Legal
Privacy Policy
Website: www.a-shopper.com · DPO: privacy@ashopper.com · Related: Cookie Policy
Last Updated: May 2026 · Effective: 1 June 2026 · Version 1.0 Legally Verified
| Detail | Information |
|---|---|
| Registered Name | A-Shopper Global Limited |
| RC Number | RC: 7835618 |
| Registered Address | [Registered Office Address], Lagos, Federal Republic of Nigeria |
| DPO Email | privacy@ashopper.com — all data subject rights requests (NDPA 2023 s.32) |
| Privacy Policy | https://www.a-shopper.com/privacy |
| Cookie Policy | https://www.a-shopper.com/cookies |
| Customer Support | support@ashopper.com |
| Legal | legal@ashopper.com |
| Compliance / AML | compliance@ashopper.com |
| Supervisory Authority | Nigeria Data Protection Commission (NDPC) — established under NDPA 2023 s.4 |
| NDPC Website / Complaints | www.ndpc.gov.ng | complaints@ndpc.gov.ng |
| DCPMI Registration | Registered with NDPC as Data Controller of Major Importance under NDPA 2023 s.44 |
1. Who We Are: Data Controller & Data Protection Officer
1.1 A-Shopper Global Limited ("A-Shopper", "we", "us", or "our") is the Data Controller of your personal data as defined under the Nigeria Data Protection Act 2023 (NDPA 2023). As Data Controller, A-Shopper determines the purposes and means of processing your personal data and bears full legal responsibility for ensuring compliance with the NDPA 2023 and the NDPA General Application and Implementation Directive 2025 (GAID 2025), which took effect on 19 September 2025 and replaced the NDPR 2019 as the primary implementing instrument.
1.2 A-Shopper is a company incorporated under the laws of the Federal Republic of Nigeria (RC: 7835618), with its registered office at [Registered Office Address], Lagos, Federal Republic of Nigeria. A-Shopper operates a dynamic engineering tools e-commerce marketplace connecting Nigerian, African and Global businesses with verified suppliers, manufacturers, and distributors — offering B2B, B2C, C2C, service-to-service, and rental commerce solutions worldwide.
1.3 Governing Law & Jurisdiction
This Privacy Policy and all data processing activities of A-Shopper are governed by the laws of the Federal Republic of Nigeria. The primary applicable framework is the Nigeria Data Protection Act 2023 as supplemented by the GAID 2025. Supplementary international frameworks (EU GDPR, UK GDPR, CCPA/CPRA, POPIA) apply to the extent required by law for Users in those jurisdictions. Where there is conflict, NDPA 2023 shall prevail for Nigerian-domiciled processing.
1.4 Data Protection Officer (DPO)
In compliance with NDPA 2023 s.32, A-Shopper has designated a dedicated Data Protection Officer with expert knowledge of data protection law and practices. The DPO is responsible for: overseeing data protection compliance; handling all data subject rights requests; advising on DPIAs; and liaising with the NDPC. Contact: privacy@ashopper.com (all data subject rights requests).
1.5 Privacy by Design & Default (NDPA 2023 s.24)
A-Shopper embeds data protection into all Platform systems and processes from inception, applying the principles of data minimisation, purpose limitation, storage limitation, and privacy by default across all operations.
1.6 Records of Processing Activities (RoPA)
A-Shopper maintains comprehensive Records of Processing Activities as required under NDPA 2023, maintained by the DPO and available to the NDPC on request.
1.7 Annual Compliance Audit Return (CAR)
As a DCPMI, A-Shopper files an annual Compliance Audit Return (CAR) with the NDPC by 31 March each year, conducted through an NDPC-licensed Data Protection Compliance Organisation (DPCO) per NDPA 2023 s.44 and GAID 2025.
2. Scope of This Privacy Policy
2.1 This Privacy Policy applies to all personal data A-Shopper collects and processes when you:
- Visit, browse, or use the A-Shopper website or mobile application (Android and iOS);
- Register for an Account or undergo KYC/Vendor verification;
- Place or receive an Order, booking, rental, or service engagement through the Platform;
- Communicate with A-Shopper or other Users through any Platform channel;
- Subscribe to marketing communications or participate in promotions or surveys;
- Access A-Shopper's APIs as a developer or technical integration partner;
- Interact with A-Shopper through social media, events, or offline channels; or
- Browse as a Guest User without a registered Account.
2.2 This Policy applies to all User categories: Buyers, Vendors, Sellers, Service Providers, Renters, Resellers, API Users, and Guest Users — worldwide.
2.3 This Policy forms part of our Terms & Conditions and should be read alongside our Cookie Policy and any role-specific data processing notices applicable to your User type.
2.4 This Policy does not govern the data practices of third-party websites, applications, or services linked to or integrated with our Platform.
