Last updated 2026-07-30
DRAFT — FOR REVIEW BY QUALIFIED NIGERIAN COUNSEL. NOT FOR PUBLICATION IN THIS FORM. Prepared by Popucáo legal-ops.
[COUNSEL: …]flags mark judgment calls.[TODO: …]marks facts nobody has supplied yet.
Document: Customer Privacy Notice Version: 0.1 draft · Date prepared: 29 July 2026 · Effective: [TODO: DATE] Who this is for: people who scan a Popucáo code, claim an offer, or buy from a shop running a Popucáo offer.
Drafting note — this notice is written to the Nigeria Data Protection Act 2023 and the NDPA General Application and Implementation Directive (GAID) 2025. The brief asked for "NDPR-compliant". The NDPR 2019 and its 2020 Implementation Framework were repealed by GAID, which took effect on 19 September 2025; since that date the NDPA 2023 and GAID are the operative instruments. Compliance with them is what matters now.
[COUNSEL: please confirm — verified 29 July 2026 by search of published law-firm commentary and the NDPC's own GAID publication, not from a gazette copy.]
You are reading this because you scanned a code, or a shop asked for your number at the till.
POPUCAO LIMITED (RC No. [TODO: RC NUMBER]) of [TODO: REGISTERED ADDRESS], Lagos, Nigeria, is the data controller for the information described in this notice.
Contact us about privacy: [TODO: PRIVACY EMAIL] Data Protection Officer: [TODO: NAME / "not yet appointed"]
[COUNSEL: GAID 2025 requires a Data Protection Officer in defined cases, and NDPC registration applies to data controllers/processors of major importance. The commonly cited trigger for GAID's core obligations is processing the personal data of more than 200 data subjects within a six-month period, with registration tiers (Ultra-High, Extra-High, Ordinary-High) carrying fees of ₦250,000 / ₦100,000 / ₦10,000 and annual Compliance Audit Returns. Popucáo will cross 200 customers quickly in a pilot. Please confirm the applicable tier, the DPO requirement, the registration deadline, and whether a Data Protection Impact Assessment is required for the phone-hashing and fraud-detection processing before launch.]
This notice is for customers — people who scan a code, claim an offer, or buy from a participating shop.
If you are an Ambassador (someone who carries a code to earn rewards) or a business using Popucáo to advertise, a separate notice applies to you, because we hold much more information about you — including your identity verification and payout details. [TODO: publish Ambassador/Advertiser privacy notice; not covered here.]
There are only two moments where anything is collected.
The offer page asks you for nothing. No name, no phone number, no email, no account, no app.
Our server does automatically record, from the scan itself:
| What | Why |
|---|---|
| The code that was scanned, and the date and time | So the right Ambassador is credited if you buy |
| Your IP address | Fraud detection — many scans of the same code from one connection in a few minutes is the signature of someone faking sales |
| Basic device information your browser sends, and a device identifier where available | Fraud detection — to spot the case where the "customer" and the code-holder are the same device |
Your IP address and device information are personal data under Nigerian law, so we tell you about them plainly rather than describing the page as anonymous.
We do not collect your location, your contacts, your photos, or anything else from your phone. We do not put your personal data in the web address of the offer page.
The shop asks for your phone number at the till and sends it to us with the sale.
Here is what happens to it, precisely:
The scrambled value lets us answer exactly one question — have we seen this same number at this same shop before? — without us knowing what the number is. It cannot be turned back into your number by us or by anyone who obtained a copy of our database, because the secret key is not in the database.
Honest limitation: a scrambled value that relates to you is still your personal data under the NDPA, and we treat it that way. We are not claiming this data is anonymous. We are claiming it is minimised, which is a different and more truthful thing.
If you email us or message support, we hold what you send us and our reply, so we can deal with your question.
