Privacy Policy
Last updated: June 6, 2026
This website and related services are owned and operated by STORVLY NIGERIA LIMITED. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Storvly.
1. Information We Collect
We collect information that you provide directly to us, information collected automatically, and information from third-party sources:
A. Information You Provide Directly
- Account Information: Full name, email address, phone number (mobile and WhatsApp-enabled numbers), password (encrypted), and date of birth when you create a vendor or buyer account
- Business Information: Business name, business registration number (CAC/BN where applicable), business address, tax identification number (TIN), store description, and product listings
- Financial Information: Bank account details (account number, bank name, account holder name) for payout processing. Payment card information is collected and stored exclusively by Paystack (our PCI-DSS compliant payment processor) — Storvly never accesses or stores full payment card details
- Transaction Data: Order history, purchase amounts, payment methods used, refund requests, chargeback disputes, and shipping/delivery information
- Communications Data: Messages sent through our support system, feedback submitted, survey responses, and WhatsApp/SMS opt-in preferences
- Identity Verification Data: Government-issued ID (BVN, NIN, or passport) for KYC/AML compliance where required for high-value transactions or vendor verification
- Content Uploads: Product images, store logos, banners, and custom CSS/HTML for store themes
B. Information Collected Automatically
- Device Information: IP address, browser type and version, operating system, device identifiers (IMEI, advertising ID where applicable), screen resolution, and language preferences
- Usage Information: Pages visited, features used, time spent on platform, search queries, click patterns, session recordings (anonymized), and navigation paths
- Location Data: Approximate geographic location derived from IP address. We do not collect precise GPS coordinates unless explicitly authorized by you
- Cookies & Tracking: Session cookies, authentication tokens, preference cookies, and analytics cookies (see Cookies section for details)
- Log Data: Server logs including access times, error reports, API requests, and system performance metrics for security and debugging purposes
C. Information from Third-Party Sources
- Payment Provider Data: Transaction status updates, payout confirmations, and fraud risk scores from Paystack
- WhatsApp Delivery Data: Message delivery status (sent, delivered, read, failed) and phone number verification status from Meta WhatsApp Business API
- SMS Delivery Data: SMS delivery confirmations and failure reasons from Termii SMS gateway
- Business Verification Data: CAC business registration validation, BVN verification status (where consent provided), and fraud/risk intelligence from third-party verification services
2. How We Use Your Information
We use the information we collect for the following purposes:
Service Delivery & Operations
- Create and manage your vendor or buyer account
- Process transactions, manage subscriptions, and facilitate payouts
- Enable product listings, store customization, and inventory management
- Provide customer support and respond to inquiries
- Send transactional notifications (order confirmations, payment receipts, delivery updates)
Communications & Notifications
- Send one-time passwords (OTP) for account verification and security via SMS and WhatsApp
- Deliver WhatsApp Business messages for order updates, payment confirmations, payout alerts, and account notices (where you have opted in)
- Send SMS notifications as a fallback when WhatsApp delivery fails
- Send technical notices, system updates, policy changes, and security alerts via email
- Send marketing communications about new features, promotions, and platform improvements (opt-out available)
Platform Improvement & Analytics
- Analyze usage patterns to improve platform features and user experience
- Conduct market research, A/B testing, and performance optimization
- Generate aggregated, anonymized statistics and reports
- Track conversion rates, cart abandonment, and sales funnels to help vendors optimize their stores
Security, Fraud Prevention & Compliance
- Detect and prevent fraud, unauthorized access, account takeovers, and prohibited transactions
- Monitor for suspicious activity, chargebacks, and money laundering (AML compliance)
- Verify vendor and buyer identities (KYC) where required by law or for high-risk transactions
- Enforce our Terms of Service and investigate policy violations
- Comply with legal obligations, court orders, regulatory requests, and tax reporting requirements
- Maintain audit logs for dispute resolution and legal proceedings
3. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your information in the following circumstances:
With Third-Party Service Providers
We work with trusted third-party service providers who perform services on our behalf under strict data processing agreements. These include:
- • Paystack Payments Limited — Payment processing, transaction handling, payout settlement, fraud detection, and card tokenization. Regulated by the Central Bank of Nigeria (CBN). Data shared: transaction amounts, order details, customer payment information, bank account details. Paystack Privacy Policy
- • Meta Platforms, Inc. (WhatsApp Business API) — Delivery of transactional WhatsApp messages including order notifications, payment confirmations, OTP codes, and account alerts. Data shared: phone numbers, message content (order details, payment amounts, verification codes), message delivery status. WhatsApp Business Policy
- • Termii Inc. — SMS delivery for OTP verification codes and fallback notifications when WhatsApp is unavailable. Licensed telecommunications service provider. Data shared: phone numbers, SMS message content (verification codes, critical alerts). Termii Privacy Policy
- • Amazon Web Services (AWS) — Cloud hosting infrastructure, database storage, file storage (product images, store assets), backup and disaster recovery. Data shared: all platform data stored on AWS servers located in AWS data centers. AWS Privacy Policy
- • SendGrid / Mailgun (Email Service Providers) — Transactional and marketing email delivery. Data shared: email addresses, email content, delivery status.