3. Personal Data We Collect
3.1 We collect personal data you provide directly, data generated automatically through Platform use, and data received from trusted third-party sources:
| Category | Data Points Collected | Purpose |
|---|---|---|
| Identity Data | Full legal name, username, date of birth, gender, nationality, government-issued ID number (NIN, passport, driver's licence) | Account creation, KYC verification, fraud prevention |
| Contact Data | Email address, phone number(s), delivery address(es), billing address. Next of kin contact collected on voluntary, explicit-consent basis only for account recovery in exceptional circumstances. | Order fulfilment, communications, customer support, account recovery |
| Financial Data | Bank account details, tokenised card data (full card numbers are NEVER stored), payment history, wallet balance, escrow records | Payment processing, refunds, escrow management, AML compliance |
| Transaction Data | Order history, items purchased, cart data, rental records, service bookings, returns, cancellations, dispute records | Order management, analytics, dispute resolution |
| KYC & Compliance Data | Government ID documents, CAC certificate, Tax Identification Number (TIN under the Nigeria Tax Act), proof of address, directors' details, PEP and sanctions screening results | KYC verification, AML compliance under ML(PP)A 2022, vendor onboarding |
| Technical Data | IP address, device ID, browser type and version, operating system, screen resolution, login timestamps, session tokens, referral URLs. MAC addresses are NOT collected. | Platform security, fraud detection, session management |
| Usage & Behavioural Data | Pages visited, search queries, click patterns, product views, session duration, feature usage, A/B test group | Personalisation, analytics, product improvement, marketing optimisation |
| Communications Data | Platform messages between Users, support tickets, live chat transcripts, email correspondence with A-Shopper, review content | Customer support, dispute resolution, compliance monitoring, fraud detection |
| Profile Data | Username, profile photo, business description, reviews posted, ratings, wishlist items, vendor performance score | Platform experience, trust and safety, vendor quality management |
| Location Data | Approximate location from IP address; precise GPS location only where User explicitly grants device permission | Logistics optimisation, localised listings, fraud detection, regulatory compliance |
| Marketing & Preference Data | Newsletter opt-in/out status, communication preferences, promotional campaign engagement, product category interests | Targeted marketing (consent-based only), personalisation, campaign measurement |
| Vendor & Business Data | Business name, RC number, TIN (Nigeria Tax Act), product catalogue, pricing data, inventory levels, fulfilment metrics, payout bank details | Vendor onboarding, quality assurance, payment disbursement, regulatory compliance |
3.2 Special Category Data (NDPA 2023 s.30)
A-Shopper does not intentionally or routinely collect special category personal data. Where such data is collected in exceptional circumstances, explicit written consent is obtained in advance and a specific processing notice is provided.
3.3 Data About Third Parties
If you provide personal data about another person, you confirm that: (a) you have the legal right to share their data; (b) you have informed them about this Privacy Policy; and (c) they are aware their data will be processed as described herein.
3.4 Mandatory vs. Optional Data
Fields marked mandatory during registration, KYC, or checkout are required for service delivery. Optional fields are clearly labelled.
4. How We Collect Your Personal Data
4.1 Data You Provide Directly
- Registration and Account creation: name, email, password, phone number;
- KYC verification submissions: identity documents, proof of address, business documents;
- Order placement and checkout: delivery address, payment details;
- Vendor onboarding: business registration, TIN (Nigeria Tax Act), bank account details;
- Customer support interactions: tickets, live chat, email enquiries; and
- Reviews, ratings, Platform feedback, and marketing preference settings.
4.2 Data Collected Automatically
- Cookies, web beacons, pixel tags, session storage, and similar tracking technologies — see Section 12 and GAID 2025 Art.19;
- Server access logs: IP address, access time, pages requested, HTTP referrer;
- Device and browser information: device model, OS version, browser type, screen resolution; and
- Location data: approximate location from IP address; precise GPS location only with explicit User device permission. MAC addresses are not collected.
4.3 Data Received from Third Parties
- Identity verification and KYC results from NDPC-accredited verification partners;
- Payment and fraud risk signals from CBN-licensed payment processors;
- Business registration data from the Corporate Affairs Commission (CAC);
- Sanctions, PEP, and adverse media screening results from accredited compliance providers; and
- Social media profile data where you register or log in via a social platform.
