A Shopper Global Limited

Legal

Privacy Policy

How we collect, use, protect, share, and govern your personal data. This Policy is legally binding and forms part of our Terms & Conditions. By accessing or using the Platform you confirm that you have read and understood this Policy. If you do not agree, please do not use the Platform.
Primary framework: Nigeria Data Protection Act 2023 (NDPA 2023) | GAID 2025. Supplementary: EU GDPR | UK GDPR | CCPA/CPRA | POPIA.
Website: www.a-shopper.com · DPO: privacy@ashopper.com · Related: Cookie Policy

Last Updated: May 2026 · Effective: 1 June 2026 · Version 1.0 Legally Verified

DetailInformation
Registered NameA-Shopper Global Limited
RC NumberRC: 7835618
Registered Address[Registered Office Address], Lagos, Federal Republic of Nigeria
DPO Emailprivacy@ashopper.com — all data subject rights requests (NDPA 2023 s.32)
Privacy Policyhttps://www.a-shopper.com/privacy
Cookie Policyhttps://www.a-shopper.com/cookies
Customer Supportsupport@ashopper.com
Legallegal@ashopper.com
Compliance / AMLcompliance@ashopper.com
Supervisory AuthorityNigeria Data Protection Commission (NDPC) — established under NDPA 2023 s.4
NDPC Website / Complaintswww.ndpc.gov.ng | complaints@ndpc.gov.ng
DCPMI RegistrationRegistered with NDPC as Data Controller of Major Importance under NDPA 2023 s.44

1. Who We Are: Data Controller & Data Protection Officer

1.1 A-Shopper Global Limited ("A-Shopper", "we", "us", or "our") is the Data Controller of your personal data as defined under the Nigeria Data Protection Act 2023 (NDPA 2023). As Data Controller, A-Shopper determines the purposes and means of processing your personal data and bears full legal responsibility for ensuring compliance with the NDPA 2023 and the NDPA General Application and Implementation Directive 2025 (GAID 2025), which took effect on 19 September 2025 and replaced the NDPR 2019 as the primary implementing instrument.

1.2 A-Shopper is a company incorporated under the laws of the Federal Republic of Nigeria (RC: 7835618), with its registered office at [Registered Office Address], Lagos, Federal Republic of Nigeria. A-Shopper operates a dynamic engineering tools e-commerce marketplace connecting Nigerian, African and Global businesses with verified suppliers, manufacturers, and distributors — offering B2B, B2C, C2C, service-to-service, and rental commerce solutions worldwide.

1.3 Governing Law & Jurisdiction

This Privacy Policy and all data processing activities of A-Shopper are governed by the laws of the Federal Republic of Nigeria. The primary applicable framework is the Nigeria Data Protection Act 2023 as supplemented by the GAID 2025. Supplementary international frameworks (EU GDPR, UK GDPR, CCPA/CPRA, POPIA) apply to the extent required by law for Users in those jurisdictions. Where there is conflict, NDPA 2023 shall prevail for Nigerian-domiciled processing.

1.4 Data Protection Officer (DPO)

In compliance with NDPA 2023 s.32, A-Shopper has designated a dedicated Data Protection Officer with expert knowledge of data protection law and practices. The DPO is responsible for: overseeing data protection compliance; handling all data subject rights requests; advising on DPIAs; and liaising with the NDPC. Contact: privacy@ashopper.com (all data subject rights requests).

1.5 Privacy by Design & Default (NDPA 2023 s.24)

A-Shopper embeds data protection into all Platform systems and processes from inception, applying the principles of data minimisation, purpose limitation, storage limitation, and privacy by default across all operations.

1.6 Records of Processing Activities (RoPA)

A-Shopper maintains comprehensive Records of Processing Activities as required under NDPA 2023, maintained by the DPO and available to the NDPC on request.

1.7 Annual Compliance Audit Return (CAR)

As a DCPMI, A-Shopper files an annual Compliance Audit Return (CAR) with the NDPC by 31 March each year, conducted through an NDPC-licensed Data Protection Compliance Organisation (DPCO) per NDPA 2023 s.44 and GAID 2025.

2. Scope of This Privacy Policy

2.1 This Privacy Policy applies to all personal data A-Shopper collects and processes when you:

  • Visit, browse, or use the A-Shopper website or mobile application (Android and iOS);
  • Register for an Account or undergo KYC/Vendor verification;
  • Place or receive an Order, booking, rental, or service engagement through the Platform;
  • Communicate with A-Shopper or other Users through any Platform channel;
  • Subscribe to marketing communications or participate in promotions or surveys;
  • Access A-Shopper's APIs as a developer or technical integration partner;
  • Interact with A-Shopper through social media, events, or offline channels; or
  • Browse as a Guest User without a registered Account.

2.2 This Policy applies to all User categories: Buyers, Vendors, Sellers, Service Providers, Renters, Resellers, API Users, and Guest Users — worldwide.

2.3 This Policy forms part of our Terms & Conditions and should be read alongside our Cookie Policy and any role-specific data processing notices applicable to your User type.