- • Google Analytics — Website analytics, user behavior tracking, performance monitoring. Data shared: anonymized usage data, IP addresses (anonymized), device information, page views. Google Privacy Policy
- • Meta Pixel (Facebook Pixel) — Optional vendor tool for storefront analytics and advertising. Data shared (when vendors enable): page visits, product views, add-to-cart events, purchases, user device/browser data. Meta Privacy Center
These service providers are contractually obligated to protect your data, use it only for the purposes specified by us, and comply with applicable data protection laws including Nigeria's NDPR.
With Other Users (Platform Transparency)
Certain information is visible to other platform users for marketplace functionality: vendor store names, business descriptions, product listings, reviews, and ratings. Buyer names and delivery addresses are shared with vendors to fulfill orders.
For Legal Compliance & Safety
We may disclose information if required by Nigerian law, court order, subpoena, or regulatory authority (including NITDA, CBN, EFCC, or law enforcement). We may also disclose information to: (a) protect our legal rights or defend against legal claims, (b) prevent fraud, security threats, or illegal activity, (c) protect the safety of our users or the public, (d) comply with tax reporting obligations (FIRS), or (e) enforce our Terms of Service.
Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice on the platform before your information is transferred and becomes subject to a different privacy policy.
With Your Consent
We may share information with your explicit consent for specific purposes.
4. Messaging & Communications Consent
By creating an account, verifying your phone number, or making a purchase on Storvly, you expressly consent to receive the following types of communications:
OTP & Verification Messages
One-time passwords (OTP) and security codes sent via SMS or WhatsApp for account verification, login authentication, phone number verification, and transaction authorization. These messages are critical for account security and cannot be opted out.
WhatsApp Business Notifications
Transactional notifications delivered via Meta WhatsApp Business API including: new order alerts, payment confirmations, payout notifications, order status updates, failed payout alerts, account security notices, and subscription reminders. These messages are sent to your WhatsApp-enabled phone number after you complete phone verification and opt-in. You may manage your WhatsApp notification preferences in your account settings, but disabling all notifications may impact your ability to receive time-sensitive updates about your store operations.
Data Shared with Meta: Your phone number, message content (order details, amounts, status updates), message ID, delivery timestamps, and read receipts are shared with Meta Platforms, Inc. to facilitate message delivery.
SMS Fallback Notifications
When WhatsApp delivery fails or is unavailable, critical notifications (primarily OTP codes and urgent account alerts) will be sent via SMS through Termii Inc. Standard SMS charges from your mobile carrier may apply. SMS messages are limited to essential, time-sensitive communications only.
Data Shared with Termii: Your phone number, SMS message content, and delivery status.
Transactional Emails
Order confirmations, payment receipts, payout notifications, password reset links, account security alerts, billing invoices, and policy updates. You may not opt out of transactional emails as they are essential to service delivery and compliance with consumer protection laws.
Marketing Communications (Opt-Out Available)
Product announcements, new feature releases, platform updates, promotional offers, educational content, and vendor success tips. You may opt out at any time by: (a) clicking the "Unsubscribe" link at the bottom of any marketing email, (b) adjusting email preferences in your account settings, or (c) emailing unsubscribe@storvly.com. Opt-out requests are processed within 48 hours.
Important: Message delivery depends on factors outside our control, including mobile network availability, phone number validity, WhatsApp account status, and carrier restrictions. Storvly is not liable for non-delivery, delays, or charges imposed by your telecommunications provider. You are responsible for maintaining accurate, up-to-date contact information.
