top of page

Data Privacy and Security Policy

Effective Date: 1 August 2025

Xclusiv Retail Marketplace Innovation LTD

​

Introduction

Who we are. Xclusiv Retail Marketplace Innovation LTD, a company registered in Nigeria, is the controller of your personal data.

What we collect. Account and contact details, order and delivery information, content you post or send, device and usage data, and identity documents where verification is required.

Card details. Handled by our licensed payment processor. We never see or store your full card number.

Whom we share with. Sellers fulfilling your orders, service providers operating the platform, and authorities where the law requires it. We do not sell your personal data.

Age. Xclusiv is for adults. You must be 18 or over to hold an account.

Your control. Access, correct, export, delete, object, restrict, and withdraw consent — through the app or by emailing our Data Protection Officer.

​

1. Who we are and how to contact us

Xclusiv Retail Marketplace Innovation LTD ("Xclusiv", "we", "us") is a company incorporated in the Federal Republic of Nigeria with registration number 7011699, with its registered office at 10 Sardauna Crescent, Nassarawa GRA, Kano, Nigeria. We are the data controller for the personal data described in this policy.

Contact us at privacy@getxclusiv.com or on +2349160421001, or by post at the address above marked for the attention of the Data Protection Officer. The DPO is your first point of contact for anything in this policy, including requests to exercise your rights.

We are registered with the Nigeria Data Protection Commission as a data controller of major importance under registration [NUMBER].

​

2. What this policy covers

This policy applies to the Xclusiv mobile applications, the website at xclusiv.info, and any related services we provide. It explains what personal data we collect, why, on what legal basis, whom we share it with, how long we keep it, and what you can ask us to do.

It does not cover the practices of sellers on the marketplace, payment providers, or third-party sites you reach through links in the app. Those organisations handle your data under their own policies, and section 21 explains the limits of our responsibility.

​

3. The words we use

We use the terms defined in the Nigeria Data Protection Act 2023. In short:

Personal data is any information relating to you as an identified or identifiable person.

Sensitive personal data is a protected subset that includes biometric data and data revealing health, religion, ethnic origin, political opinions or sexual orientation.

Processing is anything done with personal data, including collecting, storing, using, sharing and deleting it.

A controller decides why and how data is processed. A processor acts on a controller's instructions.

​

4. The personal data we collect

We collect the following, and nothing beyond what is described here.

Account data — username, email address, phone number, password (stored only as a salted hash, never in readable form), profile photo, and date of birth for age verification. Collected from you at sign-up.

Order and delivery data — items bought or sold, order history, delivery and billing address, delivery status, returns and refunds. Collected from you and from our delivery partners.

Payment data — card brand, last four digits, expiry, a payment token, transaction amounts and dates. We do not receive or store your full card number, CVV or bank credentials. Collected through our payment processor.

Content you create — listings, photographs and videos of items, social posts, comments, reviews and ratings. Collected from you.

Messages — text, images and files you send and receive through in-app chat, and the time they were sent. Collected from you and the people you message.

Identity verification data — government-issued ID, a selfie where a match is required, and the result of the check. See section 6. Collected from you and our verification provider.

Device and technical data — device model, operating system version, app version, language, time zone, a device identifier, IP address, and crash reports. Collected automatically when you use the app.

Usage data — screens viewed, searches, items viewed and saved, purchases, and how you interact with listings and posts. Collected automatically.

Location data — country and approximate region inferred from your IP address. Precise device location only if you grant the permission, and only for the Employee attendance feature. You can withdraw that permission at any time in your device settings.

Support data — messages to our support team, reports you make about other users, and our replies. Collected from you.

We do not collect your contacts, your photo library beyond the individual files you choose to upload, your call or SMS history, or data from other apps on your device.

​

5. Why we use your data, and our legal basis

Every use below rests on one of the lawful bases in section 25 of the Nigeria Data Protection Act.

To create and run your account — using account data. Legal basis: performance of our contract with you.

To process orders, payments, delivery, returns and refunds — using order, payment and delivery data. Legal basis: performance of our contract with you.

To show your listings, posts and profile to other users — using content you create and account data. Legal basis: performance of our contract with you.

To deliver messages between users — using message data. Legal basis: performance of our contract with you.

To prevent fraud, counterfeit listings, scams and abuse, and to keep the marketplace safe — using device, usage, order, message and verification data. Legal basis: our legitimate interest in protecting users and the platform, balanced against your interests.