2.4 This Policy does not govern the data practices of third-party websites, applications, or services linked to or integrated with our Platform.

3. Personal Data We Collect

3.1 We collect personal data you provide directly, data generated automatically through Platform use, and data received from trusted third-party sources:

CategoryData Points CollectedPurpose
Identity DataFull legal name, username, date of birth, gender, nationality, government-issued ID number (NIN, passport, driver's licence)Account creation, KYC verification, fraud prevention
Contact DataEmail address, phone number(s), delivery address(es), billing address. Next of kin contact collected on voluntary, explicit-consent basis only for account recovery in exceptional circumstances.Order fulfilment, communications, customer support, account recovery
Financial DataBank account details, tokenised card data (full card numbers are NEVER stored), payment history, wallet balance, escrow recordsPayment processing, refunds, escrow management, AML compliance
Transaction DataOrder history, items purchased, cart data, rental records, service bookings, returns, cancellations, dispute recordsOrder management, analytics, dispute resolution
KYC & Compliance DataGovernment ID documents, CAC certificate, Tax Identification Number (TIN under the Nigeria Tax Act), proof of address, directors' details, PEP and sanctions screening resultsKYC verification, AML compliance under ML(PP)A 2022, vendor onboarding
Technical DataIP address, device ID, browser type and version, operating system, screen resolution, login timestamps, session tokens, referral URLs. MAC addresses are NOT collected.Platform security, fraud detection, session management
Usage & Behavioural DataPages visited, search queries, click patterns, product views, session duration, feature usage, A/B test groupPersonalisation, analytics, product improvement, marketing optimisation
Communications DataPlatform messages between Users, support tickets, live chat transcripts, email correspondence with A-Shopper, review contentCustomer support, dispute resolution, compliance monitoring, fraud detection
Profile DataUsername, profile photo, business description, reviews posted, ratings, wishlist items, vendor performance scorePlatform experience, trust and safety, vendor quality management
Location DataApproximate location from IP address; precise GPS location only where User explicitly grants device permissionLogistics optimisation, localised listings, fraud detection, regulatory compliance
Marketing & Preference DataNewsletter opt-in/out status, communication preferences, promotional campaign engagement, product category interestsTargeted marketing (consent-based only), personalisation, campaign measurement
Vendor & Business DataBusiness name, RC number, TIN (Nigeria Tax Act), product catalogue, pricing data, inventory levels, fulfilment metrics, payout bank detailsVendor onboarding, quality assurance, payment disbursement, regulatory compliance

3.2 Special Category Data (NDPA 2023 s.30)

A-Shopper does not intentionally or routinely collect special category personal data. Where such data is collected in exceptional circumstances, explicit written consent is obtained in advance and a specific processing notice is provided.

3.3 Data About Third Parties

If you provide personal data about another person, you confirm that: (a) you have the legal right to share their data; (b) you have informed them about this Privacy Policy; and (c) they are aware their data will be processed as described herein.

3.4 Mandatory vs. Optional Data

Fields marked mandatory during registration, KYC, or checkout are required for service delivery. Optional fields are clearly labelled.

4. How We Collect Your Personal Data

4.1 Data You Provide Directly

  • Registration and Account creation: name, email, password, phone number;
  • KYC verification submissions: identity documents, proof of address, business documents;
  • Order placement and checkout: delivery address, payment details;
  • Vendor onboarding: business registration, TIN (Nigeria Tax Act), bank account details;
  • Customer support interactions: tickets, live chat, email enquiries; and
  • Reviews, ratings, Platform feedback, and marketing preference settings.

4.2 Data Collected Automatically

  • Cookies, web beacons, pixel tags, session storage, and similar tracking technologies — see Section 12 and GAID 2025 Art.19;
  • Server access logs: IP address, access time, pages requested, HTTP referrer;
  • Device and browser information: device model, OS version, browser type, screen resolution; and
  • Location data: approximate location from IP address; precise GPS location only with explicit User device permission. MAC addresses are not collected.

4.3 Data Received from Third Parties

  • Identity verification and KYC results from NDPC-accredited verification partners;
  • Payment and fraud risk signals from CBN-licensed payment processors;
  • Business registration data from the Corporate Affairs Commission (CAC);
  • Sanctions, PEP, and adverse media screening results from accredited compliance providers; and
  • Social media profile data where you register or log in via a social platform.

5. Lawful Basis for Processing Your Personal Data

5.1 A-Shopper processes your personal data only where a valid and documented lawful basis exists under NDPA 2023 s.25. The six lawful bases under s.25(1) are: (a) Consent; (b) Contract; (c) Legal obligation; (d) Vital interests; (e) Public task/interest; (f) Legitimate interests:

