CrowweMessaging, social networking, calling and digital payment services

Privacy Policy

How your information is collected, used, shared and protected when you use Crowwe.

Platform operator and controller
IPI Solutions Nigeria Limited
Platform developer
Gloomme Business Connections Limited
Last updated / effective
6 September 2026 / 6 September 2026
Version
2.1
Privacy contact
privacy@ipi.ng
Data Protection Officer
dpo@ipi.ng

Privacy at a glance#

At a glance What it means
What we collect Account and profile information; messages and content; call metadata; payment and KYC information; contacts and social connections; location, device, cookie and usage data.
Why we use it To provide Crowwe, deliver communications and transactions, verify users, personalise the service, prevent fraud and abuse, comply with law and improve reliability.
Who receives it People and businesses you interact with, IPI Group service companies, payment and identity partners, infrastructure providers, advisers and authorities where lawfully required.
Our advertising position Crowwe does not sell personal data for money and does not share it for cross-context behavioural advertising. Non-essential tracking requires a lawful choice where applicable.
Your control You can use account and device settings, withdraw optional permissions, opt out of marketing and submit access, correction, deletion, objection or other rights requests.
Contact Email privacy@ipi.ng or the Data Protection Officer at dpo@ipi.ng.

Please read the full Policy because the details depend on the Crowwe feature you use, the choices you make and the law that applies to you. Feature-specific and just-in-time notices may supplement this Policy; if they conflict, the more specific notice governs that feature.

Find information quickly#

Scope, responsibility and privacy principles: Sections 1–3.

Data collected, purposes and user choices: Sections 4–6.

Social features, payments and automated tools: Sections 7–9.

Disclosures, international transfers and retention: Sections 10–12.

Individual rights, cookies, security and children: Sections 13–16.

Third parties, policy changes, complaints and regional terms: Sections 17–19 and Appendix A.

1. Scope of this Policy#

This Policy explains how personal data is collected and used when you visit a Crowwe website that links to it; create or use a Crowwe account; send messages, join groups, make calls, publish content, buy or sell goods, use payment features, contact support or otherwise interact with Crowwe. Personal data means information relating to an identified or reasonably identifiable individual.

This Policy does not govern a merchant’s independent use of order or customer information, a payment provider’s regulated services, an app store, or another third-party service. Those organisations may act as separate controllers and their own privacy notices apply. This Policy also does not cover employment, recruitment or supplier-personnel data; a separate notice applies where relevant.

2. Who is responsible for your data#

Crowwe is owned and operated by IPI Solutions Nigeria Limited, a Nigerian company and a member of IPI Group Limited. Unless a feature-specific notice says otherwise, IPI Solutions Nigeria Limited is the data controller responsible for deciding why and how Crowwe processes personal data.

Gloomme Business Connections Limited develops and supports the platform under an intra-group service arrangement and, for those activities, processes personal data on documented instructions from IPI Solutions Nigeria Limited. Other IPI Group companies may provide security, infrastructure, administration or support services as processors. If any group company determines the purposes and essential means of processing for its own functions, it acts as a separate or joint controller for that processing and will provide any notice required by law.

Registered contact address: Plot 8 Zambezi Crescent, Maitama, Abuja FCT, Nigeria

Lagos office: Plot 169 Karimu Kotun, Victoria Island, Lagos, Nigeria

Privacy team: privacy@ipi.ng

Data Protection Officer: dpo@ipi.ng

The DPO oversees Crowwe’s privacy programme, advises on high-risk processing, monitors compliance and serves as a contact point for individuals and supervisory authorities. You may contact the DPO directly and without charge.

3. Our privacy commitments#

Crowwe applies the following principles across the life cycle of personal data:

Lawfulness, fairness and transparency: use data only on a valid legal basis and explain the use in clear language.

Purpose limitation: collect data for specified purposes and do not reuse it incompatibly without a new legal basis and notice.

Data minimisation: request only what is reasonably necessary for the selected feature, transaction, safety control or legal duty.

Accuracy: provide tools and procedures to correct or update data.

Storage limitation: retain identifiable data only for justified periods and securely delete or anonymise it afterwards.

Security and confidentiality: use proportionate technical and organisational safeguards based on risk.