5. Lawful Basis for Processing Your Personal Data
5.1 A-Shopper processes your personal data only where a valid and documented lawful basis exists under NDPA 2023 s.25. The six lawful bases under s.25(1) are: (a) Consent; (b) Contract; (c) Legal obligation; (d) Vital interests; (e) Public task/interest; (f) Legitimate interests:
| Processing Activity | Lawful Basis | NDPA 2023 s.25(1) | Notes |
|---|---|---|---|
| Account registration & management | Contract | s.25(1)(b) | Necessary to provide Platform services to User |
| Order processing & fulfilment | Contract | s.25(1)(b) | Required to execute Transactions between parties |
| Payment processing & escrow | Contract + Legal obligation | s.25(1)(b)+(c) | Compliance with Nigeria Tax Act & CBN regulations |
| KYC & identity verification | Legal obligation | s.25(1)(c) | ML(PP)A 2022 & CBN KYC Regulations under CBN Act 2007 |
| AML & sanctions screening | Legal obligation | s.25(1)(c) | ML(PP)A 2022 s.9 — mandatory record-keeping & screening |
| Fraud prevention & platform security | Legitimate interest | s.25(1)(f) | LIA conducted & documented by DPO; available on request |
| Customer support & dispute resolution | Contract | s.25(1)(b) | Service delivery obligation to registered Users |
| Legal compliance & court/regulatory orders | Legal obligation | s.25(1)(c) | NDPA 2023, GAID 2025, judicial & regulatory requirements |
| Tax record-keeping & financial reporting | Legal obligation | s.25(1)(c) | Nigeria Tax Act — mandatory tax record-keeping obligation |
| Platform analytics & performance improvement | Legitimate interest | s.25(1)(f) | Improving services; LIA conducted, pseudonymised where possible |
| AI/ML model training | Legitimate interest | s.25(1)(f) | Strictly anonymised data only; no personal data linkage |
| Personalised product recommendations | Legitimate interest / Consent | s.25(1)(a)/(f) | Consent obtained where profiling has significant legal effect per s.37 |
| Marketing & promotional communications | Consent | s.25(1)(a) | Explicit opt-in required; freely & independently withdrawable |
| Special/sensitive category data | Explicit consent | s.25(1) / s.30 | Only where strictly necessary with prior explicit consent |
| Minors' data (emergency processing only) | Legal obligation | s.25(1)(c) | Child Rights Act 2003 + NDPA s.31 — immediate closure & deletion |
5.2 Legitimate Interest Assessments (LIA)
Where s.25(1)(f) is applied, A-Shopper has conducted a formal, documented LIA confirming our interests do not override your fundamental rights. LIA records are available on written request from the DPO.
5.3 Consent Standards (NDPA 2023 s.25(1)(a))
Consent is freely given, specific, informed, and obtained through a clear affirmative action. It is never bundled as a condition of unrelated service and may be withdrawn at any time per s.35.
5.4 Purpose Limitation (NDPA 2023 s.24(1)(b))
Data will not be used for a new, incompatible purpose without fresh notification and, where required, a fresh lawful basis.
5.5 AI/ML Systems
AI/ML training is conducted exclusively on genuinely anonymised or aggregated datasets that cannot be re-linked to any individual.
6. How We Use Your Personal Data
6.1 Platform Operation & Service Delivery
- Creating, managing, and securing your Account; processing Orders, refunds, and returns;
- Managing escrow, rental deposits, and fund disbursements;
- Facilitating communications between Buyers, Vendors, and Service Providers; and
- Sending essential transactional communications: Order confirmations, receipts, delivery updates.
6.2 Security, Fraud Prevention & Legal Compliance
- KYC verification, AML/PEP/sanctions screening per ML(PP)A 2022;
- Detecting, preventing, and investigating fraud and Platform abuse; and
- Maintaining audit trails and compliance records as required by Nigerian law.
6.3 Platform Improvement, Research & Analytics
- Analysing usage patterns, developing new features, A/B testing, and Platform optimisation; and
- Training AI/ML systems using strictly anonymised and aggregated data only.
6.4 Marketing, Personalisation & Recommendations (Consent-Based Only)
- Sending promotional communications only with your explicit opt-in consent under NDPA 2023 s.25(1)(a);
- Delivering personalised product recommendations; and
- Running targeted advertising through approved digital marketing channels.
6.5 Trust, Safety & Quality Assurance
- Monitoring Vendor performance, facilitating the review and rating system; and
- Enforcing our Terms & Conditions and Platform policies.
7. Data Sharing, Disclosure & Third-Party Processors
| Recipient | Data Shared | Purpose & Safeguard |
|---|---|---|
| Vendors & Service Providers | Name, delivery address, order details, contact info | Order fulfilment — minimum data only; DPA in place |
| Payment Processors (CBN-licensed) | Tokenised card data, transaction amount, billing address | Payment processing — PCI-DSS certified; DPA and SCCs where applicable |
| Logistics & Delivery Partners | Name, address, order ID, contact number | Delivery fulfilment — DPA in place; no secondary use permitted |
| KYC / Identity Verification Partners | Identity documents, biographic data | KYC/AML legal obligation — NDPC-accredited processors; DPA in place |
| Cloud & IT Infrastructure Providers | Encrypted platform data | Platform hosting — DPA; encryption at rest and in transit |
| Analytics Providers | Pseudonymised or aggregated usage data | Platform improvement — anonymisation applied; no personal data sold |
| Marketing & Advertising Platforms | Hashed email, device IDs (consent-based only) | Targeted advertising — consent obtained before sharing; data minimisation applied |
| Legal & Regulatory Authorities (NFIU, EFCC, NDPC, CBN) | Data as required by law or court order | ML(PP)A 2022, NDPA 2023, judicial orders — legal obligation; User notified where permitted |
| Fraud Prevention Services | Transaction data, behavioural signals | Fraud prevention — legitimate interest; accredited partners with DPA only |
| Business Acquirers / Successors | Account and transaction data on verified business transfer | Business continuity — Users notified in advance; data protection obligations preserved |
7.1 Data Processing Agreements (DPAs)
All third-party processors are contractually required to: (a) process data only on A-Shopper's documented instructions; (b) implement appropriate technical and organisational security measures; (c) assist in fulfilling data subject rights; and (d) comply with NDPA 2023 and GAID 2025.
