Legal

Privacy Policy

Learn how Afrigora collects, uses, stores, and protects your personal information — for the Afrigora customer app and Afrigora Pro. Includes account closure (#account-closure), messaging safety, AI Assistant, wallet/KYC, bills, measurements, referrals, biometrics, and subprocessors.

Last updated: July 28, 2026

01

Introduction

This Privacy Policy explains how Afrigora ("Afrigora", "we", "us", or "our") handles personal information when you visit https://afrigora.biz, use our mobile experiences, create an account, place orders, book tailoring services, or interact with our marketplace.

You do not need an account to read this policy.

By creating an account, placing an order, funding a wallet, or otherwise using Afrigora, you acknowledge that you have read and understood this Privacy Policy.

This policy should be read together with our Terms & Conditions and Refund Policy.

See Scope of this policy (#scope) for which apps and roles are covered and how to contact us for privacy requests.

02

Scope of this policy

This Privacy Policy applies to Afrigora services, including the website at https://afrigora.biz, the Afrigora customer mobile app and web experiences, and Afrigora Pro (the vendor, tailor, and producer mobile app). Unless a feature is clearly customer-only or Pro-only, the same privacy rules apply across products that share your Afrigora account.

Afrigora Pro sellers

  • Afrigora Pro is for vendors, tailors, producers, and related business roles: store and portfolio listings, order fulfilment, payouts, consultations, peer messaging with customers, wallet and bills, push alerts, and optional AI Assistant tools.
  • Pro users process customer data when fulfilling orders (for example delivery contacts and measurements). You must use that data only to complete the transaction and comply with applicable law — not for unrelated marketing without consent.
  • Account closure on Pro uses deactivation (not the customer Delete account API). See Account closure (#account-closure).

Data controller & privacy contact

  • Afrigora is the data controller for personal information described in this policy (operated from Nigeria unless we state otherwise for a specific service).
  • Privacy and data-rights requests: support@afrigora.biz (same address as general support unless we publish a dedicated privacy inbox).
  • Phone: 08035099186. Data & account requests form: https://afrigora.biz/privacy/data-request.
  • When you exercise rights, we may verify your identity (email reply, OTP, or other reasonable check) before changing or deleting data.

Related policies

  • Terms & Conditions (https://afrigora.biz/terms) — including acceptable use in chat and consequences for abuse.
  • Refund Policy (https://afrigora.biz/refund-policy) — wallet refunds, order refunds, and related money handling.
  • Google Play and other store listings may ask separate questions about user-generated content and generative AI; this policy describes how we process messaging and AI data in practice.
03

Account closure, deactivation & deletion

Afrigora operates two mobile experiences: the Afrigora customer app and Afrigora Pro for vendors, tailors, and producers. How you close your account depends on which app and role you use. Closure flows require email OTP where noted and are subject to our Terms (Suspension & Termination).

Two apps — which flow to use

  • Afrigora (customer app / customer web): for shoppers and personal accounts. Use Profile → Delete account when you want to close your customer account.
  • Afrigora Pro (vendor, tailor, producer app): for business accounts. Use Deactivate account in Settings. Pro does not offer the same in-app Delete account button as the customer app — deactivation is the self-service closure path for business users.
  • Both apps connect to the same Afrigora account platform. If one login has customer and business roles, you may need both flows or support help to close everything.

Customer app — delete account (not hard delete)

  • Where: Afrigora → Profile → Delete account (or the supported web flow when available).
  • Web reference: https://afrigora.biz/privacy#account-closure (this section).
  • Before you can delete: no open orders and no open Save Small goals (active or paused).
  • Security: email OTP to your registered email (send OTP from the closure flow, then confirm delete).
  • If you cannot use the in-app flow, email support@afrigora.biz from your registered address with your deletion request — we will verify you and guide you through closure or erasure where permitted.
  • Google Sign-In: if you registered with Google, deleting your Afrigora account closes access to Afrigora only — it does not delete your Google account.
  • Effect: account is soft-deleted or anonymized for login — you cannot sign in again, sessions end. This is account closure, not immediate erasure of every database row.
  • We may retain order, payment, wallet/KYC, chat/dispute, and fraud-prevention records as described below and in our Terms.

Afrigora Pro — deactivate account (not delete)

  • Where: Afrigora Pro → Settings → Deactivate account (not “Delete account”). Pro does not use the customer Delete account API.
  • Before you can deactivate: no open orders to fulfill and no customers with open Save Small goals on your products (active or paused).
  • Security: email OTP to your registered email, same as other closure actions.
  • Effect: you lose access immediately — sessions end, you cannot sign in until support reactivates where appropriate. Store and tailor listings go offline; new customers generally cannot discover those listings while inactive.
  • Profile and business data: your account is marked inactive; public storefront presentation is removed or hidden as the product implements. We do not promise immediate erasure of all profile, listing, message, or media rows.
  • Messages: past peer threads may remain visible to other participants; your ability to send new messages stops with access.
  • Wallet: wallet balance, transaction history, and payout-related records typically remain for accounting, tax, AML, and dispute purposes after deactivation — withdrawal or settlement may be required before deactivation where the app enforces it.
  • Reactivation: contact support@afrigora.biz if you believe deactivation was in error or you need your business account restored.
  • Deactivation is not full data erasure. Request additional erasure via https://afrigora.biz/privacy/data-request where the law allows.

What we keep after delete or deactivate

  • Transaction and wallet ledgers, BVN/KYC audit trails, order and payout history, and records needed for tax, accounting, anti-money-laundering, chargebacks, or disputes.
  • Content tied to legal holds, open investigations, or completed orders that other users or regulators reasonably expect to remain auditable.
  • Data that no longer identifies you may be kept in aggregated or anonymized form for analytics and service improvement.

Staff-initiated deactivation

  • Afrigora staff may deactivate accounts for policy, safety, fraud, or operational reasons, with effects similar to self-deactivation for business users.
  • Staff action does not erase all historical records. Contact support if you believe a deactivation was made in error.

