Privacy Policy
How Nura Mustapha Technologies Limited collects, processes, stores, and protects your retail business data — in plain language.
Privacy Policy
Last Updated: August 2026 — Version 2.0This Privacy Policy explains how Nura Mustapha Technologies Limited (“we”, “us”, “our”, “SwiftPOS”) collects, uses, stores, and discloses personal data when you access or use the SwiftPOS platform at swiftpos.ng and app.swiftpos.ng. We process personal data in strict compliance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Commission (NDPC) General Application and Implementation Directive 2025 (GAID).
1 Who We Are & Regulatory Roles
SwiftPOS is a cloud-based Point of Sale and retail management software platform developed and operated by Nura Mustapha Technologies Limited, a private limited liability company registered in the Federal Republic of Nigeria with the Corporate Affairs Commission (RC 9679645).
Under the Nigeria Data Protection Act 2023 (NDPA), our legal role depends on the context of processing:
- SwiftPOS as Data Controller: We act as the Data Controller for direct Merchant account information, billing records, identity details, customer support enquiries, and analytics data collected on our marketing website (swiftpos.ng).
- SwiftPOS as Data Processor: For all end-customer records (names, phone numbers, credit balances) and staff accounts entered into or generated within your Tenant Environment, the Merchant acts as the Data Controller. SwiftPOS acts strictly as a Data Processor processing that data on the Merchant’s documented instructions in accordance with our Data Processing Agreement (DPA).
2 Scope of this Policy
This Policy applies to:
- Business owners, administrators, and managers who register and maintain a SwiftPOS account (“Merchants”);
- Cashiers, store employees, and other staff users added to a Merchant’s tenant environment (“Staff Users”);
- End customers of Merchants whose personal details (name, phone number, credit balances) are recorded in SwiftPOS;
- Visitors to the SwiftPOS marketing website at swiftpos.ng.
This Policy does not govern the privacy practices of third-party websites or services that may be linked from our platform.
3 Personal Data We Collect
3.1 Merchant Account & Registration Data
When you create a SwiftPOS account, we collect:
- Full legal name of the account holder;
- Business name and company type;
- Email address and phone number;
- Hashed account password (we never store passwords in plain text);
- Company URL slug (unique identifier used to access your tenant environment);
- Physical store address(es) and branch locations;
- Business registration number (CAC number), if provided voluntarily;
- Subscription plan tier and billing cycle preference;
- Payment transaction reference IDs from our payment processors.
3.2 Staff & Cashier Data
When a Merchant creates staff accounts, we collect for each staff member:
- Full name and assigned username;
- Contact email address or phone number;
- Role designation (Administrator, Manager, Cashier, or custom roles);
- Role-based permission settings and custom capability overrides;
- Hashed cashier transaction PIN (used for sales authorization and pricing overrides);
- Login timestamps and session history;
- IP addresses and device information associated with each login session.
3.3 Product & Inventory Data
To provide inventory management services, we store:
- Product names, SKUs, barcodes, and category assignments;
- Retail selling prices, wholesale cost prices, and VAT/tax configurations;
- Stock quantity levels across single and multiple branches;
- Supplier information (name, contact, payment terms);
- Purchase order records, received quantities, and stock adjustment histories;
- Product images and descriptions uploaded by the Merchant.
3.4 Sales & Transaction Data
- All sales transactions processed through Classic POS, Smart Grid POS, and Barcode POS interfaces;
- Items sold, quantities, unit prices, applicable discounts, and VAT amounts;
- Payment methods (cash, bank transfer, QR code, card, or split payment);
- Receipt data including QR code identifiers;
- Transaction timestamps, cashier identifier, and POS terminal session ID;
- Order reversals, voids, and adjustment records;
- End-of-Day (EOD) cash reconciliation records and variance reports.
3.5 Customer (End-Customer) Data
Merchants may record their own customers’ information in SwiftPOS for the purpose of credit sales and customer loyalty management. This may include:
- Customer name and phone number;
- Outstanding credit balances and credit sale histories;
- Payment receipt logs associated with a named customer.
Merchants are solely responsible for obtaining any required consent from their end-customers before recording personal data in SwiftPOS.
3.6 Audit Trail & System Event Data
To protect Merchants against internal theft and unauthorized activity, SwiftPOS records an immutable audit log capturing 24 distinct system event types, including:
- Login and logout events with IP addresses and timestamps;
- Product price modifications and bulk price changes;
- Stock adjustment, stock addition, and write-off events;
- Transaction override requests, discount approvals, and PIN verifications;
- Sales deletion, order cancellation, and transaction reversal events;
- Account configuration changes (plan upgrades, branch additions, receipt customizations);
- Export and data download activities.
