Privacy Policy
Last updated: September 23, 2026
1. Introduction
This Privacy Policy explains what personal data Cashflow collects, why, how we use and protect it, and the choices and rights you have. It applies to everyone who uses Cashflow — account holders, their team members, and, where relevant, the customers and vendors whose details a business stores in the platform. It should be read together with our Terms of Service.
2. Information we collect
Information you give us directly:
- Account details — name, email address, password (stored hashed, never in plain text), and phone number where provided;
- Business details — business name, address, phone, email, tax identification (TIN), registration (RC) number, bank details, and branding assets (logo, signature) you upload;
- Business records you create — customers, vendors, employees, items, documents, payments, journal entries, bank transactions and similar records, which may include personal data about your own customers, vendors and staff;
- Support and contact-form messages you send us.
Information collected automatically:
- Usage data — pages and features accessed, actions taken (recorded in an in-app audit trail visible to your business's Owner/Admin), timestamps;
- Device and log data — IP address, browser type, and similar technical information, used for security and troubleshooting;
- Cookies and similar technologies — see section 5.
Information from third parties: payment confirmations and transaction references from our payment gateways (Paystack, Flutterwave); status updates from the NRS e-invoicing sandbox, where you use that integration.
3. How we use information
- To provide, maintain and secure the Cashflow platform and the features you use;
- To process subscription payments and manage billing;
- To send service communications (e.g. payment confirmations, invoice reminders, low-stock alerts, scheduled document emails) that you or your business have configured;
- To respond to support requests and contact-form submissions;
- To detect, prevent and investigate fraud, abuse and security incidents;
- To improve the product — understanding how features are used in aggregate, never by selling individual data;
- To comply with legal, tax and regulatory obligations.
4. Our legal basis for processing (NDPR/NDPA)
Under the NDPR and the NDPA 2023, we rely on one or more of the following legal bases for each processing activity: performance of our contract with you (running the service you signed up for), your consent (e.g. optional cookies, marketing communications), our legitimate interests (e.g. securing the platform, preventing fraud, improving the product), and compliance with a legal obligation (e.g. tax and financial record-keeping). Where consent is our basis, you can withdraw it at any time.
5. Cookies & similar technologies
We use a small number of cookies and browser storage entries:
- Strictly necessary — a session cookie that keeps you signed in, and a CSRF token that protects your forms from cross-site attacks. These can't be switched off, as the service won't function without them.
- Preference — remembers choices like light/dark mode and whether you've dismissed our cookie notice. Stored in your browser only (localStorage), never sent to our servers.
We don't currently use third-party advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings at any time; strictly necessary cookies are required to stay signed in.
6. How we share information
We don't sell your personal data. We share it only:
- With payment gateways (Paystack, Flutterwave) to process subscription and, where you use payment links, customer payments;
- With infrastructure and service providers who host our servers and database, store uploaded media, and deliver transactional email — bound by confidentiality and data-processing obligations;
- With the NRS e-invoicing system, where you choose to submit documents through that integration;
- Within your own business — data you enter is visible to the team members and roles your business's Owner/Admin gives access to;
- If required by law, court order, or to protect the rights, property or safety of Cashflow, our users, or the public;
- In connection with a merger, acquisition or asset sale, subject to the same protections described here.
7. Data storage & security
We apply technical and organizational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, role-based access control within each business, per-business data isolation, and audit logging of record changes. No system is 100% secure, but we work to keep Cashflow as safe as reasonably possible and to respond quickly if something goes wrong.
8. Your rights
Subject to applicable law (including the NDPR/NDPA), you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data — most account and business details can be edited directly in the app;
- Delete your account or business data, subject to records we're legally required to keep (e.g. financial records for tax purposes);
- Export your data in a portable format;
- Object to or restrict certain processing, including withdrawing consent where consent is our legal basis;
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data has been mishandled.
To exercise any of these rights, contact us at noreply@notify.cashflow.ng.
9. Data retention
We retain personal and business data for as long as your account or business is active, and for a reasonable period afterward to allow reactivation, comply with tax/financial record-keeping obligations, resolve disputes, and enforce our agreements. When no longer needed, data is deleted or anonymized.
10. Children's privacy
Cashflow is a business tool and isn't directed at children. We don't knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we'll remove it.
11. International transfers
Some of our infrastructure and service providers may process data outside Nigeria. Where that happens, we require appropriate safeguards consistent with NDPR/NDPA requirements for cross-border data transfer.
12. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we'll give reasonable notice (for example, by email or an in-app notice) before they take effect.
13. Contact us
Questions, requests, or concerns about this policy or your data can be sent to noreply@notify.cashflow.ng or via our contact page.