Request full erasure or additional data rights

  • After delete or deactivate, you may still ask us to limit processing or erase personal data where the law allows and retention is not required.
  • Use this page (https://afrigora.biz/privacy/data-request) or email **support@afrigora.biz** from your registered email. Say whether you use **Afrigora**, **Afrigora Pro**, or both.
  • Include: full name, account email, request type (access, correction, erasure, export, objection), and any order or wallet context.
  • We will verify you own the account (email reply, OTP, or other reasonable check). We aim to respond within a reasonable time; wallet/KYC/dispute cases may take longer.
  • We cannot guarantee immediate hard deletion of all copies when law, fraud prevention, or backup systems require retention — we will explain what was erased, anonymized, or kept and why.

Step-by-step instructions and support contact: https://afrigora.biz/privacy/data-request. Neither delete nor deactivate removes every record instantly; see “Request full erasure” above.

04

Authentication methods

Email and phone

  • Email address and phone number for registration, login, OTP, order updates, and account security.
  • Profile name, avatar, and business details you choose to display.

Password

  • Where you use email/password sign-in, passwords are stored using industry-standard hashing — not in plain text.

Email OTP

  • One-time codes sent to your registered email for password reset, account deletion, account deactivation, and other sensitive account actions where enabled.
  • Phone verification may use SMS or OTP flows where the product supports them.

Google Sign-In

  • If you choose Continue with Google, Afrigora receives profile information Google shares (such as name, email, and avatar) to create or link your account.
  • Closing or deleting your Afrigora account does not delete your Google account. See Account closure (#account-closure) and our Terms (Suspension & Termination).
05

Information We Collect

We collect information that you provide directly, information generated through your use of the platform, and limited information from trusted service providers.

Information you provide

  • Account details such as name, phone number, email address, password, and profile information.
  • Delivery addresses, billing details, and contact preferences.
  • Order information, including product selections, customization instructions, and communication with sellers or tailors.
  • Body measurements, design preferences, and fitting notes submitted for tailoring or custom clothing services.
  • BVN, date of birth, and other Know Your Customer (KYC) details required to create or verify a wallet.
  • Wallet funding, withdrawal, transfer, bills payment, and other financial transaction details.
  • Messages, chat attachments (including photos, videos, voice notes, and documents), reviews, ratings, support requests, and dispute-related submissions.
  • Questions and prompts you send to the in-app AI Assistant and the replies it returns (see AI Assistant (#ai-assistant)).
  • Business or vendor information if you register as a seller, tailor, or service provider.

AI Assistant (customer app)

  • The automated AI Assistant in the Afrigora customer app (and similar assistant entry points in other apps) is not the same as messaging other users.
  • We process your questions/prompts, the assistant’s replies, and session history to run the feature and support the service.
  • Outputs can be wrong or incomplete and are not professional, legal, medical, or financial advice.
  • Report and block tools apply to user-to-user chat only, not to AI threads.
  • When we use a third-party LLM, it is listed under Subprocessors (#subprocessors) and Data collection & sharing (third parties) (for example OpenAI).

Information collected automatically

  • Device type, browser, operating system, IP address, and general location derived from IP.
  • Precise device location when you grant location permission (for example delivery, attendance, or nearby-store features).
  • Camera and microphone captures when you grant permission (for example body scans, profile or chat media, or voice notes).
  • Push notification device tokens via Firebase Cloud Messaging (FCM) when you enable notifications.
  • Pages viewed, search queries, referral URLs, session activity, and interaction with listings or ads.
  • Cookies, local storage, and similar technologies used to keep you signed in and improve site performance.
  • Log data such as timestamps, error reports, and security events.

Information from third parties

  • Paystack and other payment processors confirming checkout payment status.
  • Xpress Payments and related wallet or biller partners for wallet identity checks and money movement.
  • BVN/KYC verification partners returning identity match results needed for wallet compliance.
  • Bodygram returning measurement outputs from a camera-based scan you initiate.
  • GIG Logistics and other delivery partners providing shipment updates.
  • Google (Sign-In, Firebase/FCM) when you use those features.
  • Google Workspace (transactional email) delivering OTP and service messages we send.
  • Identity or fraud-prevention providers where verification is required.

Sensitive categories such as BVN/KYC, biometrics-related body data, financial data, location, camera/microphone content, chat media, and push tokens are described in detail in the section “Sensitive Data, Device Permissions & Third Parties” below.

06

Sensitive Data, Device Permissions & Third Parties

Certain Afrigora features require sensitive personal data or device permissions. We only collect or process these when needed for the feature you use, and (where required) after you grant permission in your device, browser, or account settings. You can usually refuse or withdraw permission, but some features will then be unavailable.

1. BVN and KYC (identity verification)

  • What we collect: Bank Verification Number (BVN), full name, date of birth, phone number, address, and related identity fields needed to create, verify, or operate an Afrigora wallet or meet financial compliance rules.
  • Why we collect it: To verify that you are who you say you are, prevent duplicate or fraudulent wallets, comply with Nigerian financial and anti-money-laundering expectations, and enable wallet funding, payouts, bills, and related money features.
  • How it is processed: BVN/KYC may be checked with licensed identity or wallet partners (for example wallet infrastructure providers). We use the result to open or maintain your wallet; we do not use BVN for marketing.
  • Sharing: Shared only with verification and wallet partners that need it to complete the check, and with authorities when legally required. The same BVN generally cannot be linked to multiple Afrigora accounts.
  • Your choice: Wallet and some payment features require successful KYC. If you do not wish to provide BVN/KYC, you may still browse and use non-wallet parts of the marketplace where available, but wallet creation and related money services will not complete.