7.2 Sub-Processors
A current list of key sub-processors is available on request from privacy@ashopper.com.
7.3 Legal Disclosures
A-Shopper may disclose personal data to the NFIU, EFCC, NDPC, CBN, FCCPC, or other authorities without prior User notice where legally compelled.
8. International Data Transfers
8.1 Personal data may be transferred to and processed in countries outside Nigeria. For all international transfers, A-Shopper ensures at least one safeguard under NDPA 2023 s.41–43 and GAID 2025 Art.46:
- Transfer to countries formally recognised by the NDPC as providing adequate data protection (NDPA 2023 s.42);
- Standard Contractual Clauses (SCCs) or equivalent data transfer agreements (NDPA 2023 s.43);
- Binding contractual obligations on the receiving entity requiring NDPA 2023-equivalent standards; or
- Your explicit, informed consent to the specific transfer after being informed of the possible risks.
8.2 BCRs are not relied upon as the NDPC has not yet established a BCR approval framework. For EU/EEA transfers, EU-approved SCCs are applied.
8.3 Transfer risk assessments are conducted before transferring data to jurisdictions with potentially lower protection than NDPA 2023. Details of safeguards are available on written request from privacy@ashopper.com.
9. Data Retention: How Long We Keep Your Data
9.1 A-Shopper retains personal data only as long as necessary to fulfil the purposes for which it was collected, in compliance with NDPA 2023 s.24(1)(d) and GAID 2025 Art.49:
| Data Category | Retention Period | Legal / Regulatory Basis |
|---|---|---|
| Account & Profile Data | Duration of account + 2 years post-closure | Legitimate interest — post-closure dispute resolution (NDPA 2023 s.25(1)(f)); GAID 2025 Art.49(3) |
| Transaction & Order Records | 6 years from last transaction | NDPR Implementation Framework s.8.2 — 6 years after last transaction in contractual agreement |
| Financial & Payment Records | 7 years from transaction date | Nigeria Tax Act — mandatory tax record-keeping; CBN regulations under CBN Act 2007 |
| Communications Data | 3 years from last interaction | NDPR Implementation Framework s.8.2 — within limitation window for contractual claims |
| KYC / Identity Documents | 5 years after account closure or last transaction | ML(PP)A 2022 s.9 — mandatory minimum AML record-keeping period |
| AML Screening & SAR Records | 5 years from date of report or relevant transaction | ML(PP)A 2022 s.9 — mandatory minimum under Nigerian AML law |
| Marketing Preference Records | Until consent withdrawn or account closed | Consent-based per NDPA 2023 s.25(1)(a); s.35 right to withdraw at any time |
| Cookie & Tracking Data | 13 months rolling | GAID 2025 Art.19 — data minimisation principle; international best practice |
| Technical / Server Logs | 12 months rolling | Legitimate interest — security & fraud prevention (NDPA 2023 s.25(1)(f)) |
| Legal & Dispute Records | Duration of matter + 6 years post-resolution | Nigeria Limitation Act — 6-year limitation period for contractual claims |
| Regulatory Correspondence | 10 years from date of correspondence | NDPC, CBN, FCCPC record-keeping requirements under applicable regulations |
| Backup & Archive Data | Up to 12 months beyond primary retention | Business continuity — encrypted at rest; no active processing during archive period |
9.2 Secure Deletion
Upon expiry of the applicable retention period, personal data is securely and irreversibly deleted or anonymised per GAID 2025 Art.49(3).
9.3 Account Closure
All personal data not subject to a legal retention obligation will be securely deleted within 30 days of Account closure. You may request a copy of your data before closure using your Right to Data Portability (s.38).
10. Data Security: How We Protect Your Information
10.1 A-Shopper implements a comprehensive, multi-layered security framework in compliance with NDPA 2023 s.39:
10.1a Technical Security Measures
- AES-256 encryption at rest; TLS 1.2/1.3 encryption in transit;
- Full tokenisation of payment card data — complete card details are never stored;
- Multi-factor authentication (MFA) for all User Accounts and administrative access;
- Role-based, least-privilege access controls; WAF, intrusion detection, and DDoS mitigation; and
- Regular vulnerability scanning, independent penetration testing, and secure SDLC.
10.1b Organisational Security Measures
- Mandatory annual data protection and information security training for all staff;
- Binding confidentiality and non-disclosure agreements for all employees and contractors; and
- Annual DCPMI Compliance Audit Return (CAR) filed with the NDPC; DPIAs for all new high-risk processing.
10.2 Personal Data Breach Response (NDPA 2023 s.40)
- Immediately contain and investigate the breach upon discovery;
- Notify the NDPC within 72 hours of becoming aware of a breach likely to pose risk to individuals' rights and freedoms — as confirmed by NDPA 2023 s.40 and GAID 2025;
- Notify affected Users without undue delay where the breach is likely to result in high risk to their rights; and
- Document the breach and all remediation actions in our breach register; conduct post-incident review.
10.3 If you suspect unauthorised access to your Account, change your password immediately and contact support@ashopper.com.