5. Analytics & Tracking Technologies
We use analytics and advertising tools to understand platform usage, measure performance, and improve our services:
Google Analytics
We use Google Analytics to collect aggregated, anonymized data about visitor behavior, traffic sources, page performance, and conversion funnels. Data collected includes: page views, session duration, bounce rates, device types, browsers, geographic location (country/city level), and user flow. IP addresses are anonymized. You can opt out by installing the Google Analytics Opt-out Browser Add-on.
Meta Pixel (Facebook Pixel) — Optional Vendor Tool
Vendors may optionally enable the Meta Pixel on their storefront pages to track advertising effectiveness and build custom audiences for Facebook/Instagram ads. When enabled, Meta Pixel collects: page visits, product views, add-to-cart events, purchases, device data, browser data, and cookie identifiers. This data is shared directly with Meta Platforms, Inc. Visitors can opt out via Meta Ad Preferences or by disabling third-party cookies in their browser.
Performance Monitoring
We use error tracking and performance monitoring tools to identify bugs, measure page load times, and diagnose technical issues. These tools may collect error logs, stack traces, request/response data, and session replays (anonymized).
All analytics data is used solely for service improvement, fraud prevention, and platform optimization. We do not sell analytics data to third parties.
6. Cookies & Similar Technologies
We use cookies, web beacons, local storage, and similar technologies to provide, secure, and improve our services. By using Storvly, you consent to our use of cookies as described below:
Essential Cookies (Always Active)
Required for platform functionality. Include: session authentication tokens, CSRF protection, shopping cart state, language preferences, and security cookies. These cannot be disabled without breaking core features.
Functional Cookies
Remember your preferences: notification settings, dashboard layout, store theme customizations, and recent searches.
Analytics Cookies
Track usage patterns, measure performance, and generate statistics. Managed by Google Analytics and our internal analytics platform.
Advertising Cookies (Vendor-Controlled)
Set by Meta Pixel when vendors enable it on their storefronts. Used for retargeting and conversion tracking.
Managing Cookies: Most browsers allow you to block or delete cookies via settings. Note that disabling essential cookies will prevent you from using core platform features. Instructions: AllAboutCookies.org
7. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements:
Active Account Data
Retained for the duration of your active account plus 90 days after account closure (to handle refunds, chargebacks, and support requests).
Transaction & Financial Records
Retained for 7 years from transaction date to comply with Nigerian tax laws (FIRS), anti-money laundering regulations (EFCC), and accounting standards.
Communications & Support Tickets
Retained for 3 years for dispute resolution, quality assurance, and compliance audits.
Marketing Data & Consent Records
Retained until you withdraw consent or 2 years after last interaction, whichever comes first.
Security Logs & Audit Trails
Retained for 1 year for security monitoring, fraud detection, and incident response.
Anonymized Analytics Data
May be retained indefinitely for research, trend analysis, and service improvement (cannot be linked back to you).
After retention periods expire, we securely delete or anonymize your data. Backups may retain data for an additional 30-90 days before permanent deletion. Some data may be retained longer where required by law or court order.
8. International Data Transfers
Storvly primarily operates within Nigeria, but we use third-party service providers located outside Nigeria that may process your data internationally:
Amazon Web Services (AWS)
Platform data is hosted on AWS infrastructure. While we use AWS regions closest to Nigeria (typically AWS Europe or Middle East), data may be transferred to AWS data centers globally for redundancy, backup, and disaster recovery. AWS complies with international data protection standards including SOC 2, ISO 27001, and GDPR frameworks.
Meta Platforms, Inc. (WhatsApp)
WhatsApp messages are processed by Meta's WhatsApp Business API infrastructure, which operates globally. Meta is headquartered in the United States and subject to U.S. data protection laws. WhatsApp Privacy Policy
Email Service Providers
Transactional emails may be routed through servers located in the United States or Europe operated by SendGrid, Mailgun, or similar providers.
By using Storvly, you acknowledge and consent to the transfer of your data outside Nigeria for the purposes described in this Privacy Policy. We ensure that all international data transfers comply with the Nigeria Data Protection Regulation (NDPR) 2019 requirements, including data transfer agreements, adequate safeguards, and security measures.
9. Nigeria Data Protection Regulation (NDPR) Compliance
Storvly is committed to full compliance with the Nigeria Data Protection Regulation (NDPR) 2019 issued by the National Information Technology Development Agency (NITDA):
Data Controller
Storvly Nigeria Limited (RC: [Company Registration Number]) acts as the Data Controller for all personal data collected and processed through the platform.