Processing ActivityLawful BasisNDPA 2023 s.25(1)Notes
Account registration & managementContracts.25(1)(b)Necessary to provide Platform services to User
Order processing & fulfilmentContracts.25(1)(b)Required to execute Transactions between parties
Payment processing & escrowContract + Legal obligations.25(1)(b)+(c)Compliance with Nigeria Tax Act & CBN regulations
KYC & identity verificationLegal obligations.25(1)(c)ML(PP)A 2022 & CBN KYC Regulations under CBN Act 2007
AML & sanctions screeningLegal obligations.25(1)(c)ML(PP)A 2022 s.9 — mandatory record-keeping & screening
Fraud prevention & platform securityLegitimate interests.25(1)(f)LIA conducted & documented by DPO; available on request
Customer support & dispute resolutionContracts.25(1)(b)Service delivery obligation to registered Users
Legal compliance & court/regulatory ordersLegal obligations.25(1)(c)NDPA 2023, GAID 2025, judicial & regulatory requirements
Tax record-keeping & financial reportingLegal obligations.25(1)(c)Nigeria Tax Act — mandatory tax record-keeping obligation
Platform analytics & performance improvementLegitimate interests.25(1)(f)Improving services; LIA conducted, pseudonymised where possible
AI/ML model trainingLegitimate interests.25(1)(f)Strictly anonymised data only; no personal data linkage
Personalised product recommendationsLegitimate interest / Consents.25(1)(a)/(f)Consent obtained where profiling has significant legal effect per s.37
Marketing & promotional communicationsConsents.25(1)(a)Explicit opt-in required; freely & independently withdrawable
Special/sensitive category dataExplicit consents.25(1) / s.30Only where strictly necessary with prior explicit consent
Minors' data (emergency processing only)Legal obligations.25(1)(c)Child Rights Act 2003 + NDPA s.31 — immediate closure & deletion

5.2 Legitimate Interest Assessments (LIA)

Where s.25(1)(f) is applied, A-Shopper has conducted a formal, documented LIA confirming our interests do not override your fundamental rights. LIA records are available on written request from the DPO.

5.3 Consent Standards (NDPA 2023 s.25(1)(a))

Consent is freely given, specific, informed, and obtained through a clear affirmative action. It is never bundled as a condition of unrelated service and may be withdrawn at any time per s.35.

5.4 Purpose Limitation (NDPA 2023 s.24(1)(b))

Data will not be used for a new, incompatible purpose without fresh notification and, where required, a fresh lawful basis.

5.5 AI/ML Systems

AI/ML training is conducted exclusively on genuinely anonymised or aggregated datasets that cannot be re-linked to any individual.

6. How We Use Your Personal Data

6.1 Platform Operation & Service Delivery

  • Creating, managing, and securing your Account; processing Orders, refunds, and returns;
  • Managing escrow, rental deposits, and fund disbursements;
  • Facilitating communications between Buyers, Vendors, and Service Providers; and
  • Sending essential transactional communications: Order confirmations, receipts, delivery updates.

6.2 Security, Fraud Prevention & Legal Compliance

  • KYC verification, AML/PEP/sanctions screening per ML(PP)A 2022;
  • Detecting, preventing, and investigating fraud and Platform abuse; and
  • Maintaining audit trails and compliance records as required by Nigerian law.

6.3 Platform Improvement, Research & Analytics

  • Analysing usage patterns, developing new features, A/B testing, and Platform optimisation; and
  • Training AI/ML systems using strictly anonymised and aggregated data only.

6.4 Marketing, Personalisation & Recommendations (Consent-Based Only)

  • Sending promotional communications only with your explicit opt-in consent under NDPA 2023 s.25(1)(a);
  • Delivering personalised product recommendations; and
  • Running targeted advertising through approved digital marketing channels.

6.5 Trust, Safety & Quality Assurance

  • Monitoring Vendor performance, facilitating the review and rating system; and
  • Enforcing our Terms & Conditions and Platform policies.

7. Data Sharing, Disclosure & Third-Party Processors

RecipientData SharedPurpose & Safeguard
Vendors & Service ProvidersName, delivery address, order details, contact infoOrder fulfilment — minimum data only; DPA in place
Payment Processors (CBN-licensed)Tokenised card data, transaction amount, billing addressPayment processing — PCI-DSS certified; DPA and SCCs where applicable
Logistics & Delivery PartnersName, address, order ID, contact numberDelivery fulfilment — DPA in place; no secondary use permitted
KYC / Identity Verification PartnersIdentity documents, biographic dataKYC/AML legal obligation — NDPC-accredited processors; DPA in place
Cloud & IT Infrastructure ProvidersEncrypted platform dataPlatform hosting — DPA; encryption at rest and in transit
Analytics ProvidersPseudonymised or aggregated usage dataPlatform improvement — anonymisation applied; no personal data sold
Marketing & Advertising PlatformsHashed email, device IDs (consent-based only)Targeted advertising — consent obtained before sharing; data minimisation applied
Legal & Regulatory Authorities (NFIU, EFCC, NDPC, CBN)Data as required by law or court orderML(PP)A 2022, NDPA 2023, judicial orders — legal obligation; User notified where permitted
Fraud Prevention ServicesTransaction data, behavioural signalsFraud prevention — legitimate interest; accredited partners with DPA only
Business Acquirers / SuccessorsAccount and transaction data on verified business transferBusiness continuity — Users notified in advance; data protection obligations preserved

7.1 Data Processing Agreements (DPAs)

All third-party processors are contractually required to: (a) process data only on A-Shopper's documented instructions; (b) implement appropriate technical and organisational security measures; (c) assist in fulfilling data subject rights; and (d) comply with NDPA 2023 and GAID 2025.

