Last updated: September 22, 2026 · Effective: September 22, 2026
This Privacy Policy explains how iFAMED App (RC 7434818) (“iFAMED”, “we”, “us”) collects, uses, shares, protects, retains, and deletes personal and sensitive user data in the iFAMED mobile app for Android and iOS, the iFAMED web app, and ifamed.co. iFAMED App is the developer of the iFAMED app and the data controller for the information described here.
The table below summarises every category of personal and sensitive user data the app collects, who we share it with, and why. It matches the Data safety disclosures on our Google Play store listing. Each category is described in full in section 2.
| Data we collect | Shared with | Why we need it |
|---|---|---|
| Name, username, email address, phone number, date of birth | Identity, payment, email and SMS providers | Account creation, sign-in, identity verification, transaction receipts |
| Government ID number (BVN or NIN) | Identity verification providers | Legally required KYC/AML checks. Stored only as a one-way hash |
| Bank account details, virtual account number, wallet balance, transaction and ledger history, crypto wallet address | Payment processor, utility payment partner | Deposits, withdrawals, trades, bill payments, regulatory records |
| Gift card brand, region, value, code and evidence photos | Not shared, except with a redemption counterparty where the trade requires it | Completing the trade, fraud review, dispute resolution |
| Photos: verification selfie, profile photo | Identity verification providers (selfie only) | Face-match check for higher verification tiers; your profile picture |
| Phone, meter and smart card numbers you enter for bill payments | Utility payment partner | Delivering the airtime, data, electricity, TV or betting top-up you bought |
| Device fingerprint hash, push notification token, session device label | Push notification provider (token only) | Account security, fraud prevention, delivering notifications you enable |
| IP address and the country it resolves to, on gift card sales only | Fraud-scoring provider | Fraud risk scoring. The IP address itself is not stored in our database |
| In-app activity, support messages, notification history | Not shared | Running the app, answering support requests, investigating disputes |
What we never collect: your contacts, SMS or call logs, calendar, health or fitness data, browsing history, list of installed apps, precise device location, or an advertising identifier. The app contains no advertising SDKs and no third-party analytics or tracking SDKs.
We never sell your personal data, never share it with data brokers, and never use or transfer it for advertising, ad targeting, or credit scoring by anyone.
We collect information you give us directly, information generated by using the app, and information from the identity, payment, and delivery partners we work with to provide our services.
Full name, username, email address, phone number, date of birth, and a hashed password or transaction PIN (we never store these in plain text). If you sign up through a referral link, we also record which account referred you and your own referral code. If you upload a profile photo, it is stored in private storage and shown only to you and to our support and compliance team.
To meet Nigerian AML/KYC requirements, we verify your BVN or NIN through Prembly (our primary verification partner) or Dojah (backup). Higher verification tiers also require a selfie for a face-match check. Your selfie is uploaded directly to secure storage, used once to complete the check, and deleted immediately afterwards — regardless of outcome — with an automatic daily cleanup as a backstop for anything left over. We do not keep your BVN, NIN, name, phone number, or photo as returned by the verification provider: what we store is an irreversible cryptographic hash of your ID number, its last four digits, your date of birth as you entered it, and whether the check passed.
Bank account name, number, and bank name when you add a withdrawal account (we confirm the account name with our payment processor, BudPay, before saving it); the naira virtual account details generated for you to fund your wallet; and your transaction, receipt, and ledger history.
When you sell a gift card, we collect the brand, region, value, and the card itself: photo evidence (kept for fraud review and dispute resolution) and the card code, which is encrypted before it ever touches our database. Every time a member of our team accesses a stored card code, that access is individually logged.
Two automated checks run over the photos you upload, on our servers, purely to flag trades for a human to look at more closely. We read the image's technical metadata (the camera make and model, and whether editing software was recorded) — we do not read or store GPS or other location metadata. And we run text recognition over the image to check that the code shown matches the code you typed; the recognised text is redacted before anything is stored. Neither check can block a trade on its own.
When you sell crypto, you send it to a shared deposit address we control for that asset and network — we don't collect a wallet address from you for this. When you buy crypto, we store the destination wallet address you provide so we know where to send your purchase.
Phone numbers, meter numbers, and smart card numbers you enter to buy airtime, data, electricity, TV, or to fund a betting wallet — shared with our utility payment partner to complete the purchase.
A device fingerprint (a one-way hash generated on your device, not raw device details); a device label and activity timestamps for each signed-in session, so you can see and revoke your active sessions; and — for gift card sales specifically — your IP address, which we check against a fraud-reputation service. The result of that check is cached for 24 hours against a hash of your IP rather than the IP itself, and we keep the country your IP resolved to, not the IP address, once the check is done.
If you allow notifications, the app registers a push token — an identifier for that one app install, not for you or your device hardware — along with the platform (Android or iOS). It is used only to deliver transaction and security notifications to that install, and it stops working when you turn notifications off or uninstall the app.
The app requests a permission only at the point where you use the feature that needs it, and explains why before asking. You can refuse or later withdraw any of these in your device settings; the rest of the app keeps working, and only the specific feature stops.
To create and secure your account, verify your identity as required by law, process trades and payments, detect and prevent fraud, provide customer support, send you transaction and security notifications, and meet our regulatory obligations as a Nigerian financial-services provider. We do not use your data for any purpose that is unrelated to running iFAMED, and we will ask for your consent before we ever use it for a materially different purpose than the ones listed here.
Under the Nigeria Data Protection Act 2023, each of these uses relies on one of the following lawful bases:
Automated risk scoring (see the device and fraud-prevention data above) may automatically flag or temporarily pause a transaction for review; it does not by itself close your account or make a final decision without a team member being able to review it on request.
