MoniBoat

Privacy Notice

Plain-language notice covering personal data, device permissions, retention, disclosure, user rights, account closure, and security practices for MoniBoat services.

Last revised: 7 August 2026 MoniBoat Digital Technologies Ltd.

1About this Notice

MoniBoat treats careful handling of personal data as part of delivering trustworthy digital credit services.

This Notice describes, in plain terms:

how to close an account or ask for data removal.

Please review this Notice before creating an account or continuing to use MoniBoat.

Using the MoniBoat app or sending information through our channels means you have seen this Notice. When the law requires a separate consent, MoniBoat will ask for it before collecting or using the related data or permission.

You may decline or later withdraw consent. Doing so can limit features that depend on that information or permission.

2Operator Details

MoniBoat is operated by:

In this Notice:

“Service” means the MoniBoat mobile app, related support channels, and connected operational processes.

3What this Notice Covers

This Notice applies to personal data handled through:

vendors that support MoniBoat under contract.

Depending on your journey, MoniBoat may support registration, identity checks, credit review, payouts, repayments, notifications, and support. Not every data type listed below applies to every user.

4Laws We Follow

We aim to process personal data consistently with Nigerian privacy, consumer-protection, AML/CFT, KYC, and cybersecurity rules that apply to digital lending.

Those rules may include:

other binding statutes, directives, or court orders.

References include later amendments and replacement instruments.

5Information MoniBoat May Obtain

We follow minimisation: we seek only what is reasonably needed for service delivery, verification, risk control, compliance, or support.

5.1Profile and sign-up details

Examples include full name, mobile number, email, date of birth, gender, nationality, marital status, residential address, authentication credentials, and login or registration logs.

5.2Identity and KYC materials

We may process NIN, BVN, ID type and number, ID images, verification outcomes, screening results, fraud signals, and related audit trails.

Government identifiers are used for verification, compliance, security, underwriting support, and transaction integrity—not for unrelated advertising, and not for sale or public posting.

5.3Work and income context

Where needed for a credit request, we may collect employment status, occupation, employer details, declared income range, and similar capacity information you submit.

5.4Banking and repayment records

We may process bank name, account number, BVN, ownership-check results, disbursement and repayment status, settlement references, and investigation records tied to a payment.

Sensitive payment credentials are handled only through authorised payment channels where applicable.

5.5Contacts you type in yourself

If a feature asks for an emergency or reference contact, you may enter a name, relationship, and phone number.

Manually entered contacts will not be sold, used for unrelated ads, handed to unrelated marketers, or used for threatening or harassing outreach. Please tell the other person before you share their details.

5.6Selfie, document photo, and liveness results

To confirm you are a real person and to reduce impersonation, MoniBoat may ask for an ID photo, a selfie, a liveness capture, match scores, pass/fail outcomes, and verification logs.

Biometric templates created only for a check are removed or irreversibly detached from your identity within 24 hours after a successful check, unless a longer hold is required by law or an active fraud case.

Biometrics are not used for advertising, behavioural marketing, or unrelated tracking.

5.7Device and network signals

For security and reliability we may collect limited technical data such as device make/model, OS version, app version, install ID, language, IP address, network type, time zone, session times, crash diagnostics, and security events.

These signals help detect abuse, investigate faults, and keep accounts safe. They are not intended as a way to read unrelated personal content on your phone.

5.8Financial SMS (permission-based)

If MoniBoat offers an SMS-assisted verification or risk feature, the OS permission is requested first. With permission, we may process sender details, message body, date/time, and transaction-related indicators.

Uses are limited to verification, account protection, fraud prevention, and proportionate risk assessment—not ads, not selling message content, and not sharing content with unrelated parties.

After processing, data that is no longer needed is deleted, de-identified, or taken out of day-to-day use.

5.9Approximate location (optional)

MoniBoat may ask for coarse (approximate) location—not precise GPS tracking. With your permission, we may collect a one-time or limited location sample such as latitude, longitude, and accuracy, typically as a broad city- or area-level signal.

This signal may support fraud prevention, account protection, and proportionate credit-risk checks. Location is optional: you can refuse or skip it and still continue onboarding or use core features that do not depend on it.

You may change or withdraw location access later in Android settings. Without permission, MoniBoat will not read location from the device.

5.10Narrow app-security indicators

Where lawful and supported by the OS, MoniBoat may evaluate limited signals linked to elevated fraud risk (for example tampering, root/emulator environments, overlays, or malware indicators).

We do not aim to inventory every installed app, continuously watch unrelated usage, pull unrelated app content, or use install data for advertising.

5.11Camera and files you choose

Camera access is requested only when you start a capture (selfie, ID photo, liveness, or similar). The camera is not meant to run silently in the background.

When a file is needed, MoniBoat uses the system picker and receives only the item you confirm. We do not require open-ended access to your entire gallery or general storage.

