Legal
Privacy Policy
Last updated: 27 June 2026
Your data is yours. We only collect what we need to run your services, we tell you plainly what that is, and we never sell it. This page is the whole story: what we hold, why we hold it, how long we keep it, and the rights you have over it under the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR). No fine print doing quiet work.
1. Who We Are
Opkip ("we", "us") operates the Opkip platform, a recurring home-services scheduling and accountability product available at opkip.com and via our mobile app. We are the data controller for personal data collected through our platforms.
For privacy enquiries or to exercise your rights, contact us at privacy@opkip.com. A Data Protection Officer will be designated prior to launch.
2. Data We Collect
We collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity & contact | Name, phone number, email (optional) |
| Account security | Account PIN (stored as a hash, never readable), one-time codes |
| Location | Your country and coarse service area (neighbourhood); and, if you save a property, a precise address detail (street/building) — see §4 |
| Plans & content | Plan titles/descriptions, notes, ratings, service requests, invites, and messages you submit |
| Provider data | If you onboard as a provider: business name, description, coverage areas, rates, WhatsApp number, and a government/business identity document type and number for verification. For roles with unsupervised home access, also a criminal background check result and a guarantor or reference’s name and contact details. |
| Device & technical | A device signal/fingerprint, IP address, app/usage data, and audit logs of sensitive actions |
| Derived safety data | Hashed phone numbers and hashed device signals used for abuse prevention and ban enforcement |
We do not knowingly collect data from anyone under 18. Opkip is currently in an early phase where payment for services happens directly between you and your provider, outside the platform — we do not yet collect card, wallet, or escrow data. We'll update this policy before that changes.
3. Why We Collect It (Lawful Basis)
We process your data on the following lawful bases under the NDPA:
- ContractTo provide the service you signed up for — matching, scheduling, delivery confirmation.
- Legal obligationResponding to lawful requests and regulatory compliance.
- Legitimate interestsProvider verification, fraud/abuse prevention, security, and audit logging.
- ConsentTransactional and optional communications, you can withdraw consent at any time.
4. Your Address Is Specially Protected
Your saved address detail is the most sensitive data we hold, and we minimise its exposure:
- Provider matching uses only the coarse area, never the street address.
- The street address is never shown in the marketplace, to unassigned providers, or to other clients.
- It is released only to the single provider assigned to your plan, only shortly before the scheduled delivery window, and is withdrawn once the cycle settles.
5. Who We Share It With
We do not sell your personal data. We share it only with:
- The other party to your plan, limited, need-to-know (e.g. your first name to the assigned provider; the gated address near the delivery window).
- Supabase, database and authentication infrastructure.
- WhatsApp / SMS provider (Twilio), OTP delivery and notifications.
- Legal authorities, when required by law, court order, or regulatory demand — see §8.
All third-party processors act on our instructions under appropriate agreements.
6. Data Retention
We keep personal data only as long as needed for the purposes above and to meet legal obligations:
- Financial records (once payments move through the platform): 7 years
- Audit logs of admin actions: 7 years
- Auth event logs (login, OTP): 1 year
- General application logs: 90 days
- Delivery codes: deleted 48 hours after dispatch, or immediately on use
When you delete your account, your personal data is anonymised immediately; logs store hashed, not plaintext, phone numbers.
7. Security
We use technical and organisational measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, bcrypt-hashed PINs, role/row-level access controls, rate limiting, content sanitisation, and audit logging.
No system is completely immune to risk. If a breach occurs that is likely to affect your rights, we will notify you and the relevant authority for your location (see §8 below) within 72 hours of becoming aware of it, as required by law.
8. Your Rights, and Who Regulates Us Where You Are
Subject to law, you may request to:
- Access, request a copy of personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to legal retention obligations)
- Restrict or port your data, receive it in a machine-readable format
- Object to certain processing, and withdraw consent
Opkip operates beyond Nigeria, and the regulator you may complain to depends on where you are. We apply the rights above everywhere by default, regardless of which specific law technically applies to you:
| If you are in | The relevant authority is |
|---|---|
| Nigeria | Nigeria Data Protection Commission (NDPC), under the NDPA 2023 / NDPR |
| United Kingdom | Information Commissioner's Office (ICO), under UK GDPR / the Data Protection Act 2018 |
| Ghana | Data Protection Commission (DPC), under the Data Protection Act, 2012 (Act 843) |
| Kenya | Office of the Data Protection Commissioner (ODPC), under the Data Protection Act, 2019 |
| United States | No single federal authority — state-level law may apply (e.g. California’s CPPA under the CCPA/CPRA); the FTC addresses general consumer-protection complaints |
| European Union / EEA | Your national Data Protection Authority, under the GDPR — applies if you’re in the EU/EEA even though we don’t currently have an EU-denominated market |
| Anywhere else | Contact privacy@opkip.com directly; we’ll apply the substance of the rights above regardless of a formal local regulator |
To exercise these rights, email privacy@opkip.com. We will verify your identity before acting on any request.
9. Cookies
Our web app uses session cookies for authentication only (httpOnly, Secure, SameSite, not accessible to JavaScript). We do not use advertising, marketing, or tracking cookies, and we do not load third-party analytics scripts.
10. Law Enforcement & Legal Disclosure
We may preserve, access, and disclose data to comply with a valid legal process or lawful request, to enforce our Terms, to address fraud/security, or to protect the rights or safety of Opkip, our users, or the public (including to prevent imminent harm). We verify the legal basis, disclose the minimum necessary, and log every disclosure.
11. International Transfers
Our infrastructure and core team are based in Nigeria, so data from users anywhere is typically processed there and by our hosting/SMS sub-processors. Where that means transferring your data across a border — including from the UK, Ghana, Kenya, the US, or the EU/EEA into Nigeria — we use safeguards consistent with both the NDPA and, where applicable, your home jurisdiction's transfer rules (e.g. UK GDPR's transfer safeguard requirements, or GDPR Standard Contractual Clauses for EU/EEA users).
12. Children
Opkip is not intended for users under 18. We do not knowingly collect personal data from children. If you believe we have data about a child, contact us immediately at privacy@opkip.com.
13. Changes to This Policy
We may update this policy and will notify you of material changes in-app or by other reasonable means.
14. Contact
For any privacy-related questions, requests, or complaints, contact us:
Opkip
Email: privacy@opkip.com
If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority for your location — see the table in §8 above. For Nigeria, that's the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.