Payth logo
Effective 10 Aug 2026
Statement 01 · Privacy

Privacy Policy

This explains what Payth collects, why, and how it's protected — in plain terms, the way we'd want it explained to us.

01

Who this covers

This policy applies to everyone who uses the Payth mobile app or related services ("Payth", "we", "us"). By creating an account, you agree to the collection and use of information as described here. If you don't agree, please don't use the app.

Payth is operated by [Your Company Legal Name], registered in Nigeria. We process personal data in line with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Commission's (NDPC) regulations.

02

Information we collect

  • Identity & KYC data — full name, date of birth, phone number, email, BVN, government ID, and a selfie/liveness photo, collected to verify who you are, as required by CBN and NDPC rules for financial services.
  • Account & security data — your PIN (stored as an irreversible hash, never in plain text), OTP verification records, and device identifiers used to secure sign-in.
  • Financial & transaction data — account balances, transfer history, beneficiary details, amounts, fees, and stamp duty applied on eligible transfers.
  • Device & usage data — device model, OS version, app version, crash logs, IP address, and general app-usage patterns.
  • Support data — anything you share when you contact us for help.
03

How we use it

  • To create and secure your account, and verify your identity before enabling transfers.
  • To process transactions — bank transfers, virtual account funding, and fee/stamp duty calculation.
  • To detect and prevent fraud, unauthorised access, and money-laundering activity.
  • To meet our regulatory obligations to the Central Bank of Nigeria and other authorities.
  • To send transaction alerts, OTPs, and service notices — and, only with your consent, product updates.
  • To improve app stability and performance using crash and usage data.
04

Who we share it with

We don't sell your personal data. We share only what's needed, with:

  • Payment processing partners (including Paystack and our payment processor Bachs) — to create virtual accounts, move funds, and confirm payments via webhook.
  • Banking partners — to complete the bank transfers you initiate.
  • Regulators and law enforcement — where required by Nigerian law, such as CBN reporting obligations or a lawful request.
  • Service providers who host our infrastructure or support our operations, bound by confidentiality obligations.
05

How we protect it

Sensitive data is encrypted in transit (TLS) and at rest. PINs are hashed, never stored or transmitted as plain text. Webhook calls from payment partners are verified with HMAC-SHA512 signatures before we trust them, and transaction updates are processed with idempotency checks and database transactions so balances can't be double-counted or corrupted.

Session credentials on your device are kept in secure, encrypted device storage rather than plain app storage.

06

How long we keep it

We retain KYC and transaction records for as long as your account is active, and for a minimum retention period afterward as required by CBN/NDPC recordkeeping rules — typically not less than five years after account closure. You can request deletion of data we're not legally required to retain (see Section 08).

07

Your rights

  • Access the personal data we hold about you.
  • Ask us to correct inaccurate information.
  • Withdraw consent for non-essential processing (e.g. marketing messages).
  • Request deletion of data that isn't subject to a legal retention requirement.
  • Lodge a complaint with the Nigeria Data Protection Commission.
To exercise any of these, contact us at [support@paythy.xyz]. We'll respond within the timeframe required by the NDPA.
08

Children's privacy

Payth is intended for users 18 and older, in line with standard eligibility for financial accounts. We don't knowingly collect data from anyone under 18. If we learn we have, we'll delete it.

09

Changes to this policy

We'll update the "Effective" date at the top whenever this policy changes, and notify you in-app for material changes before they take effect.

Questions about your data?

Reach our data protection contact at [privacy@payth.app] or write to [Your Company Legal Name, registered address].

Statement 02 · Terms

Terms of Service

The agreement between you and Payth for using the app to hold a balance, fund it, and send transfers.

01

Acceptance

By registering for or using Payth, you agree to these Terms and to our Privacy Policy. If you're using Payth on behalf of a business, you confirm you have authority to bind that business to these Terms.

02

What Payth does

Payth provides a mobile wallet with a dedicated virtual account, allowing you to fund your balance, view transaction history, and send bank transfers within Nigeria, subject to applicable transfer fees and government-mandated stamp duty on qualifying transactions. Payth is a technology platform; underlying payment processing and settlement is carried out by our licensed payment processing partners.

03

Eligibility

  • You must be at least 18 years old and legally able to enter a binding contract.
  • You must complete identity verification (KYC) before you can fund your account or transact.
  • You must provide accurate, current information and keep it up to date.
04

Your account & security

You're responsible for keeping your login credentials, PIN, and OTPs confidential, and for all activity carried out under your account. Tell us immediately at [support@paythy.xyz] if you suspect unauthorised access. We may require re-verification (OTP or PIN) for sensitive actions like transfers or changing account details.

