Legal

Privacy Policy

Last updated: 27 June 2026

Your data is yours. We only collect what we need to run your services, we tell you plainly what that is, and we never sell it. This page is the whole story: what we hold, why we hold it, how long we keep it, and the rights you have over it under the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR). No fine print doing quiet work.

1. Who We Are

Opkip ("we", "us") operates the Opkip platform, a recurring home-services scheduling and accountability product available at opkip.com and via our mobile app. We are the data controller for personal data collected through our platforms.

For privacy enquiries or to exercise your rights, contact us at privacy@opkip.com. A Data Protection Officer will be designated prior to launch.

2. Data We Collect

We collect the following categories of personal data:

CategoryExamples
Identity & contactName, phone number, email (optional)
Account securityAccount PIN (stored as a hash, never readable), one-time codes
LocationYour country and coarse service area (neighbourhood); and, if you save a property, a precise address detail (street/building) — see §4
Plans & contentPlan titles/descriptions, notes, ratings, service requests, invites, and messages you submit
Provider dataIf you onboard as a provider: business name, description, coverage areas, rates, WhatsApp number, and a government/business identity document type and number for verification. For roles with unsupervised home access, also a criminal background check result and a guarantor or reference’s name and contact details.
Device & technicalA device signal/fingerprint, IP address, app/usage data, and audit logs of sensitive actions
Derived safety dataHashed phone numbers and hashed device signals used for abuse prevention and ban enforcement

We do not knowingly collect data from anyone under 18. Opkip is currently in an early phase where payment for services happens directly between you and your provider, outside the platform — we do not yet collect card, wallet, or escrow data. We'll update this policy before that changes.

3. Why We Collect It (Lawful Basis)

We process your data on the following lawful bases under the NDPA:

  • ContractTo provide the service you signed up for — matching, scheduling, delivery confirmation.
  • Legal obligationResponding to lawful requests and regulatory compliance.
  • Legitimate interestsProvider verification, fraud/abuse prevention, security, and audit logging.
  • ConsentTransactional and optional communications, you can withdraw consent at any time.

4. Your Address Is Specially Protected

Your saved address detail is the most sensitive data we hold, and we minimise its exposure:

  • Provider matching uses only the coarse area, never the street address.
  • The street address is never shown in the marketplace, to unassigned providers, or to other clients.
  • It is released only to the single provider assigned to your plan, only shortly before the scheduled delivery window, and is withdrawn once the cycle settles.

5. Who We Share It With

We do not sell your personal data. We share it only with:

  • The other party to your plan, limited, need-to-know (e.g. your first name to the assigned provider; the gated address near the delivery window).
  • Supabase, database and authentication infrastructure.
  • WhatsApp / SMS provider (Twilio), OTP delivery and notifications.
  • Legal authorities, when required by law, court order, or regulatory demand — see §8.

All third-party processors act on our instructions under appropriate agreements.

6. Data Retention

We keep personal data only as long as needed for the purposes above and to meet legal obligations:

  • Financial records (once payments move through the platform): 7 years
  • Audit logs of admin actions: 7 years
  • Auth event logs (login, OTP): 1 year
  • General application logs: 90 days
  • Delivery codes: deleted 48 hours after dispatch, or immediately on use

When you delete your account, your personal data is anonymised immediately; logs store hashed, not plaintext, phone numbers.

7. Security

We use technical and organisational measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, bcrypt-hashed PINs, role/row-level access controls, rate limiting, content sanitisation, and audit logging.

No system is completely immune to risk. If a breach occurs that is likely to affect your rights, we will notify you and the relevant authority for your location (see §8 below) within 72 hours of becoming aware of it, as required by law.

8. Your Rights, and Who Regulates Us Where You Are

Subject to law, you may request to:

  • Access, request a copy of personal data we hold about you
  • Correct inaccurate data
  • Delete your data (subject to legal retention obligations)
  • Restrict or port your data, receive it in a machine-readable format
  • Object to certain processing, and withdraw consent

Opkip operates beyond Nigeria, and the regulator you may complain to depends on where you are. We apply the rights above everywhere by default, regardless of which specific law technically applies to you:

If you are inThe relevant authority is
NigeriaNigeria Data Protection Commission (NDPC), under the NDPA 2023 / NDPR
United KingdomInformation Commissioner's Office (ICO), under UK GDPR / the Data Protection Act 2018
GhanaData Protection Commission (DPC), under the Data Protection Act, 2012 (Act 843)
KenyaOffice of the Data Protection Commissioner (ODPC), under the Data Protection Act, 2019
United StatesNo single federal authority — state-level law may apply (e.g. California’s CPPA under the CCPA/CPRA); the FTC addresses general consumer-protection complaints
European Union / EEAYour national Data Protection Authority, under the GDPR — applies if you’re in the EU/EEA even though we don’t currently have an EU-denominated market
Anywhere elseContact privacy@opkip.com directly; we’ll apply the substance of the rights above regardless of a formal local regulator

To exercise these rights, email privacy@opkip.com. We will verify your identity before acting on any request.

9. Cookies

Our web app uses session cookies for authentication only (httpOnly, Secure, SameSite, not accessible to JavaScript). We do not use advertising, marketing, or tracking cookies, and we do not load third-party analytics scripts.

10. Law Enforcement & Legal Disclosure

We may preserve, access, and disclose data to comply with a valid legal process or lawful request, to enforce our Terms, to address fraud/security, or to protect the rights or safety of Opkip, our users, or the public (including to prevent imminent harm). We verify the legal basis, disclose the minimum necessary, and log every disclosure.

11. International Transfers

Our infrastructure and core team are based in Nigeria, so data from users anywhere is typically processed there and by our hosting/SMS sub-processors. Where that means transferring your data across a border — including from the UK, Ghana, Kenya, the US, or the EU/EEA into Nigeria — we use safeguards consistent with both the NDPA and, where applicable, your home jurisdiction's transfer rules (e.g. UK GDPR's transfer safeguard requirements, or GDPR Standard Contractual Clauses for EU/EEA users).

12. Children

Opkip is not intended for users under 18. We do not knowingly collect personal data from children. If you believe we have data about a child, contact us immediately at privacy@opkip.com.

13. Changes to This Policy

We may update this policy and will notify you of material changes in-app or by other reasonable means.

14. Contact

For any privacy-related questions, requests, or complaints, contact us:

Opkip

Email: privacy@opkip.com

If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority for your location — see the table in §8 above. For Nigeria, that's the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.