2. Biometrics and body-related data

  • Body measurements: We collect fitting data (for example chest, waist, hip, height, and other tailor measurements). Where you use a guided body scan, camera frames or scan outputs may be processed to derive those measurements.
  • Device biometrics (Face ID / fingerprint): Optional biometric unlock on your device only — for example Profile → Biometric security for faster sign-in or wallet access. Afrigora does not receive or store fingerprint or face templates on our servers. With your opt-in, login tokens or wallet-related secrets may be stored in device secure storage; you can turn this off in app settings. See Biometric security (#biometrics).
  • Why we collect body data: To support custom clothing, tailoring, size recommendations, and order accuracy between you, sellers, and tailors.
  • How body data is processed: Manual measurements you type are stored on your Afrigora profile. Scan-based measurements are generated through our body-scan flow (see Bodygram below) and then saved to your account for tailoring use.
  • Sharing: Measurement data may be shared with the tailor, seller, or service provider fulfilling your order or booking. It is not sold to advertisers.
  • Your choice: You may enter measurements manually instead of scanning where the product allows. You can update or remove measurement profiles through account tools where available, subject to open orders that still need the data.

3. Location data

  • What we collect: Approximate location from IP address by default. Precise GPS or device location when you grant location permission — for example to set a delivery address, find nearby stores or services, support logistics, or (for staff/agent tools) verify attendance or field activity.
  • Why we collect it: To show relevant marketplace content, complete deliveries, calculate logistics context, prevent fraud/abuse, and operate location-dependent staff or agent features.
  • How it is processed: Location may be attached to an address, order, report, or attendance record. We do not continuously track you in the background for advertising.
  • Sharing: Shared with delivery/logistics partners or internal operations only as needed for the feature. Map or geocoding providers may receive coordinates to reverse-geocode an address.
  • Your choice: You can deny or revoke location permission in your device or browser settings. Without precise location, some delivery, nearby, or attendance features may not work; you can often still enter an address manually.

4. Camera and microphone

  • What we collect: Images, video frames, or audio you capture or upload after granting camera and/or microphone permission — including body-scan camera access, profile or product photos, chat photos/videos, and voice notes.
  • Why we collect it: To run body scanning, upload media for listings or support, send chat attachments, and improve order or dispute clarity.
  • How it is processed: Media is transmitted securely to our servers (and, for body scan, to the scan provider described below). We request permission only when a feature needs it; we do not access camera or mic silently.
  • Sharing: Chat and order media may be visible to the other party in that conversation or order. Body-scan camera processing is handled with Bodygram as described below. Hosting/CDN providers may store media files under our contracts.
  • Your choice: You can refuse camera or microphone access. Scanning, voice notes, or in-app capture will then be unavailable, but you may still upload files from your gallery where the feature allows, or use text-only options.

5. Chat media and messaging content

  • What we collect: Text messages and any media you attach in in-app chat or support threads — including images, videos, voice notes, documents, and metadata such as timestamps and participants.
  • Why we collect it: To enable customer–seller–tailor–support communication, resolve disputes, moderate abuse, and keep a record of order-related instructions.
  • How it is processed: Messages are stored on Afrigora systems and shown to participants in the relevant thread. Moderators or support staff may access content when investigating reports, safety issues, or payment disputes.
  • Sharing: Visible to the other participants in the chat and to authorized Afrigora staff for support, trust & safety, or legal compliance. Not used to sell ads based on private message content.
  • Your choice: Do not send sensitive data you do not want stored. You may request deletion of account-related data subject to our retention rules for open disputes, fraud prevention, and legal holds.

6. Push notifications and Firebase Cloud Messaging (FCM)

  • What we collect: A device or browser push token, notification permission status, and related delivery metadata when you enable push notifications on web or mobile.
  • Why we collect it: To send transactional and service alerts — for example order updates, wallet activity, chat or support notices, security alerts, and (where you allow) promotional messages.
  • How it is processed: We use Firebase Cloud Messaging (FCM), a Google service, to deliver pushes to your device. Your token is linked to your Afrigora account or device session so we can target the correct user.
  • Sharing: Device tokens and notification payloads are processed by Google/Firebase as our push infrastructure provider, under their terms and privacy policy, solely to deliver messages we initiate.
  • Your choice: You can deny notification permission or disable pushes in device/browser settings or in-app notification preferences where available. Essential in-app inbox messages may still appear when you open Afrigora.

7. Bodygram (third-party body scan provider)

  • What it is: Bodygram is a third-party body-scanning service embedded or opened in our measurements flow so you can generate tailor measurements with your camera instead of measuring manually.
  • Minimum age (16+): Bodygram body scanning is intended only for users aged 16 and older, consistent with Bodygram’s platform requirements and our Children’s Privacy section below. By starting a Bodygram scan you confirm you are at least 16. Users under 16 must not use Bodygram scanning; use manual measurements instead or ask a parent or guardian to manage sizing on your behalf outside this scan feature.
  • What is shared with Bodygram: When you start a scan, we may provide a short-lived scan token and necessary session context (including age and related scan parameters you enter). Bodygram processes camera input on their systems to compute body measurements. Resulting measurement data is returned to Afrigora and saved to your profile.
  • Why we use it: To offer accurate, guided sizing for custom and tailored clothing.
  • Independent processing: Bodygram processes scan data under its own privacy practices while the scan runs. Afrigora does not control Bodygram’s internal cameras pipelines; we receive the measurement outputs needed for your order.
  • Your choice: Bodygram scanning is optional. You may decline camera access or enter measurements manually. If you use the scan, you acknowledge that Bodygram will process the scan session as described in their documentation and privacy terms.