Accountability and privacy by design: assess higher-risk features, document decisions, manage vendors and build protective defaults into the service.

These commitments reflect the Nigeria Data Protection Act 2023 (NDPA), the NDPA General Application and Implementation Directive 2025 (GAID) and internationally recognised privacy principles. Other laws, including the Swiss Federal Act on Data Protection (FADP), the EU GDPR, UK data protection law and US state privacy laws, apply only when their territorial and material requirements are met.

Crowwe’s accountability programme includes, where appropriate to the nature and risk of the processing, records of processing activities, privacy-by-design reviews, data-protection impact assessments, documented legitimate-interest and transfer assessments, processor due diligence and contracts, access reviews, staff training, incident exercises and periodic review of retention and security controls.

4. Personal data we collect#

4.1 Information you provide#

Account and identity data: name, username, display name, email address, telephone number, date of birth, profile image, password or other authentication credentials and account settings.

Communications and content: direct and group messages, voice notes, photos, videos, documents, links, posts, stories, comments, reactions, reviews, reports and other material you create, upload or share.

Call information: participants, date, time, duration, call type and network-quality information. Audio and video content is transmitted to provide the call and is not intentionally recorded or retained by Crowwe after the call unless a recording or storage feature is clearly offered and activated.

Payments and transactions: payment account or wallet details, tokenised card information received from payment partners, wallet balance, sender and recipient identifiers, amount, date, status, reference and limited transaction context needed to complete or investigate a payment.

Identity verification and KYC data: NIN, BVN, passport or other approved identification, date of birth, address and verification results where needed for payment, fraud-prevention or regulatory requirements.

Merchant and business data: business name, category, CAC information, tax identifier, business and delivery addresses, authorised representative and beneficial-owner information where required, settlement account details, product listings, prices and fulfilment records.

Support and research data: enquiries, complaint records, survey responses, feedback and information you provide when Crowwe investigates an issue.

4.2 Information collected through the service#

Device and log data: IP address, device and app identifiers, operating system, browser, device model, language, time zone, carrier or network, app version, push-notification token, crash data, diagnostic logs and security events.

Usage and interaction data: features used; pages, merchants and products viewed; search queries; clicks; session frequency and duration; purchases; follows; blocks; mutes; group membership; and interaction with recommendations or notifications.

Location data: approximate location inferred from IP address and, only with device permission, precise location used for location-based features, nearby services, delivery or security.

Cookies and similar technologies: cookie identifiers, pixels, local storage, mobile software development kits and related signals described in Section 14.

Derived information: recommendations, audience or preference indicators, fraud and security risk signals, and other inferences generated from account, device, transaction and usage data.

4.3 Contacts and data about other people#

If you choose to sync your address book, Crowwe may receive contact names and telephone numbers to help you find people you know. Contact access is optional and controlled through your device. Do not upload another person’s information unless you are authorised to do so. You can stop syncing and request deletion of previously uploaded contacts, subject to security and legal retention needs.

Other users may also provide information about you when they add you to a group, send you money, tag or mention you, upload their contacts, report content or otherwise interact with you. Merchants, payment partners and delivery providers may send Crowwe transaction, fulfilment or dispute updates.

If you do not have a Crowwe account but believe another user uploaded your contact details, you may ask the privacy team to confirm whether Crowwe holds matching contact data and to delete or restrict it where required by law. Crowwe may need limited information to verify the request and may retain a suppression value to prevent the same contact from being re-uploaded.

4.4 Data from third parties#

Social sign-in providers, if you choose to use a linked sign-in option.

CBN-licensed payment providers, banks or wallet operators, including transaction confirmations, payment tokens and risk signals.

Identity, sanctions, fraud-prevention and KYC providers, including verification status and legally permitted source information.

Merchants, delivery providers, customer-support suppliers and other partners involved in a transaction you request.

Publicly available and lawful sources used for business verification, fraud prevention, security or compliance.

4.5 Sensitive personal data#

Some Crowwe features can involve data that is sensitive under applicable law, including government identifiers, financial account details, precise location, authentication credentials and the contents of private communications. Crowwe uses enhanced access controls and limits this data to purposes connected with the feature, security or law. If a future identity flow uses a selfie, liveness check or biometric template, Crowwe will provide a specific notice and obtain any consent or other legal authorisation required before collection.

