BEEZENDS Privacy Policy
1. Who we are and how to contact us
BEEZENDS GLOBAL PAY SERVICES LTD is a private limited company registered in the Federal Republic of Nigeria with the Corporate Affairs Commission (CAC) under the Companies and Allied Matters Act 2020 (RC No. RC 9267990). Our registered office is No 10 Osimiri Street, G.R.A., Enugu State, Nigeria. BEEZENDS GLOBAL PAY SERVICES LTD operates its wallet and payment services in partnership with licensed Nigerian payment providers.
- Privacy / data-protection enquiries (Data Protection Officer: Kaycee Orji): kaycee4pals@gmail.com, tel. +234 803 094 2344
- General support and account-deletion requests: kaycee4pals@gmail.com, tel. +234 803 094 2344
- Website: https://beezends.com
This policy is issued in accordance with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and applicable guidelines of the Central Bank of Nigeria (CBN) on Know-Your-Customer (KYC) and Anti-Money-Laundering (AML).
2. Scope
This policy applies to the BEEZENDS mobile application for Android and iOS (package com.beezends.ngn), the website beezends.com, and any related services. It applies to individual users, merchants, enterprise members, job seekers, riders and drivers.
3. What data we collect
The categories below describe the data we collect, why we need it, and whether it is required to use the relevant feature.
3.1 Identity and KYC data
| Data | Purpose | Required? |
|---|---|---|
| Full legal name, date of birth, gender, nationality | Account identity; regulatory KYC | Required for wallet tiers |
| National Identification Number (NIN) and Bank Verification Number (BVN) | Identity verification with an accredited provider; CBN tiered-KYC compliance; fraud prevention | Required to unlock wallet Tier 1 and above |
| Selfie / short liveness video | Facial comparison against the photo held on the NIN record (liveness and face-match) | Required for Tier 1 verification |
| Residential address and address-proof document (where requested) | Higher-tier KYC | Required only for higher tiers |
| Corporate registration data (CAC number, company name, directors) for businesses | Know-Your-Business (KYB) for enterprise and merchant accounts | Required for business accounts |
How we store it. The full NIN/BVN you submit is passed to our verification provider. In our verification records we store only a masked form (for example *******1234) and a one-way cryptographic hash of the number, together with the match results (name match, date-of-birth match, face-match score, liveness result). The NIN photograph returned by the provider is not retained. Your KYC profile (name, date of birth, address, document links) is stored in your user record and is visible only to you and to authorised compliance staff.
3.2 Contact and account data
- Mobile phone number (verified by SMS one-time code) – required to create an account and to sign in.
- Email address (optional, verified if provided) – recovery, receipts and notifications.
- Username, display name, profile photo, cover image, country / state / city – shown to other users in BeeChat, BeeMoments and BeeJobs.
- Password (stored as a salted hash), gesture-lock pattern, and whether biometric unlock is enabled. Biometric data itself (face or fingerprint) never leaves your device; we only use the operating system’s confirmation result.
- Referral code and unique BEEZENDS account number.
3.3 Financial and transaction data
- Wallet balance, ledger postings, and the full history of deposits, transfers, withdrawals, bill payments (airtime, data, utilities), order payments, payroll and ride fares.
- Counterparty details for each transaction (name, account number or BEEZENDS ID) and payment reference numbers from our payment partners.
- Linked bank accounts: bank name, bank code, account name and account number (used for withdrawals and inbound transfers). We do not store card PANs or CVVs; card payments are handled by the payment processor.
- Virtual account numbers issued in your name by partner banks for receiving deposits.
- Merchant / shop data, invoices, product catalogues, orders and reviews for BeeMalls sellers.
- Payroll and salary information for enterprises that use BeeWorkspace payroll.
3.4 Location data
- BeeRides: precise GPS location while you request or perform a ride (pickup, drop-off, route, driver position) – required for the feature.
- BeeWorkspace attendance: precise location at clock-in / clock-out, and periodic heartbeats during a shift if your employer enables geo-fenced attendance – required only if your employer uses this feature.
- Saved places: home / work addresses you choose to save.
- Map display: Google Maps is used to render maps and geocode addresses.
Location is collected only while the app is in use (foreground). We do not collect background location.
3.5 Photos, videos, audio and files
- Camera: QR-code scanning (pay / receive / add friend), profile and moment photos, KYC selfie, attendance selfie (if enabled by employer), video calls.