7.2 Sub-Processors

A current list of key sub-processors is available on request from privacy@ashopper.com.

7.3 Legal Disclosures

A-Shopper may disclose personal data to the NFIU, EFCC, NDPC, CBN, FCCPC, or other authorities without prior User notice where legally compelled.

8. International Data Transfers

8.1 Personal data may be transferred to and processed in countries outside Nigeria. For all international transfers, A-Shopper ensures at least one safeguard under NDPA 2023 s.41–43 and GAID 2025 Art.46:

  • Transfer to countries formally recognised by the NDPC as providing adequate data protection (NDPA 2023 s.42);
  • Standard Contractual Clauses (SCCs) or equivalent data transfer agreements (NDPA 2023 s.43);
  • Binding contractual obligations on the receiving entity requiring NDPA 2023-equivalent standards; or
  • Your explicit, informed consent to the specific transfer after being informed of the possible risks.

8.2 BCRs are not relied upon as the NDPC has not yet established a BCR approval framework. For EU/EEA transfers, EU-approved SCCs are applied.

8.3 Transfer risk assessments are conducted before transferring data to jurisdictions with potentially lower protection than NDPA 2023. Details of safeguards are available on written request from privacy@ashopper.com.

9. Data Retention: How Long We Keep Your Data

9.1 A-Shopper retains personal data only as long as necessary to fulfil the purposes for which it was collected, in compliance with NDPA 2023 s.24(1)(d) and GAID 2025 Art.49:

Data CategoryRetention PeriodLegal / Regulatory Basis
Account & Profile DataDuration of account + 2 years post-closureLegitimate interest — post-closure dispute resolution (NDPA 2023 s.25(1)(f)); GAID 2025 Art.49(3)
Transaction & Order Records6 years from last transactionNDPR Implementation Framework s.8.2 — 6 years after last transaction in contractual agreement
Financial & Payment Records7 years from transaction dateNigeria Tax Act — mandatory tax record-keeping; CBN regulations under CBN Act 2007
Communications Data3 years from last interactionNDPR Implementation Framework s.8.2 — within limitation window for contractual claims
KYC / Identity Documents5 years after account closure or last transactionML(PP)A 2022 s.9 — mandatory minimum AML record-keeping period
AML Screening & SAR Records5 years from date of report or relevant transactionML(PP)A 2022 s.9 — mandatory minimum under Nigerian AML law
Marketing Preference RecordsUntil consent withdrawn or account closedConsent-based per NDPA 2023 s.25(1)(a); s.35 right to withdraw at any time
Cookie & Tracking Data13 months rollingGAID 2025 Art.19 — data minimisation principle; international best practice
Technical / Server Logs12 months rollingLegitimate interest — security & fraud prevention (NDPA 2023 s.25(1)(f))
Legal & Dispute RecordsDuration of matter + 6 years post-resolutionNigeria Limitation Act — 6-year limitation period for contractual claims
Regulatory Correspondence10 years from date of correspondenceNDPC, CBN, FCCPC record-keeping requirements under applicable regulations
Backup & Archive DataUp to 12 months beyond primary retentionBusiness continuity — encrypted at rest; no active processing during archive period

9.2 Secure Deletion

Upon expiry of the applicable retention period, personal data is securely and irreversibly deleted or anonymised per GAID 2025 Art.49(3).

9.3 Account Closure

All personal data not subject to a legal retention obligation will be securely deleted within 30 days of Account closure. You may request a copy of your data before closure using your Right to Data Portability (s.38).

10. Data Security: How We Protect Your Information

10.1 A-Shopper implements a comprehensive, multi-layered security framework in compliance with NDPA 2023 s.39:

10.1a Technical Security Measures

  • AES-256 encryption at rest; TLS 1.2/1.3 encryption in transit;
  • Full tokenisation of payment card data — complete card details are never stored;
  • Multi-factor authentication (MFA) for all User Accounts and administrative access;
  • Role-based, least-privilege access controls; WAF, intrusion detection, and DDoS mitigation; and
  • Regular vulnerability scanning, independent penetration testing, and secure SDLC.

10.1b Organisational Security Measures

  • Mandatory annual data protection and information security training for all staff;
  • Binding confidentiality and non-disclosure agreements for all employees and contractors; and
  • Annual DCPMI Compliance Audit Return (CAR) filed with the NDPC; DPIAs for all new high-risk processing.

10.2 Personal Data Breach Response (NDPA 2023 s.40)

  • Immediately contain and investigate the breach upon discovery;
  • Notify the NDPC within 72 hours of becoming aware of a breach likely to pose risk to individuals' rights and freedoms — as confirmed by NDPA 2023 s.40 and GAID 2025;
  • Notify affected Users without undue delay where the breach is likely to result in high risk to their rights; and
  • Document the breach and all remediation actions in our breach register; conduct post-incident review.

10.3 If you suspect unauthorised access to your Account, change your password immediately and contact support@ashopper.com.

