number.
5.2 Simplified Tokenized Verification Flow
User provides identity information → Secure verification request → Approved identity-verification provider → Authorized identity source → Verification result/token/reference → FINTACLOUD stores the minimum verification information reasonably necessary. FINTACLOUD Privacy Policy • August 30, 2026
6Tokenization Is Not the Same As Anonymization
Tokenization does not necessarily make information anonymous. A token may still relate to an identifiable person, particularly where FINTACLOUD, an identity provider, or another authorized party can associate the token with the underlying identity. Accordingly, FINTACLOUD treats tokenized personal data as protected information where applicable. Tokenization is used as one layer of a broader data-protection strategy intended to reduce unnecessary storage of raw identifiers, reduce exposure during routine processing, limit internal access, reduce the consequences of certain security incidents, and separate identity verification from ordinary transaction processing where practicable.
7Raw NIN and BVN Handling
FINTACLOUD follows a data-minimization approach to NIN, BVN, and similar identifiers. Where our technical architecture permits, FINTACLOUD seeks to avoid retaining complete raw identity numbers after the verification purpose has been completed. We may instead retain:
verification status verification date verification provider verification reference tokenized identifier identity-match result KYC level risk status information required to demonstrate that appropriate verification occurred
If raw identity information must be processed temporarily to perform a verification request, we seek to limit its use to the verification purpose and protect it using appropriate technical and organizational safeguards. We will not represent that raw identity information is never processed where the technical operation of a verification service requires such processing.
8Payment and Financial Information
When you fund a transaction, receive settlement, request a withdrawal, or use another paymentrelated service, information may include:
transaction amount payment status and reference bank name account name and account number where necessary payment method settlement destination transaction date and time refund and chargeback information FINTACLOUD Privacy Policy • August 30, 2026
other financial transaction metadata
Payment card information may be collected and processed directly by authorized Payment Providers. Where payment credentials are collected through a Payment Provider’s hosted infrastructure, FINTACLOUD may receive a payment token, transaction reference, authorization status, or limited card metadata rather than complete payment-card credentials. FINTACLOUD does not intentionally store card security codes such as CVV/CVC values after payment authorization. FINTACLOUD may use different authorized Payment Providers or financial institutions for different transactions or services. Information reasonably necessary to create payment instructions or virtual accounts, verify or reconcile payments, process settlement or withdrawals, issue refunds or reversals, prevent fraud, or comply with applicable requirements may be transmitted to the Payment Provider selected for the applicable transaction. Where virtual accounts or bank-transfer collection methods are used, FINTACLOUD may process an assigned virtual-account number, Payment Provider transaction identifier, payer or source-account information made available by the Payment Provider, payment-verification status, reconciliation information, and related payment-event metadata.
9Transaction Information
FINTACLOUD may process Buyer and Seller identifiers, product or service descriptions, transaction value, delivery charges, transaction status and timestamps, inspection periods, delivery status, settlement status, refund information, transaction messages, dispute status, and other information necessary to operate a protected transaction. Transaction records may be retained where reasonably necessary for accounting, fraud prevention, dispute resolution, regulatory compliance, security, or legal obligations.
10Delivery and Logistics Information
Where delivery tracking is enabled, FINTACLOUD may process delivery address, courier or logistics provider, tracking number, shipment status, delivery confirmation, delivery timestamp, recipient confirmation, proof of delivery, and related logistics information. Third-party logistics providers may independently process information under their own privacy policies. Where integrated delivery services are used, FINTACLOUD may transmit the minimum information reasonably necessary to selected logistics providers to obtain delivery quotes, create or manage shipments, arrange pickup, track delivery, verify delivery events, cancel shipments, process returns, or support transaction disputes.