3.7 AI Assistant & Smart Scanner Interaction Data
For Merchants on plans with access to the SwiftPOS AI Business Assistant and AI Camera Item Scanner:
- User prompt inputs and inventory query parameters submitted to the AI assistant;
- Camera-captured images of product packaging submitted for automated SKU extraction;
- AI-generated responses, purchase order drafts, and tool execution logs;
- Daily token usage counts and rate-limit tracking metrics;
- Session identifiers linking queries to authenticated user sessions.
Zero Foundation Model Training: Personal Data, proprietary financial records, and product scan payloads processed by SwiftPOS AI features are processed ephemerally and are never used to train, fine-tune, or improve public third-party foundation models.
3.8 Website & Analytics Data
When you visit swiftpos.ng, we collect standard web analytics information including IP address, browser type, referring URL, pages visited, and session duration through Google Analytics (GA4). This data is processed in aggregate and is used solely for improving our marketing website and product.
4 How We Use Your Data
| Purpose | Data Used |
|---|---|
| Providing & operating the SwiftPOS platform | Account data, inventory data, transaction data, staff credentials |
| Processing sales & managing POS sessions | Product data, cashier credentials, transaction data |
| Generating reports & business intelligence | Sales data, profit/loss data, stock data |
| Delivering daily operational email summaries | Sales summaries, cash variance, profit margin digests |
| Detecting & flagging suspicious activity | Audit log data, transaction patterns, discount frequencies |
| Sending low-stock & credit-owing notifications | Inventory levels, customer credit data, contact information |
| Billing & subscription management | Account data, payment references, plan tier data |
| AI assistant & camera scan operations | Prompt data, session metrics, item image recognition payloads |
| Security & fraud prevention | IP addresses, login history, audit trail data |
| Legal compliance & regulatory obligations | Account data, transaction records, as required by Nigerian law |
| Product improvement & analytics | Aggregated, anonymized usage data |
5 Legal Basis for Processing (NDPA 2023)
Under Section 25 of the Nigeria Data Protection Act 2023 (NDPA), we process personal data on the following lawful bases:
- Performance of a Contract (Section 25(1)(b)): Processing necessary for the performance of our subscription contract with the Merchant (account registration, core POS services, billing, reporting, customer support).
- Compliance with Legal Obligations (Section 25(1)(c)): Compliance with applicable Nigerian statutes and regulatory directives (such as FIRS tax auditing requirements, NDPC filings, and judicial processes).
- Legitimate Interests (Section 25(1)(f)): Platform security, fraud prevention, immutable audit trails, multi-tenant integrity, and performance analytics — provided such interests do not override fundamental data subject rights.
- Consent (Section 25(1)(a)): Where explicit consent is obtained for specific non-core activities (such as newsletter subscriptions or marketing notifications), which can be withdrawn at any time.
6 Third-Party Data Processors (Sub-processors)
We engage trusted third-party service providers who process data strictly on our instructions under formal data processing contracts:
| Processor / Category | Purpose | Data Shared |
|---|---|---|
| Monnify (Moniepoint MFB) | Subscription billing & payment processing | Merchant name, email, payment reference IDs |
| Email SMTP Provider | Transactional emails, daily report delivery | Email address, report content |
| SMS Gateway | Customer credit notifications, security alerts | Phone number, notification content |
| Cloud AI API Providers (Gemini / OpenAI) | Conversational business insights & camera item scan | Ephemeral prompt data & SKU recognition (no training) |
| Cloud Hosting & Storage Infrastructure | Server infrastructure & database storage | Encrypted platform database volumes & backups |
| Google Analytics (GA4) | Marketing website telemetry (swiftpos.ng only) | Anonymized browsing metrics, IP address |
We do not sell, rent, or monetize your personal or business data to any third party for marketing or commercial purposes.
7 Offline Mode & PWA Data Storage
SwiftPOS operates as a Progressive Web App (PWA) with offline-first capabilities. When you use SwiftPOS in an environment without internet connectivity:
- Product catalogs, pricing data, and active shopping carts are cached locally on your device using browser Service Workers and IndexedDB;
- Transactions processed offline are stored temporarily on the local device with a unique
client_idUUID to prevent duplication; - Upon reconnection, offline transactions automatically synchronize with our cloud servers;
- Locally cached data on your device is subject to your browser's storage settings. SwiftPOS is not responsible for data loss caused by manually clearing browser storage, device resets, or browser cache purges before synchronization is complete.