To verify identity where a transaction or feature requires it — using identity verification data. Legal basis: legal obligation where applicable; otherwise your explicit consent.

To fix faults, monitor performance and improve the service — using device, usage and crash data. Legal basis: our legitimate interest in maintaining a working product.

To recommend items and content you may like — using usage data and purchase history. Legal basis: our legitimate interest in a useful product. You can turn personalisation off at settings section of the apps.

To send marketing messages about Xclusiv — using account and usage data. Legal basis: your consent, which you can withdraw at any time.

To operate non-essential cookies, analytics and advertising technologies — using device and usage data. Legal basis: your consent.

To handle disputes, enforce our terms, and establish or defend legal claims — using any relevant category. Legal basis: our legitimate interest in enforcing our rights.

To meet tax, accounting, anti-money-laundering and other legal duties — using order, payment and identity data. Legal basis: legal obligation.

Where we rely on legitimate interest, we have assessed that our interest does not override your rights, and you can object at any time under section 19. Where we rely on consent, you can withdraw it as easily as you gave it, and withdrawing does not affect processing that already took place.

​

6. Identity documents and biometric data

Some features and transactions require us to confirm you are who you say you are. Where that applies, we ask for a government-issued identity document and, where a match is needed, a photograph of your face.

A facial comparison between your photograph and your ID creates biometric data, which is sensitive personal data under section 30 of the Act. We carry out that comparison only with your explicit consent, given separately at the point of verification. If you would rather not, contact our DPO about the manual alternative.

The check is performed by our partner SMILE ID acting on our instructions. We keep the document image and any biometric template for 30 DAYS after the check is completed, then delete them. We keep only the outcome, the date, and the document type, which we need to evidence that the check was done. Access is restricted to trained staff, and every access is logged. We do not use these documents for any other purpose, and we do not use them to train models.

​

7. Children and young people

Xclusiv is an adult service. You must be 18 or over to create an account, buy, sell or post. Under the Nigeria Data Protection Act, a person under 18 is a child.

We ask for your date of birth at sign-up and refuse registration for those under 18. We do not knowingly collect data from children. If we learn that an account belongs to someone under 18, we close it and delete the associated personal data, keeping only the minimum record needed to prevent the account being reopened.

If you believe a child is using Xclusiv, tell our DPO at privacy@getxclusiv.com, and we will act within 7 days.

​

8. What other people can see

Some of what you put on Xclusiv is public by design. The following are visible to anyone using the platform: your username, your profile photo, your listings and their images, your social posts and comments, and your seller ratings and reviews.

These are not public: your email address, phone number, delivery and billing address, payment details, identity documents, and the contents of your private messages.

You can delete your posts and listings at any time, and they will stop being visible on Xclusiv. But we cannot recall copies other people have already saved, screenshotted or shared elsewhere. Treat anything you post publicly as something you cannot fully take back.

​

9. If you sell on Xclusiv

Sellers give us additional information: business or trading name, bank or settlement account details, tax identification number, and any identity or business documents we need to verify you. We process it to operate your seller account, pay you, and meet our tax and anti-money-laundering duties — on the basis of our contract with you and our legal obligations.

When a buyer places an order, we give you their name, delivery address and the contact details needed to fulfil it. You become a controller of that data in your own right. Under your seller agreement, you may use it only to fulfil and support that order, you must not use it for your own marketing, and you must delete it once the order and any return period are complete.

Buyers can see your seller name, ratings, reviews, response times and [ANY OTHER SELLER METRICS SHOWN].

​

10. Messages

Messages between users are stored on our servers, encrypted in transit and at rest. They are not end-to-end encrypted, which means we are technically able to access them. We do so only in these situations: when a user reports a message to us, when we are investigating fraud or a safety risk, when it is necessary to resolve a dispute you have raised, or when we are legally compelled. Every such access is restricted to authorised staff and recorded.

Deleting a message removes it from your view and, where the feature supports it, from the recipient's. It does not guarantee removal of copies the recipient has saved.

​

11. Payments

Card and payment details are collected directly by Flutterwave, a licensed payment service provider, through its own secure interface. They do not pass through Xclusiv's systems and we do not store them. The processor handles that data as a controller under its own privacy policy, which you can read at https://flutterwave.com/ng/payment-protection-promise.

