Back to home

Privacy Policy

Effective date: 27 March 2026 · Last updated: 27 March 2026

TapPay Technologies Ltd, operating as Valescrow (“we”, “our”, “us”), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard your personal data when you use the Valescrow web portal, API, SDK, and related services (the “Service”).

This policy complies with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), the UK GDPR, and the EU GDPR where applicable.

1. Data We Collect

1.1 Information You Provide

  • Email address — Used for account creation, magic link authentication, and notifications.
  • Organisation details — Business name, category, and contact information provided during merchant activation.
  • API configuration — Webhook URLs, API key metadata, and integration settings.
  • Allocation data — Titles, descriptions, recipient details, condition configurations, and funding information you create through the platform.

1.2 Information Collected Automatically

  • Session data — IP address, browser type, and login timestamps for security monitoring.
  • Transaction data — Allocation amounts, timestamps, blockchain transaction hashes, and disbursement records.
  • API usage — Endpoint calls, response codes, and rate limit data for service reliability.
  • Audit logs — Immutable records of all allocation state changes for compliance.

1.3 Information We Never Collect

  • Private keys or wallet recovery phrases — self-custody wallets are managed entirely on user devices.
  • Raw BVN data — only boolean verification results are stored.
  • Milestone secrets — these are never returned in any API response.

2. How We Use Your Data

  • Provide the Service — Process allocations, execute disbursements, deliver webhooks, and manage API access.
  • Security & fraud prevention — Detect suspicious activity, enforce limits, and monitor for AML compliance.
  • Legal compliance — Meet obligations under Nigerian financial regulations and international data protection laws.
  • Service improvement — Analyse anonymised usage patterns to improve reliability. All analytics data has PII stripped.

3. Legal Basis for Processing

  • Contractual necessity — Processing required to provide the escrow and settlement service.
  • Legal obligation — AML monitoring, audit log retention (7 years for institutional compliance).
  • Consent — Email notifications and marketing communications.
  • Legitimate interest — Security monitoring, fraud prevention, and platform improvement.

4. Data Sharing

We share your data only when necessary:

  • Payment partners — Squad, Flutterwave, and Transak for processing deposits and withdrawals.
  • Blockchain — Transaction data is recorded on the public Celo blockchain.
  • Regulatory authorities — When required by law, including suspicious transaction reports.

We never sell your personal data. We never share your data for advertising purposes.

5. Data Retention

  • Allocation audit logs: 7 years (institutional compliance)
  • Transaction records: 5 years (CBN AML requirement)
  • KYC verification results: 5 years after account closure
  • Security events: 1 year
  • Session logs: 90 days
  • Webhook delivery logs: 1 year
  • API usage logs: 90 days

Expired data is automatically purged by scheduled processes.

6. Data Security

  • All communications use TLS 1.3 encryption.
  • Database access is controlled by Row Level Security (RLS) policies.
  • API keys are stored as salted hashes — raw keys are shown once at generation.
  • Webhook secrets are encrypted at rest.
  • Allocation audit logs are append-only — no update or delete policies.

7. Your Rights

Under the NDPA 2023, UK GDPR, and EU GDPR, you have the right to:

  • Access — Request a copy of all personal data we hold about you.
  • Rectification — Correct inaccurate personal data through your organisation settings.
  • Erasure — Delete your account and associated data. Note: audit logs are retained per compliance requirements.
  • Data portability — Export your allocation data in CSV format via the portal.
  • Withdraw consent — Opt out of non-essential communications at any time.

8. Blockchain Data

Valescrow operates on the Celo blockchain. Allocation funding, disbursement, and fee transactions are recorded on-chain. These records are public and immutable. We take steps to prevent wallet addresses from being linked to organisational identity on our public-facing pages.

9. International Transfers

Your data may be processed in countries outside Nigeria, including the United States and the European Union. All international transfers are protected by appropriate safeguards.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email and by updating the date at the top of this page. Continued use after changes constitutes acceptance.

11. Contact Us

For questions about this Privacy Policy or to exercise your data rights:

Email: privacy@valescrow.com
Address: TapPay Technologies Ltd, Lagos, Nigeria

You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local data protection authority.

Home·Terms of Service·Privacy Policy