11. Your Data Protection Rights
11.1 Under NDPA 2023 and GAID 2025, you have the following rights. All section references are verified against the gazetted NDPA 2023 text:
| Your Right | What It Means | How to Exercise |
|---|---|---|
| Right to be Informed (NDPA 2023 s.34(1)(a); s.27) | Receive clear, concise, transparent information about how your data is processed — purposes, lawful basis, retention period, recipients, and any automated decision-making — before or at the point of collection. | Provided in this Privacy Policy; contact: privacy@ashopper.com |
| Right of Access (NDPA 2023 s.34(1)(b)) | Obtain a copy of personal data A-Shopper holds about you in a commonly used electronic format. Response within 30 days. Free of charge except where request is manifestly unfounded, excessive, or repetitive. | Email: privacy@ashopper.com — Subject: 'Data Access Request' |
| Right to Rectification (NDPA 2023 s.34(1)(c)) | Correct any inaccurate, outdated, incomplete, or misleading personal data without undue delay. Where error is caused by A-Shopper, correction is at no cost to you. | Account Settings or email: privacy@ashopper.com |
| Right to Erasure (NDPA 2023 s.34(1)(d)) | Request deletion of personal data where: it is no longer necessary for original purpose; consent is withdrawn; or processing was unlawful. Subject to legal retention obligations under Nigeria Tax Act, ML(PP)A 2022 etc. | Email: privacy@ashopper.com — Subject: 'Erasure Request' |
| Right to Restrict Processing (NDPA 2023 s.34(1)(v)) | Request temporary suspension of processing — for example while accuracy is contested, processing was unlawful, or you need data for a legal claim. | Email: privacy@ashopper.com — Subject: 'Restriction Request' |
| Right to Data Portability (NDPA 2023 s.38) | Receive personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller. Applies only where processing is based on consent (s.25(1)(a)) or contract (s.25(1)(b)). | Email: privacy@ashopper.com — Subject: 'Portability Request' |
| Right to Object (NDPA 2023 s.36) | Object to processing based on legitimate interest (s.25(1)(f)). Processing must stop unless A-Shopper demonstrates compelling grounds. Right to object to direct marketing is absolute; no override permitted. | Account Settings > Privacy or email: privacy@ashopper.com |
| Rights re. Automated Decisions (NDPA 2023 s.37) | Not be subject to solely automated decisions producing significant legal or similar effects. Request human review, express your view, and challenge incorrect automated decisions. | Email: privacy@ashopper.com — Subject: 'Automated Decision Review' |
| Right to Withdraw Consent (NDPA 2023 s.35) | Withdraw consent for any consent-based processing at any time, as easily as consent was given, without detriment. A-Shopper will cease processing within 10 business days. Does not affect prior lawful processing. | Account Settings > Communications Preferences or email us |
| Right to Complain (NDPA 2023 s.34; s.46) | Lodge a complaint with the NDPC where you believe your rights have been violated — after first raising with A-Shopper. | www.ndpc.gov.ng | complaints@ndpc.gov.ng |
11.2 How to Submit a Request
Email privacy@ashopper.com with your full name, Account email, the right you wish to exercise, and sufficient detail to identify the relevant data. Acknowledged within 5 business days; full response within 30 days.
11.3 Consent Withdrawal (NDPA 2023 s.35)
A-Shopper will cease the relevant processing within 10 business days of a valid withdrawal. The withdrawal mechanism is as easy as the consent mechanism.
11.4 Complaints (NDPA 2023 s.46)
If dissatisfied with A-Shopper's response, lodge a complaint with the NDPC at www.ndpc.gov.ng | complaints@ndpc.gov.ng. EU/EEA Users may also complain to their local supervisory authority. UK Users may contact the ICO at www.ico.org.uk.
12. Cookies & Tracking Technologies
12.1 A-Shopper uses cookies and similar tracking technologies in compliance with GAID 2025 Art.19:
| Cookie Type | Purpose | Disableable? | Duration |
|---|---|---|---|
| Strictly Necessary | Session management, login authentication, shopping cart, security tokens, CSRF protection. Core to Platform function. | No. Platform cannot function without these. | Session / up to 24hrs |
| Performance & Analytics | Usage patterns, page visits, error tracking, load times. Data aggregated and anonymised; no individual profiling. | Yes, via consent banner | Up to 13 months |
| Functional / Preference | Language, currency, layout preferences, recently viewed items, 'remember me' login settings. | Yes, via consent banner | Up to 12 months |
| Marketing & Targeting | Relevant advertising, campaign tracking, retargeting. Set ONLY with prior explicit consent per GAID 2025 Art.19. | Yes; withdraw consent anytime | Up to 90 days |
| Third-Party / Social | Set by providers (e.g. Google Analytics, Meta Pixel). A-Shopper does not control these cookies. | Yes, via browser settings or consent banner | Varies by provider |
12.2 Cookie Consent (GAID 2025 Art.19)
On first visit, a clear consent banner is presented. Only Strictly Necessary cookies are set before consent. No pre-ticked boxes. You may Accept All, Reject Non-Essential, or Customise by category.
12.3 Cookie preferences can be updated anytime through Account Settings > Cookie Preferences, your browser settings, or by emailing privacy@ashopper.com. Full Cookie Policy: https://www.a-shopper.com/cookies.