Crowwe will not use sensitive personal data to infer health, religious or philosophical beliefs, ethnicity, political opinions, trade-union membership, sexual orientation or similar protected characteristics for advertising. A biometric template, if introduced, will be segregated, retained only for the disclosed verification purpose and period, and will not be used to train a general-purpose artificial-intelligence model.

Crowwe does not ask you to place information about health, religion, ethnicity, political opinion, sexuality or similar highly sensitive matters in public posts or profiles. If you choose to reveal such information, your audience may view, copy or further disclose it. Please use privacy settings and exercise care.

5. How and why we use personal data#

Where applicable law requires a legal basis or justification, Crowwe links each processing purpose to the appropriate ground. The ground can differ by country and feature. Where data is sensitive, Crowwe also satisfies any additional statutory condition.

Purpose Data typically used Basis or justification
Create and manage accounts Identity, contact, authentication, profile and settings Contract; legitimate interests in account administration; consent for optional profile elements
Deliver messages, groups, posts and calls Content, call metadata, contacts, social graph, device and network data Contract; legitimate interests in reliable delivery and abuse prevention; consent for optional permissions
Facilitate payments, orders and settlements Identity, payment, transaction, merchant, delivery and support data Contract; legal obligation; legitimate interests in completing and reconciling transactions
Verify identity and meet KYC/AML duties Identity documents, NIN/BVN, verification results, transaction and risk data Legal obligation; legitimate interests; substantial public-interest or other sensitive-data condition where required
Protect users and the platform Account, device, log, content-report, transaction and derived risk data Legal obligation; legitimate interests in security, fraud prevention, safety and enforcement
Personalise feeds and recommendations Usage, interaction, social graph, location and inferred preferences Contract or legitimate interests; consent where required for tracking or precise location
Measure and improve Crowwe Usage, diagnostics, survey and aggregated or pseudonymised data Legitimate interests in product quality and business continuity; consent for non-essential analytics where required
Send service and marketing communications Contact, account, transaction, preference and engagement data Contract or legal obligation for service notices; consent or legitimate interests where permitted for marketing
Handle claims, audits and corporate events Relevant account, transaction, communication and compliance records Legal obligation; legitimate interests in legal rights, governance, audit and business continuity

When Crowwe relies on legitimate interests, it considers the necessity of the processing, its benefit, the reasonable expectations of users and the potential impact on rights. Crowwe uses safeguards such as minimisation, restricted access, opt-outs and pseudonymisation where appropriate. You may object to this processing as described in Section 13.

When Crowwe relies on consent, the request will be specific and separate from general terms where appropriate. You may refuse or withdraw consent without losing unrelated core services. Withdrawal does not make earlier processing unlawful.

6. Required and optional information#

Crowwe will identify information required to open an account, complete a transaction, verify identity or satisfy law. If you do not provide required data, Crowwe may be unable to create the account, activate a regulated feature, process a payment or comply with a request. Profile customisation, precise location, contact syncing, camera, microphone, photo-library access, marketing and non-essential analytics are optional unless a particular action you request cannot work without the relevant permission.

You can change many permissions in the Crowwe or device settings. Revoking a permission stops future collection through that permission but does not automatically delete data already lawfully collected. You may request deletion under Section 13, subject to applicable exceptions.

7. Social features, messages and calls#

7.1 Public and audience-limited content#

Your display name, username, profile photo and public posts may be visible to other users or the public, depending on your settings and the feature. Content shared with a group is visible to group participants. Search engines may index genuinely public content. Other people can copy, record, download or reshare content, so deletion from Crowwe may not remove copies held outside Crowwe.

7.2 Private communications#

Messages and call content are delivered to the participants you select. Crowwe processes associated content and metadata as technically necessary to deliver, synchronise, secure and troubleshoot the service, respond to user reports and comply with law. Where a feature is described in the app as end-to-end encrypted, rely on the in-app security indicator for that feature; metadata such as participants, time and duration may still be processed.

7.3 Reporting and safety#

A person who reports a message, account or post may provide Crowwe with the reported content and surrounding information. Crowwe may review that material to enforce its rules, protect users, investigate fraud or comply with law. Crowwe seeks to limit review to what is reasonably necessary and authorised.

