Privacy Policy
Last updated August 2026
Smartvendor LTD ("Smartvendor", "Company", "we", "us", "our") operates a social commerce platform that enables merchants to sell products and services to their customers through WhatsApp and Telegram, alongside our website.
The privacy of our users is important to us, and we assure you of our unflinching commitment to protecting and safeguarding it. This Privacy Policy explains your personal information/data which we collect, how we collect it, why we collect it, what we do with it, and how we protect it (as regulated by the NDPA), when you use our Service. This policy applies to our website, WhatsApp and Telegram platforms, and services (collectively "Our Services").
This Policy does not apply to services not provided, owned or controlled directly by Smart Vendor — i.e. services provided by Smart Vendor's merchants or services owned or controlled by third-party websites. On some occasions, Smart Vendor processes personal data on behalf of merchants. When we do, we act as a service provider or "Data Processor" to those merchants, but we do not control and are not responsible for their privacy practices.
By using the Service, or submitting information through our platforms, you agree and expressly consent to the collection, use, processing, storage, transfer and disclosure of your personal data/information in accordance with this Privacy Policy, Acceptable Use Policy and Terms of Use. If you do not consent or agree with our privacy policy, please do not use our site, platform, or services.
1. Interpretation and Definitions
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
- "Account" means a unique account created for you to access our Service or parts of our Service ("Smart Vendor Account").
- "Affiliate" means an entity that controls, is controlled by or is under common control with a party; where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- "Cookies" are small files placed on your computer, mobile device or any other device by a website, which save details of your browsing history on that website for ease of use and full functionality of the website.
- "Country" refers to Nigeria.
- "Device" means any device that can access the Service, such as a computer, a mobile phone, or a digital tablet.
- "NDPA" means the Nigerian Data Protection Act 2023.
- "Personal Data" is any information that is associated or relates to a specific individual and can be used to identify that person — any information relating to an identified or identifiable natural person ("Data Subject"), directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity. It can be anything from a name, address, a photo, an email address, bank details, posts on social networking websites, medical information, and other unique identifiers such as (but not limited to) MAC address, IP address, IMEI number, IMSI number, SIM, or other Personally Identifiable Information (PII).
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means — collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination, alignment or combination, restriction, erasure or destruction.
- "Service" refers to the website, mobile applications, software applications ("Apps") and/or payment platforms offered by Smart Vendor, and all activities relating thereto.
- "Sites" means any Smart Vendor platform, including but not limited to mobile applications, websites, and social media platforms.
- "Service Provider" means any natural or legal person who processes data on behalf of Smart Vendor — third-party companies or individuals employed by Smart Vendor to facilitate or provide the Service, to perform services related to the Service, or to assist Smart Vendor in analysing how the Service is used.
- "Sensitive Personal Data" means data relating to religious or other beliefs, sexual orientation, health, race, ethnicity, political views, trade union membership, criminal records or any other sensitive personal information.
- "Third-party Social Media Service" refers to any website or social network through which a User can log in or create an Account to use the Service.
- "Usage Data" refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
- "We", "Us" or "Our" in this Policy refers to Smart Vendor.
- "Website" refers to Smart Vendor's website, accessible from https://smartvendor.store/.
- "You" means the individual accessing or using our Service, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
2. Scope and Consent
2.1. By signing up for the use of any of our services or accessing any of our platform, its content, features, technologies, or functions, you hereby consent to this Privacy Policy. You reserve the right to exercise your data protection rights as listed under the NDPA.
2.2. This Privacy Policy governs the use of Smart Vendor's Services by registered and non-registered users, unless otherwise agreed through written contract.
3. Types of Data Collected and How We Collect It
3.1. Personal Data: your data is collected electronically and manually when you visit any of our platforms and register to use any of our services. The types of personal data collected include, but are not limited to:
- Information provided during sign-up or onboarding: to access and use the Service, you must create a Smart Vendor account by entering your first name, last name, date of birth, business email, business name, type of business, business/company information, directors' KYC information, your phone number, and other information that assists in providing you with access to and use of the Service. This data is necessary for us to verify your identity, determine your eligibility to use, and give you access to the Service.
- Payment information: to facilitate processing payments and/or refunds, you need to provide a payment method and information such as your name, entity name, billing address, residential address, bank account information, Bank Verification Number (BVN), and date, time and amount of transaction, and such other applicable information as requested by our third-party payment service or a regulatory body.
- Information collected with cookies: we use cookies on certain pages of our Service to analyse Service usage, in order to improve our content and product offerings, improve our marketing and promotional efforts, and customize our Service's content, layout and services. See Clause 11 below.