11. Your Data Protection Rights

11.1 Under NDPA 2023 and GAID 2025, you have the following rights. All section references are verified against the gazetted NDPA 2023 text:

Your RightWhat It MeansHow to Exercise
Right to be Informed (NDPA 2023 s.34(1)(a); s.27)Receive clear, concise, transparent information about how your data is processed — purposes, lawful basis, retention period, recipients, and any automated decision-making — before or at the point of collection.Provided in this Privacy Policy; contact: privacy@ashopper.com
Right of Access (NDPA 2023 s.34(1)(b))Obtain a copy of personal data A-Shopper holds about you in a commonly used electronic format. Response within 30 days. Free of charge except where request is manifestly unfounded, excessive, or repetitive.Email: privacy@ashopper.com — Subject: 'Data Access Request'
Right to Rectification (NDPA 2023 s.34(1)(c))Correct any inaccurate, outdated, incomplete, or misleading personal data without undue delay. Where error is caused by A-Shopper, correction is at no cost to you.Account Settings or email: privacy@ashopper.com
Right to Erasure (NDPA 2023 s.34(1)(d))Request deletion of personal data where: it is no longer necessary for original purpose; consent is withdrawn; or processing was unlawful. Subject to legal retention obligations under Nigeria Tax Act, ML(PP)A 2022 etc.Email: privacy@ashopper.com — Subject: 'Erasure Request'
Right to Restrict Processing (NDPA 2023 s.34(1)(v))Request temporary suspension of processing — for example while accuracy is contested, processing was unlawful, or you need data for a legal claim.Email: privacy@ashopper.com — Subject: 'Restriction Request'
Right to Data Portability (NDPA 2023 s.38)Receive personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller. Applies only where processing is based on consent (s.25(1)(a)) or contract (s.25(1)(b)).Email: privacy@ashopper.com — Subject: 'Portability Request'
Right to Object (NDPA 2023 s.36)Object to processing based on legitimate interest (s.25(1)(f)). Processing must stop unless A-Shopper demonstrates compelling grounds. Right to object to direct marketing is absolute; no override permitted.Account Settings > Privacy or email: privacy@ashopper.com
Rights re. Automated Decisions (NDPA 2023 s.37)Not be subject to solely automated decisions producing significant legal or similar effects. Request human review, express your view, and challenge incorrect automated decisions.Email: privacy@ashopper.com — Subject: 'Automated Decision Review'
Right to Withdraw Consent (NDPA 2023 s.35)Withdraw consent for any consent-based processing at any time, as easily as consent was given, without detriment. A-Shopper will cease processing within 10 business days. Does not affect prior lawful processing.Account Settings > Communications Preferences or email us
Right to Complain (NDPA 2023 s.34; s.46)Lodge a complaint with the NDPC where you believe your rights have been violated — after first raising with A-Shopper.www.ndpc.gov.ng | complaints@ndpc.gov.ng

11.2 How to Submit a Request

Email privacy@ashopper.com with your full name, Account email, the right you wish to exercise, and sufficient detail to identify the relevant data. Acknowledged within 5 business days; full response within 30 days.

11.3 Consent Withdrawal (NDPA 2023 s.35)

A-Shopper will cease the relevant processing within 10 business days of a valid withdrawal. The withdrawal mechanism is as easy as the consent mechanism.

11.4 Complaints (NDPA 2023 s.46)

If dissatisfied with A-Shopper's response, lodge a complaint with the NDPC at www.ndpc.gov.ng | complaints@ndpc.gov.ng. EU/EEA Users may also complain to their local supervisory authority. UK Users may contact the ICO at www.ico.org.uk.

12. Cookies & Tracking Technologies

12.1 A-Shopper uses cookies and similar tracking technologies in compliance with GAID 2025 Art.19:

Cookie TypePurposeDisableable?Duration
Strictly NecessarySession management, login authentication, shopping cart, security tokens, CSRF protection. Core to Platform function.No. Platform cannot function without these.Session / up to 24hrs
Performance & AnalyticsUsage patterns, page visits, error tracking, load times. Data aggregated and anonymised; no individual profiling.Yes, via consent bannerUp to 13 months
Functional / PreferenceLanguage, currency, layout preferences, recently viewed items, 'remember me' login settings.Yes, via consent bannerUp to 12 months
Marketing & TargetingRelevant advertising, campaign tracking, retargeting. Set ONLY with prior explicit consent per GAID 2025 Art.19.Yes; withdraw consent anytimeUp to 90 days
Third-Party / SocialSet by providers (e.g. Google Analytics, Meta Pixel). A-Shopper does not control these cookies.Yes, via browser settings or consent bannerVaries by provider

12.2 Cookie Consent (GAID 2025 Art.19)

On first visit, a clear consent banner is presented. Only Strictly Necessary cookies are set before consent. No pre-ticked boxes. You may Accept All, Reject Non-Essential, or Customise by category.

12.3 Cookie preferences can be updated anytime through Account Settings > Cookie Preferences, your browser settings, or by emailing privacy@ashopper.com. Full Cookie Policy: https://www.a-shopper.com/cookies.