Data Protection Officer (DPO)
For data protection inquiries, complaints, or to exercise your NDPR rights, contact our Data Protection Officer at: dpo@storvly.com
Lawful Basis for Processing
We process your data based on: (a) your consent (e.g., marketing emails, WhatsApp notifications), (b) contractual necessity (to provide services you requested), (c) legal obligation (tax compliance, KYC/AML), and (d) legitimate business interests (fraud prevention, platform security).
Data Subject Rights
You have rights under NDPR including access, rectification, erasure, objection, data portability, and withdrawal of consent. See "Your Rights" section for full details.
NITDA Audit Registration
Storvly maintains ongoing compliance with NITDA's data protection audit and registration requirements.
10. Data Security
We implement comprehensive technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:
Technical Safeguards
TLS/SSL encryption for data in transit (HTTPS), AES-256 encryption for data at rest, bcrypt password hashing, encrypted database connections, secure API authentication (OAuth 2.0, JWT tokens), DDoS protection (Cloudflare), firewall configurations, intrusion detection systems (IDS), and regular security patching.
Organizational Safeguards
Role-based access controls (RBAC), multi-factor authentication (MFA) for staff access, background checks for employees with data access, confidentiality agreements, security awareness training, incident response procedures, and third-party security audits.
Payment Security
All payment card data is handled exclusively by Paystack, a PCI-DSS Level 1 certified payment processor. Storvly never stores, processes, or has access to full payment card numbers.
Limitations
While we use industry-standard security measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security and are not liable for unauthorized access resulting from circumstances beyond our reasonable control (e.g., sophisticated cyber attacks, zero-day exploits). You are responsible for maintaining the security of your account password and login credentials.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
Notify Regulatory Authorities
Report the breach to NITDA within 72 hours of discovery, as required by NDPR.
Notify Affected Users
Inform you without undue delay via email, in-app notification, or prominent website notice if the breach is likely to result in high risk to your rights (e.g., exposure of passwords, financial data, or sensitive personal information).
Mitigation & Remediation
Take immediate action to contain the breach, assess impact, implement security patches, and provide guidance on protective measures you can take (e.g., password reset, monitoring for fraud).
You can report suspected security incidents to our security team at: security@storvly.com
12. Your Rights Under NDPR
Under the Nigeria Data Protection Regulation (NDPR) 2019, you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you. We will provide this within 30 days in a commonly used electronic format.
Right to Rectification
Update or correct inaccurate or incomplete personal information. Most data can be updated directly in your account settings.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data where: (a) it is no longer necessary for the purposes collected, (b) you withdraw consent and there is no other legal basis, (c) you object and there are no overriding legitimate grounds, or (d) the data was unlawfully processed. Note: we may be required to retain certain data to comply with legal obligations (tax, fraud prevention, dispute resolution).
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.
Right to Data Portability
Receive your personal data in a structured, commonly used, machine-readable format (JSON, CSV) and transmit it to another service provider where technically feasible.
Right to Withdraw Consent
Withdraw your consent for processing at any time (for WhatsApp notifications, marketing emails, etc.) without affecting the lawfulness of processing based on consent before withdrawal.
Right to Lodge a Complaint
File a complaint with NITDA if you believe your data rights have been violated: nitda.gov.ng | Email: info@nitda.gov.ng
To Exercise Your Rights: Email our Data Protection Officer at dpo@storvly.com or submit a request via your account settings. We will respond within 30 days. Identity verification may be required to protect against fraudulent requests.
13. Children's Privacy
Our service is not intended for individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at dpo@storvly.com. We will take steps to delete such information from our systems within 7 business days.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will notify you by:
- • Sending an email to your registered email address at least 30 days before changes take effect
- • Displaying a prominent notice on the platform homepage and dashboard
- • Updating the "Last updated" date at the top of this page
Continued use of Storvly after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you may close your account within the notice period by contacting support@storvly.com.
We recommend reviewing this Privacy Policy periodically for any changes. Previous versions are available upon request by contacting our Data Protection Officer.
Questions About Privacy or Data Protection?
If you have any questions about this Privacy Policy, how we handle your data, or wish to exercise your NDPR rights, please contact us:
Data Protection Officer: dpo@storvly.com
General Support: support@storvly.com
Security Incidents: security@storvly.com