Skip to content
Privacy

Your data, protected.

How we collect, use, and protect personal data — written to comply with Nigerian, African, and international data-protection law.

Effective 1 January 2026 · v3.2

  • We collect only what we need

    Your business data, account details, and the minimum required to run the platform.

  • We protect what we hold

    TLS 1.3 in transit, AES-256 at rest, role-based access, and audited backups.

  • We don't sell your data

    Not to advertisers, not to data brokers, not to AI training companies. Ever.

  • You stay in control

    Export, correct, or delete your data at any time — directly from your dashboard.

Aligned with

  • NDPR 2019 (Nigeria)
  • NDPA 2023 (Nigeria)
  • GDPR (EU/UK)
  • POPIA (South Africa)
  • DPA 2019 (Kenya)
  • DPA 2012 (Ghana)
  • Loi 2013-450 (Côte d'Ivoire)
  • CCPA / CPRA (California)

1. Who we are

Rosiovend Limited ("Rosiovend", "we", "us", "our") operates the Rosiovend platform at rosiovend.com. We are registered in the Federal Republic of Nigeria with our principal office at Victoria Island, Lagos.

Under most data-protection laws applicable to our service, we act as the data controller for personal data collected through our marketing site, our authentication system, and our own billing operations. For your business's customer and staff data uploaded to the Service, you are the data controller and we act as your data processor.

2. Scope of this policy

This Privacy Policy applies to:

  • Visitors to rosiovend.com and our marketing pages.
  • Business owners and admins who register a Rosiovend account.
  • Staff members invited by a registered business.
  • Customers of registered businesses interacting with Rosiovend-hosted storefronts (where Rosiovend is a processor).

If you are a customer of a Rosiovend-powered business, that business is the data controller for your data. Direct privacy requests to that business; we will assist them in responding.

3. Data we collect

We collect the following categories of personal data:

Categories of personal data Rosiovend collects
Account dataName, email, phone number, password hash, business name, business address, country, role
Identity verificationGovernment-issued ID number (NIN, Ghana Card, etc.) and document images for KYC where regulation requires it
Payment dataBilling address, last-4 of card, payment method token (full card numbers handled by PCI-DSS-compliant processors — we never store them)
Business operational dataOrders, customers, inventory, staff records, transactions, product images and descriptions you upload
Usage dataPages visited, features used, IP address, device type, browser, session duration, click events
CommunicationsSupport tickets, emails to our team, in-app chat transcripts, feedback submissions
Cookies & similarSee our Cookie Policy for the full list and durations

4. How we use your data

We use personal data to:

  • Provide, maintain, and improve the Service.
  • Authenticate you and protect your account.
  • Process payments and send invoices and receipts.
  • Send service-essential notifications (security alerts, billing, system updates).
  • Respond to support requests and feedback.
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Comply with legal, tax, anti-money-laundering, and regulatory obligations.
  • Conduct anonymised, aggregated product analytics to improve Rosiovend.
  • Send marketing communications (only with your consent — and you can opt out at any time).

6. Who we share data with

We share personal data only in these circumstances:

  • Payment processors (Paystack, Flutterwave) — to process transactions you authorise.
  • Cloud infrastructure providers — for hosting, storage, and content delivery (under data-processing agreements).
  • Communications providers — email, SMS, and WhatsApp delivery partners (transit data only).
  • AI service providers — to power AI-assisted features, with strict data-handling terms; we do not allow your data to be used for model training.
  • Professional advisors — auditors, lawyers, and accountants under confidentiality.
  • Legal requirements — when compelled by valid court order, regulator request, or applicable law.
  • Business transfer — in a merger, acquisition, or asset sale, with prior notice to you and the same protections.

We do not sell personal data. We do not share personal data with advertisers or data brokers.

7. International data transfers

Wherever possible, your data is stored within Africa (primarily Nigeria and South Africa). Some service providers operate from the European Union, the United Kingdom, or the United States. When data is transferred outside your country of registration, we use safeguards required by applicable law:

  • Standard Contractual Clauses (where required by GDPR / UK GDPR).
  • NITDA-approved data-protection agreements for Nigerian residents.
  • POPIA section 72 cross-border transfer safeguards for South African residents.
  • Provider certifications (ISO 27001, SOC 2 Type II) where applicable.

8. How long we keep data

We retain personal data only as long as necessary for the purposes described in this policy, or as required by law:

Data retention periods by record type
Active account dataFor the duration of your subscription
Closed accounts12 months after termination, then deleted or anonymised
Financial / transaction recordsUp to 7 years (tax authority requirements)
KYC / identity records5 years after relationship ends (AML requirements)
Marketing consent recordsUntil withdrawn, plus 2 years for proof of consent
Support tickets3 years after resolution
Server logs90 days, except where retained for security investigation

9. Your rights

Subject to the law that applies to you, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (subject to our legal retention duties).
  • Restriction — limit how we process your data while we resolve a complaint.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — at any time, where processing is based on consent.
  • Lodge a complaint with your data-protection authority (see below).

To exercise any right, email privacy@rosiovend.com or use the in-app Privacy Centre in your dashboard. We will respond within 30 days (or sooner where the law requires).

Your data-protection authority

  • Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
  • Ghana: Data Protection Commission — dataprotection.org.gh
  • Kenya: Office of the Data Protection Commissioner — odpc.go.ke
  • South Africa: Information Regulator — inforegulator.org.za
  • Côte d'Ivoire: ARTCI — artci.ci

10. Automated decisions & AI

We use AI and automated systems to power features such as fraud detection, inventory forecasting, menu intelligence, and the AI assistant. Where an automated decision could have a significant effect on you (for example, blocking a transaction flagged as fraudulent), you have the right to:

  • Request human review of the decision.
  • Express your point of view and provide additional context.
  • Receive an explanation of the logic involved.

AI features are designed to assist, not replace, human judgment. Your data is not used to train external AI models without your explicit consent.

11. Children's data

Rosiovend is a business platform and not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact privacy@rosiovend.com and we will delete it promptly.

12. Security

We apply technical and organisational measures appropriate to the risk:

  • TLS 1.3 encryption in transit; AES-256 at rest.
  • Role-based access controls and least-privilege principles for our staff.
  • Multi-factor authentication for all production systems.
  • Continuous security monitoring, dependency scanning, and quarterly penetration testing.
  • Encrypted, geo-redundant backups and tested disaster-recovery procedures.
  • Mandatory security training for every Rosiovend employee.

If you believe you have found a security issue, please report it to security@rosiovend.com. We commit to acknowledge within 24 hours.

13. Cookies

We use cookies and similar technologies to keep you signed in, remember preferences, and measure how the Service is used. Full details, including how to control cookies, are in our Cookie Policy.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 14 days before they take effect, by email and via in-app notification. The "Effective" date at the top of this page shows when it was last updated.

15. Contact our DPO

For privacy questions, data-subject requests, or to contact our Data Protection Officer:

Rosiovend Limited — DPO

Victoria Island, Lagos, Federal Republic of Nigeria