We do not sell your personal data. We share it only with the service providers that help us run iFAMED, each only for the purpose described, and each bound by contract to use it for that purpose alone:
We may also disclose information where required by law or a valid request from a competent authority — see our Law Enforcement Requests page. If iFAMED is ever involved in a merger, acquisition, or sale of assets, we will notify you before your personal data is transferred and becomes subject to a different privacy policy.
Some of the providers above process data on servers outside Nigeria. Where that happens, we transfer your data only under the conditions permitted by the Nigeria Data Protection Act 2023 — to a destination with adequate protection, or under contractual terms that require the provider to protect it to the standard this policy describes.
All traffic between the app and our servers is encrypted in transit with TLS, and data is encrypted at rest by our hosting providers. Passwords and transaction PINs are hashed, never stored in plain text. Your BVN/NIN is stored only as a one-way cryptographic hash. Gift card codes are encrypted before storage, and every decryption is logged to an individual admin. Selfies used for identity verification are deleted immediately after the check completes. Profile photos, selfies, and gift card evidence live in private storage buckets that are never publicly readable and are served only through short-lived signed links. Bank account details are stored with restricted, access-controlled database access, and staff access to customer data is limited to the people whose role requires it. No system is completely secure, and we continue to invest in improving these protections.
If a breach of your personal data occurs that is likely to result in a risk to your rights, we will report it to the Nigeria Data Protection Commission within 72 hours of becoming aware of it and notify you directly where the law requires.
We keep each category of data only as long as it is needed for the purpose it was collected for, or for as long as Nigerian AML/CFT recordkeeping regulation requires — whichever is longer. Our retention schedule is:
| Data | Kept for |
|---|---|
| Verification selfies | Deleted as soon as the face-match check resolves, pass or fail. A daily sweep deletes anything left behind, including abandoned uploads older than 24 hours |
| IP address (gift card sales) | Never written to our database. The risk result is cached against a hash of the IP for 24 hours, then discarded |
| Account profile, wallet, saved bank accounts, notifications, sessions | While your account is open. Deleted when you delete your account |
| Push tokens | Until you turn notifications off, uninstall the app, or delete your account; stale tokens are retired automatically |
| Device fingerprint hashes | While your account is open, then deleted — unless the device has been blacklisted for confirmed fraud, in which case the hash is kept for 5 years |
| KYC records (hashed ID number, last 4 digits, date of birth, check outcome) | 5 years after your account closes or your last transaction, whichever is later, as required by the Money Laundering (Prevention and Prohibition) Act 2022 and the CBN AML/CFT/CPF Regulations |
| Transaction, ledger, and receipt records | 5 years from the date of the transaction, for the same reason |
| Gift card evidence photos, encrypted card codes, and fraud review notes | 5 years from the date of the trade, then deleted. Held longer only where a specific dispute, chargeback, investigation, or lawful request is still open |
Once a retention period ends, the data is deleted or irreversibly anonymised.
You can delete your iFAMED account and its associated data at any time from inside the app, at Settings → Security → Delete Account, or on the web without installing the app. Both routes, and what is removed, are set out on our Delete Your Account page. Deletion is free, needs no explanation from you, and takes effect immediately once your wallet balance is zero.
Deleting your account permanently removes your profile, wallet, saved bank accounts, notifications, push tokens, and active sessions from our production database, along with your device fingerprint hashes — except any hash blacklisted for confirmed fraud, which is kept for 5 years as set out in section 7.
Three sets of records are kept after deletion, all on the retention periods in section 7:
Where a specific dispute, chargeback, fraud investigation, or lawful request from a competent authority is still open, the records it concerns are kept until that matter closes, even if the period above has already run. Everything we retain is locked to compliance use only — it is never used to contact you, market to you, or rebuild your account.
Under the Nigeria Data Protection Act 2023, you have the right to access a copy of your personal data, to correct it, to request its deletion (subject to our regulatory retention obligations), to object to or restrict certain uses of it, to receive it in a portable format, to withdraw a consent you previously gave, and to request human review of any automated fraud or risk decision that affects you. Contact us using the details below to exercise these rights; we respond within 30 days and will not charge you or degrade your service for asking.
You can also manage some of these directly: edit your profile in the app, turn push notifications off in the app or in your device settings, revoke a device permission in your device settings, and sign out active sessions from the security screen. You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe we have not handled your data lawfully.
We use cookies and local storage only to keep you signed in and to remember your device for security purposes — not for third-party advertising or tracking. We do not use an advertising identifier and we do not embed advertising or analytics SDKs.
iFAMED is a financial service for adults. It is not directed at children, it is not designed for or targeted at anyone under 18, and we do not knowingly collect personal data from anyone under 18. Age is checked at identity verification, and an account we find belongs to a minor is closed and its data deleted beyond what the law requires us to retain. If you believe a child has given us personal data, contact us at the address below and we will remove it.
We may update this policy as our services or legal obligations change, and we will update the date at the top of this page when we do. If a change materially affects how we handle data we already hold about you, we will notify you in the app or by email before it takes effect, and we will obtain your consent where the law requires it. Changes never apply retroactively to data collected under an earlier version without your consent.
The data controller for the information described in this policy, and the developer of the iFAMED app, is iFAMED App (RC 7434818), registered in No. 7, Kunle Shodiya Street, Kings Garden, Happy Land Estate, Ajah, Lagos State, Nigeria. Our privacy point of contact for questions about this policy, about your data, or to exercise any of the rights above is support@ifamed.co. You can also reach us through the help center.