1About this Notice
MoniBoat treats careful handling of personal data as part of delivering trustworthy digital credit services.
This Notice describes, in plain terms:
- what categories of information MoniBoat may obtain
- why that information is needed
- which device permissions may appear in the app
- when information may be disclosed to others
- how long records are kept
- the safeguards we apply
- choices and rights available to you; and
how to close an account or ask for data removal.
Please review this Notice before creating an account or continuing to use MoniBoat.
Using the MoniBoat app or sending information through our channels means you have seen this Notice. When the law requires a separate consent, MoniBoat will ask for it before collecting or using the related data or permission.
You may decline or later withdraw consent. Doing so can limit features that depend on that information or permission.
2Operator Details
MoniBoat is operated by:
In this Notice:
- “MoniBoat,” “we,” “us,” and “our” mean MoniBoat Digital Technologies Ltd. and the MoniBoat service
- “you” means anyone who opens, registers for, applies through, or otherwise uses MoniBoat; and
“Service” means the MoniBoat mobile app, related support channels, and connected operational processes.
3What this Notice Covers
This Notice applies to personal data handled through:
- the MoniBoat Android application
- onboarding, KYC, and eligibility checks
- loan application, disbursement, and repayment flows
- customer care and complaint handling
- security and anti-fraud tooling; and
vendors that support MoniBoat under contract.
Depending on your journey, MoniBoat may support registration, identity checks, credit review, payouts, repayments, notifications, and support. Not every data type listed below applies to every user.
4Laws We Follow
We aim to process personal data consistently with Nigerian privacy, consumer-protection, AML/CFT, KYC, and cybersecurity rules that apply to digital lending.
Those rules may include:
- the Nigeria Data Protection Act 2023 and related implementation guidance
- the Nigeria Data Protection Regulation 2019, where still relevant
- the Money Laundering (Prevention and Prohibition) Act 2022
- Central Bank of Nigeria KYC / AML expectations for lending and payments; and
other binding statutes, directives, or court orders.
References include later amendments and replacement instruments.
5Information MoniBoat May Obtain
We follow minimisation: we seek only what is reasonably needed for service delivery, verification, risk control, compliance, or support.
5.1Profile and sign-up details
Examples include full name, mobile number, email, date of birth, gender, nationality, marital status, residential address, authentication credentials, and login or registration logs.
5.2Identity and KYC materials
We may process NIN, BVN, ID type and number, ID images, verification outcomes, screening results, fraud signals, and related audit trails.
Government identifiers are used for verification, compliance, security, underwriting support, and transaction integrity—not for unrelated advertising, and not for sale or public posting.
5.3Work and income context
Where needed for a credit request, we may collect employment status, occupation, employer details, declared income range, and similar capacity information you submit.
5.4Banking and repayment records
We may process bank name, account number, BVN, ownership-check results, disbursement and repayment status, settlement references, and investigation records tied to a payment.
Sensitive payment credentials are handled only through authorised payment channels where applicable.
5.5Contacts you type in yourself
If a feature asks for an emergency or reference contact, you may enter a name, relationship, and phone number.
Manually entered contacts will not be sold, used for unrelated ads, handed to unrelated marketers, or used for threatening or harassing outreach. Please tell the other person before you share their details.
5.6Selfie, document photo, and liveness results
To confirm you are a real person and to reduce impersonation, MoniBoat may ask for an ID photo, a selfie, a liveness capture, match scores, pass/fail outcomes, and verification logs.
Biometric templates created only for a check are removed or irreversibly detached from your identity within 24 hours after a successful check, unless a longer hold is required by law or an active fraud case.
Biometrics are not used for advertising, behavioural marketing, or unrelated tracking.
5.7Device and network signals
For security and reliability we may collect limited technical data such as device make/model, OS version, app version, install ID, language, IP address, network type, time zone, session times, crash diagnostics, and security events.
These signals help detect abuse, investigate faults, and keep accounts safe. They are not intended as a way to read unrelated personal content on your phone.
5.8Financial SMS (permission-based)
If MoniBoat offers an SMS-assisted verification or risk feature, the OS permission is requested first. With permission, we may process sender details, message body, date/time, and transaction-related indicators.
Uses are limited to verification, account protection, fraud prevention, and proportionate risk assessment—not ads, not selling message content, and not sharing content with unrelated parties.
After processing, data that is no longer needed is deleted, de-identified, or taken out of day-to-day use.
5.9Approximate location (optional)
MoniBoat may ask for coarse (approximate) location—not precise GPS tracking. With your permission, we may collect a one-time or limited location sample such as latitude, longitude, and accuracy, typically as a broad city- or area-level signal.
This signal may support fraud prevention, account protection, and proportionate credit-risk checks. Location is optional: you can refuse or skip it and still continue onboarding or use core features that do not depend on it.
You may change or withdraw location access later in Android settings. Without permission, MoniBoat will not read location from the device.