7.4 Content rights#

You retain ownership of content you create. Any licence Crowwe needs to host, transmit, display, moderate and back up that content is addressed in the Terms of Service. This Policy explains the related personal-data processing and does not expand that licence.

8. Payments, merchants and identity verification#

Crowwe provides an interface for payments and commerce but is not itself a bank or licensed payment institution. Payment execution, wallet funding, card processing and settlement are performed by appropriately regulated partners. Those partners may act as independent controllers for regulatory, fraud, dispute and transaction-record duties, and their privacy notices also apply.

Crowwe does not intentionally store a full payment-card number or card security code. Card details are submitted to the payment provider and Crowwe receives a token, status and limited transaction information.

A payment recipient receives information reasonably necessary to identify and reconcile the payment, such as display name, amount, date and reference. Other users do not receive your underlying bank or card details from Crowwe.

Merchants receive the information needed to accept, fulfil, deliver, refund and support an order. A merchant may have its own legal duties for customer and transaction records.

Crowwe or its verification partner may request NIN, BVN, passport or other approved evidence when required for identity, account recovery, payment limits, fraud prevention or compliance.

Crowwe may place a transaction or feature under review, request additional verification, delay settlement or restrict access where risk controls or law reasonably require it. Section 9 explains safeguards for automated tools.

9. Personalisation, automated tools and profiling#

Crowwe may use rules, statistical models and machine-assisted tools to rank feeds, recommend content or merchants, detect spam and fraud, identify security threats, prioritise reports and support moderation. Typical inputs include account age, settings, connections, interaction history, device and network signals, transaction patterns and reports. These tools can affect what you see or trigger a request for verification, a temporary hold, a content review or an account restriction.

Crowwe will not make a decision based solely on automated processing that produces legal or similarly significant effects unless it is authorised by law, necessary for a contract or based on valid explicit consent and appropriate safeguards are in place. Where applicable, Crowwe will identify that the decision is automated, provide meaningful information about the principal logic and consequences, allow you to express your point of view and contest the outcome, and arrange review by a person with authority to change the decision.

Private message or call content will not be used to train a general-purpose artificial-intelligence model unless Crowwe first offers a separate, prominent and informed choice, the user affirmatively opts in and the use is lawful. A biometric template will not be used for general-purpose model training. Aggregated or de-identified service data may be used to improve reliability, safety and performance only with technical and contractual safeguards against re-identification and with access limited to the stated purpose.

10. When we disclose personal data#

Crowwe discloses personal data only for defined purposes and with proportionate safeguards. Recipients can include:

Recipient Why and what may be disclosed
People and groups you choose Profile details, content, messages, call information and payment identifiers necessary for the interaction you initiate.
Merchants and fulfilment partners Order, contact, delivery, transaction and dispute information needed to complete and support a purchase.
IPI Group service companies Data needed for platform development, infrastructure, security, support, compliance and administration under appropriate intra-group terms.
Vendors and processors Cloud hosting, content delivery, communications, analytics, support, security, moderation, verification and marketing services under contractual confidentiality, security and purpose limits.
Payment and identity partners Information needed to authenticate, verify, execute, settle, monitor, refund or investigate a transaction and meet regulatory duties.
Professional advisers and auditors Information reasonably necessary for legal advice, audit, insurance, risk management, certification or defence of claims.
Authorities and emergency recipients Information disclosed in response to valid legal process, a binding duty, regulatory request or a good-faith emergency involving serious harm, after appropriate review.
Corporate transaction parties Relevant information under confidentiality and security controls for a merger, financing, reorganisation, acquisition or sale, with notice where required.

Crowwe does not sell personal data for money. Crowwe does not disclose personal data to third parties for cross-context behavioural advertising. If Crowwe materially changes this position, it will first update this Policy, provide any legally required notice and consent or opt-out control, and honour recognised opt-out signals where required.

A recipient may process data as Crowwe’s processor, a joint controller or an independent controller depending on the service and applicable law. Crowwe uses contracts and due diligence appropriate to the recipient’s role, but independent controllers remain responsible for their own processing.

