Last updated 29 August 2026. Have a qualified lawyer review this before you rely on it, and check it against the Nigeria Data Protection Act obligations that apply to you.
Your name, email, username and optionally your phone number. Transaction records, order history and support conversations. Technical data such as IP address and sign-in times, which we keep because it is how account takeover is detected.
We never see or store your bank card details — funding is by transfer to a dedicated account number issued by our payment provider. Passwords are stored only as a one-way hash and cannot be read by us or anyone else.
Account details a vendor uploads for delivery are encrypted at rest. They are decrypted only when the buyer who paid for that unit opens their order.
To run your account, complete transactions, hold escrow, resolve disputes, prevent fraud, and meet legal obligations.
Our payment provider, to issue your funding account and process transfers. Our SMS provider, for number verification orders. Law enforcement, where we are legally required. Nobody else, and we do not sell data.
Messages between buyers and vendors are stored and scanned for contact details. Blocked attempts are logged, because a repeated pattern is how off-platform fraud is identified.
Account and transaction records for as long as your account is open and afterwards where tax or legal obligations require. Support conversations for two years.
You may request a copy of your data, ask for corrections, or ask us to close your account and delete what we are not required to keep. Write to us and we will respond within 30 days.
A session cookie to keep you signed in. That is the only one we set ourselves.
Traffic is encrypted in transit. Passwords are hashed. Delivery credentials are encrypted at rest. Administrative sessions expire after 30 minutes and every privileged action is logged.
Privacy questions or requests: support@infinitylogz.com