- Correspondence: if you correspond with us via email, phone, text, or another method, we may gather the information you submit in a file specific to you. This can also be used for quality assurance purposes.
3.2. Usage Data
- When you access Smart Vendor services, our servers automatically record some technical information that your browser sends whenever you visit a website — links you have clicked, length of visit on certain pages, unique device identifier, log-in information, location, and other device details.
- When you access the Service by or through a mobile device, we may automatically collect information that your browser sends.
- We also automatically record information about your interactions with our website/services, to help us improve them. This includes records of your transactions and other activities related to our services, such as date and time of your sessions, the pages you view, links to/from any page, and time spent in a session.
- We may also use information provided by third parties like social media sites, financial institutions, open government databases, and verification agencies, and may infer additional personal data. Information about you provided by you or any other person to other websites or platforms is not controlled by Smart Vendor, and we are not liable for how they use it.
3.3. As a principle, we do not collect any sensitive personal data. In the event we do, we will ensure strict compliance with data protection and privacy laws.
3.4. This Privacy Policy applies to Smart Vendor services only. We do not exercise control over sites displayed or linked from within our various services and are not responsible for their privacy statements. Please consult such third parties' own privacy statements.
3.5. You reserve the right to decline provision of any personal data or restrict access to such data. However, if you choose not to provide necessary personal data, our services or features may not be fully available or functional.
4. Use of Your Personal Data
4.1. We may use your Personal Data for the following purposes:
- Providing you our agreed services; creating and managing any accounts you may have with us, verifying your identity, providing our services, troubleshooting problems, and responding to your enquiries.
- Processing your payment transactions (including authorization, clearing, chargebacks and other related dispute resolution activities).
- Monitoring your usage of our services and maintaining our Service with a secure, smooth, efficient, and customized experience and customer support.
- Using information provided by third parties like social media sites, financial institutions, open government databases, and verification agencies, and inferring additional personal data as needed.
- Managing your Account, managing risk, and detecting, preventing and/or remediating fraud, unauthorized transactions, violations of policies, or other potentially prohibited or illegal activities.
- Managing and protecting our information technology infrastructure from cyber-attacks and other forms of hacking activity.
- Performing creditworthiness and solvency checks.
- Carrying out Know Your Customer (KYC), compliance and risk assessments on your Account as required by applicable laws and regulations — including but not limited to Anti-Money Laundering, Anti-Corruption and Anti-Terrorism Financing rules — or as requested by any judicial process, law enforcement or governmental authority having or claiming jurisdiction over Smart Vendor or its affiliates.
- Carrying out due diligence and verifying information provided with third parties.
- Contacting you via email, telephone calls, SMS, or other equivalent forms of electronic communication — such as a mobile application's push notifications — regarding updates or informative communications related to the functionalities, products or contracted services, including security updates, when necessary or reasonable for their implementation.
- Using data analytics to improve our website, products or services, and user experiences.
- Notifying you of new products, functionalities, services and/or offerings, or any enhancements/amendments to existing ones. You have the right to contact us via [email protected] to be unsubscribed from our mailing lists at any time.
4.2. If we intend to process your personal information for any purpose other than those listed in this policy, we will seek your consent before further processing commences.
5. Retention of Your Personal Data
5.1. We will retain your Personal Data only for as long as necessary for the purposes set out in this Privacy Policy and in accordance with applicable data protection laws — to perform our Services, comply with legal obligations, resolve disputes, and enforce our legal agreements and policies. This also applies to deactivated accounts.
5.2. We also retain Usage Data for internal analysis purposes, generally for a shorter period, except when it's used to strengthen security or improve the functionality of our Service, or we're legally obligated to retain it for longer.
5.3. We aim to maintain our services in a manner that protects information from accidental or malicious destruction. We therefore reserve the right not to immediately delete residual copies from our servers, and may retain such information in our backup systems after you delete information from our services.
5.4. Once it's no longer necessary for us to retain your Personal Data, we may dispose of it in a secure manner in compliance with limitation periods under applicable law.
6. Security, Protection and Storage of Personal Data
6.1. We store and process your personal information on computers in Nigeria, Africa and elsewhere in the world where our facilities or service providers are located. Regardless of where your information is processed, we apply the same protections described in this policy.
6.2. We have implemented access control measures, and physical, administrative and technical security protocols and standards, to secure and protect your information — including the use of encryption and firewall technologies. We also carry out periodic security updates to keep our security infrastructure in line with industry standards.