13. Children's Privacy
13.1 The Platform is designed exclusively for adults. Registration constitutes confirmation that you are 18 or older. Under NDPA 2023 s.31 and the Child Rights Act 2003, a child is any person under 18.
13.2 A-Shopper does not maintain a parental consent mechanism for underage registration. The Platform is exclusively for adults.
13.3 Discovery of Underage User
If A-Shopper discovers a child's data has been collected, A-Shopper will immediately, under NDPA 2023 s.31 and the Child Rights Act 2003: (a) suspend the Account; (b) permanently delete all associated personal data within 30 days; (c) reverse or cancel associated Transactions where possible; and (d) notify the parent or guardian where contact details are available.
13.4 Parents or guardians who believe a child has registered must contact privacy@ashopper.com immediately.
14. Marketing Communications & Your Choices
14.1 With your freely given, specific consent under NDPA 2023 s.25(1)(a), A-Shopper may send promotional communications via email, in-Platform notifications, push notifications, and SMS. Marketing consent is never bundled with consent for other Platform services.
14.2 Opting Out
Withdraw marketing consent at any time by: (a) clicking 'Unsubscribe' in any marketing email; (b) updating Account Settings > Communications Preferences; or (c) emailing privacy@ashopper.com with subject 'Marketing Opt-Out'. Effective within 10 business days per s.35.
14.3 Right to Object to Direct Marketing (NDPA 2023 s.36(3))
Where you object to direct marketing processing, A-Shopper shall immediately cease all direct marketing — this right is absolute and no override is permitted under NDPA 2023.
14.4 Essential transactional communications — Order confirmations, receipts, security alerts — are sent under contract basis (s.25(1)(b)) and cannot be deactivated while your Account is active.
15. Automated Decision-Making & Profiling
15.1 A-Shopper uses automated processing for the following activities, disclosed in advance per NDPA 2023 s.27(g): (a) Fraud detection — real-time transaction risk scoring — may result in Transaction blocking; (b) KYC & identity screening — may result in Account restriction; (c) Vendor performance scoring — affects Vendor ranking; (d) Product recommendations — no significant legal effect; and (e) Payment risk assessment — may result in payment delay.
15.2 Your Rights Under NDPA 2023 s.37
Where automated processing produces a significant legal effect on you, you have the right to: (a) be informed; (b) request human review; (c) express your view; and (d) challenge and request reversal of incorrect decisions.
15.3 Request human review by emailing privacy@ashopper.com with subject 'Automated Decision Review'. We will respond within 15 business days.
16. Data Protection Impact Assessments (DPIAs)
16.1 A-Shopper conducts DPIAs before commencing any processing likely to result in a high risk to the rights and freedoms of individuals, as required by NDPA 2023 s.28 and GAID 2025. DPIA trigger circumstances include:
| DPIA Trigger (NDPA 2023 s.28; GAID 2025) | Examples Relevant to A-Shopper |
|---|---|
| Large-scale profiling of individuals | Behavioural analytics, personalised recommendation engine, targeted advertising profiling |
| Processing of sensitive/special category data at scale | Biometric identity verification, health data, ethnic/political data |
| Systematic monitoring of publicly accessible areas | Geolocation tracking, platform behavioural surveillance |
| Automated decision-making with significant legal effects | Fraud scoring leading to account suspension, payment risk scoring |
| Children's data processing | Any processing where minors may be identified or present |
| Novel technologies or new processing purposes | AI/ML system deployment, new data sharing partnerships, new analytics tools |
| Cross-border data transfers to high-risk jurisdictions | Transfers to countries with materially lower data protection standards |
16.2 Where a DPIA reveals unmitigated high risk, A-Shopper will consult the NDPC before commencing the relevant processing. DPIA records are maintained by the DPO and available to the NDPC on request.
17. Vendor, Seller & Business User Data
17.1 In addition to general User data, A-Shopper processes the following for Vendors, Sellers, and Service Providers: business registration details including TIN (Nigeria Tax Act); director and beneficial ownership information; product catalogue data; performance metrics; financial disbursement details; and compliance records.
17.2 Vendor performance data — ratings, review scores, fulfilment metrics — may be visible to Buyers as part of A-Shopper's trust and transparency framework. Individual Vendor data is never sold or shared for third-party commercial purposes.
18. User-to-User Communications & Data
18.1 Platform messaging may be accessed by A-Shopper strictly for: (a) dispute resolution; (b) fraud detection and Platform security; (c) policy enforcement; and (d) legal compliance. A-Shopper does not conduct blanket real-time monitoring.
18.2 You must not use Platform messaging to share third-party personal data without consent, arrange off-Platform Transactions, harass Users, or conduct any unlawful activity.
19. Third-Party Links, Integrations & Social Media
19.1 The Platform may link to third-party websites and services. A-Shopper is not responsible for their privacy practices. Please review the privacy policy of any third-party platform before providing personal data.
19.2 Social Login
If you register or log in using Google, Facebook, or Apple, that platform may share profile data with A-Shopper, governed by your settings on that platform. A-Shopper uses social login data only for Account creation and authentication.