11Dispute and Evidence Data
When a dispute is opened, FINTACLOUD may collect and process evidence including:
photographs continuous unboxing videos product videos FINTACLOUD Privacy Policy • August 30, 2026
receipts and invoices screenshots and correspondence delivery documentation and courier information serial numbers, IMEI numbers, or product identifiers transaction histories written statements other evidence voluntarily submitted or reasonably required
Dispute evidence may contain personal information. Users should avoid including unnecessary personal information concerning themselves or third parties. Users should not submit another person’s NIN, BVN, payment credentials, passwords, authentication codes, or unrelated sensitive personal information as dispute evidence unless FINTACLOUD specifically requests information that may lawfully be provided for the applicable dispute.
12Device, Security, and Technical Information
We may automatically collect:
IP address device and browser type operating system session identifiers login timestamps and authentication events approximate location derived from technical information where permitted transaction-link access events security events and fraud indicators error logs application performance information
provider event identifiers, webhook or API events, payment-verification records, shipment-event records, timestamps, and related security or fraud metadata This information may be used to maintain security, detect unauthorized activity, investigate fraud, prevent abuse, diagnose technical problems, and improve Platform reliability.
13How We Use Personal Data
Provide the Service
create and manage accounts create Protected Transactions process transaction instructions manage delivery and inspection periods facilitate settlements and withdrawals provide transaction history operate merchant dashboards
Verify Identity
FINTACLOUD Privacy Policy • August 30, 2026
perform KYC and KYB verify businesses and bank-account information reduce identity fraud satisfy regulatory or Payment Provider requirements
Protect Buyers and Sellers
detect suspicious transactions prevent account takeover investigate disputes detect fraudulent evidence identify transaction abuse enforce Platform rules
Comply With Legal Requirements
comply with applicable laws and lawful regulatory requests comply with court orders perform AML or fraud investigations maintain required records cooperate with authorized law-enforcement agencies where legally required
Improve FINTACLOUD
improve fraud detection and risk models improve transaction workflows identify service problems develop new features improve Platform performance
14Lawful Bases for Processing
Depending on the activity and applicable law, FINTACLOUD may rely on contract, legal obligation, legitimate interests, or consent. Legitimate interests may include fraud prevention, cybersecurity, service security, dispute resolution, Platform improvement, enforcement of our Terms, and protection of FINTACLOUD and its users, provided those interests are not overridden by applicable data-protection rights. Where processing is based on consent, consent may be withdrawn subject to applicable law and any processing independently justified under another lawful basis.
15Who We Share Information with
FINTACLOUD does not sell personal data to advertisers or data brokers. We may disclose information where reasonably necessary to:
Payment Providers and financial institutions for payment instructions, virtual accounts, collection, payment verification and reconciliation, settlement, withdrawals, refunds, reversals, chargebacks, fraud prevention, and compliance identity-verification providers for KYC, KYB, identity matching, fraud prevention, and account verification FINTACLOUD Privacy Policy • August 30, 2026
logistics providers for delivery quotes, shipment creation, pickup, delivery, tracking, delivery verification, proof of delivery, returns, and related dispute support cloud and technology providers for hosting, security, communications, storage, analytics, and technical operations professional advisers such as lawyers, auditors, accountants, compliance consultants, and dataprotection professionals regulators and law enforcement where required or permitted by law parties involved in a legitimate merger, acquisition, financing, restructuring, investment, or sale, subject to appropriate safeguards
16We Do Not Sell Your Personal Data
FINTACLOUD’s business model is based on protected commerce and transaction services. It is not based on selling users’ identity information. We do not sell NIN, BVN, identity-verification information, payment information, transaction histories, dispute evidence, or other personal data to advertising companies or data brokers.
17Data Minimization
FINTACLOUD seeks to collect and retain only information reasonably necessary for defined purposes. Where practical, we may use tokens, reference identifiers, masked or truncated information, role-based access, aggregated information, and de-identified information instead of exposing complete sensitive data throughout our systems. Employees, contractors, and service providers should receive access only where reasonably necessary for their authorized functions.
18Security
Depending on the system and data involved, safeguards may include:
encryption in transit encryption at rest where appropriate tokenization access controls authentication and authorization controls password hashing audit logging and monitoring rate limiting secure application-development practices database protections backup and recovery controls fraud-detection systems security testing incident-response procedures FINTACLOUD Privacy Policy • August 30, 2026
No internet-connected system can guarantee absolute security. FINTACLOUD does not claim that a security incident can never occur. Our commitment is to implement safeguards proportionate to the nature and risk of the information we process and to continuously evaluate our security posture.