8. Financial data

  • What we collect: Wallet balances and ledgers; funding, withdrawal, transfer, and bills-payment records; transaction amounts, references, status, and timestamps; bank or mobile-money account details you submit for payouts; card or checkout details handled by payment partners; and related receipts or dispute evidence.
  • Why we collect it: To operate your Afrigora wallet, process marketplace payments, refunds, commissions, bills (airtime, data, utilities, and similar), prevent fraud, and meet accounting and regulatory obligations.
  • How it is processed: Checkout card and bank payments are processed by Paystack (and similar processors where used). Wallet and bills run through Xpress Payments and licensed partners when enabled. Card numbers and sensitive payment credentials are typically collected directly by those processors and are not stored in full on Afrigora servers. We store transaction references and status needed for your history and support.
  • Sharing: Shared with Paystack, Xpress Payments, banks, mobile-money operators, biller partners, and — where required — auditors or regulators. Counterparties on a transfer or order may see limited payment status needed to complete the trade.
  • Your choice: Using wallet, checkout, withdrawals, or bills requires processing of financial data. If you do not want this processing, do not fund a wallet or complete paid transactions. You can request transaction history access or account closure subject to legal retention periods.

Granting a permission or completing KYC does not mean we will use that data for unrelated purposes. We limit use to operating Afrigora, securing accounts, fulfilling orders, and complying with law.

07

How We Use Your Information

We use personal information to

  • Create and manage accounts, authenticate users, and provide customer support.
  • Verify identity through BVN/KYC where wallet or regulated payment features require it.
  • Process orders, payments, wallet transactions, bills, refunds, and dispute reviews.
  • Connect customers with sellers, tailors, and service providers and display relevant marketplace content.
  • Facilitate measurements (manual or Bodygram scan), custom orders, consultations, and order fulfillment.
  • Deliver in-app and push notifications (including via FCM) for orders, wallet activity, chat, and security.
  • Enable chat and support communications, including media you attach.
  • Use location, camera, or microphone only for the features you invoke and permissions you grant.
  • Improve platform performance, detect fraud, enforce our policies, and protect users.
  • Send marketing or promotional communications where permitted by law and your preferences.
  • Comply with legal obligations, respond to lawful requests, and resolve complaints.

We do not sell your personal information to third-party advertisers.

08

User-generated content (UGC)

This section covers public and listing-related content you create on the marketplace. For peer direct messages (report, block, retention), see Messaging between users (#messaging-safety). For the AI Assistant, see #ai-assistant.

What counts as UGC

  • Product reviews, ratings, Q&A, and public feedback on stores or services.
  • Store, tailor, and listing content you upload (descriptions, images, portfolio media, ads).
  • Reports you file about stores or products (see also Store reports).

How we use UGC

  • To display listings, fulfill orders, and resolve disputes.
  • For trust & safety: review of reported content, enforcement of community standards, and fraud prevention.
  • To comply with law or respond to valid legal requests involving harmful or illegal content.

Visibility and retention

  • Public reviews and listing media may be visible to other users and search engines according to your listing settings.
  • UGC may be retained while an account is active and for a period afterward for disputes, legal holds, and audit — even if you close an account, where retention is required.

Your choices

  • Do not post content you do not want stored or displayed publicly.
  • You may request removal of certain UGC or account data subject to our retention rules — see Your Rights and our Data & account requests page.
09

Messaging between users (UGC)

Peer direct messages support orders, consultations, tailoring, and marketplace support between customers, sellers, tailors, producers, and Afrigora staff. This section does not cover the AI Assistant (#ai-assistant).

What we collect and process

  • Message content: text and attachments you send (for example images, voice messages when you use the microphone, documents).
  • Conversation metadata: timestamps, read/delivery indicators, conversation and message identifiers, and participant account IDs and display names needed to deliver chat.
  • Messages are stored and processed on Afrigora systems so threads sync across your devices and counterparties can receive them.

Voice messages

  • You may send voice messages in marketplace chat. We collect the audio you record, store it, and transmit it like other message content so the recipient can play it.
  • Microphone access is used only when you choose to record a voice message — not for always-on listening.

Reports

  • When you report a user or message, we collect the reason, optional comment or description, and links to the reported user, conversation, and/or message ID.
  • The customer app may also let you attach evidence images to a report.
  • Reports are submitted to Afrigora and reviewed by authorised staff (for example admin, editor, operations, or accountant roles with moderation access).
  • Submitting a report does not guarantee immediate removal of content or accounts; we review each case against our Terms and safety policies.
  • False or abusive use of the report tool may lead to restrictions on your account.

Block lists

  • Block relationships are stored on Afrigora servers and are the source of truth for who can message whom.
  • When you block someone, new peer messages between you and that user are generally prevented in both directions. Blocked users may be hidden from your inbox.
  • You can manage blocks from Profile → Blocked users and may unblock a user from that list where the app supports it.
  • Blocking does not cancel open orders; use order support or disputes for transaction issues.

Hide, archive, and delete conversation

  • You can hide or archive a thread from your inbox without blocking the other person.
  • Hide, archive, or delete conversation actions affect your inbox view only — they do not delete messages from the other participant’s thread or from server records needed for safety, disputes, or legal compliance.

When you report a message

  • We collect the report reason, optional comment, and linked message, conversation, and user identifiers. Authorised staff (for example admin, editor, or accountant roles with moderation access) review reports; cases may be resolved or dismissed. Related data is kept for safety and legal retention as described below.

Moderation outcomes

  • Staff may resolve, dismiss, or escalate reports and may warn, restrict, suspend, or remove accounts or content where policies are violated.
  • When a report case is closed, the reporter may receive an in-app or push notification where the product supports it.
  • Authorised staff may access reported message excerpts and related account data to investigate; internal admin tools are not described in detail here.

Retention

  • Messages, block records, and report data are retained for as long as needed for service delivery, safety, fraud prevention, dispute resolution, and legal compliance — typically including a period after account closure where law or active investigations require it. We will publish more specific retention schedules when finalised.

