Privacy Policy
Effective Date: February 2026
Version: v1.0-2026-02
1. Data Controller Identity
Credit Nigeria operates as the data controller responsible for your personal data processed through this platform. As the data controller, we determine the purposes and means of processing your personal information in accordance with the Nigeria Data Protection Act (NDPA) 2023.
For any questions or concerns regarding how we handle your data, please contact our Data Protection Officer at privacy@creditnigeria.com.
2. Lawful Basis for Processing
We process your personal data based on your explicit consent, as required by NDPA Section 25. When you submit a loan application through our platform, you provide informed, freely given, specific, and unambiguous consent to the processing of your personal data.
Your consent is recorded with the following details for audit purposes:
- Timestamp of consent (date and time of submission)
- IP address at the time of consent
- Consent version identifier (to track policy changes)
You may withdraw your consent at any time. See Section 12: Consent Withdrawal for details.
3. Categories of Personal Data Collected
We collect and process the following categories of personal data when you use our loan matching service:
Personal Information
- Full name (first name and surname)
- Email address
- Work email address (if provided)
- Phone number
- Date of birth
- State of residence
Identity Verification
- Bank Verification Number (BVN) — stored only as a SHA-256 cryptographic hash, never in plain text
Employment Information
- Employment status
- Employer name
- Monthly salary
- Employment duration
Financial Information
- Existing loan obligations
- Monthly loan repayment amounts
- Loan default history
- Debt-to-income ratio (calculated from your inputs)
Bank Data (Optional)
If you choose to complete bank verification through our Mono integration, the following data may be accessed and stored:
- Your bank statement document (PDF), which is securely stored in our cloud storage for verification purposes
- Transaction summaries (derived from AI analysis of the statement)
- Income patterns
- Spending analysis
Technical Data
- IP address (used for CAPTCHA verification and rate limiting)
- Browser information (used for bot protection via Cloudflare Turnstile)
4. Purpose of Processing
Your personal data is processed for the following purposes:
- Loan matching: Comparing your profile against lender eligibility criteria to identify suitable loan offers
- Identity verification: Verifying your identity through your BVN and bank account information
- Credit assessment: AI-powered analysis of bank statements to assess your financial health and verify self-reported income, including analysis of spending patterns such as gambling activity, which some lenders use as an eligibility criterion
- Communication: Sending application status updates and reminders via SMS (primary channel, delivered by BulkSMS Nigeria) with email as automatic fallback. SMS opt-out is available at any time by replying STOP to any message, or by emailing privacy@creditnigeria.com.
- Security: Fraud prevention, duplicate application detection, rate limiting, and bot protection
- Legal compliance: Meeting Nigerian financial regulatory requirements
5. Third-Party Data Processors
We share your data with the following third-party processors to deliver our service. Each processor is bound by data processing agreements and is authorized to process data only for the stated purpose.
Mono (Nigeria)
Service: Bank account linking, identity verification, and bank statement retrieval.
Data shared: BVN (for identity verification only), bank account access token.
Purpose: Income verification and identity matching.
OpenAI (United States)
Service: AI-powered bank statement analysis.
Data shared: Anonymized transaction summaries only. No names, account numbers, or other personally identifiable information is sent to OpenAI.
Purpose: Assess monthly income, loan repayment patterns, and spending analysis.
Note: This involves a cross-border data transfer to the United States. See Section 6.
Resend (United States)
Service: Transactional email delivery (automatic fallback channel when SMS is unavailable, opted out, or rate limited; also the primary channel for lender-side notification emails).
Data shared: Email address, first name, and lender name (in confirmation emails).
Purpose: Sending application status notifications and lender selection confirmations when SMS delivery is not possible.
Note: Cross-border transfer to the United States.
BulkSMSNigeria.com Ltd (Nigeria)
Service: Transactional SMS delivery — the primary channel we use to keep you informed about your loan application (welcome, forwarded, approval, rejection, reassignment, disbursement, and reminder messages).
Data shared: Your Nigerian mobile phone number (in E.164 format), your first name, and the message body for the specific application event. No BVN, bank data, salary, employer name, or AI analysis results are shared.
Purpose: Delivering operational status updates and reminders related to your loan application.
Sub-processors: BulkSMS Nigeria routes messages via the four Nigerian Mobile Network Operators (MTN, Glo, Airtel, 9mobile) for the final delivery leg.
Opt-out: Reply STOP to any SMS from us at any time, or email privacy@creditnigeria.com. When opted out, we will fall back to email for any operational notifications you have not also opted out of.
Note: BulkSMS Nigeria is Nigeria-based, so this processing occurs in-country (no cross-border transfer).
Cloudflare (United States)
Service: Turnstile CAPTCHA bot protection.
Data shared: IP address and browser fingerprint.
Purpose: Preventing automated abuse of the application form.
Note: Cross-border transfer to the United States.
Upstash (United States)
Service: Rate limiting service.
Data shared: IP address and hashed access tokens. No personally identifiable information is stored.
Purpose: Preventing abuse and ensuring fair access to the platform.
Note: Cross-border transfer to the United States.
Supabase (United States)
Service: Database, file storage, and authentication infrastructure.
Data shared: All application data as described in Section 3.
Purpose: Secure data storage, management, and real-time status updates.
Note: Cross-border transfer to the United States.
Vercel (United States)
Service: Application hosting and edge network delivery.
Data shared: IP address, request metadata, and application traffic routed through Vercel's global edge network.
Purpose: Hosting the Credit Nigeria web application and delivering content with low latency.
Note: Cross-border transfer to the United States.
Lender Partners (Nigeria)
Service: Loan processing, underwriting, and disbursement.
Data shared: Full application details, including personal, employment, financial, and bank verification data.
