Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your data.

Last updated: 20 March 2026

Introduction

ZoboLedger ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our WhatsApp-native bookkeeping service. We comply with the Nigeria Data Protection Regulation (NDPR) 2019.

What Information We Collect

Account Information

  • WhatsApp phone number (required)
  • Email address (optional, for account recovery)
  • Business name
  • Business sector and location

Identity Information (Encrypted)

  • CAC registration number (for businesses)
  • National Identification Number - NIN (for individuals)
  • Tax Identification Number - TIN (if provided)

Transaction Data

  • Transaction amounts and descriptions
  • Receipt images (for OCR processing)
  • Voice messages (transcribed for processing)
  • Transaction categories and tax classifications

How We Use Your Information

To provide bookkeeping services and categorize your transactions

To generate tax-ready reports compliant with FIRS requirements

To compute tax liabilities (CIT, VAT, WHT) per Nigerian regulations

To send you daily reminders and monthly financial summaries

To improve our AI categorization and service quality

How We Protect Your Data

Enterprise-Grade Encryption

All sensitive data (TIN, NIN, CAC numbers) is encrypted using strong AES encryption before storage, with keys managed by Google Cloud KMS. All data in our database is encrypted at rest using AES-256.

Secure Infrastructure

Your data is stored on Google Cloud Platform with enterprise-grade security and encryption at rest.

Access Controls

Only you can access your data. We use Firebase security rules to ensure complete data isolation.

NDPR Compliant

We fully comply with the Nigeria Data Protection Regulation (NDPR) 2019.

Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We only share data when:

  • Required by law or regulatory authorities (e.g., FIRS audit requests)
  • Necessary to provide our services (e.g., WhatsApp Business API, Google Cloud services)
  • You explicitly request us to share it (e.g., exporting reports)

Your Rights

Under NDPR, you have the right to:

Access Your Data

Request a copy of all data we have about you

Correct Your Data

Update or correct any inaccurate information

Delete Your Data

Request deletion of your account and all associated data

Withdraw Consent

Stop using our service and request data deletion at any time

To exercise these rights: Send a message to our WhatsApp bot with "Delete My Data" to delete your account, or send "My profile" to view your data. For other data-related requests (access, correction, export), email us at support@zoboledger.com and we'll assist you.

Data Retention

We retain your data for as long as your account is active or as needed to provide our services. For tax compliance purposes, we may retain certain financial records for up to 7 years as required by Nigerian tax law. You can request deletion of your data at any time, subject to legal retention requirements.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes via WhatsApp or email. The "Last updated" date at the top of this page indicates when the policy was last revised.