20. International Users & Cross-Jurisdictional Rights
20.1 A-Shopper serves Users globally and is committed to upholding data protection rights regardless of User location.
20.2 EU & EEA Users — EU GDPR
EU GDPR applies if you are located in the EU/EEA. Additional rights include: right to object (Article 21); right re. automated decisions (Article 22); right to complain to your local supervisory authority. Cross-border transfers to Nigeria are protected by EU-approved SCCs.
20.3 United Kingdom Users — UK GDPR
UK GDPR applies if located in the UK. Transfers use International Data Transfer Agreements (IDTAs) or UK-approved SCCs. Complaints: ICO — www.ico.org.uk.
20.4 California, United States Users — CCPA/CPRA
CCPA/CPRA rights include: Right to Know; Right to Delete; Right to Correct; Right to Opt-Out of data sale (A-Shopper does not sell personal data); and Right to Non-Discrimination.
20.5 South Africa — POPIA
South African data subjects' POPIA rights — including the right to object and the right to erasure — are honoured as supplementary protections.
20.6 Other Jurisdictions
Where other national frameworks apply — including Kenya's Data Protection Act 2019 or Canada's PIPEDA — A-Shopper uses reasonable endeavours to honour those rights as supplementary protections. The primary governing law for all A-Shopper processing is the Nigeria Data Protection Act 2023.
21. Data Minimisation, Purpose Limitation & Accuracy
21.1 Data Minimisation (NDPA 2023 s.24(1)(c))
A-Shopper collects only personal data that is adequate, relevant, and strictly limited to what is necessary for the documented purpose.
21.2 Purpose Limitation (NDPA 2023 s.24(1)(b))
Data will not be used for a new, incompatible purpose without: (a) notification to you; (b) a fresh lawful basis where required; and (c) opportunity to object.
21.3 Accuracy (NDPA 2023 s.24(1)(e))
A-Shopper takes reasonable steps to ensure personal data is accurate, complete, not misleading, and kept up to date. Corrections can be made through Account Settings or by contacting privacy@ashopper.com.
22. Penalties for Non-Compliance
22.1 A-Shopper takes its obligations under NDPA 2023 seriously. The penalties for non-compliance are substantial, and we are committed to full compliance to protect both our Users and our organisation. The regulatory penalty framework under NDPA 2023 s.49 is:
| Violation Type | Penalty | Legal Basis |
|---|---|---|
| Non-compliance by a DCPMI (Data Controller of Major Importance) | Fine of NGN 10,000,000 OR 2% of annual gross revenue (whichever is greater) | NDPA 2023 s.49 |
| Non-compliance by other Data Controllers / Processors | Fine of NGN 2,000,000 OR 2% of annual gross revenue (whichever is greater) | NDPA 2023 s.49 |
| Failure to comply with NDPC enforcement orders | Additional fine of up to NGN 10,000,000 and/or up to 1 year imprisonment for principal officers | NDPA 2023 s.48 |
| Civil damages to affected Data Subject | Compensation payable to the Data Subject for harm caused by violation | NDPA 2023 s.51 |
| Account for profits from violation | A-Shopper required to account for and surrender profits derived from unlawful processing | NDPA 2023 s.48 |
| Referral to other regulators | NDPC may refer matter to CBN, FCCPC, EFCC, or other authorities for sector-specific sanction | NDPA 2023 s.48 |
22.2 In addition to regulatory penalties, any Data Subject who suffers harm as a result of A-Shopper's violation of the NDPA 2023 may seek civil damages through the courts under NDPA 2023 s.51.
22.3 A-Shopper maintains appropriate compliance and governance frameworks, undergoes annual DCPMI audits, and cooperates fully with all NDPC investigations and enforcement activities to minimise the risk of violation and protect the interests of our Users.
23. Whistleblower & Internal Reporting
23.1 A-Shopper maintains an internal data protection reporting mechanism consistent with GAID 2025 and the obligations of a DCPMI. Any employee, contractor, vendor, or User who becomes aware of a potential data protection violation, data breach, or unlawful processing activity is encouraged to report it promptly.
23.2 Internal Reporting Channels
- Data Protection Officer (DPO): privacy@ashopper.com — The primary internal channel for all data protection concerns, including suspected breaches, unlawful processing, or non-compliance with this Policy or NDPA 2023.
- Compliance Team: compliance@ashopper.com — For AML, KYC, and regulatory compliance concerns including suspected violations of ML(PP)A 2022 or CBN regulations.
- Legal Team: legal@ashopper.com — For concerns involving potential legal exposure, regulatory proceedings, or court orders.
23.3 Non-Retaliation Commitment
A-Shopper prohibits retaliation against any person who, in good faith, reports a suspected data protection concern through any internal or external channel. Reports made in good faith will not result in any adverse employment or contractual consequences.
23.4 External Reporting
Nothing in this Policy prevents any person from reporting a data protection concern directly to the NDPC (complaints@ndpc.gov.ng), the NFIU, the EFCC, or any other applicable regulatory authority, without first raising the matter internally.