- Photo library: images and videos you choose to send in chat, post in BeeMoments, attach to tasks or documents, or upload as product images / KYC documents.
- Microphone: voice messages and voice / video calls.
- Documents you upload to BeeWorkspace document storage and share with colleagues.
- Saved receipts / images written to your gallery when you choose to save them.
3.6 Messages and social content
- Chat messages (text, images, voice, video, files, location, business cards), group memberships, message reactions and recall / edit history, stored on our servers so they can be delivered across your devices and to recipients. Messages are encrypted in transit (TLS) and at rest on our storage; they are not end-to-end encrypted.
- Voice / video call metadata (participants, start / end time, duration). Call media is transmitted in real time via Agora and is not recorded by BEEZENDS.
- BeeMoments posts, comments, likes, reposts, view counts and audience settings.
- Friend lists, follows, blocks and in-app contact lists. We do not read your phone’s address book.
- Job applications, CVs / résumés and application answers submitted through BeeJobs; job postings by employers.
- Support tickets and in-app support chat.
3.7 Device, technical and usage data
- Push-notification token (Expo Push / Firebase Cloud Messaging on Android, APNs on iOS).
- Device identifier generated for the app installation, device model and OS version (from expo-device / expo-application), app version.
- IP address and user-agent at login and for security-relevant actions (login history, wallet audit logs, admin audit trails).
- Session / refresh tokens and their device binding.
- Crash and diagnostic logs kept in our server logs.
We do not use third-party advertising SDKs, advertising identifiers (IDFA / GAID), or cross-app analytics trackers.
4. Why we use your data (legal bases)
| Purpose | Legal basis (NDPA s.25) |
|---|---|
| Creating and operating your account, delivering the wallet, chat, calls, moments, workspace, jobs, mall and ride services | Performance of a contract |
| Identity verification (NIN / BVN / face match), transaction monitoring, sanctions and AML screening, record keeping | Legal obligation (CBN KYC / AML-CFT regulations) |
| Fraud prevention, account security, login alerts, abuse and spam detection | Legitimate interest; legal obligation |
| Push notifications about payments, messages, calls, rides, tasks and approvals | Performance of a contract; consent for marketing notices |
| Customer support and dispute resolution | Performance of a contract; legitimate interest |
| Service improvement, aggregated statistics | Legitimate interest |
| Marketing communications | Consent (you can opt out at any time) |
5. Who we share data with
We share personal data only with the processors and partners needed to run the service. Each is bound by contract or by their own regulatory licence to protect your data.
| Recipient | Role | Data shared | Location |
|---|---|---|---|
| Blusalt Financial Services (TrustPro API) | Identity verification (NIN, BVN, NIN photo match, CAC search) | NIN / BVN, name, date of birth, selfie image or liveness video; CAC number for businesses | Nigeria |
| Licensed Nigerian payment / banking partners (including CoralPay and Paystack) | Payment processing, virtual accounts, bank transfers, bill payments, card acquiring | Name, phone, email, bank account details, transaction amounts and references | Nigeria |
| Agora.io | Real-time voice and video calling | Temporary call-channel identifiers and media streams during a call | Global edge network |
| Expo (Expo Application Services) and Google Firebase Cloud Messaging / Apple Push Notification service | Push-notification delivery | Push token, notification title / body | USA / global |
| Cloudflare, Inc. (R2 object storage) | Storage of uploaded files (photos, videos, voice notes, documents, KYC documents, product images) | Uploaded files and their metadata | Global (Cloudflare data centres) |
| Alibaba Cloud (Germany, Frankfurt region) | Hosting of our application servers and databases | All data described in section 3 | Germany (EU) |
| Google LLC (Maps Platform) | Map display, geocoding, place search | Location coordinates and address queries | Global |
| Blusalt Financial Services (TrustPro SMS gateway) | Delivery of one-time passcodes (SMS OTP) | Phone number | Nigeria |
| Regulators, law enforcement and courts | Where required by law (e.g. CBN, NFIU, EFCC, NDPC) | As lawfully required | Nigeria |
| Other users | Per your actions: a payee sees your name and account number; chat recipients see your profile and messages; enterprise administrators see attendance, tasks and payroll of their employees; riders and drivers see each other’s name, photo, rating and live position during a ride | As described | — |
We do not sell personal data and we do not share it with data brokers or advertisers.