Community standards (see Terms)

  • Harassment, scams, hate, threats, sexual exploitation, violence, impersonation, and spam are prohibited in peer chat under our Terms & Conditions.
  • This Privacy Policy explains how we handle chat data; acceptable use and enforcement consequences are in our Terms — not a substitute for reading them.
10

AI Assistant (generative AI)

The Afrigora AI Assistant — including the AI Assistant tab in the Afrigora customer app and routes such as /ai-assistant in mobile apps — is separate from user-to-user chat: automated software responses, not human Afrigora support. Report and block tools for peer messaging do not apply to AI threads.

What we collect and why

  • Prompts you send, replies the assistant returns, session identifiers, and server-side session history so the feature works across visits, improves reliability, and helps answer questions about Afrigora features and how to use the platform.
  • Afrigora does not expose third-party API keys in client apps; processing happens on our backend.

Automated responses and limitations

  • Outputs are AI-generated and may be incomplete or inaccurate. They are not professional, legal, medical, or financial advice.
  • Do not enter passwords, OTP codes, BVN, bank or card numbers, or other highly sensitive credentials in AI prompts.
  • For orders, payments, or account issues, use support, order details, or wallet tools — not the assistant alone.

Third-party LLM provider

  • When local FAQ or knowledge cannot answer, our backend may send your prompt and limited context to OpenAI (GPT-4o) under our agreement with that provider. We do not use your AI chats to train public third-party models.
  • OpenAI’s privacy practices are described at https://openai.com/policies/privacy-policy/ (subject to change by OpenAI).
  • See Subprocessors (#subprocessors) and Data collection & sharing (third parties).

Retention

  • AI session data is kept for as long as needed to operate the feature, prevent abuse, and improve reliability, then deleted or anonymized according to schedules we publish when finalised. Contact us if you have questions about a specific session.

Reports and blocking

  • Peer messaging report and block tools do not apply to AI Assistant threads. Contact support if you have a concern about an AI response.
11

Wallet setup & identity (KYC)

Creating and using an Afrigora wallet may require identity verification beyond everyday shopping. This section supplements Financial & wallet data above.

Information for wallet creation

  • We may collect BVN, date of birth, legal name, phone number, address, and related KYC fields to verify identity, prevent fraud, and meet regulatory requirements for wallet, transfer, withdrawal, and bills features.
  • Verification is processed with licensed partners (for example Xpress Payments and identity-check providers). Afrigora does not use BVN for marketing.
  • Wallet funding in current Afrigora and Pro builds emphasises bank transfer to virtual account details shown in the app — not card top-up on the wallet itself. Checkout may still use Paystack where offered.

Transfer PIN

  • You choose a transfer PIN (or equivalent authorization) to confirm wallet transfers and sensitive money actions. The PIN is used to authorize transactions; it is not a biometric template and is handled according to our security practices for credentials.

Retention after account closure

  • Wallet balances, ledger entries, BVN/KYC audit trails, and bills or transfer records may be retained after account deletion or deactivation where required by law, accounting, anti-money-laundering rules, chargebacks, or disputes.
  • See Account closure (#account-closure) and Data retention on this page.

Minimum age for wallet and regulated money features: see Children's Privacy. Wallet creation is not offered to users below the stated minimum age.

12

Financial & wallet data (summary)

Wallet, checkout, bills, referrals, and marketplace payments involve financial personal data. Section 8 above describes collection in detail; this summary highlights safety and sharing.

Afrigora offers a digital wallet funded only by bank transfer (account details shown in the app). Checkout and some international orders may use Paystack; card details are entered on Paystack’s pages, not stored in the Afrigora app. Wallet and payment records may be kept after account deletion where required by law or to resolve disputes.

Refund and chargeback rules for orders and wallet activity are described in our Refund Policy (https://afrigora.biz/refund-policy).

Key points

  • Wallet creation and higher-risk money features may require BVN/KYC verification through Xpress Payments and licensed partners.
  • Checkout card payments are processed by Paystack; card data is collected on Paystack pages, not stored in full on Afrigora servers.
  • Transaction history, balances, bills payments, withdrawals, and referral commissions are processed to provide the service and meet regulatory expectations.
  • Financial records may be retained after account closure for accounting, tax, anti-fraud, and dispute resolution.
13

Bills, airtime & data (wallet debits)

When you pay electricity, TV/cable, education products, airtime, or mobile data from your Afrigora wallet, we process the purchase through our bill-payment infrastructure.

See also Wallet setup & identity (#wallet-kyc), Financial & wallet data, and https://afrigora.biz/refund-policy.

Data we process

  • Meter numbers, smartcard or decoder IDs, education registration details, biller and product codes, phone numbers for top-ups, amounts, and transaction references.
  • Wallet debit status and receipts shown in your transaction history.

Processors and utilities

  • Bills are fulfilled through Xpress Payments biller services (and underlying network operators, DISCOs, cable providers, and education boards). Afrigora does not operate electricity, telecom, or cable networks — we route payment and return fulfilment status.
  • Validated account details may be sent to the biller or aggregator to complete the purchase.
  • Disputes and refunds for wallet debits and bill purchases are handled under our Refund Policy where applicable.
14

Body measurements & Bodygram scan

Tailoring and custom clothing on Afrigora may use measurements you enter manually or generate through an optional camera-based scan.

Device biometrics (fingerprint or face unlock) are described in Biometric security (device-only) — separate from Bodygram body measurements.

Manual measurements

  • You can save measurement sets on your profile (for example chest, waist, hip, length). These may be shared with tailors and sellers fulfilling your orders.

Bodygram scan (optional)

  • When you start a scan, you may use an in-app WebView or guided flow powered by Bodygram. Camera (and microphone only if the scan flow requires it) input is processed by Bodygram to produce measurement outputs returned to Afrigora.
  • Bodygram scanning is for fit and tailoring only — not medical diagnosis or clinical use. Users under 16 must not use Bodygram scanning; parental guidance is required for minors using manual measurements.
  • Review Bodygram’s privacy terms when you use the scan feature.

Retention

  • Measurements remain tied to your account until you delete them or close your account, subject to open orders and tailor jobs that still require the data.
15

Referral & Invite & earn

Afrigora offers optional referral codes so you can invite shoppers and business users to the marketplace.