10.1 Government, regulatory and emergency requests#

Crowwe reviews requests from public authorities for legal validity, authority, scope and necessity. Where lawful and reasonably practicable, Crowwe seeks clarification, narrows requests to the minimum responsive data and challenges demands that appear unlawful, disproportionate or overbroad. Crowwe notifies the affected person before disclosure unless prohibited by law or unless notice would create a material risk to another person, an investigation or the integrity of the service.

A voluntary emergency disclosure is limited to information Crowwe reasonably believes is necessary to address an imminent risk of death or serious physical harm. Crowwe documents and subsequently reviews emergency disclosures. Nothing in this section prevents Crowwe from preserving information in response to a valid preservation request while the requesting authority obtains the required legal process.

11. Data location and international transfers#

Crowwe hosts its primary service environment in Nigeria. However, some suppliers, technical support personnel, communications routes or users may be located in other countries, so personal data can be accessed or transferred internationally. A transfer can also occur when you communicate with a person in another country.

For a transfer from Nigeria, Crowwe applies the NDPA and GAID requirements, documents the transfer basis and assesses the adequacy of protection or another permitted ground. Depending on the transfer, safeguards may include contractual clauses, binding corporate rules, recognised certification or codes, technical controls and a transfer-risk assessment. Statutory derogations, including explicit consent, are used only where lawful and appropriate rather than as a routine substitute for safeguards.

Where EU or UK transfer rules apply, Crowwe uses an applicable adequacy decision or approved contractual mechanism, such as EU Standard Contractual Clauses or a UK transfer instrument, together with supplementary safeguards where necessary. You may contact the DPO for information about the safeguards relevant to your data, subject to lawful redactions.

Where the Swiss FADP applies, Crowwe discloses personal data abroad only where the destination provides adequate protection or another permitted safeguard or statutory exception applies. Crowwe will identify the destination country or countries and, where applicable, the safeguard on request, subject to lawful restrictions. Recognised standard contractual clauses are supplemented where a transfer assessment indicates that additional measures are necessary.

12. Retention and deletion#

Crowwe retains identifiable data only for as long as reasonably necessary for the purpose described in this Policy, including service delivery, user choices, security, dispute resolution, accounting, KYC/AML and other legal duties. The schedule below states Crowwe’s general approach; a shorter or longer period may apply where law, a legal hold, an active investigation or a user’s valid request requires it.

Data category General retention period or criterion
Account and profile While the account is active. After closure, core identity, verification and account-history records may be kept for up to 5 years where needed for payments, fraud prevention, claims or law; other profile data is ordinarily deleted or anonymised sooner.
Posts and social content Until you delete the content or close the account, subject to recipient copies, moderation evidence, legal holds and time-limited backups.
Messages and shared media For as long as needed to provide message history and user-selected storage, subject to deletion controls, recipient copies, safety reports, disputes and legal duties.
Call content and metadata Call audio and video are not intentionally retained after the call unless a disclosed recording feature is used. Call metadata may be retained for up to 2 years for history, reliability, safety and disputes.
Transactions, settlement and tax records Generally up to 7 years from the transaction or the end of the relevant relationship, or the period required by applicable financial, tax, accounting and limitation rules.
KYC and identity evidence Generally 5 years after the last relevant transaction or closure of the regulated relationship, unless another legal period applies.
Imported contacts While contact syncing is enabled or reasonably needed to provide contact matching; deleted or de-identified after syncing is stopped and deletion is requested, subject to security and backup cycles.
Precise location Normally no more than 90 days after the relevant delivery or location feature, unless needed for an active dispute, fraud investigation, safety incident or legal duty.
Security and fraud logs Normally up to 5 years after the event or investigation, depending on severity, legal duties and limitation periods.
Support, privacy and consent records Normally 3 years after case closure or withdrawal, and longer where reasonably needed to demonstrate compliance or handle a claim.
De-identified analytics May be retained for longer where it cannot reasonably be linked back to an individual and safeguards against re-identification remain in place.

Deletion from active systems may not be immediate where data remains in encrypted backups that rotate on a defined schedule. During that interval, Crowwe isolates the data from ordinary use and deletes or overwrites it in line with the backup cycle. Crowwe may retain the minimum information needed to record that a deletion or opt-out request was honoured.