We receive and keep a transaction record: amount, date, status, card brand, last four digits and a token that lets you pay again without re-entering details. We keep these records for the period in section 16 because tax and accounting law requires it.

​

12. Cookies, SDKs and similar technologies

On getxclusiv.com, xclusiv.info, xclusiv.business, xclusiv.app, we use cookies. In the apps we use software development kits that perform similar functions. Both are covered by Article 19 of the General Application and Implementation Directive, which requires your consent for anything that is not strictly necessary.

Strictly necessary technologies keep you logged in, protect against fraud, balance load and remember your settings. These run without consent because the service does not work without them.

Analytics technologies tell us which features are used and where the app fails.

Advertising and attribution technologies measure campaigns and, where you allow it, show you relevant advertising.

Analytics and advertising technologies run only if you consent. We ask for that consent the first time you use the app or the site, with accept and reject presented equally. You can change your choice at any time in the settings sections. On iOS we will also ask separately, through Apple's App Tracking Transparency prompt, before using your advertising identifier.

​

13. Personalisation and automated decisions

We use what you view, search for, save and buy to decide which items and posts to show you. This is profiling. It affects what you see, not what you are allowed to do, and you can turn it off in the settings sections — you will still see the marketplace, just not ordered around your activity.

Some decisions are taken automatically to protect the platform: [FOR EXAMPLE BLOCKING A TRANSACTION FLAGGED AS FRAUDULENT, SUSPENDING AN ACCOUNT, HOLDING A PAYOUT, REMOVING A LISTING].

Where an automated decision significantly affects you, you have the right under section 37 of the Act to ask for a person to review it, to explain your side, and to contest the outcome. Write to our DPO and a member of staff who was not involved in the original decision will look at it.

​

14. Who we share your data with

Sellers receive your name, delivery address and order details, so they can fulfil your order.

Delivery and logistics partners receive your name, address and phone number, to deliver and to handle returns.

Payment processors receive payment and transaction data, to take payment and pay sellers.

Cloud hosting and storage providers host the platform and its data.

Identity verification providers receive identity documents, to run the check in section 6.

Analytics, crash reporting and messaging providers receive device and usage data, to keep the product working and to contact you.

Professional advisers receive data relevant to legal, audit, insurance or accounting matters.

Authorities and courts receive data required by a valid legal demand — see below.

A buyer or successor. If Xclusiv is sold or merges, your data transfers with the business. We will tell you beforehand and this policy will continue to apply until it is replaced.

Every service provider acts on our written instructions under a contract requiring confidentiality, appropriate security and restrictions on onward transfer. None of them may use your data for their own purposes.

We do not sell your personal data, and we do not share it with third parties for their own marketing.

Legal demands. We disclose data to law enforcement, regulators or courts only where we receive a valid, lawful demand that has been properly served on us. We review each one, and we refuse or challenge demands that are overbroad, defective or unlawful. We will tell you when your data has been requested unless the law prohibits us or notice would defeat a genuine investigation.

​

15. Sending data outside Nigeria

Some of our providers operate outside Nigeria, so your data may be transferred to the United States and Singapore. Sections 41 to 43 of the Act permit such a transfer only where there is adequate protection at the destination or an approved safeguard is in place.

For each transfer we rely on one of: a determination by the Nigeria Data Protection Commission that the destination provides adequate protection; standard contractual clauses or binding corporate rules imposing protections equivalent to Nigerian law; an approved certification or code of conduct; or, where none applies, your explicit and informed consent. We also assess whether local law at the destination could undermine those protections before we transfer.

To see which mechanism applies to a particular transfer, or to request a copy of the safeguards, email our DPO.

​

16. How long we keep your data

Account data — while your account is open, then [30 DAYS] after you close it.

Order, payment and tax records — [6 YEARS] from the transaction, as required by Nigerian tax and company law.

Identity verification documents — [30 DAYS] after the check completes. The outcome is kept as long as required.

Messages — [6 YEARS], or until you delete them, whichever is sooner.

Listings and public posts — until you delete them or close your account.

Device and usage data — [6 YEARS].

Support and dispute records — [6 YEARS] after the matter closes.

Fraud and safety records — as long as needed to prevent the same person returning, and no longer than [6 YEARS].

Anti-money-laundering records, where applicable — 5 years from the end of the relationship or the transaction.

