NDPR & ISO/IEC 27001 Aligned

Privacy Policy

Your trust is our most valuable asset. Discover how CardSOFT safeguards your personal information, financial identifiers, and gift card submission proofs.

1 Introduction and Scope

CardSOFT ("we", "our", or "us") respects your fundamental right to privacy. This Privacy Policy outlines our procedures regarding the collection, handling, storage, encryption, and disclosure of personal data collected from users of our trading platform, APIs, and customer service desks in accordance with the Nigeria Data Protection Act (NDPA) and the Nigeria Data Protection Regulation (NDPR).

2 Information We Collect

In order to deliver secure digital asset liquidity and fulfill legal compliance, we collect the following categories of data:

A. Personal Identification Data Full legal name, verified email address, phone number, and account passwords (stored via non-reversible bcrypt hashes).
B. Banking & Financial Details Nigerian bank name, account number, verified account holder name (retrieved through NIBSS bank lookup), and payout transaction histories. CardSOFT never stores user debit card numbers or bank PINs.
C. Gift Card Uploads & Verification Proofs Photographic images of physical cards, digital e-code screenshots, cashier sales receipts, card serial numbers, and claims histories.
D. Device & Technical Telemetry IP address, browser user-agent, operating system, geolocation approximations, login timestamps, and session activity logs.

3 How We Use Your Data

We process your data strictly for legitimate operational purposes:

  • Executing gift card rate appraisals, balance verifications, and automated trade settlements.
  • Disbursing instant cash withdrawals to your verified Nigerian commercial bank accounts.
  • Detecting, preventing, and prosecuting money laundering, stolen card usage, or account takeover attempts.
  • Communicating critical trade updates, security notifications, and responding to support tickets.

4 Security of Gift Card Files and Cryptographic Protection

All photographic files uploaded during card submissions are stored on air-gapped, private disks with randomized filenames. They are never placed in public web directories or indexed by search engines. Access to card evidence is strictly restricted to cleared compliance personnel via role-based access control (RBAC), and authenticated via time-limited cryptographically signed URLs. All data in transit is encrypted using industry-standard TLS 1.3/256-bit SSL encryption.

5 Third-Party Processors & Disclosures

We do not sell, rent, or trade your personal data to marketing brokers or third parties. We share limited subsets of data only with:

  • Licensed Payment Aggregators (e.g. Paystack / Interswitch): To initiate and reconcile direct NGN bank transfers.
  • Transactional Mail Gateways: For delivering account verification notices and trade security alerts.
  • Law Enforcement & Regulatory Authorities: Where mandated by a court order or formal statutory investigation regarding financial crimes or stolen funds.

6 Data Retention and User Rights

In compliance with Central Bank of Nigeria (CBN) anti-money laundering regulations, financial transaction logs and proof records are retained for a statutory minimum of five (5) years. Users maintain the right to:

  • Request a digital copy of all personal profile information held by CardSOFT.
  • Request the correction of inaccurate contact or identity records.
  • Request account closure once all pending balances and trading obligations are settled.

7 Data Protection Officer Contact

If you have questions regarding this Privacy Policy, your rights under the NDPR, or data security practices, please contact our Data Protection Officer at [email protected].