Data we process

  • Your customer and vendor referral codes, who signed up with your code (attribution), referred orders or sales, commission rates, amounts earned, and payout status to your wallet.
  • For customer referrals, commissions may relate to tax on referred users’ orders; for vendor referrals, commissions may relate to platform fees on referred sellers’ sales — as shown in your Invite & earn dashboard.

Purpose

  • To operate the rewards program, credit your wallet, prevent abuse of codes, and meet accounting obligations.
16

Biometric security (device-only)

Afrigora Pro and the Afrigora customer app offer optional Face ID, fingerprint, or other device biometrics (Profile → Biometric security) to unlock the app or confirm wallet and transfer screens. This is separate from Bodygram body scanning.

How it works

  • Biometrics are used only on your device to unlock the app or wallet UI faster. Biometric templates stay in your operating system secure enclave — Afrigora does not receive, transmit, or store fingerprint or face data on our servers.
  • With your opt-in, the app may store login tokens or wallet-related secrets in device secure storage (for example Keychain or Keystore) so you do not re-enter credentials each time.

Your choices

  • You can turn biometric unlock off in Profile → Biometric security (or equivalent settings) and use password or PIN instead.
  • Denying OS biometric permission disables this convenience feature only; core account security still uses your password, OTP, and transfer PIN where applicable.
17

Push notifications

We use push services (including Google Firebase Cloud Messaging) to deliver alerts you enable on your device or browser.

Data

  • Firebase Cloud Messaging (FCM) device push token and, where the app collects it, a device identifier linked to your account for targeting notifications.
  • Notification titles, bodies, and deep-link metadata for orders, messages, wallet or payout alerts, and account events.

How to disable

  • Turn off notifications in your phone or browser OS settings, and adjust in-app notification preferences where available.
  • You may still see in-app inbox or order updates when you open Afrigora.
18

Store reports (marketplace)

In addition to message reports, you can report a store or marketplace listing from Profile → My reports (or equivalent).

What you submit

  • Reason, description, optional images, and the store or listing being reported.

Use and retention

  • Staff review store reports for policy, safety, and fraud. Reports are kept as long as needed for investigations, disputes, and legal compliance — separate from chat message report records.
19

Shipping, location & addresses

Delivery, store fulfilment, and address book features use location and address data as described below.

Addresses you provide

  • Delivery, billing, store, tailor, pickup, and fulfilment addresses you type or save — including Nigeria and international destinations where offered.
  • Postal codes, landmarks, and contact phone numbers on those addresses.

Location and maps

  • Approximate location from IP address for general site experience.
  • Precise GPS or device location when you grant permission — for example to suggest an area label, pick a delivery point, or use “near me” features on web or mobile.
  • Coordinates may be sent to map or geocoding providers (for example OpenStreetMap Nominatim on supported web flows) to reverse-geocode a label; we do not use continuous background location tracking for advertising.

Sharing and retention

  • Addresses and phone numbers are shared with sellers, tailors, and logistics partners (for example GIG Logistics) only as needed to quote, fulfil, and track orders.
  • Saved addresses remain on your account until you remove them or close your account, subject to order history and legal retention.

International checkout

  • Some international orders may be priced or paid in USD through Paystack-hosted checkout. Card and payment data for those orders are handled on Paystack pages, not stored in full on Afrigora servers.
20

Save Small savings goals

Save Small lets you lock wallet funds toward specific marketplace products and redeem them at checkout with a vendor discount.

Data and funds

  • Goal amounts, linked products, contribution schedule, progress, and wallet debits for contributions are stored with your account.
  • Reserved stock on vendor products may apply while your goal is active.

Account closure

  • You must cancel or complete open Save Small goals (active or paused) before customer account deletion or vendor deactivation can proceed.
  • See Account closure (#account-closure) and our Terms.
21

Local device storage

Mobile and web apps may store small amounts of data on your device for performance and offline UX. Server records remain the source of truth for account, wallet, blocks, and messages.

Examples

  • Cached block lists or conversation UI state so the inbox loads faster.
  • AI Assistant session identifiers in local app storage to resume a thread.
  • Login tokens or wallet-related secrets in OS secure storage when you enable biometric or “remember me” features — see Biometric security (#biometrics).
22

Optional features (translation & analytics)

In-app translation

  • If message or listing translation is enabled in your build, user-visible text you choose to translate may be sent to Google Cloud Translation or a similar service (or our proxy) to return a translation. We will update this policy when that feature is generally available in production.

Analytics and crash reporting

  • We may use analytics or crash-reporting tools in some app builds to understand stability and usage. When active, those tools receive technical diagnostics (for example device model, OS version, crash stack traces) as configured for each release. We do not list a specific vendor here until it is confirmed for all Pro production builds.
24

How We Share Information

We share personal information only when necessary to operate the marketplace, complete transactions, or meet legal requirements.

If Afrigora is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction subject to appropriate protections.

See Data collection & sharing (third parties) below for a partner-by-partner list aligned with app-store data safety disclosures.

We may share information with

  • Sellers, tailors, and service providers involved in fulfilling your order or consultation (including relevant measurements and order chat).
  • Paystack for checkout payments; Xpress Payments for wallet, bills, and related KYC when you use wallet features.
  • BVN/identity verification partners when you create or verify a wallet.
  • Bodygram when you start a camera-based measurement scan (16+ only).
  • Google Sign-In (optional), Google Firebase (FCM) for push delivery, and Google Workspace for transactional email we send.
  • GIG Logistics and other delivery partners; OpenStreetMap Nominatim for reverse geocoding on supported web features.
  • Hosting and object-storage providers (for example Linode) that store media and platform data under contract.
  • Professional advisers, auditors, or authorities when required by law or to protect rights and safety.
  • Other parties with your direction or consent, such as when you choose to share order details externally.