13. Your rights and choices#

Depending on the law that applies and the nature of the processing, you may have the following rights. They are not absolute, and Crowwe will explain any lawful limitation.

Right What it generally allows
Be informed Receive clear information about collection, use, sharing, transfers, retention and rights.
Access and know Confirm whether Crowwe processes your data and receive a copy plus relevant processing information.
Correct Correct inaccurate data and complete data that is materially incomplete.
Delete Request deletion where the data is no longer needed, consent is withdrawn, processing is unlawful or another legal ground applies.
Restrict Ask Crowwe to limit use while accuracy, an objection or the lawfulness of processing is assessed.
Object Object to legitimate-interest processing based on your circumstances and object at any time to direct marketing.
Portability Receive qualifying data you provided in a structured, commonly used and machine-readable form and, where technically feasible, transmit it to another controller.
Withdraw consent Withdraw consent as easily as it was given, without affecting earlier lawful processing.
Automated decisions Obtain applicable information, express your view, contest a significant solely automated decision and request human review.
Complain and appeal Ask Crowwe to review a privacy concern or refusal, and complain to the NDPC or another competent authority.
Non-discrimination Exercise applicable privacy rights without unlawful discrimination, retaliation or denial of service unrelated to the requested data.

13.1 How to exercise a right#

Use available account or privacy settings for routine profile, permission, marketing and content controls.

For a formal request, email privacy@ipi.ng or dpo@ipi.ng and describe the account, right and country or state relevant to the request. You may use the subject line ‘Privacy Rights Request’.

Crowwe may ask for information reasonably necessary to verify identity or authority. Verification data will be used only for the request and related security or legal records.

Crowwe will respond within the period required by applicable law, ordinarily within one month. If an extension is lawful and necessary, Crowwe will explain the reason and expected date.

Requests are generally free. Crowwe may refuse or charge a reasonable fee only where applicable law permits, such as for a manifestly unfounded, excessive or repetitive request. An authorised agent may act for you where local law allows, subject to proof of authority and identity safeguards.

Deleting the Crowwe app from a device does not delete the account. Use the in-app account-deletion control, if available, or contact the privacy team. Crowwe may need to retain transaction, KYC, fraud or legal records after account deletion as described in Section 12.

13.2 Review and appeal#

If Crowwe refuses or limits a request, it will explain the decision and the applicable legal ground unless law restricts that explanation. Where applicable law provides an appeal, you may ask the DPO to conduct a fresh review by a person who did not make the initial decision. Crowwe will provide the appeal method and response period with its decision. An internal review does not affect your right to complain to a competent supervisory authority or seek another remedy.

14. Cookies, app permissions and communications#

14.1 Cookies and similar technologies#

Technology category Purpose Your control
Strictly necessary Authentication, session security, load balancing, fraud prevention, preferences required for a requested service and shopping or payment flows. Required for the service; not used for unrelated advertising
Functional Language, display, accessibility and optional feature preferences. Manage through cookie or app settings where available
Analytics and performance Understand feature use, diagnose faults and improve reliability using aggregated or pseudonymised measurements where feasible. Consent or opt-out provided where required
Personalisation Remember interests and tailor feeds, search or recommendations within Crowwe. Manage through privacy, recommendation or cookie settings where available
Marketing measurement Measure Crowwe campaigns or referrals. Crowwe does not use this category to sell data or share it for cross-context behavioural advertising. Used only with a valid lawful choice where required

Non-essential cookies and similar technologies will not be placed before a legally valid choice where prior consent is required. Crowwe will make rejecting or withdrawing non-essential choices as accessible as accepting them and will not use deceptive or coercive interface design to obtain a choice. Browser settings can block cookies, but blocking strictly necessary technologies may prevent sign-in or other requested functions. Where applicable, Crowwe will treat a legally recognised browser-based opt-out signal, such as Global Privacy Control, as an opt-out for the covered processing.

14.2 Device permissions#

Contacts: find and invite people you know, only if you enable syncing.

Camera, microphone, photos and files: make calls or create and share content you select.

Location: provide location-based services or delivery, including precise location only when enabled.

Notifications: deliver message, call, payment, security and optional marketing alerts.

You can revoke device permissions through operating-system settings. Some requested features will then stop working.

