Your information, handled with care

Privacy Policy

This policy explains what Thapi collects, why we use it, who processes it, and the choices available to you.

Effective 26 August 2026 · Version 1.0

Identity checks
BVN or NIN + selfie
Bank records retained
Minimised details
Privacy contact
privacy@thapi.app
01

Scope and who we are

This Privacy Policy applies to the Thapi website, applications, protected transaction links, support channels, and related services. Thapi determines how personal information is used for operating the platform, subject to applicable Nigerian data-protection law.

When a specialist provider independently determines how it handles information, its own privacy notice may also apply. We encourage you to read provider notices presented during identity, banking, or payment flows.

02

Information we collect

We collect only information reasonably needed to provide, secure, and improve protected transactions.

  • Account information, including email address, authentication records, temporary Thapi ID, avatar, and Google profile information when you choose Google sign-in.
  • Identity-verification information, including BVN or NIN method, legal name, last four digits, selfie and liveness results, photo-match results, provider references, and verification status.
  • Banking information used for account resolution and payouts, including bank, account number submitted for resolution, resolved account name, last four digits, match score, and payout status.
  • Transaction information, including buyer and seller roles, invite details, product or service terms, price, fees, attachments, delivery evidence, status, messages, disputes, refunds, and payouts.
  • Technical and support information, such as IP address, device and browser signals, timestamps, security events, diagnostics, and communications with support.
03

How we receive information

We receive information directly from you, from the counterparty to a protected order, from Google when you use Google sign-in, and from service providers that confirm identity, bank account, payment, delivery, fraud, or compliance events.

A buyer or seller may provide an intended counterparty’s email, phone number, or social contact when creating a protected invitation. The recipient can review the invitation before joining or accepting an order.

04

Why we use personal information

We process information to provide accounts and transactions, verify identity and payout ownership, calculate and display fees, communicate order events, prevent fraud, investigate disputes, comply with legal duties, maintain records, secure the service, and improve reliability.

Depending on the activity, our lawful basis may be performance of a contract, compliance with a legal obligation, your consent where required, or our legitimate interests in running a safe service where those interests do not override your rights.

05

Google sign-in data

If you choose Continue with Google, Google provides basic account information such as your Google account identifier, email address, name, and profile image. We use it only to authenticate you, create or link your Thapi account, protect sessions, and provide account support.

Thapi does not request access to your Gmail, Google Drive, contacts, calendar, or other sensitive Google services for ordinary sign-in. We do not sell Google user data or use it for targeted advertising.

06

BVN, NIN, selfie, and identity checks

Identity details and selfie information are submitted to our identity-verification provider, currently Dojah, to validate the identifier, perform liveness and photo matching, retrieve a verified legal name, and detect duplicate or suspicious identities.

Thapi’s application records are designed not to retain the complete BVN or NIN after verification. We retain minimised results such as the method, last four digits, a protected identity fingerprint, legal name, scores or outcomes, provider references, timestamps, and audit events. The provider may retain information under its own notice and legal obligations.

07

Bank resolution and payments

Bank details are submitted to our bank-resolution provider, currently Paystack, to confirm the account name and compare it with your verified identity. Thapi retains the bank, resolved name, last four digits, verification result, and related audit information rather than the complete account number in its application records.

Payment and payout providers may process account, transaction, and compliance information under their own privacy notices. Thapi does not ask for or store your card PIN, online banking password, or one-time banking password.

08

How information is shared

We share information only where needed to provide the service, protect users, comply with law, or complete a transaction.

  • With Supabase for authentication, database, storage, and backend services; Vercel for application hosting; Dojah for KYC; Paystack and other approved financial providers for account resolution, collections, and payouts.
  • With the other party to an order, limited to information needed to understand the counterparty, agreed terms, transaction status, delivery, and dispute. We do not expose full BVN, NIN, selfie, or bank account number to the counterparty.
  • With professional advisers, auditors, insurers, regulators, law-enforcement bodies, courts, or authorities where reasonably necessary or legally required.
  • In connection with a genuine corporate restructuring, financing, acquisition, or transfer, subject to appropriate confidentiality and data-protection safeguards.
09

International processing

Some technology providers may process or store information outside Nigeria. Where personal information is transferred internationally, we take reasonable steps to use lawful transfer mechanisms, contractual protections, access controls, and providers with appropriate security commitments.

10

How long we keep information

We retain account and transaction records for as long as needed to provide the service and meet fraud-prevention, dispute, audit, tax, anti-money-laundering, regulatory, and legal requirements. Retention length depends on the record, order status, provider rules, and applicable law.

When information is no longer required, we delete, anonymise, or securely isolate it, unless a legal hold, unresolved dispute, fraud investigation, or enforceable obligation requires longer retention. Closing an account does not automatically erase records we are legally required to keep.

11

How we protect information

We use layered safeguards including authenticated access, row-level data controls, limited provider permissions, encrypted transport, secret management, audit records, minimised identity and bank records, rate limits, and monitoring appropriate to the service.

No online system is completely risk-free. You should use a strong password, protect your email and device, avoid sharing verification codes, and report suspected account compromise promptly.

12

Your rights and choices

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or information about how your personal data is used. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.

We may need to verify your identity before acting on a request, and some rights may be limited by legal, security, fraud-prevention, or recordkeeping duties. You may also lodge a complaint with the Nigeria Data Protection Commission.

13

Children’s privacy

Thapi is intended for adults aged 18 and over. We do not knowingly create accounts for children or process their identity for protected transactions. Contact us if you believe a child has provided information to Thapi.

14

Updates and contact

We may update this Policy as our service, providers, or legal obligations change. We will publish the revised effective date and provide additional notice where a change is material.

For privacy questions or rights requests, email privacy@thapi.app. For transaction support, use the Help area in your Thapi account or email support@thapi.app.