When a period ends we delete the data or irreversibly anonymise it. Data deleted from our live systems persists in encrypted backups for up to [6 YEARS] before those backups are overwritten. Where the law requires us to keep something — a tax record, for example — we keep it even if you ask us to delete it, and we tell you when that is the reason.

​

17. How we protect your data

We maintain the following controls:

  • Encryption of data in transit using TLS, and of stored data at rest

  • Passwords stored only as salted hashes, never in a form we can read

  • Role-based access control, so staff reach only the data their job requires

  • Multi-factor authentication on administrative accounts

  • Logging and monitoring of access to accounts, messages and identity documents

  • Security assessment of providers before we engage them

  • Regular vulnerability testing and patching

  • Data protection training for staff who handle personal data

  • A documented incident response plan, tested periodically

No system is perfectly secure, and we do not claim otherwise. You can protect your own account by using a password you use nowhere else and enabling two-factor authentication in the settings section.

​

18. If something goes wrong

If a personal data breach occurs, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as section 40 of the Act requires. Where the breach is likely to result in a high risk to your rights, we will tell you directly and without undue delay, explaining what happened, what data was involved, what we are doing, and what you should do. We keep a register of all incidents, including those we assess as not requiring notification.

​

19. Your rights

Under the Nigeria Data Protection Act you have the right to:

  • Be informed about how your data is used — this policy

  • Access a copy of the personal data we hold about you

  • Correct data that is inaccurate or incomplete

  • Delete your data where we no longer have a reason to keep it

  • Restrict how we use your data while a dispute about it is resolved

  • Object to processing based on our legitimate interests. If you object to direct marketing we will stop, always and immediately.

  • Port your data — receive it in a structured, commonly used, machine-readable format, or have us send it to another service where technically feasible

  • Withdraw consent at any time, as easily as you gave it

  • Ask for human review of a significant decision made solely by automated means

  • Complain to the Nigeria Data Protection Commission

How to exercise them. Many are built into the app: update your profile, change privacy settings, download your data and delete your account in the settings section. For anything else, email our DPO at privacy@getxclusiv.com. You can also request account deletion from the web at https://www.xclusiv.info/delete.

What happens next. We acknowledge every request within 7 days and respond substantively within 30 days. If a request is unusually complex we may extend by a further 30 days, and we will tell you why within the first 30. Requests are free. We may ask you to confirm your identity before we act — to stop someone else obtaining your data — and we will ask only for what is needed to do that.

If you are not satisfied. Tell our DPO and we will escalate the matter internally. You can complain at any time to the Nigeria Data Protection Commission, without going through us first. Details are at ndpc.gov.ng.

​

20. Marketing

We send marketing messages only if you have opted in. Every message carries a one-click unsubscribe, and you can change your preferences in the settings section.

Opting out of marketing does not stop service messages — order confirmations, delivery updates, security alerts and policy changes — which we must send to operate your account.

​

21. Links to other services

The app and site contain links to sites and services we do not control, including sellers' own channels and payment pages. We are not responsible for their privacy practices. Read their policies before giving them your data.

​

22. Changes to this policy

We review this policy at least once a year and update it when our practices or the law change. For material changes we will give you at least 14 days' notice in the app and by email before they take effect. Minor corrections take effect on publication. Every version carries an effective date, and previous versions are archived at https://www.xclusiv.info/achive.

​

23. Additional rights in certain regions

Transfers to Nigeria are made under standard contractual clauses approved by the European Commission, together with a transfer impact assessment. Email our DPO for a copy.

California. If you are a California resident, you have rights to know, delete, correct and limit the use of sensitive personal information, and to opt out of any sale or sharing for cross-context behavioural advertising. We do not sell personal information. We will not discriminate against you for exercising these rights. Contact our DPO to make a request.

​

24. Contact

Data Protection Officer Xclusiv Retail Marketplace Innovation LTD 10 Sardauna Crescent, Nassarawa GRA, Kano, Nigeria [privacy@etxclusiv.com] [+2349160421001]

General enquiries: support@getxclusiv.com

Supervisory authority: Nigeria Data Protection Commission, ndpc.gov.ng

​

Version history

Version 1.0 — effective 2025. Full restatement for the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025. Lawful bases added, age threshold raised to 18, retention periods published, transfer mechanisms and breach commitment added.

​

​

 

​

bottom of page