5.12Support conversations

If you contact us, we may keep messages, tickets, complaint details, timestamps, and attachments you send, for as long as needed to help you and for a reasonable follow-up period.

5.13Data from partners

We may receive verification, bank-validation, payment status, fraud, sanctions, credit-related, or regulatory information from authorised providers, banks, bureaux, or competent authorities—only where the transfer is lawful and relevant.

6Device Permissions

Permissions appear only when a feature needs them:

Network / basic technical access — to reach our servers, protect sessions, and diagnose issues.

You can change permissions in system settings. Turning a permission off may disable the related feature.

7Why We Use Your Data

MoniBoat may use personal data to:

meet lawful requests from regulators, courts, or enforcement bodies.

We will not stretch data into a clearly incompatible purpose without a proper legal basis or extra notice where required.

8Lawful Bases

Depending on the activity, processing may rest on:

Vital or public interest — rare cases involving safety or an official mandate.

9Automated Checks

MoniBoat may use automated tools to assist identity checks, fraud detection, eligibility scoring, or transaction risk review.

Where Nigerian law requires human involvement, an explanation, or a challenge right for a high-impact solely automated decision, we will provide those safeguards. You may contact us to ask about an assessment, add information, or request a review.

10Sharing

We disclose personal data only for a legitimate purpose and only to the extent needed.

10.1Vendors

Hosting, security, messaging, identity/liveness, payments, analytics, and support vendors may process data under confidentiality and security terms, solely for contracted work.

10.2Banks and payment partners

Banks, processors, and settlement partners may receive data to validate accounts, move funds, reconcile payments, investigate issues, or meet their own legal duties.

10.3Credit bureaux and compliance providers

Licensed Nigerian credit bureaux (including FirstCentral and CRC where applicable) and KYC/fraud/sanctions providers may receive relevant loan, repayment, or verification data.

10.4Authorities

We may disclose data when required by law, court order, regulator instruction, or to protect users, investigate fraud, or assert legal rights. Bodies may include CBN, NDPC, NFIU, tax authorities, courts, and law enforcement.

10.5Corporate changes

In a financing, merger, or sale, limited information may be shared with advisers or successors under confidentiality, with notice or consent where the law requires it.

11Cross-Border Access

Data may be hosted or accessed in Nigeria or in another country where an approved vendor operates.

Transfers outside Nigeria follow NDPA requirements and may use adequacy findings, contractual clauses, technical controls, risk assessments, or other recognised mechanisms. You may ask us for a high-level description of safeguards, subject to security limits.

12How Long We Keep Data

We keep information only as long as needed for the purpose, taking into account legal, tax, KYC/AML, dispute, fraud, and audit needs.

Typed reference contacts: removed or de-identified after account deletion unless a limited hold is required.

When a period ends, data is securely deleted, anonymised, or taken out of ordinary use, subject to backups and legal holds.

13Your Rights

Subject to identity checks and lawful limits, you may request access, correction, erasure, restriction, objection (including to marketing), portability where applicable, withdrawal of consent, and review of certain automated outcomes.

Erasure does not override mandatory KYC/AML, tax, fraud, audit, outstanding-loan, or litigation holds.

Email MoniBoatCustomerService@gmail.com. We will respond within statutory timelines and explain any lawful refusal. You may also complain to the Nigeria Data Protection Commission.

14Closing Your Account

Use Delete Account in MoniBoat, or email us about closure.

We may verify identity first. Outstanding balances must normally be cleared before closure completes.

After approval, access ends and data that is no longer needed is deleted or irreversibly de-identified. Records required for legal, regulatory, fraud, financial, or dispute purposes may remain for the applicable period.

15Security

We apply organisational and technical controls aimed at reducing unauthorised access, loss, alteration, or misuse. Measures may include TLS for transit, AES-256 (or equivalent) for sensitive storage, least-privilege access, MFA for staff, monitoring, vendor diligence, and incident response.

No online system is perfectly safe. Please use strong credentials, protect OTP codes, keep your device updated, and tell us quickly if you suspect misuse.

16If a Breach Occurs

We will investigate, contain, document, and remediate incidents affecting personal data. Where the legal threshold is met, we will notify the NDPC and affected users in the manner and time the law requires.

17Age Limit

MoniBoat is for users aged 18 or older. We do not knowingly serve children. If we learn an under-18 account exists, we will disable it and delete related data except where a short legal or fraud hold is required.

18Changes to this Notice

We may update this Notice when products, permissions, security practices, or laws change. The date at the top shows the current version. Material changes may be highlighted in the app, by email, or another clear channel.

19Language

If translations exist and conflict with the English text, the English version controls to the extent permitted by law.

20Contact

For privacy questions, data requests, deletion help, or security concerns:

Do not email passwords, PINs, or OTP codes. If you remain unhappy with our reply, you may escalate to the Nigeria Data Protection Commission or another competent authority.

© 2026 MoniBoat Digital Technologies Ltd. All rights reserved.