13. Children's Privacy

13.1 The Platform is designed exclusively for adults. Registration constitutes confirmation that you are 18 or older. Under NDPA 2023 s.31 and the Child Rights Act 2003, a child is any person under 18.

13.2 A-Shopper does not maintain a parental consent mechanism for underage registration. The Platform is exclusively for adults.

13.3 Discovery of Underage User

If A-Shopper discovers a child's data has been collected, A-Shopper will immediately, under NDPA 2023 s.31 and the Child Rights Act 2003: (a) suspend the Account; (b) permanently delete all associated personal data within 30 days; (c) reverse or cancel associated Transactions where possible; and (d) notify the parent or guardian where contact details are available.

13.4 Parents or guardians who believe a child has registered must contact privacy@ashopper.com immediately.

14. Marketing Communications & Your Choices

14.1 With your freely given, specific consent under NDPA 2023 s.25(1)(a), A-Shopper may send promotional communications via email, in-Platform notifications, push notifications, and SMS. Marketing consent is never bundled with consent for other Platform services.

14.2 Opting Out

Withdraw marketing consent at any time by: (a) clicking 'Unsubscribe' in any marketing email; (b) updating Account Settings > Communications Preferences; or (c) emailing privacy@ashopper.com with subject 'Marketing Opt-Out'. Effective within 10 business days per s.35.

14.3 Right to Object to Direct Marketing (NDPA 2023 s.36(3))

Where you object to direct marketing processing, A-Shopper shall immediately cease all direct marketing — this right is absolute and no override is permitted under NDPA 2023.

14.4 Essential transactional communications — Order confirmations, receipts, security alerts — are sent under contract basis (s.25(1)(b)) and cannot be deactivated while your Account is active.

15. Automated Decision-Making & Profiling

15.1 A-Shopper uses automated processing for the following activities, disclosed in advance per NDPA 2023 s.27(g): (a) Fraud detection — real-time transaction risk scoring — may result in Transaction blocking; (b) KYC & identity screening — may result in Account restriction; (c) Vendor performance scoring — affects Vendor ranking; (d) Product recommendations — no significant legal effect; and (e) Payment risk assessment — may result in payment delay.

15.2 Your Rights Under NDPA 2023 s.37

Where automated processing produces a significant legal effect on you, you have the right to: (a) be informed; (b) request human review; (c) express your view; and (d) challenge and request reversal of incorrect decisions.

15.3 Request human review by emailing privacy@ashopper.com with subject 'Automated Decision Review'. We will respond within 15 business days.

16. Data Protection Impact Assessments (DPIAs)

16.1 A-Shopper conducts DPIAs before commencing any processing likely to result in a high risk to the rights and freedoms of individuals, as required by NDPA 2023 s.28 and GAID 2025. DPIA trigger circumstances include:

DPIA Trigger (NDPA 2023 s.28; GAID 2025)Examples Relevant to A-Shopper
Large-scale profiling of individualsBehavioural analytics, personalised recommendation engine, targeted advertising profiling
Processing of sensitive/special category data at scaleBiometric identity verification, health data, ethnic/political data
Systematic monitoring of publicly accessible areasGeolocation tracking, platform behavioural surveillance
Automated decision-making with significant legal effectsFraud scoring leading to account suspension, payment risk scoring
Children's data processingAny processing where minors may be identified or present
Novel technologies or new processing purposesAI/ML system deployment, new data sharing partnerships, new analytics tools
Cross-border data transfers to high-risk jurisdictionsTransfers to countries with materially lower data protection standards

16.2 Where a DPIA reveals unmitigated high risk, A-Shopper will consult the NDPC before commencing the relevant processing. DPIA records are maintained by the DPO and available to the NDPC on request.

17. Vendor, Seller & Business User Data

17.1 In addition to general User data, A-Shopper processes the following for Vendors, Sellers, and Service Providers: business registration details including TIN (Nigeria Tax Act); director and beneficial ownership information; product catalogue data; performance metrics; financial disbursement details; and compliance records.

17.2 Vendor performance data — ratings, review scores, fulfilment metrics — may be visible to Buyers as part of A-Shopper's trust and transparency framework. Individual Vendor data is never sold or shared for third-party commercial purposes.

18. User-to-User Communications & Data

18.1 Platform messaging may be accessed by A-Shopper strictly for: (a) dispute resolution; (b) fraud detection and Platform security; (c) policy enforcement; and (d) legal compliance. A-Shopper does not conduct blanket real-time monitoring.

18.2 You must not use Platform messaging to share third-party personal data without consent, arrange off-Platform Transactions, harass Users, or conduct any unlawful activity.

19. Third-Party Links, Integrations & Social Media

19.1 The Platform may link to third-party websites and services. A-Shopper is not responsible for their privacy practices. Please review the privacy policy of any third-party platform before providing personal data.

19.2 Social Login

If you register or log in using Google, Facebook, or Apple, that platform may share profile data with A-Shopper, governed by your settings on that platform. A-Shopper uses social login data only for Account creation and authentication.

