Privacy Policy
QoinPay Technologies · Last updated 1 August 2026
This policy explains how QoinPay Technologies ("QoinPay", "we", "us") collects, uses, discloses and protects personal data when you use our websites, merchant and government portals, hosted checkout and APIs (together, the "Services"). It is written to comply with the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act, and is aligned with the EU General Data Protection Regulation (GDPR) for data subjects in the European Economic Area and the United Kingdom.
1. Who we are and our roles
For visitors to our websites and applicants to our merchant programme, QoinPay is a data controller. When we process payment data on behalf of a merchant, bank or government body using our platform, we generally act as a data processor (or "data administrator" under the NDPR) on that customer's instructions, and their own privacy notice governs how your data is used. Our headquarters are at 14 Adeola Odeku Street, Victoria Island, Lagos, Nigeria, with offices in London, Singapore and Dubai.
2. Data we collect
Data you provide
Account registration details (name, email, business information), know-your-customer (KYC) documentation, contact-form submissions and support correspondence.
Payment data
When you pay through our hosted checkout we process the transaction amount, currency, reference, your email address for receipts, and the payment credentials required by the selected method. Card numbers are tokenized on capture; we retain only truncated identifiers and network tokens, never full card numbers in plaintext.
Data collected automatically
IP address (used, among other purposes, to detect your country and present locally relevant payment methods), device and browser characteristics, and logs of API and portal activity retained for security and audit purposes.
3. Why we process data (lawful bases)
We process personal data only where a lawful basis applies:
Contract — to provide the Services, process payments and settle funds. Legal obligation — KYC, anti-money-laundering screening, sanctions checks, tax and record-keeping duties. Legitimate interests — fraud prevention, platform security, service improvement and business communications, always balanced against your rights. Consent — for optional marketing communications, which you may withdraw at any time.
4. Sharing and disclosure
We share data with: the banks, card schemes and payment gateways needed to execute a transaction; the merchant or government body you are paying; regulated identity and fraud-screening providers; our audited infrastructure sub-processors; and regulators, law enforcement or courts where legally required. We do not sell personal data, and we never share it for third-party advertising.
5. International transfers
Where data leaves Nigeria, the EEA or the UK, we rely on appropriate safeguards — adequacy decisions where available, standard contractual clauses, and NDPR-compliant transfer conditions — and we offer in-country processing options to customers in jurisdictions with data-residency requirements.
6. Retention
Transaction and KYC records are retained for the periods required by financial regulation (typically five to seven years), after which they are deleted or irreversibly anonymized. Account data is retained while your account is active and for a limited period afterwards. Security logs are retained for at least twelve months.
7. Your rights
Subject to law, you may request access to, correction of, or deletion of your personal data; object to or restrict processing; request portability of data you provided; and withdraw consent where processing is based on it. To exercise any right, email privacy@qoinpay.com. We respond within the statutory period (30 days under GDPR; NDPR timelines where applicable). You may also lodge a complaint with the Nigeria Data Protection Commission or your local supervisory authority.
8. Security
Personal data is protected with encryption in transit (TLS 1.2+) and at rest (AES-256-GCM), strict access controls, tokenization of payment credentials and continuous monitoring, under our PCI DSS 4.0, ISO 27001 and SOC 2 Type II programmes. See our Security & Compliance page for detail.
9. Cookies
We use strictly necessary cookies for session management and CSRF protection. We do not use third-party advertising or cross-site tracking cookies on our Services.
10. Changes and contact
We will post any material change to this policy here and, where required, notify you directly. Questions and requests: our Data Protection Officer at privacy@qoinpay.com, or by post to QoinPay Technologies, 14 Adeola Odeku Street, Victoria Island, Lagos, Nigeria.