6.3. Our website uses Secure Sockets Layer/Transport Layer Security (SSL/TLS) to ensure secure transmission of your personal data — confirmed by the padlock symbol and "https://" in your browser's address bar when accessing https://smartvendor.store/. This ensures data transmitted during a session is encrypted before transmission and decrypted at the receiving end, so it cannot be read in transit.
6.4. The security of your Personal Data is important to us, and we always use reasonable measures and industry standards to protect your information. However, note that transmission of data over the internet or other electronic form is never 100% secure.
6.5. In the event of an actual or suspected breach of your personal information, we will inform you as soon as possible and use best efforts to remedy the breach within one (1) month from the date we report it to you.
6.6. We will not be held responsible for unauthorized access to your Personal Data. You're responsible for reporting any unusual events that may indicate a breach in your data security. We will then investigate whether the breach was related to data transmissions from our Services and let you know what steps can be taken to rectify the problem. Further action, such as reporting incidents to the police or other relevant authorities, may also be required.
7. Transfer of Your Personal Data
7.1. Your information, including Personal Data, is processed at our operating offices and any other places where the parties involved in processing are located — meaning it may be transferred to, and maintained on, computers located outside your state, province, country or other governmental jurisdiction. Your consent to this Privacy Policy, followed by your submission of such information, represents your agreement to that transfer.
7.2. International data transfers: your Personal Data may be transferred to countries which may not have the same data protection laws as the country you initially provided it in — but whenever we transfer or transmit your Personal Data internationally, we take reasonable steps to ensure it's handled securely in line with applicable data protection laws and standard contractual clauses. You have a right, upon request, to be informed of the appropriate safeguards for data protection in the destination country.
7.3. We take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Policy, and no transfer of your Personal Data will take place to an organization or a country unless adequate controls are in place, including the security of your data.
8. Access to Your Data
8.1. If you are a registered user, you may access your personal information using your secure login credentials to access the relevant system features. If you are a non-registered user, you may request your personal information by emailing [email protected].
8.2. This information should only be used for your own purposes — not to circumvent the platform, or be distributed to other parties who may use it to jeopardize the interest of Smart Vendor or the usage of Smart Vendor's platform.
8.3. You have the right to request that we stop using your data, return your data to you, or transmit it directly to another data controller. Withdrawal of your consent at any time does not affect the lawfulness of processing based on your consent before its withdrawal. To exercise your rights in this regard, notify us at [email protected] and your request will be treated promptly.
8.4. You can also let us know if you feel your personal information is being processed in any way other than how you consented to it being used. We will take reasonable steps to ensure it's processed as you consented, or we may delete it based on your instruction. We may not accede to your request if it's unrealistic, impractical, or detrimental to our compliance with applicable regulation or law.
8.5. If the information you have supplied to us is wrong, you can request its correction or deletion — unless we have to keep it for legitimate business or legal purposes. When responding to a request to update your personal information, we may ask you to verify your identity first. We may reject requests that are unreasonably repetitive, require disproportionate technical effort, risk the privacy of others, or would be extremely impractical (for instance, requests concerning information residing on backup systems). Where we can provide information access and correction, we will do so for free, except where it would require disproportionate effort.
8.6. You may also deactivate your Account at any time, which shall be construed as withdrawal of consent. You may contact us to deactivate your Account at any time at [email protected].
9. Disclosure of Your Personal Data
9.1. We will not share, sell, trade, rent or disclose your personal data with a third party without your consent, except as necessary to provide the Services or as described in this Privacy Policy.
9.2. When transacting with others, we may provide those parties with information to complete the transaction — such as your name, User ID, or contact details — needed to promote the reliability and security of the transaction. If a transaction is held, fails, or is later invalidated, we may also provide details of the unsuccessful transaction.
9.3. We work with third parties, including merchants, to enable them to accept or send payments from or to you, using Smart Vendor. A third party may share information about you with us, such as your email address or mobile phone number, to inform you that a payment has been sent to you or when you attempt to pay a merchant. We use this to confirm you are a Smart Vendor customer, and we also validate your status as a Smart Vendor customer to third parties on your instruction.
9.4. Law enforcement: under certain circumstances, Smart Vendor may be required to disclose your Personal Data if required to do so by law or in response to valid requests by government authorities.
9.5. Your card information may be available for your subsequent re-use if you chose to be remembered on a previous attempt.
9.6. Smart Vendor will not disclose your personal data — including your credit/debit card number or bank account number — to anyone excluding its merchants and relevant regulatory bodies, except with your express permission.
9.7. In addition to the above, Smart Vendor may share your Personal Data with third parties — including our merchants, affiliates, parent company, employees, officers, service providers, suppliers, agents and sub-contractors — as may be reasonably necessary only in the following circumstances:
- Fraud prevention and risk management.