05

Fees & charges

Transfers may attract a service fee and, where applicable under Nigerian law, a stamp duty charge on qualifying transactions. Fees are shown before you confirm any transfer, so you always see the total cost before you send. Fees may change from time to time; changes will be reflected in-app before you confirm a transaction.

06

Acceptable use

You agree not to use Payth for:

  • Money laundering, terrorism financing, or any other unlawful financial activity.
  • Fraud, or transactions involving stolen funds or accounts.
  • Attempting to reverse-engineer, tamper with, or interfere with the app or its security.
  • Any purpose that violates Nigerian law or CBN regulations.

We may suspend or close accounts that violate this section, and may report suspicious activity to relevant authorities.

07

Third-party services

Payth relies on regulated third-party partners — including Paystack and our payment processor Bachs — to move and settle funds. Their own terms may also apply to the processing of a given transaction. We're not responsible for delays or failures caused by a partner's systems, but we'll work with you to resolve issues raised through them.

08

Liability

Payth is provided "as is." To the extent permitted by Nigerian law, we're not liable for indirect or consequential losses arising from your use of the app, service interruptions, or third-party payment delays outside our control. Nothing in these Terms limits liability that cannot be limited under Nigerian law.

09

Suspension & termination

You may close your account at any time by contacting support, subject to settling any outstanding balance. We may suspend or close accounts for suspected fraud, legal/regulatory reasons, or breach of these Terms, and will notify you where we're able to.

10

Governing law

These Terms are governed by the laws of the Federal Republic of Nigeria. Disputes will first be raised with our support team; unresolved disputes are subject to the exclusive jurisdiction of Nigerian courts.

11

Changes to these Terms

We may update these Terms as Payth evolves. We'll flag material changes in-app before they take effect; continued use after that point means you accept the updated Terms.

Need help?

Contact support at [support@paythy.xyz] for anything to do with your account, a transfer, or these Terms.

Statement 03 · Data safety

Data Safety

A straight answer to what app stores ask: what's collected, whether it's shared, and how it's secured. Use this to complete Google Play's Data Safety form and Apple's App Privacy (nutrition label) questions.

01

Data collected

Category Examples Purpose Optional?
Name & contact info Full name, email, phone number Account creation, verification, alerts Required
Identity documents BVN, government ID, selfie/liveness KYC / regulatory identity verification Required
Financial info Balance, transaction history, beneficiary details Providing the wallet & transfer service Required
Authentication data PIN (hashed), OTP records Account & transaction security Required
Device identifiers Device model, OS, app version, IP Security, fraud prevention, diagnostics Required
App activity Crash logs, in-app actions Stability & performance improvement Required
02

Data shared with third parties

Recipient Data shared Reason
Paystack Identity, transaction data Virtual account creation, payment settlement
Bachs (payment processor) Transaction data Processing transfers & webhooks
Partner banks Beneficiary & transfer details Completing bank transfers
Regulators (CBN / NDPC) KYC & transaction records, where legally required Regulatory compliance

We do not sell personal data, and we do not share data with advertisers.

03

Security practices

  • Encrypted in transit All data sent over TLS.
  • Encrypted at rest Sensitive fields encrypted in the database.
  • PIN hashing PINs are never stored or logged in plain text.
  • Webhook verification Inbound payment events verified via HMAC-SHA512 before being trusted.
  • Secure device storage Session tokens kept in encrypted on-device storage, not plain app storage.
  • User-initiated deletion You can request account and data deletion, subject to regulatory retention rules.
04

Requesting deletion

Email [support@paythy.xyz] from your registered address to request account closure and data deletion. We'll delete everything we're not legally obligated to retain (KYC and transaction records fall under mandatory CBN/NDPC retention periods and will be securely retained, then deleted, per that schedule).

05

Store submission checklist

  • Google Play Data Safety form: use Section 01 (Data collected) and 02 (Data shared) to answer the collection/sharing questions, and Section 03 for the "data is encrypted in transit" and "you can request data deletion" toggles.
  • Apple App Privacy "nutrition label": map Section 01 rows to Apple's categories (Contact Info, Financial Info, Identifiers, Diagnostics, User Content) and mark Financial Info / Identity as "Used to track you: No" unless that changes.
  • Host this page at a public URL and link it in both store listings' Privacy Policy field.
Placeholders in brackets — company legal name, registered address, and contact emails — need your real details filled in before submission.