Legal Document

Privacy Policy

๐Ÿ“… Effective: 1 May 2026 ๐Ÿ”„ Last updated: 8 May 2026 ๐Ÿ‡ณ๐Ÿ‡ฌ NDPR Compliant
01 โ€” Overview

Introduction

OjaLocal ("we", "our", "us") operates an online fresh produce and livestock marketplace connecting Nigerian farmers and merchants directly with buyers. We are committed to protecting your personal information and your right to privacy.

This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights under the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023.

Plain English summary: We collect only what we need to run the marketplace. We do not sell your data. You can request deletion of your account at any time.

By using OjaLocal โ€” whether as a buyer, merchant, or visitor โ€” you agree to the practices described in this policy. If you do not agree, please do not use our platform.

02 โ€” Identity

Who We Are

OjaLocal is a Nigerian agricultural technology platform. For the purposes of data protection law, OjaLocal is the Data Controller responsible for your personal information.

DetailInformation
Platform nameOjaLocal Fresh Market
Country of operationFederal Republic of Nigeria
Regulatory frameworkNDPR 2019 / NDPA 2023
Contact emailsupport@ojalocal.com
03 โ€” Collection

Data We Collect

Information you give us

  • Account data: Full name, email address, password (encrypted), account type (buyer or merchant)
  • Order data: Delivery address, phone number, items purchased, quantity, total amount paid
  • Merchant data: Business name, business location, product listings, pricing, inventory batches, harvest records including weather conditions
  • Payment data: Transaction reference numbers only โ€” we never store full card numbers or bank details
  • Dispute data: Order disputes and supporting descriptions you submit
  • Communications: Support emails and messages you send us

Information we collect automatically

  • Browser type and device type
  • IP address and approximate location (city level)
  • Pages visited and time spent on the platform
  • Session activity for security and fraud prevention
We do not collect: Your BVN, NIN, full card numbers, CVV codes, bank account passwords, or any biometric data.
04 โ€” Purpose

How We Use Your Data

PurposeLegal Basis (NDPR)
Creating and managing your accountContract performance
Processing orders and paymentsContract performance
Sending order confirmation emailsContract performance
Sending low-stock and restock alerts to merchantsLegitimate interest
Notifying buyers when a product is back in stockConsent (you ordered the product)
Resolving disputes between buyers and merchantsLegal obligation / legitimate interest
Preventing fraud and securing the platformLegitimate interest / legal obligation
Improving the platform through analyticsLegitimate interest
Complying with Nigerian law and court ordersLegal obligation

We will never use your data for purposes incompatible with what is described above without obtaining your explicit consent first.

05 โ€” Sharing

Sharing Your Data

We do not sell, rent, or trade your personal data. We share your data only in these limited circumstances:

With merchants (sellers)

When you place an order, your name, phone number, and delivery address are shared with the relevant merchant so they can fulfil your order. This is necessary for the contract between you and the merchant.

With service providers

  • Supabase โ€” secure cloud database hosting (data stored in compliance with international security standards)
  • Paystack โ€” payment processing (governed by Paystack's own privacy policy)
  • Flutterwave โ€” payment processing (governed by Flutterwave's own privacy policy)
  • Resend โ€” transactional email delivery

All service providers are contractually required to handle your data securely and only for the purposes we specify.

With regulators and law enforcement

We may disclose your data where required by Nigerian law, court order, or to protect the rights and safety of our users.

We will never share your data with advertisers, data brokers, or any third party for marketing purposes without your explicit consent.
06 โ€” Payments

Payment Data

All payment processing is handled directly by Paystack and Flutterwave โ€” both regulated Nigerian payment processors licensed by the Central Bank of Nigeria (CBN).

OjaLocal only stores:

  • Transaction reference numbers (for order tracking and dispute resolution)
  • Payment amounts (for order records)
  • Payment method used (Paystack or Flutterwave)

We never store, see, or have access to your card numbers, bank account numbers, or payment PINs. Those remain entirely within the payment processors' secure environments.

Every payment is verified server-side before an order is confirmed, reducing fraud risk for both buyers and merchants.

07 โ€” Retention

How Long We Keep Your Data

Data TypeRetention PeriodReason
Account informationDuration of account + 1 yearAccount management
Order records7 yearsNigerian tax / FIRS compliance
Payment transaction refs7 yearsCBN regulation compliance
Dispute records3 years after resolutionLegal protection
Session / login tokens30 days (auto-expire)Security
Deleted account data30 days after deletion requestFraud prevention window

After the retention periods above, your data is permanently deleted or anonymised so it can no longer identify you.

08 โ€” Rights

Your Rights Under NDPR / NDPA

As a Nigerian data subject, you have the following rights:

  • Right to access: Request a copy of all personal data we hold about you
  • Right to rectification: Ask us to correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your account and personal data (subject to legal retention requirements)
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interest
  • Right to restrict processing: Request we limit how we use your data while a dispute is resolved
  • Right to withdraw consent: Where we rely on consent, withdraw it at any time

To exercise any of these rights, email us at privacy@ojalocal.com. We will respond within 30 days as required by NDPR.

If you are unsatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng.

09 โ€” Security

How We Protect Your Data

  • All data is encrypted in transit using TLS 1.2 / 1.3
  • Passwords are hashed using industry-standard algorithms โ€” we cannot read your password
  • Database access is protected by Row Level Security (RLS) โ€” users can only access their own data
  • Authentication tokens expire after 1 hour and sessions expire after 30 minutes of inactivity
  • Payment verification is performed server-side before orders are confirmed
  • Secret API keys are stored in secure server-side environment variables, never in the browser
In the event of a data breach that risks your rights or freedoms, we will notify you and the NDPC within 72 hours of becoming aware of it, as required by NDPR.
10 โ€” Cookies

Cookies & Local Storage

OjaLocal does not use third-party advertising cookies. We use browser localStorage for the following essential purposes only:

ItemPurposeExpires
oja_tokenKeep you logged in between page loads1 hour (auto-refreshed)
oja_refreshSilently renew your login session30 days
oja_userStore your name and role to display in the UI30 days or on logout

These are strictly necessary for the platform to function. No data stored locally is shared with advertisers or analytics companies.

11 โ€” Children

Children's Privacy

OjaLocal is not intended for use by anyone under the age of 18 years. We do not knowingly collect personal data from minors.

If you believe a child has provided us with personal information, please contact us immediately at privacy@ojalocal.com and we will delete the data promptly.

12 โ€” Updates

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send registered users an email notification of material changes
  • Display a notice on the OjaLocal homepage for 30 days

Your continued use of OjaLocal after changes take effect constitutes acceptance of the updated policy.

13 โ€” Contact

Contact Us

For any privacy-related questions, data requests, or concerns, please reach us through any of the following:

OjaLocal Data Protection

๐Ÿ“งPrivacy requests: privacy@ojalocal.com
๐Ÿ› General support: support@ojalocal.com
๐ŸŒPlatform: ojalocal.com
โฑResponse time: Within 30 days of receiving your request