- For customer service purposes.
- Protecting and defending the rights of Smart Vendor.
- For compliance with applicable laws, anti-money laundering and counter-terrorist financing verification requirements.
- With Service Providers, to enable them to monitor and analyze the use of our Service and support our business operations.
- To prevent or investigate possible wrongdoing in connection with the Service.
- To protect the personal safety of Users of the Service or the public.
- To protect against legal liability.
- Where disclosure is necessary for the performance of a contract to which you are party, or to take steps at your request prior to entering into a contract with us — including disclosing your personal data to third parties during our verification exercise to determine your identity or eligibility to use our service.
- With our affiliates and partners, where necessary.
- With other users — when you share Personal Data or otherwise interact in public areas with other users, such information may be viewed by all users and may be publicly distributed outside. If you interact with other users or register through a Third-Party Social Media Service, your contacts on that service may see your Personal Data.
9.8. You accept that your pictures and testimonials on social media platforms about Smart Vendor can be used for limited promotional purposes by us or our agents. This does not include your trademark or copyright-protected materials.
9.9. Where your employee, as part of the process of application for a service from Smart Vendor or a third party, requires their data to be provided in support of such an application, we are obligated to avail such a request upon the employee giving the requisite authorisation as the Data Owner/Data Subject, in the form prescribed by us or the third party.
9.10. We may disclose personal data as part of a corporate transaction or proceeding, such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets. In this case, your Personal Data may be transferred and become subject to a different privacy policy.
9.11. We work with third parties, including merchants, to facilitate the receipt of your payments. Third parties involved in transactions may have their own privacy policies, and Smart Vendor does not allow the other transacting party to use this information for anything other than providing agreed Services. Smart Vendor is not responsible for their actions, including their information protection practices.
9.12. We may also disclose/share your personal data, transaction history/data, business information and any other data generated by us pursuant to your use of our services with our affiliates, parent company, sister-companies, subsidiaries, and business partners, for business synergy purposes and for the provision of other services to you. In this case your personal data becomes subject to a different privacy policy. We will always comply with the provisions of all applicable data protection law.
10. Your Rights Under the NDPA
You have data protection rights and are entitled to the following:
- The right to access — you have the right to request copies of your Personal Data from us. We may charge a reasonable fee for this service, in consideration of the administrative cost of accomplishing the request.
- The right to rectification — you have the right to request correction of any information you believe and have proven to have been captured inaccurately, or completion of any information you believe is incomplete.
- The right to erasure — you have the right to request erasure of your Personal Data, under certain conditions listed in the NDPA, subject to regulatory requirements or law enforcement needs.
- The right to restrict processing — you have the right to request restriction of the processing of your Personal Data, under certain conditions listed in the NDPA.
- The right to object to processing — you have the right to object to the processing of your Personal Data, under certain conditions.
- The right to data portability — you have the right to request the transfer of data collected to another organization, or directly to you, where technically feasible, without unnecessary hindrance.
Any requests arising from the rights above will be handled within two (2) to four (4) working weeks.
11. Tracking Technologies and Cookies
11.1. We use cookies and similar tracking technologies to track activity on our Service and store certain information.
11.2. When you browse our website, we use cookies to ensure a seamless experience across all the functions you access. Cookies are necessary for our website to perform normally — some manage your session so you transition smoothly between pages while logged in, while others are more persistent and remain on your device for longer.
11.3. Cookies allow a website to recognize a particular device or browser. There are several types of cookies we use:
| Type of Cookie | Usage |
|---|---|
| Third-Party Cookies | May be placed on your computer when you visit the Site by companies that run certain services we offer. These allow the third party to gather and track certain information about you. Can be manually disabled. |
| Our Cookies | "First-party" cookies, either permanent or temporary — necessary for the Site to work properly and provide certain features. Some may be manually disabled in your browser, though this may affect functionality. |
| Personalization Cookies | Recognize repeat visitors to the Site — used to record your browsing history, pages visited, and settings/preferences each time you visit. |
| Site Management Cookies | Maintain your identity or session on the Site so you're not logged off unexpectedly, and information you enter is retained from page to page. Can't be turned off individually, but you can disable all cookies in your browser. |
11.4. Tracking: in addition to cookies, we may use web beacons, pixel tags, and other tracking technologies to help customize the Site and improve your experience. A "web beacon" or "pixel tag" is a tiny object or image embedded in a web page or email, used to track the number of users who have visited particular pages or viewed emails, and to acquire other statistical data — collecting only a limited set of data, such as a cookie number, time and date of view, and a description of the page/email on which they reside. Web beacons and pixel tags cannot be declined, but you can limit their use by controlling the cookies that interact with them.
