Effective Date: January 2026
BillVault (“BillVault”, “we”, “our”, “us”) is a cross-border payment and financial services platform providing virtual USD cards, international payments, bill payments, digital asset services, and flight booking services. Your privacy matters to us. This Privacy Policy explains how we collect, use, share, and protect your information in accordance with NDPR (Nigeria Data Protection Regulation) and NDPA 2023.
1. Information We Collect
We may collect the following categories of information:
a. Personal Information
- Full name
- Phone number
- Email address
- Date of birth
- Government-issued identification and verification details (KYC)
- Address and nationality
- Flight booking information: passenger details, ticketing information, travel itinerary, passport/ID numbers, frequent flyer numbers
b. Financial and Transaction Data
- Payment and transaction history
- Virtual card usage
- Wallet balances and activity
- Fiat and digital asset deposits and withdrawals
- Flight booking payment details (if paid via BillVault platform)
c. Device and Technical Information
- IP address
- Device identifiers
- Browser type and operating system
- App usage data and logs
d. Location Information
- Approximate location data may be collected for fraud prevention, compliance, security, and flight booking operational purposes (e.g., verifying origin/destination, regulatory compliance)
2. How We Use Your Information
We use your information to:
- Verify identity and comply with KYC, AML, and counter-terrorism financing laws
- Provide virtual cards, payment processing, digital asset, and flight booking services
- Facilitate international transactions, settlements, and ticket issuance
- Prevent fraud, unauthorized access, and suspicious activity
- Improve platform performance and user experience
- Communicate important service updates, security alerts, and notices
- Meet legal, regulatory, and reporting obligations, including those specific to air travel
3. Legal Basis for Processing
We process your data based on one or more of the following grounds:
- Performance of a contract (e.g., flight booking or financial service)
- Legal and regulatory compliance
- Legitimate business interests
- Your consent, where required by law
4. Data Sharing and Disclosure
We do not sell your personal data.
We may share information with:
- Regulatory authorities and law enforcement when legally required
- Payment processors, card networks, and banking partners to deliver services
- Airlines and flight booking infrastructure providers to facilitate ticketing and travel services
- Blockchain analytics and compliance providers for risk monitoring
- Fraud prevention and identity verification partners
- Technology and infrastructure providers operating under strict confidentiality
All third parties are required to protect your data and use it only for authorized purposes.
5. International Data Transfers
BillVault operates globally. Your information, including flight booking details, may be processed
or stored outside your country of residence. We implement appropriate safeguards, contractual
protections, and security controls to ensure your data remains protected in accordance with
applicable laws.
6. Data Security
We employ industry-standard safeguards, including:
- Encryption of sensitive data
- Secure access controls and authentication
- Continuous system monitoring
- Periodic security assessments
Despite our efforts, no system is completely secure. Users share information at their own risk.
7. Your Rights (NDPR-Compliant)
Under Nigerian data protection law, you have the following rights regarding your personal data:
- Right of Access – Request access to personal data we hold about you and information on how it is processed.
- Right to Rectification – Correct inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten) – Request deletion of personal data where processing is no longer necessary or consent is withdrawn.
- Right to Restrict Processing – Limit the processing of personal data in specific circumstances.
- Right to Data Portability – Receive your personal data in a structured, commonly used, and machine-readable format and transfer it to another service provider.
- Right to Object – Object to the processing of your personal data for legitimate interests, direct marketing, or other purposes permitted under law.
- Right to Withdraw Consent – Withdraw consent where processing is based on your prior consent without affecting the lawfulness of processing before withdrawal.
Requests to exercise these rights may be sent to: dpo@billvault.app. BillVault will respond
within the timelines required by law.
8. Cookies and Tracking
We use cookies and similar technologies to improve functionality and analyze usage. This
includes flight booking services. You may manage cookie preferences through your device or
browser settings.
9. Updates to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated
through the app or via email.
10. Contact
Support: support@billvault.app
Data Protection Officer: dpo@billvault.app