Public or profile information

  • Reviews, ratings, and public profile details you choose to make visible on the platform.
  • Store or tailor listings, portfolio media, and business contact details submitted for marketplace display.
25

Data collection & sharing (third parties)

The list below names main third parties that collect or receive personal data when you use Afrigora features. Use the same names and purposes when completing app-store data safety or similar disclosure forms. Details for sensitive categories (BVN/KYC, camera, chat, financial data) are in the sections above.

Paystack (payments)

  • Role: Payment processor when you pay by card, bank transfer, or other Paystack-supported methods at checkout (including international USD checkout where offered).
  • Data collected or shared: Name, email, phone, order amount and currency, transaction references; payment credentials you enter on Paystack-hosted checkout (Afrigora does not store full card numbers).
  • Purpose: Authorize payment, prevent fraud, and return payment status to Afrigora so orders can be fulfilled.
  • When it applies: Only when you select Paystack (or are redirected to Paystack) — not for wallet-only checkout.

Xpress Payments (wallet & bills)

  • Role: Licensed wallet infrastructure and bill-payment (airtime, data, utilities, cable, etc.) partner when wallet features are enabled.
  • Data collected or shared: KYC fields (including BVN where required), name, phone, date of birth, address, wallet and transaction amounts, bank details for withdrawals, bill account numbers you submit.
  • Purpose: Create and operate your wallet, process transfers, withdrawals, bills, and regulatory identity checks.
  • When it applies: When you create or use an Afrigora wallet, pay bills, or move money through wallet rails — not for browsing-only use.

Google — Sign-In (optional)

  • Role: OAuth sign-in if you choose “Continue with Google” on web or supported apps.
  • Data collected or shared: Google account identifier, name, email address, and profile image as permitted by Google and your account settings.
  • Purpose: Register or sign in without a separate password; link your Google identity to your Afrigora account.
  • When it applies: Only when you initiate Google sign-in — not required to use email/password registration.

Google Firebase Cloud Messaging (FCM)

  • Role: Push notification delivery infrastructure.
  • Data collected or shared: Device or browser push token, notification payload (titles, bodies, deep-link metadata), and delivery metadata.
  • Purpose: Send transactional alerts (orders, wallet, chat, security) and, where permitted, promotional pushes.
  • When it applies: After you enable notifications on a device or browser that registers for FCM.

Google Workspace (transactional email)

  • Role: Email delivery provider for service messages sent by Afrigora (SMTP).
  • Data collected or shared: Your email address and message content such as OTP codes, password-reset links, order or account notices we send.
  • Purpose: Deliver verification, security, and transactional email you request or that is necessary to operate your account.
  • When it applies: When we send email to the address on your account (registration, login OTP, account closure OTP, support replies, etc.).

OpenAI (AI Assistant)

  • Role: Large language model provider when the in-app AI Assistant cannot answer from local FAQ/knowledge.
  • Data collected or shared: Your question/prompt and limited session context sent by Afrigora backend; response text returned to display in the assistant.
  • Purpose: Generate helpful marketplace answers; not used to sell ads.
  • When it applies: Only when you use the AI Assistant and the backend escalates beyond local knowledge — not for peer-to-peer chat.

Bodygram (optional body scan)

  • Role: Third-party body-scanning service for camera-based measurements.
  • Data collected or shared: Scan session token, age (16+ required), gender, height, weight, and camera input processed on Bodygram systems; measurement outputs returned to Afrigora.
  • Purpose: Generate tailor measurements when you choose scan instead of manual entry.
  • When it applies: Only when you start a Bodygram scan in the measurements flow — optional; users under 16 must not use this feature.

GIG Logistics (shipping)

  • Role: Delivery and logistics partner for domestic and international shipments where GIG is used.
  • Data collected or shared: Recipient and sender names, phone numbers, delivery addresses, order/shipment references, and package details needed to quote and ship.
  • Purpose: Price delivery, book shipments, and provide tracking updates.
  • When it applies: When your order includes delivery fulfilled through GIG (or related logistics flows).

OpenStreetMap Nominatim (geocoding — web)

  • Role: Reverse geocoding on the website when you use location-based features (for example “near me” on consultation).
  • Data collected or shared: Latitude and longitude coordinates you allow the browser to share for that request.
  • Purpose: Convert coordinates into a readable area label; coordinates are sent to Nominatim under their usage policy.
  • When it applies: Only when you use features that call our reverse-geocode proxy with your coordinates.

Cloud hosting & object storage

  • Role: Infrastructure providers (for example Linode Object Storage and related hosting) that store app data and user-uploaded media under contract.
  • Data collected or shared: Account data, chat and listing media, profile images, and other files you upload, stored encrypted in transit (HTTPS) and protected by access controls.
  • Purpose: Host the platform, serve images and attachments, and run backups.
  • When it applies: Throughout normal use of Afrigora when content is saved to our systems.

Marketplace counterparties (not ads)

  • Role: Sellers, tailors, producers, and customers involved in your orders — not third-party advertisers.
  • Data collected or shared: Order details, relevant measurements, delivery contact info, chat messages, and payment status needed to complete the transaction.
  • Purpose: Fulfill orders, consultations, and custom work you request.
  • When it applies: When you place orders, book services, or message other users about a transaction.

We do not sell personal information to third-party advertisers. Optional features (Google sign-in, Bodygram scan, push notifications, wallet) only share data when you use those features. For access, correction, or deletion requests, see Data & account requests.

26

Subprocessors & international processing

The table below summarizes main processors that handle personal data on our behalf. A fuller feature-by-feature list is in Data collection & sharing (third parties). Data may be processed in Nigeria and other countries where we or these providers operate.

For access, correction, or deletion requests, see https://afrigora.biz/privacy/data-request or contact support@afrigora.biz.