Purpose: Loan evaluation and processing.
Important: Your data is shared with a specific lender only after you explicitly select that lender from the list of matched offers. You choose which lender receives your information.
6. Cross-Border Data Transfers
Several of our data processors — OpenAI, Resend, Cloudflare, Upstash, Supabase, and Vercel — process data outside Nigeria, in the United States.
Legal basis: These transfers are conducted in accordance with NDPA Section 43, on the grounds that the transfer is necessary for the performance of a contract between you (the data subject) and Credit Nigeria (the data controller).
All US-based processors maintain industry-standard security certifications, including SOC 2 and ISO 27001 where applicable. We have entered into Data Processing Agreements with these processors that include appropriate safeguards for your personal data.
7. BVN Handling
Your Bank Verification Number (BVN) is treated with the highest level of security:
- Your raw BVN is not stored by our application — only a SHA-256 cryptographic hash is used for duplicate detection, and a separate verified hash from bank verification is stored for audit purposes.
- The initial BVN hash is used solely for duplicate application detection — ensuring you do not have a conflicting active application.
- During bank verification through Mono, a separate verified BVN hash is generated and stored to maintain an audit trail of identity verification.
- Your BVN is used only for identity verification with your chosen lender and is transmitted securely to Mono's Identity API for this purpose.
8. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. The following retention periods apply:
- Access tokens: 7 days from creation. After expiry, tokens can no longer be used to access your application.
- Duplicate check window: 30 days. This is the lookback period used to detect conflicting active applications — it does not determine how long BVN hashes are retained. BVN hashes are retained for the duration of the application record (90 days for unmatched applications, 1 year for matched applications).
- Application data (unmatched or not qualified): 90 days after submission, then archived.
- Application data (matched and forwarded to a lender): Applications that have been matched or forwarded to a lender are archived 1 year after the last activity on the application.
- Data subject request records: 3 years, in compliance with regulatory requirements.
- Consent records: Retained as long as the associated application data exists, plus 1 year after archival, to demonstrate lawful processing.
9. Data Subject Rights (NDPA Sections 34-40)
Under the Nigeria Data Protection Act 2023, you have the following rights regarding your personal data:
- Right to access: You may request a copy of all personal data we hold about you.
- Right to rectification: You may request correction of any inaccurate or incomplete personal data.
- Right to erasure (deletion): You may request deletion of your personal data, subject to legal retention requirements.
- Right to restriction: You may request that we limit the processing of your personal data in certain circumstances.
- Right to data portability: You may request to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to object: You may object to the processing of your personal data for specific purposes.
- Right to withdraw consent: You may withdraw your consent at any time, without affecting the lawfulness of processing that occurred before withdrawal.
How to exercise your rights: Submit a Data Subject Access Request by visiting our data request page or by emailing privacy@creditnigeria.com.
Response timeline: We will respond to all valid requests within 30 days of receipt. If a request is particularly complex, we will notify you of any extension within the initial 30-day period.
10. Automated Decision-Making
Credit Nigeria uses AI-powered bank statement analysis to assess your financial health. This automated analysis evaluates:
- Monthly salary patterns and income consistency
- Existing loan repayment history
- Gambling activity and expenditure patterns
- Overall financial stability
This analysis contributes to — but does not solely determine — lender matching decisions. Lender eligibility criteria (such as minimum salary thresholds, state of residence, and employment status) also play a significant role in determining your matched offers.
Your right to human review: You have the right to request human review of any decision that was significantly influenced by automated processing. To request a review, contact us at privacy@creditnigeria.com.
11. Security Measures
We implement a range of technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- SHA-256 hashing for sensitive identifiers (BVN) to prevent plain-text storage
- Row-Level Security (RLS) policies on all database tables, ensuring users and lenders can only access data they are authorized to view
- Rate limiting on all API endpoints to prevent abuse and brute-force attacks
- HMAC-SHA512 webhook signature verification to authenticate incoming data from third-party processors
- UUID-based access tokens that are cryptographically random and not guessable
- AI prompt injection defense for bank statement analysis to prevent manipulation of automated assessments
- CAPTCHA protection (Cloudflare Turnstile) on form submissions to prevent bot abuse
12. Consent Withdrawal
You have the right to withdraw your consent to data processing at any time. To do so:
- Email privacy@creditnigeria.com with the subject line "Consent Withdrawal"
- Or submit a request through our data request page
- SMS-only opt-out: Reply STOP to any SMS message you receive from us. This opts you out of further SMS notifications immediately. We will continue to send essential operational notices by email unless you also withdraw email consent above.
Important: Withdrawing your consent does not affect the lawfulness of any processing that occurred before the withdrawal. However, withdrawal may result in our inability to continue providing the loan matching service, as data processing is essential to matching you with suitable lenders.
13. Children's Data
Our service is restricted to persons aged 18 years and above. We do not knowingly collect, process, or store personal data from any person under the age of 18.
If we become aware that we have inadvertently collected data from a person under 18, we will take immediate steps to delete that data and close the associated application.
14. Complaint Rights
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
The NDPC is the regulatory body responsible for enforcing the Nigeria Data Protection Act 2023. You can contact the NDPC through their website at ndpc.gov.ng (opens in a new tab).
We encourage you to contact us first at privacy@creditnigeria.com so that we may attempt to resolve your concern directly.
15. Policy Updates
This privacy policy may be updated from time to time to reflect changes in our data processing practices, legal requirements, or service offerings.
The "Effective Date" and "Version" at the top of this page will be updated to reflect the latest revision.
For material changes to this policy, we will notify you via the email address associated with any active application and may require you to review and accept the updated terms. We will not rely on continued use as a substitute for explicit consent.