Privacy Policy
Effective 11 October 2026
This policy explains how JVC Projects Ltd handles personal data on RaiseAm, in line with the Nigeria Data Protection Act 2023 (NDPA). It covers merchants who use RaiseAm and customers who shop on stores built with RaiseAm.
1. Who is responsible
- Merchant accounts and our website: JVC Projects Ltd is the data controller.
- Customers of a store: the merchant who runs that store is the controller of their customers' data. RaiseAm processes it on the merchant's behalf, only to run the store. Questions about an order should go to the merchant first; we will help where we can.
2. What we collect
- Merchants: name, email, phone number, password (stored only as a secure hash), business name, type and location, store design, logo and products, plan and billing records, and Paystack keys, which are stored encrypted.
- Customers: name, phone number, email, delivery address, order details and payment status. Card details are entered on Paystack and never reach or are stored by RaiseAm.
- Everyone: basic technical data such as IP address, browser type and pages visited, for security and to count store visits.
3. Why we use it, and our lawful basis
- To provide accounts, stores, orders and payments: performance of a contract.
- To send receipts, order updates and password-reset emails: performance of a contract.
- To keep RaiseAm secure, prevent fraud and fix problems: legitimate interests.
- To keep financial and tax records: legal obligation.
- To send marketing about RaiseAm: only with your consent, which you can withdraw at any time.
4. Who we share it with
We do not sell personal data. We share it only with service providers who help us run RaiseAm, under contracts that protect it:
- Paystack, for payments;
- Amazon Web Services (AWS), Ireland (European Union), for hosting and backups;
- Cloudinary, for storing product and store images;
- Resend, for sending emails;
- the merchant whose store a customer orders from.
We may also disclose data where the law requires it, or to protect the rights and safety of users.
5. Transfers outside Nigeria
Our servers are in the European Union, and some providers operate in other countries. Where data leaves Nigeria we rely on the safeguards the NDPA allows, such as the recipient country's adequate data protection laws and contractual protections.
6. How long we keep it
- Merchant account data: while the account is open, then up to 12 months after closure, except where we must keep it longer.
- Order and payment records: up to 6 years, for accounting and tax purposes.
- Backups: overwritten on a rolling basis, normally within 14 days.
7. Your rights
Under the NDPA you can ask to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to how we use it, and withdraw consent. Email info@raiseam.ng; we will reply within 30 days. Merchants can delete their account by contacting us. If you are unhappy with our response you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng).
8. Security
We use encrypted connections (HTTPS), hashed passwords, encrypted payment keys, access controls and regular backups. No system is perfectly secure; if a breach affects your data we will tell you and the regulator as the law requires.
9. Cookies
RaiseAm uses only the cookies needed to keep you signed in and to run checkout. We do not use advertising cookies. Visits to stores are counted without advertising trackers.
10. Children
RaiseAm is for adults. We do not knowingly create accounts for anyone under 18.
11. Changes
We may update this policy and will show the new effective date here. For important changes we will tell merchants by email or in the dashboard.
JVC Projects Ltd (RC 1238780), DU15 NSITF Estate, Kagini, FCT Abuja, Nigeria. Contact: info@raiseam.ng, Support phone to be confirmed.
