Skip to content
cartinary

Privacy policy

What we hold about you, and why

This policy names the data we actually store, the five companies that receive some of it, how long we keep it, and what you can require us to do. It is written to be checked against, not skimmed.

Cartinary Limited · In effect from 22 August 2026

1. Who is responsible for your data

Cartinary Limited, of 14b Lisabi Crescent, Lagos, Nigeria, is the data controller for the platform. Write to us about anything in this policy at connect@cartinary.com.

There is a division of responsibility worth understanding. For your account, your verification details and the running of the platform, we are the controller. For a shopper’s order placed on a merchant’s storefront, the merchant is a controller of that shopper’s details in their own right, and decides how they market to them. We process that data to run the storefront and take the payment.

We handle personal data under the Nigeria Data Protection Act 2023. If you think we have got something wrong you can complain to us, and you can complain to the Nigeria Data Protection Commission.

2. What we collect

Rather than describe categories loosely, here is what is stored.

AboutWhat we holdWhere it comes from
Your accountFirst and last name, email address, password (stored only as a bcrypt hash), phone number if you give one, profile photo, whether your email and phone are verified, and your notification token if you allow push notifications.You, at signup — or from Google if you sign in with Google.
Your businessBusiness name, type, description, contact email and phone, social media links, and an office address if you add one.You.
Your staffName, email address, phone number, assigned role and invitation status for anyone you invite to your team.You, when you invite them.
Verification (merchants)Bank account number, bank name and code, the account name returned by the bank, your BVN, and a payout recipient reference. If you choose to add them: a National Identification Number and a corporate registration number, each with an optional supporting document.You, and our payment processor’s verification response.
MoneyYour wallet balance, a hashed wallet PIN, and a ledger of every credit and debit with its reference, narration and status.Generated as you transact.
OrdersItems bought, quantities and prices, order reference, payment status and method, amounts paid, and the delivery address given at checkout.The shopper, at checkout.
Shoppers (for merchants)Name, email address, phone number and delivery addresses, held against the merchant they bought from. A shopper who checks out as a guest still has a customer record.The shopper, at checkout.
AddressesStreet address, city, state, country and a place reference. Map coordinates may be sent by the address picker but are not stored.You, via Google Places lookup.
Signing inRefresh tokens with an expiry and whether they have been revoked, and one-time codes sent to verify your email, which are deleted once used.Generated when you sign in.

We do not store your card details. Card data is entered with our payment processor and never reaches our servers. We receive only the outcome of a payment, and a masked reference to the card used.

We run no advertising trackers and no third-party analytics on this site. Cookies are used to keep you signed in and to remember your theme; that is all they do.

3. Why we hold it, and on what basis

PurposeLawful basis
Creating and running your account, hosting your storefront, processing orders and paying you out.Performance of our contract with you.
Verifying your identity and bank account before we release money.Legal obligation, and our legitimate interest in preventing fraud and money laundering.
Keeping the platform secure — rate limiting, detecting abuse, investigating disputes.Our legitimate interest in protecting users and the platform.
Transactional email: order confirmations, payout notices, security and account notices.Performance of our contract. You cannot opt out of these while you hold an account.
Product news and marketing email.Your consent. Every such message carries an unsubscribe link.
Meeting our accounting, tax and regulatory obligations.Legal obligation.

We do not sell personal data, and we do not make decisions about you by automated means alone that have a legal effect on you.

4. Who else receives it

These are the companies that receive personal data because the platform genuinely depends on them. Each is bound to use it only to provide their service to us.

WhoWhat they receiveWhy
Paystack (Nigeria)Name, email, phone, bank account number and code, BVN, and payment and transfer records.Taking payments, verifying bank accounts and BVNs, and sending payouts.
Amazon Web ServicesEmail addresses and message contents; uploaded files including product images and any verification document you attach.Sending our email, and storing files.
GoogleYour Google account email and basic profile if you sign in with Google; the address text you type into an address field.Sign-in, and address lookup.
Firebase Cloud Messaging (Google)A device notification token, and the contents of the notification.Delivering push notifications, if you allow them.
SentryTechnical error reports. We deliberately keep recipient email addresses out of these.Finding and fixing faults.