8 Data Retention
| Data Category | Retention Period |
|---|---|
| Active account & merchant data | Duration of subscription + 90 days after cancellation (read-only grace period before active deletion) |
| Sales & transaction records | 7 years (in accordance with Nigerian tax regulations — FIRS statutory requirements) |
| Audit log records | 5 years from creation date |
| Staff credentials & login history | Duration of account + 90 days |
| Customer credit records | Duration of Merchant account + 90 days |
| AI assistant prompt logs | 90 days (for rate-limit enforcement and session continuity only) |
| Website analytics data | 14 months (Google Analytics standard retention) |
Upon expiry of the applicable retention period, data is securely deleted or anonymized using industry-standard cryptographic erasure methods.
9 Your Rights Under the NDPA 2023
As a data subject under the Nigeria Data Protection Act 2023, you have enforceable statutory rights regarding your personal data:
- Right to Information & Access: Request confirmation and a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate, incomplete, or misleading data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where no lawful basis exists for continued processing, subject to statutory tax retention obligations.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format (CSV export via the SwiftPOS Export Center).
- Right to Restriction: Request that we restrict the processing of your data in contested circumstances.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing relies on consent, withdraw it at any time without retroactive effect.
- Right not to be subject to solely automated decision-making: Obtain human intervention and review on material decisions.
To exercise any of these rights, submit a written request to our compliance team at compliance@swiftpos.ng. We will acknowledge and respond within 30 days.
10 Security Measures
We implement defense-in-depth technical and organizational security controls to protect your data:
- Encryption in Transit: All connections to SwiftPOS are encrypted using HTTPS/TLS 1.3 / TLS 1.2 with HSTS (HTTP Strict Transport Security) headers enforced;
- Encryption at Rest: Database volumes, file assets, and automated daily backups are encrypted at rest using AES-256;
- Password Hashing: All account passwords are salted and hashed using bcrypt / PBKDF2; raw passwords are never logged or stored;
- Cashier PIN Hashing: Cashier verification PINs are stored as salted hashes; no plaintext PINs are accessible by SwiftPOS staff;
- Multi-Tenant Isolation: Strict tenant isolation prevents cross-tenant access at both the application and database query levels;
- Role-Based Access Control (RBAC): Granular permissions restrict sensitive managerial operations to authorized roles;
- Immutable Audit Logs: Tamper-evident logging of 24 distinct system events, recording timestamps, IP addresses, and user IDs;
- Continuous Monitoring: Routine automated backups, anomaly detection, dependency auditing, and server hardening.
11 Cookies
The SwiftPOS marketing website (swiftpos.ng) uses strictly necessary session cookies and anonymized Google Analytics 4 telemetry. The SwiftPOS application (app.swiftpos.ng) uses secure session cookies and IndexedDB solely for authentication and offline POS caching.
12 Children’s Privacy
SwiftPOS is an enterprise business platform intended solely for registered business operators. We do not knowingly collect personal data from individuals under 18 years of age.
13 International & Cross-Border Data Transfers
Where processing involves transferring data across borders (such as hosting infrastructure or cloud LLM API routing), we ensure that such transfers comply with Part VIII (Sections 41–43) of the Nigeria Data Protection Act 2023 (NDPA), through adequacy mechanisms, standard contractual clauses, and enterprise data protection safeguards.
14 Supervisory Authority & Complaints
If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the national regulatory authority in Nigeria:
Nigeria Data Protection Commission (NDPC)
Website: ndpc.gov.ng
Email: info@ndpc.gov.ng
We welcome the opportunity to resolve any concern directly first. Please contact our compliance desk at compliance@swiftpos.ng.
We would, however, appreciate the opportunity to address your concerns first. Please contact us at compliance@swiftpos.ng before filing a formal complaint.
15 Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our platform features, legal requirements, or business practices. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page;
- Display an in-app notification to all logged-in Merchant administrators;
- Send an email notification to primary account holders where changes are significant.
Your continued use of SwiftPOS after the effective date of any updated Policy constitutes acceptance of the revised terms.
16 Contact Us
For all privacy and data protection enquiries, please contact our compliance team:
- Data Controller: Nura Mustapha Technologies Limited (RC 9679645)
- Email: compliance@swiftpos.ng
- General Support: contact@swiftpos.ng
- Phone / WhatsApp: +234 916 460 1810
- Office: Kano, Federal Republic of Nigeria