20. International Users & Cross-Jurisdictional Rights

20.1 A-Shopper serves Users globally and is committed to upholding data protection rights regardless of User location.

20.2 EU & EEA Users — EU GDPR

EU GDPR applies if you are located in the EU/EEA. Additional rights include: right to object (Article 21); right re. automated decisions (Article 22); right to complain to your local supervisory authority. Cross-border transfers to Nigeria are protected by EU-approved SCCs.

20.3 United Kingdom Users — UK GDPR

UK GDPR applies if located in the UK. Transfers use International Data Transfer Agreements (IDTAs) or UK-approved SCCs. Complaints: ICO — www.ico.org.uk.

20.4 California, United States Users — CCPA/CPRA

CCPA/CPRA rights include: Right to Know; Right to Delete; Right to Correct; Right to Opt-Out of data sale (A-Shopper does not sell personal data); and Right to Non-Discrimination.

20.5 South Africa — POPIA

South African data subjects' POPIA rights — including the right to object and the right to erasure — are honoured as supplementary protections.

20.6 Other Jurisdictions

Where other national frameworks apply — including Kenya's Data Protection Act 2019 or Canada's PIPEDA — A-Shopper uses reasonable endeavours to honour those rights as supplementary protections. The primary governing law for all A-Shopper processing is the Nigeria Data Protection Act 2023.

21. Data Minimisation, Purpose Limitation & Accuracy

21.1 Data Minimisation (NDPA 2023 s.24(1)(c))

A-Shopper collects only personal data that is adequate, relevant, and strictly limited to what is necessary for the documented purpose.

21.2 Purpose Limitation (NDPA 2023 s.24(1)(b))

Data will not be used for a new, incompatible purpose without: (a) notification to you; (b) a fresh lawful basis where required; and (c) opportunity to object.

21.3 Accuracy (NDPA 2023 s.24(1)(e))

A-Shopper takes reasonable steps to ensure personal data is accurate, complete, not misleading, and kept up to date. Corrections can be made through Account Settings or by contacting privacy@ashopper.com.

22. Penalties for Non-Compliance

22.1 A-Shopper takes its obligations under NDPA 2023 seriously. The penalties for non-compliance are substantial, and we are committed to full compliance to protect both our Users and our organisation. The regulatory penalty framework under NDPA 2023 s.49 is:

Violation TypePenaltyLegal Basis
Non-compliance by a DCPMI (Data Controller of Major Importance)Fine of NGN 10,000,000 OR 2% of annual gross revenue (whichever is greater)NDPA 2023 s.49
Non-compliance by other Data Controllers / ProcessorsFine of NGN 2,000,000 OR 2% of annual gross revenue (whichever is greater)NDPA 2023 s.49
Failure to comply with NDPC enforcement ordersAdditional fine of up to NGN 10,000,000 and/or up to 1 year imprisonment for principal officersNDPA 2023 s.48
Civil damages to affected Data SubjectCompensation payable to the Data Subject for harm caused by violationNDPA 2023 s.51
Account for profits from violationA-Shopper required to account for and surrender profits derived from unlawful processingNDPA 2023 s.48
Referral to other regulatorsNDPC may refer matter to CBN, FCCPC, EFCC, or other authorities for sector-specific sanctionNDPA 2023 s.48

22.2 In addition to regulatory penalties, any Data Subject who suffers harm as a result of A-Shopper's violation of the NDPA 2023 may seek civil damages through the courts under NDPA 2023 s.51.

22.3 A-Shopper maintains appropriate compliance and governance frameworks, undergoes annual DCPMI audits, and cooperates fully with all NDPC investigations and enforcement activities to minimise the risk of violation and protect the interests of our Users.

23. Whistleblower & Internal Reporting

23.1 A-Shopper maintains an internal data protection reporting mechanism consistent with GAID 2025 and the obligations of a DCPMI. Any employee, contractor, vendor, or User who becomes aware of a potential data protection violation, data breach, or unlawful processing activity is encouraged to report it promptly.

23.2 Internal Reporting Channels

  • Data Protection Officer (DPO): privacy@ashopper.com — The primary internal channel for all data protection concerns, including suspected breaches, unlawful processing, or non-compliance with this Policy or NDPA 2023.
  • Compliance Team: compliance@ashopper.com — For AML, KYC, and regulatory compliance concerns including suspected violations of ML(PP)A 2022 or CBN regulations.
  • Legal Team: legal@ashopper.com — For concerns involving potential legal exposure, regulatory proceedings, or court orders.

23.3 Non-Retaliation Commitment

A-Shopper prohibits retaliation against any person who, in good faith, reports a suspected data protection concern through any internal or external channel. Reports made in good faith will not result in any adverse employment or contractual consequences.

23.4 External Reporting

Nothing in this Policy prevents any person from reporting a data protection concern directly to the NDPC (complaints@ndpc.gov.ng), the NFIU, the EFCC, or any other applicable regulatory authority, without first raising the matter internally.

23.5 Report Handling

All internal reports are logged, investigated promptly by the DPO, and escalated to senior management and the NDPC where required under NDPA 2023 s.40 (breach notification). Reporters will receive an acknowledgement within 5 business days and a substantive response within 30 days.