Nigerian law requires us to have a lawful basis for each use.
| What we use it for | Lawful basis (NDPA 2023, s.25) |
|---|---|
| Working out which Ambassador introduced you, so the right person is paid | Our legitimate interest in operating the service, and the shop's legitimate interest in paying for results |
| Checking whether you had bought from that shop before, so the shop is charged correctly | Legitimate interests (ours and the shop's); also necessary to perform the shop's arrangement with us |
| Detecting and preventing fraud — fake sales, self-referrals, collusion | Legitimate interests; preventing loss to shops, honest Ambassadors and us |
| Keeping accurate financial records of what was earned and paid | Legal obligation (tax and company law record-keeping) |
| Answering your questions and handling complaints | Legitimate interests |
| Sending you a message about a claim, if we ever do | Consent — and only if you have given it |
We do not use your information to market to you, and we do not sell or rent it to anyone. Ever.
[COUNSEL: the legitimate-interest basis needs a documented Legitimate Interests Assessment before launch. Two points to test: (1) the incrementality check is a de-duplication of individuals across shops' customer bases — is legitimate interest the right basis, or is consent (captured by the shop at the till) required? (2) The shop is the party who collects the number and who has the direct relationship with the customer. Confirm whether Popucáo and the shop are independent controllers or joint controllers for this processing, and draft the corresponding arrangement into the Advertiser Terms.]
This is a deliberate boundary in how the product is built, not just a policy.
| Does it see your identity? | |
|---|---|
| The Ambassador whose code you scanned | Never. They see that a sale happened and its amount. They are never shown who you are, your number, or your contact details. |
| The shop you bought from | They already have your number — you gave it to them at the till. We tell them only whether this counted as a first purchase. We do not send them anything about you they did not already have, and we do not tell them anything about your purchases at other shops. |
| Other shops | Nothing. |
| Popucáo staff | Only where necessary to investigate a dispute or suspected fraud, and identifiers are masked by default. |
| Provider | What they do | What they get |
|---|---|---|
| [TODO: HOSTING PROVIDER AND REGION] | Runs our servers and database | The scrambled values and sale records described in section 3 |
| Termii (messaging) | Sends one-time codes and messages | A phone number, only where a message is actually being sent — this normally applies to Ambassadors and shop owners logging in, not to customers |
| Safe Haven Microfinance Bank Limited | Holds prepaid advertising budgets and moves payouts. Safe Haven is a licensed bank; it holds the money, not Popucáo | Business and Ambassador payment details — not customer data |
| Paystack | Collects payment from businesses for their advertising budgets | Business payment details — not customer data |
| [TODO: KYC PROVIDER] | Verifies the identity of Ambassadors and business owners | Their BVN/NIN — not customer data |
Each of these is bound to use the data only on our instructions. [TODO: put data-processing agreements in place with each before launch — required by NDPA 2023 s.29.]
We will disclose information where the law requires it — for example to a court, a regulator, or law enforcement acting on proper authority — and to our professional advisers under a duty of confidence. If our business is sold or reorganised, records may transfer to the buyer, who would be bound by this notice.
Our systems are hosted at [TODO: HOSTING PROVIDER AND REGION].
[COUNSEL: this is a real open item, not boilerplate. If hosting is outside Nigeria, NDPA 2023 ss.41–43 cross-border transfer rules apply and this section must set out the adequacy/appropriate-safeguards basis relied on. If hosting is in Nigeria, say so plainly — it is a trust advantage worth stating. The answer must be filled in before this notice is published.]
| What | How long |
|---|---|
| Scan records (code, time, IP, device information) | [TODO: e.g. 12 months], then deleted — they are only useful for fraud detection while recent |
| The scrambled value of your phone number, and the sale record | For as long as the shop's offer is running and its account is open, because that is what "have you bought here before" is measured against |
| Financial records of what was earned and paid | 6 years (or as required by Nigerian tax and company law) |
| Support messages | [TODO: e.g. 24 months] |
Our financial ledger is deliberately append-only: entries are never edited or deleted, and mistakes are corrected by adding a reversing entry. That is what makes the money records trustworthy — but it means a request to erase a financial record cannot always be met (see 8.3).
[COUNSEL: (a) confirm the statutory retention period for accounting records under the Nigeria Tax Administration Act 2025 and CAMA 2020, and the correct period for KYC/AML records; (b) confirm that an append-only ledger is compatible with the NDPA erasure right, and how to express the exemption; (c) advise on a defensible retention period for scan/IP data used for fraud detection.]