19Access to Sensitive Data
Access to sensitive identity, financial, dispute, or security information should be limited to authorized personnel and systems with a legitimate operational need. Where appropriate, FINTACLOUD may maintain records of administrative access to sensitive information. Personnel with access may be subject to confidentiality, security, and acceptable-use obligations.
20Data Retention
FINTACLOUD retains personal data only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, accounting, regulatory, fraud-prevention, security, and dispute-resolution requirements. Factors considered may include:
applicable legal requirements financial recordkeeping obligations AML/KYC requirements transaction history active disputes and potential chargebacks fraud investigations limitation periods regulatory requirements security requirements
When information is no longer reasonably required, FINTACLOUD may delete, securely destroy, de-identify, or anonymize it, subject to technical and legal limitations.
21Data-Subject Rights
Subject to applicable law, you may have rights to:
obtain information about processing request access request correction request deletion where legally applicable object to certain processing request restriction withdraw consent where applicable request portability where applicable lodge a complaint with the Nigeria Data Protection Commission
FINTACLOUD Privacy Policy • August 30, 2026
Certain requests may be limited where retention or processing is necessary for legal obligations, fraud prevention, legal claims, transaction completion, financial records, or protection of others’ rights. FINTACLOUD may verify identity before processing a rights request.
22Automated Fraud and Risk Systems
Automated systems may consider:
transaction velocity account age verification status transaction history device information IP or security indicators delivery patterns dispute history other fraud or security indicators
Automated risk systems may result in additional verification, temporary restrictions, manual review, settlement delays, or other proportionate security measures. Where applicable law provides rights concerning decisions based solely on automated processing that produce legal or similarly significant effects, FINTACLOUD will respect those rights.
23Merchant Reputation and Trust Information
FINTACLOUD may develop merchant verification, reputation, or trust features using legitimate transaction information, including verified status, number of completed transactions, transaction success rate, merchant tenure, dispute statistics, verification level, and other appropriate trust indicators. FINTACLOUD will seek to avoid publicly displaying sensitive identity information, raw financial information, NIN, BVN, private addresses, or information unnecessary for the trust feature. Where a merchant Trust Score or similar reputation system is introduced, additional disclosures may explain how relevant information is used.
24Cookies and Similar Technologies
FINTACLOUD may use cookies, local storage, session technologies, or similar technologies for authentication, security, fraud prevention, user preferences, transaction continuity, performance monitoring, and analytics. Where legally required, optional technologies will be subject to appropriate consent controls.
25International and Cross-Border Data Transfers
Some FINTACLOUD service providers may process information outside Nigeria. Where personal data is transferred internationally, FINTACLOUD will seek to use transfer mechanisms and safeguards required by applicable Nigerian data-protection law. FINTACLOUD Privacy Policy • August 30, 2026
These may include transfers to jurisdictions providing an appropriate level of protection, contractual safeguards, legally recognized transfer mechanisms, documented transfer assessments, explicit consent where legally appropriate, or another lawful transfer basis.
26Third-Party Processors
Where required, FINTACLOUD seeks contractual and organizational safeguards requiring processors to:
process information only for authorized purposes maintain appropriate confidentiality implement appropriate security assist with applicable data-subject rights appropriately manage security incidents comply with applicable data-protection requirements delete or return information where required at the end of the processing relationship
FINTACLOUD may review relevant privacy and security practices of material processors as part of vendor management.
27Data Breaches and Security Incidents
FINTACLOUD maintains processes designed to identify, investigate, contain, document, and respond to personal-data security incidents. Where a personal-data breach triggers notification obligations under applicable law, FINTACLOUD will notify the appropriate regulatory authority and affected individuals as required. Users should promptly report suspected unauthorized account access or security incidents through FINTACLOUD’s official support or security channel.