6. International transfers
Our servers are hosted by Alibaba Cloud in Frankfurt, Germany, and uploaded files are stored on Cloudflare R2. Where data leaves Nigeria we rely on the transfer mechanisms permitted by the NDPA (adequacy of the destination, contractual safeguards with the processor, or your consent given at sign-up). Identity verification and payment processing take place with Nigerian-licensed providers.
7. How long we keep data
| Data | Retention |
|---|---|
| KYC records, identity-verification results, transaction and wallet ledger records | At least 5 years after the end of the customer relationship, as required by CBN AML / CFT regulations, even if you delete your account |
| Account profile, friends, moments, chat messages, documents, job applications | Until you delete them or delete your account; when you request account deletion a 30-day cooling period starts, after which the data is anonymised and permanently removed, except where a legal hold applies |
| Attendance records, tasks and payroll created inside an enterprise | Controlled by the enterprise (your employer) as data controller; retained for the enterprise’s statutory record-keeping period |
| Ride history | Retained with transaction records (5 years) for fare disputes and regulatory audit |
| Login / security / audit logs | 12 months |
| Push token, session tokens | Until sign-out, token expiry or account deletion |
| Backups | Rolling backups are overwritten within 90 days |
8. Your rights
Under the NDPA you may:
- Access the personal data we hold about you and obtain a copy.
- Rectify inaccurate data (profile fields can be edited in the app; KYC name changes require a supported change request).
- Erase your data / delete your account (see section 9), subject to statutory retention.
- Restrict or object to processing based on legitimate interest.
- Withdraw consent for marketing or optional permissions at any time (device settings → app permissions; in-app notification settings).
- Data portability – receive your transaction history and profile in a machine-readable format.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
To exercise a right, email kaycee4pals@gmail.com from your registered email or contact us in-app. We respond within 30 days and may ask you to verify your identity first.
9. Deleting your account
You can request deletion of your BEEZENDS account and associated data:
- In the app: Me → Security Settings → Delete account (confirm with your transaction PIN or a one-time SMS code).
- By email: send “Delete my account” together with your registered phone number to kaycee4pals@gmail.com.
Before deletion you must withdraw any wallet balance and settle open orders or rides. Your account is deactivated immediately and a 30-day cooling period starts; if you change your mind, simply log in within those 30 days and the deletion is cancelled. When the cooling period ends, your profile, chat, moments, friends, documents, push tokens and login credentials are anonymised and permanently removed. KYC and transaction records are retained for the statutory period (section 7) in a restricted archive and are not used for any other purpose. Full details are on our account deletion page.
10. Security
- All traffic between the app and our servers uses HTTPS / WSS (TLS 1.2+).
- Passwords and gesture patterns are stored as salted hashes; identity numbers are stored masked and hashed; databases and object storage are encrypted at rest.
- Wallet operations require a transaction PIN, gesture lock or device biometric confirmation; sensitive changes trigger notifications.
- Access to production data is restricted to authorised staff, logged and audited.
- We will notify you and the NDPC of a personal-data breach as required by the NDPA.
11. Children
BEEZENDS is a financial service and is intended for adults only. You must be 18 years of age or older to create an account. We do not knowingly collect data from anyone under 18; if we learn that we have done so we will delete the account. Parents or guardians who believe a minor has registered should contact kaycee4pals@gmail.com.
12. Permissions requested by the app
| Permission | Why | Optional? |
|---|---|---|
| Camera | Scan QR codes, take photos, KYC selfie, video calls | Yes, asked when first needed |
| Microphone | Voice messages, voice / video calls | Yes |
| Photos / media | Choose images and videos to send or post; save receipts | Yes |
| Location (while using) | BeeRides, attendance clock-in, nearby places | Yes, required only for those features |
| Notifications | Payment, message, call and ride alerts | Yes |
| Face ID / fingerprint | Unlock the wallet and confirm payments (processed on device only) | Yes |
| Install unknown apps (Android only) | Install app updates downloaded from beezends.com when distributed outside Google Play. Not used in the Google Play build. | Yes |
13. Cookies and website
The beezends.com website uses only strictly necessary cookies (session and security). No advertising or analytics cookies are set.
14. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app and by notification at least 14 days before they take effect. The “Effective date” at the top shows the current version.
15. Contact
BEEZENDS GLOBAL PAY SERVICES LTD
No 10 Osimiri Street, G.R.A., Enugu State, Nigeria
Data Protection Officer: Kaycee Orji, kaycee4pals@gmail.com, tel. +234 803 094 2344
Support: kaycee4pals@gmail.com