Under the NDPA 2023 you can:
8.1 How to ask. Email [TODO: PRIVACY EMAIL]. We will respond within 30 days. There is no charge for a reasonable request.
8.2 A practical wrinkle, stated honestly. Because we do not store your phone number — only a scrambled version of it — we usually cannot find your records from your name or email alone. To locate them, we would need you to give us the phone number you gave the shop, so we can scramble it the same way and match it. We would use that number only for that purpose and would not keep it.
8.3 What we may not be able to delete. Where a record is part of our financial ledger, or is needed for tax, fraud, or legal reasons, we may have to keep it even after a deletion request. If that happens, we will tell you which parts we kept and why.
If you are unhappy with how we have handled your information, please tell us first at [TODO: PRIVACY EMAIL] so we can fix it.
You can also complain to:
Nigeria Data Protection Commission (NDPC) Website: ndpc.gov.ng · [TODO: confirm current complaint channel and address]
Popucáo is not for children. Our offers are for people aged 18 and over, and we do not knowingly collect information about anyone under 18. If you believe a child's information has reached us, tell us at [TODO: PRIVACY EMAIL] and we will delete it.
[COUNSEL: GAID 2025 has specific provisions on children's data and age assurance. A shop cannot realistically age-verify a walk-in customer, and some offers (food, retail) will inevitably be used by families. Please advise what is proportionate here — a stated 18+ position, or something more.]
If we change how we use your information, we will update this notice and change the date at the top. Where a change is significant, we will make it prominent on the offer page.
1. The single most important fact to check this notice against. Popucáo is not in the payment path at all. The customer scans a code, shows the short code at the counter, and pays the shop directly by whatever means the shop accepts. Popucáo receives no customer funds and no card data. This was a deliberate architectural decision taken because a CBN PSSP licence does not permit holding funds and Popucáo holds no licence (plan/01-PSSP-VERDICT.md). Where an advertiser prepays a campaign budget, those funds sit in an account at Safe Haven Microfinance Bank Limited — a licensed bank — and not with Popucáo. Please check the whole notice for any wording that could be read as Popucáo processing payments.
2. NDPR vs NDPA/GAID. The instruction was for an "NDPR-compliant" notice; the NDPR 2019 was repealed by GAID 2025 with effect from 19 September 2025. This notice is drafted to the NDPA 2023 + GAID. Please confirm and correct the internal team's terminology if I have this wrong.
3. Where the phone number actually comes from — and a stale product line that must be fixed. The number is collected by the shop, at the till, and sent to Popucáo with the sale confirmation. Popucáo hashes it immediately (HMAC-SHA256 with a secret pepper held in a secrets manager) and never stores or logs the plaintext. Two consequences:
design/04-COPY.md §7) still carries a customer consent line reading "By paying, you agree we can share your phone number with this shop…". That line is now factually wrong and inverted — the shop gives the number to us, not the other way round — and it sits on a page that no longer collects anything. It should be removed or rewritten before launch.4. Controllership between Popucáo and the shop. The shop collects the number and has the direct customer relationship; Popucáo determines the purpose of the de-duplication and fraud processing. Independent controllers or joint controllers? The answer changes the notice, the Advertiser Terms, and who must notify a breach.
5. The offer page is not "no personal data". An internal code comment describes it as holding no personal data at all. That is not quite right: opening the page records the code, time, IP address and, where sent, a device fingerprint header (apps/api/src/http/app.ts, store.recordScan). Under the NDPA those are personal data. This notice discloses them. Please confirm the disclosure and the legitimate-interest basis for fraud detection are adequate, and set a retention period.
6. Open items that must be closed before publication: hosting provider and region (cross-border transfer analysis turns on it); KYC provider identity; NDPC registration tier and whether a DPIA is required; DPO appointment; data-processing agreements with every provider in section 5.1; breach-notification deadlines; retention periods.
7. This notice covers customers only. Ambassador and Advertiser notices are still to be drafted, and they are the harder ones — they involve identity verification, financial data and payout details.
Prepared by Popucáo legal-ops (AI). Not legal advice. For review by qualified Nigerian counsel before publication.
← Back to popucáo