Processor summary

  • Paystack — checkout payments, some payouts and resolve flows; international card checkout where offered.
  • Xpress Payments — wallet, KYC, transfers, withdrawals, and biller (airtime, data, utilities, cable, education).
  • Google — optional Sign-In; Firebase Cloud Messaging (push).
  • Google Workspace — transactional email (OTP, account notices).
  • OpenAI — AI Assistant when local FAQ cannot answer (backend only).
  • Bodygram — optional body scan measurements when you start a scan.
  • GIG Logistics — shipping and delivery fulfilment.
  • Cloud hosting & object storage (for example Linode) — API, media, chat images, report evidence.
  • OpenStreetMap Nominatim — reverse geocoding on supported web features.
27

Cookies & Similar Technologies

We use cookies and similar technologies to keep the site working, remember preferences, and understand how visitors use Afrigora.

Types of cookies we may use

  • Essential cookies required for sign-in, checkout, security, and core site functionality.
  • Preference cookies that remember settings such as language or region where available.
  • Analytics cookies that help us measure traffic and improve performance.
  • Marketing cookies, where used, to understand campaign effectiveness.

Your choices

  • You can manage cookies through your browser settings.
  • Blocking essential cookies may prevent parts of the platform from working correctly.
  • Where required by law, we will request consent before placing non-essential cookies.
28

Data Retention

We retain personal information for as long as needed to provide services, complete transactions, resolve disputes, enforce agreements, and comply with legal obligations.

Account information is generally kept while your account remains active and for a reasonable period afterward unless deletion is requested and permitted by law.

Order, payment, wallet, BVN/KYC audit trails, and dispute records may be retained longer where required for accounting, tax, fraud prevention, or regulatory compliance.

Chat media, measurement profiles, and push tokens are kept while needed for the service and may be removed when you delete related content or disable notifications, subject to backup and legal holds.

When information is no longer needed, we take reasonable steps to delete, anonymize, or securely store it.

29

Security & data safety

This summary describes how we approach data safety across Afrigora products. It is intended to align with app-store data safety disclosures and our internal security practices.

We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration — including sensitive categories such as KYC, financial records, and media.

No online service can guarantee absolute security. You are responsible for keeping your password confidential and notifying us promptly if you suspect unauthorized account access.

If we become aware of a security incident that affects your personal information, we will take appropriate steps in line with applicable law.

Data safety summary

  • Data is collected for account operation, marketplace transactions, wallet and bills, tailoring and measurements, chat and support, trust & safety, and legal compliance — not sold to third-party advertisers.
  • Sensitive categories include identity/KYC (BVN), financial and wallet records, location (when permitted), camera/microphone media, chat content, push tokens, and body measurement data.
  • Data is transmitted over encrypted connections (HTTPS/TLS) in production environments. Access to production systems is restricted to authorized personnel.
  • We use contractual and organizational safeguards with Paystack, Xpress Payments, KYC, hosting, GIG, FCM, Bodygram, and email delivery partners that process data on our behalf.
  • You can request deletion or account closure subject to retention rules described in this policy and on our public data request page.
30

Your Rights & Choices

Depending on your location and applicable law (including GDPR-style rights for users in the EEA, UK, or similar jurisdictions), you may have rights regarding your personal information.

You may have the right to

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete account or profile information.
  • Request deletion or erasure of personal information, subject to legal and operational requirements.
  • Object to or restrict certain processing activities.
  • Data portability where technically feasible and required by law.
  • Withdraw consent where processing is based on consent — including revoking camera, microphone, location, or notification permissions in your device or browser.
  • Opt out of marketing emails or messages using the unsubscribe method provided.
  • Choose manual measurements instead of Bodygram scanning, and avoid wallet features if you do not wish to provide BVN/KYC.

Delete vs deactivate

  • Customer Delete account and Pro Deactivate account have different effects; neither guarantees immediate erasure of all data.
  • Reports, blocks, messages, wallet ledgers, and KYC records may be retained for safety, fraud prevention, and legal compliance after closure where permitted by law.

How to exercise your rights

  • Data controller contact for rights requests: support@afrigora.biz.
  • Use our Data & account requests page at https://afrigora.biz/privacy/data-request with your full name, registered email, request type (access, correction, erasure, export, objection), and whether you use Afrigora, Afrigora Pro, or both.
  • Customers use Profile → Delete account; Pro business users use Settings → Deactivate account with OTP — see #account-closure.
  • Update certain account details directly through your profile or settings where available.
  • Manage OS/browser permissions for location, camera, microphone, and notifications at any time.
  • We may need to retain some information to complete orders, prevent fraud, or comply with law even after a deletion request — especially KYC, financial records, and moderation reports.
31

Children's Privacy

Afrigora is not directed to children under 16, and we do not knowingly collect personal information from children under 16.

Bodygram camera-based body scanning is restricted to users 16 and older. We do not offer Bodygram scanning to accounts or sessions we know involve users under 16.

Wallet creation, BVN/KYC, and regulated money features are intended for adults who can enter into binding contracts under applicable law (typically 18+ in Nigeria). If you are under 18, use the marketplace only with a parent or guardian’s permission and do not create a wallet unless you meet eligibility shown in the app and our Terms.

If you believe a child has provided personal information to us, contact us and we will take appropriate steps to review and remove the information where required.

32

International Data Transfers

Afrigora primarily serves users in Africa and may process information in Nigeria and other countries where we or our service providers operate.

Where personal information is transferred across borders, we take reasonable steps to ensure appropriate safeguards consistent with applicable law.

34

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or business practices.

Material updates will be posted on this page with a revised date. Continued use of the platform after changes take effect constitutes acceptance of the updated policy where permitted by law.

35

Contact Us

If you have questions about this Privacy Policy or how we handle personal information, contact Afrigora using the details below.

Support channels

  • Email: support@afrigora.biz
  • Phone: 08035099186
  • Website: https://afrigora.biz

Please include your account email or phone number and a clear description of your request so we can assist you efficiently.