14.3 Service and marketing communications#

Crowwe sends service communications needed for an account or transaction, including verification codes, security alerts, policy notices, payment confirmations and support responses. These are not marketing and cannot always be disabled while the related service remains active.

Marketing email, SMS, push notifications and similar messages are sent only on a lawful basis. You can use an unsubscribe link, change notification settings or contact privacy@ipi.ng. Crowwe will keep the minimum suppression record necessary to respect the opt-out.

15. Security and personal-data breaches#

Crowwe uses administrative, technical and physical measures proportionate to the sensitivity and risk of the data. Measures may include encryption in transit and at rest where appropriate, tokenisation of card data, role-based access, multi-factor authentication for privileged access, secure software-development practices, logging and monitoring, vulnerability management, supplier assessments, staff training, backups, business-continuity controls and incident-response procedures.

Security measures evolve and no service can guarantee absolute security. Users should protect passwords and one-time codes, enable available account-security features, keep devices and apps updated, review unfamiliar activity and report suspected compromise promptly to security@crowwe.ng.

15.1 Breach response#

Crowwe assesses suspected personal-data breaches, contains and remediates them, preserves appropriate evidence and documents its decisions. Where a breach is likely to create a risk to individuals, Crowwe will notify the NDPC within the period required by the NDPA, including the applicable 72-hour period. Where a breach is likely to create a high risk, Crowwe will inform affected individuals without undue delay and provide practical protective steps. Other competent authorities will be notified within their applicable deadlines.

A user notice may be delivered by email, in-app message, SMS, website notice or another effective channel depending on urgency and reliable contact information.

Where the Swiss FADP applies, Crowwe will notify the Federal Data Protection and Information Commissioner as soon as possible if a personal-data breach is likely to result in a high risk to an individual’s personality or fundamental rights, and will inform affected individuals where necessary for their protection or when directed to do so.

16. Children’s privacy#

Crowwe is intended for people aged 18 or older. A person under 18 should not create an account, use a payment feature or provide personal data to Crowwe. Crowwe may use proportionate age-assurance measures and can suspend or close an account where it reasonably believes the user is underage.

If Crowwe learns that it collected a child’s data contrary to this rule, it will take reasonable steps to restrict and delete the data, subject to safety, evidence-preservation and legal requirements. A parent or guardian who believes a child has provided data may contact privacy@ipi.ng. Crowwe will verify the requester’s identity and relationship before disclosing or deleting information.

17. Third-party services and external links#

Crowwe may link to merchant sites, payment services, app stores, social sign-in providers or other third-party services. Crowwe does not control an independent third party’s privacy or security practices merely because its service is linked or integrated. Review the third party’s notice before providing data. Crowwe remains responsible for its own processing and for managing processors acting on its instructions.

Before appointing a processor, Crowwe assesses the provider’s competence, security and privacy controls in proportion to risk. Contracts restrict processing to documented instructions, require confidentiality and appropriate security, regulate sub-processors and international transfers, require incident assistance, and support deletion, return, audit and individual-rights obligations. Current processor categories and material changes are available from the privacy team or through the Privacy Centre where published.

18. Changes to this Policy#

Crowwe may update this Policy when its services, data practices, vendors or legal obligations change. The updated version will show a new date and version number. For a material change, Crowwe will provide a prominent in-app or website notice and, where appropriate, direct notice before the change takes effect. If a new use requires consent, Crowwe will request that consent; continued use alone will not replace consent where law requires an affirmative choice.

Crowwe will make previous versions available on request or through the Privacy Centre so users can understand material changes over time.

19. Contact, complaints and regulatory redress#

19.1 Contact Crowwe#

Contact purpose Details
Privacy team privacy@ipi.ng
Data Protection Officer dpo@ipi.ng
Security incidents security@ipi.ng
Customer support support@ipi.ng
General enquiries info@ipi.ng
Telephone +234 803 348 6748
Abuja address Plot 8 Zambezi Crescent, Maitama, Abuja FCT, Nigeria
Lagos office Plot 169 Karimu Kotun, Victoria Island, Lagos, Nigeria
Websites www.crowwe.net │ www.ipi.ng

Crowwe aims to resolve privacy concerns fairly and promptly. If you are dissatisfied with the first response, ask the DPO for an internal review and state why you believe the issue remains unresolved.