23.5 Report Handling
All internal reports are logged, investigated promptly by the DPO, and escalated to senior management and the NDPC where required under NDPA 2023 s.40 (breach notification). Reporters will receive an acknowledgement within 5 business days and a substantive response within 30 days.
24. Accessibility
24.1 A-Shopper is committed to ensuring that this Privacy Policy and all data protection information is accessible to all Users, including those with disabilities, in compliance with the spirit of the NDPA 2023 and international accessibility standards.
24.2 Alternative Formats
This Privacy Policy is available in the following alternative formats upon written request to privacy@ashopper.com:
- Large print (minimum 18pt font);
- Plain text format (for screen reader compatibility);
- Audio description (read-aloud version available on request); and
- Simplified plain language summary — a shorter, jargon-free version of this Policy for Users who require easier-to-read materials.
24.3 Language
The governing version of this Privacy Policy is in English. Where A-Shopper publishes translations into other languages for User convenience, the English version shall prevail in the event of any inconsistency.
24.4 Digital Accessibility
The A-Shopper Platform is designed with accessibility in mind, including: compliance with WCAG 2.1 Level AA guidelines; screen reader compatibility; keyboard navigation support; and adequate colour contrast ratios. Users who experience accessibility barriers on the Platform should contact support@ashopper.com.
24.5 Child-Friendly Notice
As A-Shopper is an adults-only Platform, a child-friendly version of this Privacy Policy is not published. In the event a minor is discovered to have accessed the Platform, the procedure in Section 13.3 applies immediately.
25. Changes to This Privacy Policy
25.1 A-Shopper may update this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, technological practices, or Platform operations.
25.2 Material Changes
Material changes — including new data categories, new third-party sharing, or changes reducing your rights — will be communicated to all registered Users by email and/or in-Platform notification at least 14 days before the new Effective Date. Fresh consent will be obtained where required.
25.3 Minor Changes
Minor changes — such as clarifications or formatting corrections — will be published on the Platform with a revised version number and 'Last Updated' date, without individual notification.
25.4 Continued use of the Platform after the Effective Date of a revised Policy constitutes acceptance of the updated version. If you do not agree with material changes, you may close your Account before the Effective Date.
25.5 Previous versions are archived and available on written request from privacy@ashopper.com.
26. Contact Us & How to Make a Complaint
26.1 For all questions, rights requests, accessibility requests, or concerns about this Policy or A-Shopper's data practices, contact our Data Protection Officer at privacy@ashopper.com. All contact details are consolidated in Section 1.
26.2 Response Commitment
All privacy requests acknowledged within 5 business days. Full response within 30 days. Complex requests: up to 90 days total with notification within the initial 30-day window.
26.3 Complaints Procedure
- First, raise the concern directly with A-Shopper at privacy@ashopper.com;
- If unresolved within 30 days, escalate to the NDPC under NDPA 2023 s.46 at www.ndpc.gov.ng | complaints@ndpc.gov.ng;
- EU/EEA Users may additionally complain to their local supervisory authority;
- UK Users may additionally contact the ICO at www.ico.org.uk.
26.4 Regulatory Registration
A-Shopper is registered with the NDPC as a DCPMI under NDPA 2023 s.44 and fully cooperates with all NDPC investigations, audits, and enforcement activities.
Legal Verification Statement
LEGAL VERIFICATION STATEMENT (v1.0): This Privacy Policy has been prepared by A-Shopper Global Limited with all statutory references verified against the following legislation as gazetted and enacted: Nigeria Data Protection Act 2023 (NDPA 2023) — Federal Republic of Nigeria Official Gazette, 1 July 2023, No. 37; NDPA General Application and Implementation Directive 2025 (GAID 2025) — effective 19 September 2025; Money Laundering (Prevention & Prohibition) Act 2022 (ML(PP)A 2022) s.9; Nigeria Tax Act (effective 1 January 2025); CBN Act 2007; CAMA 2020; FCCPA 2018; Terrorism (Prevention & Prohibition) Act 2022; Cybercrimes Act 2015 (as amended 2024); Child Rights Act 2003; Nigeria Limitation Act. VERIFIED NDPA 2023 SECTION MAPPING: s.24 = Data principles; s.25 = Lawful bases (a–f); s.27 = Information to data subject; s.28 = DPIA; s.30 = Sensitive data; s.31 = Children; s.32 = DPO designation; s.34 = Data subject rights (access s.34(1)(b), rectification s.34(1)(c), erasure s.34(1)(d), restriction s.34(1)(v)); s.35 = Consent withdrawal; s.36 = Right to object (s.36(3) = direct marketing); s.37 = Automated decisions; s.38 = Data portability; s.39 = Security obligations; s.40 = Breach notification (72-hour standard confirmed in gazetted text); s.41–43 = International transfers; s.44 = DCPMI registration; s.46 = Complaints to NDPC; s.48 = Enforcement orders; s.49 = Offences and penalties; s.51 = Civil remedies. BCRs excluded: NDPC has not established a BCR approval framework under NDPA 2023.
© 2026 A-Shopper Global Limited. All Rights Reserved. Governed by the laws of the Federal Republic of Nigeria. | Effective: 1 June 2026 | https://www.a-shopper.com/privacy