11.5. How we use cookies: we use cookies for a variety of reasons. In most cases there's no industry-standard option for disabling cookies without disabling the functionality and features they add to our site — it's recommended you leave on all cookies if you're unsure whether you need them, in case they're being used to provide a service you need. We use them, among other things, to keep track of services you've used, record registration information and preferences, keep you logged in, facilitate purchase procedures, and track the pages you visit — helping us understand how the Site is used and improve your experience.
11.6. If you register a profile with us, we use cookies for the management of the sign-up process, general administration, and to manage your browser session while logged in. These are usually deleted when you log out, though some may remain to remember your site preferences afterward.
11.7. Turning off/opting out of cookies: you can manually disable or delete cookies on your device. Disabling cookies may restrict your browsing experience related to important features such as logging in or navigating webpages — we recommend allowing cookies for a good user experience. Smart Vendor does not share cookie information with any other website, nor sell this data to any third party without your consent. You can instruct your browser to refuse all cookies or notify you when one is being sent.
12. Links to Other Websites
12.1. Certain service processing channels on Smart Vendor may require links to other websites. Smart Vendor is not responsible for and has no control over third-party websites, and we do not monitor or review the content of other parties' websites linked from this website.
12.2. Opinions expressed or materials appearing on such websites are not necessarily shared or endorsed by us, and Smart Vendor should not be regarded as the publisher of such opinions or materials. You agree we shall not be liable for any liability arising from your interpretation of information on any third-party website linked to Smart Vendor.
12.3. We are not responsible for the privacy practices or content of any third-party sites, and we encourage you to read their privacy statements. Evaluate the security and trustworthiness of any other site connected to or accessed through this site yourself, before disclosing any personal information to it.
12.4. Smart Vendor will not accept responsibility for any loss or damage, however caused, resulting from your disclosure to third parties of your personal information.
13. Marketing
13.1. As part of providing our services, we may share information about third-party products and services, and may share limited personal data about you in connection with our services. Our lawful basis for doing this is performance of our contract with you, or our legitimate business interest (or that of a third party).
13.2. You may opt out of marketing and promotional offers at any time. If you opt out, we may still send you messages relating to transactions and our Services in connection with our ongoing business relationship. We may ask your permission before sending other notifications.
14. Limitation of Liability
14.1. Smart Vendor will not be liable for loss of income, profits, business, opportunity, goodwill, contracts, or any indirect, special, incidental or consequential damages arising out of or in connection with the Service, any computation or failed service on Smart Vendor, or arising out of any breach of this Policy.
14.2. We will not be liable for any loss or damage arising from unauthorized access to the Service if (a) you intentionally or negligently failed to take reasonable precautions to protect your security, access codes, login details or any device used to access the Service, (b) you failed to promptly notify us that the Service was being accessed in an unauthorised way after becoming aware of it, or (c) you acted fraudulently.
14.3. Our liability to you or any third party, in any circumstance of proven liability by us, shall not exceed the fees paid to us in respect of the specific transaction that gave rise to the claim, unless otherwise specified by a court of competent jurisdiction.
14.4. This limitation of liability shall not apply if we breach any provision of the Nigerian Data Protection Act 2023 ("NDPA").
15. Children's Privacy
15.1. Our services do not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from Children. If you are a parent or guardian and are aware that your child has provided us with Personal Data, please contact us at [email protected].
15.2. If we become aware that we have collected Personal Data from a child without verification of parental consent, we take steps to remove that information from our database.
16. Providing Us with Personal Data of Another Person
If you need to provide us with personal data about another person, you must obtain that individual's express consent to share their information. You covenant to also share this Privacy Policy with those individuals, as it shall also apply to them.
17. Remedies for Personal Data Breach
Where we notice a personal data breach, or where you report one to us, we will investigate as soon as possible and notify you of the security or correctional measures to be taken — including, without limitation, reporting it to relevant government authorities.
18. Changes to This Privacy Policy
From time to time, we may change, amend or review this Privacy Policy to reflect new services or changes in our privacy practices, and place any updates on this page. If we make material changes, we will notify you by sending an email to the address you most recently provided us, or by posting notice of the changes on this site.
We request that you periodically review this Privacy Policy for recent changes to our privacy practices. If you keep using our Services, you consent to all amendments of this Privacy Policy.
Complaints
All access requests, questions, comments, complaints, and other requests regarding this privacy policy should be sent to [email protected].