Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your data.
Last updated: 20 March 2026
Introduction
ZoboLedger ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our WhatsApp-native bookkeeping service. We comply with the Nigeria Data Protection Regulation (NDPR) 2019.
What Information We Collect
Account Information
- WhatsApp phone number (required)
- Email address (optional, for account recovery)
- Business name
- Business sector and location
Identity Information (Encrypted)
- CAC registration number (for businesses)
- National Identification Number - NIN (for individuals)
- Tax Identification Number - TIN (if provided)
Transaction Data
- Transaction amounts and descriptions
- Receipt images (for OCR processing)
- Voice messages (transcribed for processing)
- Transaction categories and tax classifications
How We Use Your Information
To provide bookkeeping services and categorize your transactions
To generate tax-ready reports compliant with FIRS requirements
To compute tax liabilities (CIT, VAT, WHT) per Nigerian regulations
To send you daily reminders and monthly financial summaries
To improve our AI categorization and service quality
How We Protect Your Data
Enterprise-Grade Encryption
All sensitive data (TIN, NIN, CAC numbers) is encrypted using strong AES encryption before storage, with keys managed by Google Cloud KMS. All data in our database is encrypted at rest using AES-256.
Secure Infrastructure
Your data is stored on Google Cloud Platform with enterprise-grade security and encryption at rest.
Access Controls
Only you can access your data. We use Firebase security rules to ensure complete data isolation.
NDPR Compliant
We fully comply with the Nigeria Data Protection Regulation (NDPR) 2019.
Data Sharing
We do not sell, rent, or share your personal information with third parties for marketing purposes. We only share data when:
- Required by law or regulatory authorities (e.g., FIRS audit requests)
- Necessary to provide our services (e.g., WhatsApp Business API, Google Cloud services)
- You explicitly request us to share it (e.g., exporting reports)
Your Rights
Under NDPR, you have the right to:
Access Your Data
Request a copy of all data we have about you
Correct Your Data
Update or correct any inaccurate information
Delete Your Data
Request deletion of your account and all associated data
Withdraw Consent
Stop using our service and request data deletion at any time
To exercise these rights: Send a message to our WhatsApp bot with "Delete My Data" to delete your account, or send "My profile" to view your data. For other data-related requests (access, correction, export), email us at support@zoboledger.com and we'll assist you.
Data Retention
We retain your data for as long as your account is active or as needed to provide our services. For tax compliance purposes, we may retain certain financial records for up to 7 years as required by Nigerian tax law. You can request deletion of your data at any time, subject to legal retention requirements.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes via WhatsApp or email. The "Last updated" date at the top of this page indicates when the policy was last revised.