Beyond that, we share data where the law requires it, where a court or regulator directs us, where we need to establish or defend a legal claim, and — if the business is ever sold or merged — with the acquirer, who would be bound by this policy.

Some of these providers operate outside Nigeria, so your data may be processed abroad. Where it is, we rely on the transfer safeguards permitted by the Nigeria Data Protection Act 2023 and on the contractual protections in our agreements with them.

5. How long we keep it

  • Account and business records: while your account is open, and for six years after it closes, because transaction and tax records must be retained.
  • Verification records, including bank details and BVN: six years from the last transaction, to meet anti-money-laundering record-keeping obligations.
  • Orders and the money ledger: six years, for accounting and dispute purposes.
  • One-time verification codes: deleted as soon as they are used or expire.
  • Refresh tokens: until they expire or you sign out, whichever comes first.
  • Error reports: kept short-term for diagnosis, then discarded.

When you close an account we mark it deleted and remove it from the product. Records we are obliged to retain are kept for the periods above and then removed.

Being straight about a limitation: erasure and a copy of your data are handled by our team on request rather than by a button in the product. We are building both as self-service. Until then, ask us and we will do it.

6. What you can require of us

Under the Nigeria Data Protection Act 2023 you may ask us to:

  • Tell you what we hold about you, and give you a copy.
  • Correct anything inaccurate.
  • Delete what we hold, where we are not obliged to keep it.
  • Restrict or stop a particular use, including marketing.
  • Provide your data in a portable form, or send it to someone else.
  • Withdraw a consent you previously gave.

Email connect@cartinary.com and say what you want. We will confirm receipt and respond within 30 days. We may ask you to confirm your identity first — that check protects you, not us. If we cannot do what you have asked, we will explain why.

If a merchant holds your data because you bought from their storefront and you want it removed, tell us and we will pass the request on and follow up.

7. How we protect it

The measures in place today:

  • Passwords are stored only as bcrypt hashes. Nobody at Cartinary can read your password.
  • Wallet PINs are hashed, and repeated wrong attempts lock the wallet for a period.
  • Sessions use short-lived access tokens with refresh tokens we can revoke.
  • Requests are rate limited to blunt automated abuse and credential stuffing.
  • Payment webhooks are rejected unless their cryptographic signature verifies.
  • Uploaded files are served through expiring signed links rather than public URLs.
  • Traffic is encrypted in transit, and addresses that bounce or complain are suppressed so we stop mailing them.

No system is perfectly secure. If a breach occurs that is likely to harm you, we will tell you and the Nigeria Data Protection Commission as the Act requires.

8. Cookies and technical data

We use cookies for two things only, and neither of them tracks you across the internet.

  • Signing you in. A cookie holds your session so you are not asked for your password on every page. Blocking it will stop you being able to sign in.
  • Remembering your choice of light, dark or system appearance. This one is stored in your own browser and never sent to us.

We run no advertising cookies, no third-party analytics, no marketing pixels and no cross-site tracking. There is no consent banner on this site because there is nothing to consent to beyond the cookie that signs you in.

Separately, our servers and our hosting provider keep ordinary technical logs of requests — an IP address, a timestamp, a URL, a browser identifier. Our application does not record your IP address against your account. Those logs exist to keep the service secure and to diagnose faults, and they are held short-term.

9. Children

Cartinary is not for anyone under 18 and we do not knowingly collect children's data. If you believe a child has given us personal data, tell us at connect@cartinary.com and we will delete it.

10. Changes to this policy

When this policy changes we update the date at the top. For a change that materially affects how we use your data, we will tell account holders by email before it takes effect.