You may request this Policy or a response to a privacy request in an accessible format. Crowwe will also take reasonable steps to support another language where required by law or reasonably necessary for an individual to understand material processing information.

19.2 Nigeria Data Protection Commission#

You may lodge a complaint with the Nigeria Data Protection Commission (NDPC), including by using any complaint or grievance process made available under the NDPA and GAID. Crowwe encourages you to contact its DPO first where appropriate, but doing so does not remove your right to approach the NDPC.

NDPC website: www.ndpc.gov.ng

NDPC email: info@ndpc.gov.ng

NDPC address: 1919 Cadastral Zone C06, Mbora District, opposite Efab Estate, Abuja FCT, Nigeria

NDPC telephone: +234 (0) 916 061 5551

19.3 Other supervisory authorities#

If another privacy law applies, you may complain to the competent authority where you live, work or believe an infringement occurred. EEA users can find national authorities through the European Data Protection Board; UK users can contact the Information Commissioner’s Office; and individuals in Switzerland can contact the Federal Data Protection and Information Commissioner. Contact the DPO if you need help identifying the relevant authority.

EEA supervisory authorities: EDPB member authorities

United Kingdom authority: Information Commissioner’s Office

Swiss authority: Federal Data Protection and Information Commissioner

Appendix A. Additional regional disclosures#

A.1 Nigeria#

The NDPA and GAID are the primary cross-sector privacy rules for Crowwe’s Nigerian processing. Nigerian users may exercise the rights described in Section 13, subject to the Act, and may use Crowwe’s grievance process or complain to the NDPC. Crowwe records its lawful bases, high-risk assessments, processor arrangements, breach decisions and international-transfer safeguards as required.

A.2 European Economic Area and United Kingdom#

The EU GDPR or UK data protection law applies only where its territorial scope is met, for example where Crowwe offers relevant services to or monitors the behaviour of people in that region. Applicable lawful bases and rights are described in Sections 5 and 13. Users may object at any time to direct marketing. International transfers use the safeguards described in Section 11. If Crowwe is legally required to appoint a regional representative, current representative details will be made available through the Crowwe Privacy Centre and from the DPO.

A.3 Switzerland#

The Swiss FADP applies to processing that has effects in Switzerland within its statutory scope. Crowwe processes personal data in accordance with the principles of good faith, proportionality, transparency, purpose limitation, accuracy, storage limitation, privacy by design and privacy-friendly default settings. Swiss law does not mirror the GDPR’s legal-basis structure in every respect; where processing would otherwise constitute an unlawful infringement of personality, Crowwe will rely on consent, an overriding private or public interest, or law as a justification.

An individual in Switzerland may request information, correction, deletion or destruction, restriction, data portability where the statutory conditions are met, and may object to processing. Information requests are generally answered free of charge within 30 days, subject to lawful exceptions. If Crowwe makes an automated individual decision within Article 21 FADP, it will inform the affected individual and, on request, permit that person to express a view and obtain review by a natural person, subject to statutory exceptions.

International disclosures are governed by Section 11. If Article 14 FADP requires Crowwe to appoint a representative in Switzerland, Crowwe will publish the representative’s name and address in the Privacy Centre and in the next version of this Policy. Swiss users may contact the DPO or the Federal Data Protection and Information Commissioner.

A.4 United States state privacy laws#

If Crowwe becomes subject to a US state comprehensive privacy law, residents of the relevant state may have rights to know or access, correct, delete and obtain a portable copy of covered information; opt out of a sale, targeted advertising or certain profiling; limit specified uses of sensitive information; use an authorised agent; appeal a refusal; and exercise rights without unlawful discrimination. Crowwe’s categories of data collected and disclosed during the preceding 12 months, sources, purposes and recipients are described in Sections 4, 5 and 10. Sensitive data is used only for purposes reasonably necessary and proportionate to the requested service, security or law, and information collected to verify a rights request is not used for unrelated purposes. Crowwe does not sell personal data or share it for cross-context behavioural advertising.

A.5 Other jurisdictions#

Local law may grant additional rights or impose different time limits and exceptions. Crowwe will apply the law that governs the particular processing. A request should identify the relevant country or state so the privacy team can assess it correctly.