28Children
FINTACLOUD is not intended to be used independently by persons who do not have legal capacity to enter into the applicable transaction or agreement. We do not knowingly seek to collect children’s personal data for ordinary merchant transactions without an appropriate lawful basis and protections required by applicable law.
29User Responsibilities
Users should:
use a strong password keep authentication credentials confidential avoid sharing verification codes verify transaction links before payment avoid sending NIN or BVN through unapproved messaging channels avoid placing unnecessary personal information in dispute evidence FINTACLOUD Privacy Policy • August 30, 2026
secure email and telephone accounts notify FINTACLOUD promptly of suspected unauthorized activity
FINTACLOUD will never require users to publicly post sensitive identity information.
30Changes to This Privacy Policy
We may update this Privacy Policy when our services, technologies, legal requirements, service providers, or privacy practices change. The revised policy will display an updated effective or Last Updated date. Material changes may be communicated through the Platform, email, dashboard, or another reasonable method.
31Data Protection Contact
Questions, complaints, security concerns, and data-subject requests may be submitted through FINTACLOUD’s designated privacy or support channels. Data Protection / Privacy Contact: FINTACLOUD Email: privacy@fintacloud.com Customer Support: support@fintacloud.com General Inquiries: info@fintacloud.com Website: fintacloud.com Where required by applicable law or regulatory guidance, FINTACLOUD may also publish contact information for a designated Data Protection Officer or other responsible privacy representative.
32Complaints to the Nigeria Data Protection Commission
If you believe your personal data has been processed in violation of applicable Nigerian data-protection law, you may have the right to submit a complaint to the Nigeria Data Protection Commission (NDPC). We encourage users to contact FINTACLOUD first so that we have an opportunity to investigate and address the concern. Nothing in this Privacy Policy limits a data subject’s right to contact an appropriate regulatory authority.
33Privacy By Design
FINTACLOUD seeks to make privacy part of the architecture of protected commerce:
Collect less — request only information reasonably necessary. Tokenize sensitive identifiers — use verification references or tokens instead of repeatedly exposing raw identity numbers where possible. Separate identity from transactions — avoid unnecessary distribution of sensitive identity information across transaction systems. Restrict access — limit sensitive information to authorized personnel and systems with a legitimate need. Protect data in transit and storage — use appropriate encryption and security controls based on risk. FINTACLOUD Privacy Policy • August 30, 2026
Retain only when necessary — delete, de-identify, anonymize, or securely dispose of information when retention is no longer justified. Design for accountability — maintain appropriate records and controls to support compliance, security investigations, and data-subject rights.
34. TOKENIZED DATA — PLAIN-LANGUAGE SUMMARY What happens when I verify my identity? FINTACLOUD may securely send the information required for verification to an approved identity-verification provider. Does every FINTACLOUD system need my full NIN or BVN? Our objective is no. Where technically supported, we seek to use a verification token, reference, status, or other limited result rather than repeatedly storing or transmitting the complete identity number throughout our systems. What is a token? A token is a substitute reference used in place of sensitive information for certain processing activities. For illustration, instead of an operational system repeatedly using “NIN: 12345678901,” it may use a reference such as “Identity Reference: KYC-7F29X4.” This example does not represent FINTACLOUD’s actual token format. Does tokenization mean my information is anonymous? Not necessarily. If a token can ultimately be associated with you through authorized systems, it may still constitute personal data and FINTACLOUD will treat it accordingly. Why use tokenization? Because information that does not need to be repeatedly exposed should not be repeatedly exposed. Tokenization helps reduce the amount of sensitive identity information circulating through ordinary transaction systems.
35Our Privacy Promise
FINTACLOUD is being built around a simple principle: Trust should protect both your money and your identity. We seek to collect only what we need, protect what we collect, minimize exposure of sensitive identifiers, use tokenization where appropriate, restrict access, and process personal information only for legitimate and disclosed purposes. FINTACLOUD — Protected Commerce. Built on Trust.
FINTACLOUD Privacy Policy • August 30, 2026