Privacy Policy
How we collect, use, share and protect your personal information when you use AlecerPay.
Last updated: 16 July 2026
This document is a working draft and has not yet been reviewed by legal counsel. Items shown in square brackets are pending confirmation. Please review before publication.
This Privacy Policy explains how Penstack Nigeria Limited (RC 7244872), the company behind AlecerPay (“AlecerPay”, “we”, “us”, “our”), collects, uses, shares and protects your personal information when you use our website, mobile applications and related services (together, the “Services”).
AlecerPay is a financial technology company, not a bank or other licensed financial institution. Payment, account and settlement services are provided by our licensed financial-institution partners, and customer funds are held with those partners, not by AlecerPay. Where our partners process your data as part of delivering those regulated services, their own privacy notices may also apply.
1. Who we are
The data controller responsible for your personal data is Penstack Nigeria Limited (RC 7244872), of [Registered office address]. You can reach us at [email protected] or +234 800 ALECER (253237).
2. Information we collect
We collect information you provide directly, information generated as you use the Services, and information required to verify your identity and keep your account secure.
Information you provide
- Identity data: first and last name, gender, date of birth and profile photo.
- Contact data: email address and phone number.
- Address data: street, state and country (used for proof of address during verification).
- Government identification:BVN, NIN, passport, driver’s license and proof-of-address documents, submitted for Know Your Customer (KYC) and anti-money-laundering (AML) checks.
- Verification media: selfie and document images captured for identity verification.
- Financial data: bank account and bank-code details, SWIFT/BIC information, wallet balances, transaction history and amounts.
- Security credentials: your transaction PIN (verified server-side) and authentication settings.
Information collected automatically
- Device & push data: device type and a push notification token (for example, a Firebase Cloud Messaging token) so we can deliver notifications.
- App & usage activity: screen views and product events, used for analytics and to improve the Services.
- Diagnostics: crash logs and stability data.
We do not collect your location, and we do not use advertising identifiers (such as IDFA or GAID) or advertising SDKs.
3. How we use your information
- To create and administer your account and provide the Services.
- To verify your identity and meet KYC, AML and other legal and regulatory obligations.
- To process and settle payments, transfers, conversions and card transactions through our licensed partners.
- To authenticate you and protect against fraud and unauthorised access.
- To send you service, security and transaction notifications.
- To analyse usage, diagnose problems and improve the reliability and features of the Services.
4. Legal bases for processing
We process your data where it is necessary to perform our contract with you, to comply with a legal or regulatory obligation, to pursue our legitimate interests in operating and securing the Services, or on the basis of your consent (which you may withdraw at any time).
5. Service providers and sub-processors
We share data with trusted service providers who process it on our behalf under contractual safeguards, including:
- Google Firebase — push messaging, product analytics and crash reporting.
- PostHog — product analytics (screen views and events).
- Our licensed financial-institution partners — to open and maintain accounts, hold customer funds, and process and settle payments, and to meet their own KYC/AML obligations.
We may also disclose information to regulators, law-enforcement or other authorities where required by law.
6. Data retention
We keep your personal data for as long as your account is active and for as long afterwards as we are required to by law and applicable financial-services and record-keeping regulations, after which it is deleted or anonymised.
7. How we protect your information
We apply enterprise-grade security controls, including encryption of data in transit and at rest, systems designed to meet PCI-DSS standards, multi-factor authentication, biometric authentication options, secure on-device storage of credentials, and AI-assisted fraud monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your data.
8. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, ask us to correct or update it, request deletion, object to or restrict certain processing, or request a copy of your data in a portable format. To exercise any of these rights, contact us at [email protected]. Some data must be retained to meet legal and regulatory obligations even after an account is closed.
9. Children
The Services are not directed to children. You must be at least [18] years old to use AlecerPay. We do not knowingly collect data from anyone under this age.
10. International data transfers
AlecerPay operates in [operating countries — confirm exact list]. Where your data is transferred across borders — for example to a service provider or partner in another country — we take steps to ensure it remains protected in line with this Policy and applicable law.
11. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you through the Services.
12. Contact us
Questions about this Policy or your data? Contact Penstack Nigeria Limited at [email protected] or +234 800 ALECER (253237), or write to us at [Registered office address].
See also our Terms of Service, Cookie Policy and Compliance pages.