24. Accessibility

24.1 A-Shopper is committed to ensuring that this Privacy Policy and all data protection information is accessible to all Users, including those with disabilities, in compliance with the spirit of the NDPA 2023 and international accessibility standards.

24.2 Alternative Formats

This Privacy Policy is available in the following alternative formats upon written request to privacy@ashopper.com:

  • Large print (minimum 18pt font);
  • Plain text format (for screen reader compatibility);
  • Audio description (read-aloud version available on request); and
  • Simplified plain language summary — a shorter, jargon-free version of this Policy for Users who require easier-to-read materials.

24.3 Language

The governing version of this Privacy Policy is in English. Where A-Shopper publishes translations into other languages for User convenience, the English version shall prevail in the event of any inconsistency.

24.4 Digital Accessibility

The A-Shopper Platform is designed with accessibility in mind, including: compliance with WCAG 2.1 Level AA guidelines; screen reader compatibility; keyboard navigation support; and adequate colour contrast ratios. Users who experience accessibility barriers on the Platform should contact support@ashopper.com.

24.5 Child-Friendly Notice

As A-Shopper is an adults-only Platform, a child-friendly version of this Privacy Policy is not published. In the event a minor is discovered to have accessed the Platform, the procedure in Section 13.3 applies immediately.

25. Changes to This Privacy Policy

25.1 A-Shopper may update this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, technological practices, or Platform operations.

25.2 Material Changes

Material changes — including new data categories, new third-party sharing, or changes reducing your rights — will be communicated to all registered Users by email and/or in-Platform notification at least 14 days before the new Effective Date. Fresh consent will be obtained where required.

25.3 Minor Changes

Minor changes — such as clarifications or formatting corrections — will be published on the Platform with a revised version number and 'Last Updated' date, without individual notification.

25.4 Continued use of the Platform after the Effective Date of a revised Policy constitutes acceptance of the updated version. If you do not agree with material changes, you may close your Account before the Effective Date.

25.5 Previous versions are archived and available on written request from privacy@ashopper.com.

26. Contact Us & How to Make a Complaint

26.1 For all questions, rights requests, accessibility requests, or concerns about this Policy or A-Shopper's data practices, contact our Data Protection Officer at privacy@ashopper.com. All contact details are consolidated in Section 1.

26.2 Response Commitment

All privacy requests acknowledged within 5 business days. Full response within 30 days. Complex requests: up to 90 days total with notification within the initial 30-day window.

26.3 Complaints Procedure

  • First, raise the concern directly with A-Shopper at privacy@ashopper.com;
  • If unresolved within 30 days, escalate to the NDPC under NDPA 2023 s.46 at www.ndpc.gov.ng | complaints@ndpc.gov.ng;
  • EU/EEA Users may additionally complain to their local supervisory authority;
  • UK Users may additionally contact the ICO at www.ico.org.uk.

26.4 Regulatory Registration

A-Shopper is registered with the NDPC as a DCPMI under NDPA 2023 s.44 and fully cooperates with all NDPC investigations, audits, and enforcement activities.

Legal Verification Statement

LEGAL VERIFICATION STATEMENT (v1.0): This Privacy Policy has been prepared by A-Shopper Global Limited with all statutory references verified against the following legislation as gazetted and enacted: Nigeria Data Protection Act 2023 (NDPA 2023) — Federal Republic of Nigeria Official Gazette, 1 July 2023, No. 37; NDPA General Application and Implementation Directive 2025 (GAID 2025) — effective 19 September 2025; Money Laundering (Prevention & Prohibition) Act 2022 (ML(PP)A 2022) s.9; Nigeria Tax Act (effective 1 January 2025); CBN Act 2007; CAMA 2020; FCCPA 2018; Terrorism (Prevention & Prohibition) Act 2022; Cybercrimes Act 2015 (as amended 2024); Child Rights Act 2003; Nigeria Limitation Act. VERIFIED NDPA 2023 SECTION MAPPING: s.24 = Data principles; s.25 = Lawful bases (a–f); s.27 = Information to data subject; s.28 = DPIA; s.30 = Sensitive data; s.31 = Children; s.32 = DPO designation; s.34 = Data subject rights (access s.34(1)(b), rectification s.34(1)(c), erasure s.34(1)(d), restriction s.34(1)(v)); s.35 = Consent withdrawal; s.36 = Right to object (s.36(3) = direct marketing); s.37 = Automated decisions; s.38 = Data portability; s.39 = Security obligations; s.40 = Breach notification (72-hour standard confirmed in gazetted text); s.41–43 = International transfers; s.44 = DCPMI registration; s.46 = Complaints to NDPC; s.48 = Enforcement orders; s.49 = Offences and penalties; s.51 = Civil remedies. BCRs excluded: NDPC has not established a BCR approval framework under NDPA 2023.

© 2026 A-Shopper Global Limited. All Rights Reserved. Governed by the laws of the Federal Republic of Nigeria. | Effective: 1 June 2026 | https://www.a-shopper.com/privacy