5.10Narrow app-security indicators
Where lawful and supported by the OS, MoniBoat may evaluate limited signals linked to elevated fraud risk (for example tampering, root/emulator environments, overlays, or malware indicators).
We do not aim to inventory every installed app, continuously watch unrelated usage, pull unrelated app content, or use install data for advertising.
5.11Camera and files you choose
Camera access is requested only when you start a capture (selfie, ID photo, liveness, or similar). The camera is not meant to run silently in the background.
When a file is needed, MoniBoat uses the system picker and receives only the item you confirm. We do not require open-ended access to your entire gallery or general storage.
5.12Support conversations
If you contact us, we may keep messages, tickets, complaint details, timestamps, and attachments you send, for as long as needed to help you and for a reasonable follow-up period.
5.13Data from partners
We may receive verification, bank-validation, payment status, fraud, sanctions, credit-related, or regulatory information from authorised providers, banks, bureaux, or competent authorities—only where the transfer is lawful and relevant.
6Device Permissions
Permissions appear only when a feature needs them:
- Camera — for selfies, ID capture, or liveness when you start that flow
- SMS — only if an SMS-based financial check is available and you allow it
- Approximate location (optional) — a coarse area pin for fraud prevention and account protection; you may skip it
- Document / photo picker — to select a single file you choose; and
Network / basic technical access — to reach our servers, protect sessions, and diagnose issues.
You can change permissions in system settings. Turning a permission off may disable the related feature.
7Why We Use Your Data
MoniBoat may use personal data to:
- open and secure your account
- verify identity and documents
- complete KYC and related compliance checks
- confirm bank-account ownership
- assess credit eligibility and decide on an application
- disburse loans and process repayments
- send OTPs, reminders, and service notices
- answer support requests and disputes
- detect fraud, takeover, or abuse
- run AML/sanctions and audit controls
- keep the Service stable and improve usability; and
meet lawful requests from regulators, courts, or enforcement bodies.
We will not stretch data into a clearly incompatible purpose without a proper legal basis or extra notice where required.
8Lawful Bases
Depending on the activity, processing may rest on:
- Contract — creating an account, reviewing an application, managing a loan, or supporting repayments
- Legal duty — KYC, AML/CFT, sanctions, reporting, and record-keeping
- Consent — optional data or device access, which you can withdraw in-app, in device settings, or via our privacy email
- Legitimate interests — security, fraud prevention, service reliability, and defending legal claims, balanced against your rights; and
Vital or public interest — rare cases involving safety or an official mandate.
9Automated Checks
MoniBoat may use automated tools to assist identity checks, fraud detection, eligibility scoring, or transaction risk review.
Where Nigerian law requires human involvement, an explanation, or a challenge right for a high-impact solely automated decision, we will provide those safeguards. You may contact us to ask about an assessment, add information, or request a review.
10Sharing
We disclose personal data only for a legitimate purpose and only to the extent needed.
10.1Vendors
Hosting, security, messaging, identity/liveness, payments, analytics, and support vendors may process data under confidentiality and security terms, solely for contracted work.
10.2Banks and payment partners
Banks, processors, and settlement partners may receive data to validate accounts, move funds, reconcile payments, investigate issues, or meet their own legal duties.
10.3Credit bureaux and compliance providers
Licensed Nigerian credit bureaux (including FirstCentral and CRC where applicable) and KYC/fraud/sanctions providers may receive relevant loan, repayment, or verification data.
10.4Authorities
We may disclose data when required by law, court order, regulator instruction, or to protect users, investigate fraud, or assert legal rights. Bodies may include CBN, NDPC, NFIU, tax authorities, courts, and law enforcement.
10.5Corporate changes
In a financing, merger, or sale, limited information may be shared with advisers or successors under confidentiality, with notice or consent where the law requires it.
11Cross-Border Access
Data may be hosted or accessed in Nigeria or in another country where an approved vendor operates.
Transfers outside Nigeria follow NDPA requirements and may use adequacy findings, contractual clauses, technical controls, risk assessments, or other recognised mechanisms. You may ask us for a high-level description of safeguards, subject to security limits.
12How Long We Keep Data
We keep information only as long as needed for the purpose, taking into account legal, tax, KYC/AML, dispute, fraud, and audit needs.
- Account profile: while active, then generally up to six years after closure
- KYC / ID records: up to six years after the relationship ends when needed for compliance or disputes
- Loan and payment records: typically up to six years, or longer if a binding rule requires it
- Biometric verification data: deleted within 24 hours after successful verification, unless law or an active fraud case requires otherwise
- Device / security logs: usually no more than twelve months unless an incident or claim justifies longer
- Approximate location samples: kept only as long as needed for the related risk or verification event, then deleted or de-identified unless a dispute or fraud case requires a short hold; and
Typed reference contacts: removed or de-identified after account deletion unless a limited hold is required.
When a period ends, data is securely deleted, anonymised, or taken out of ordinary use, subject to backups and legal holds.
13Your Rights
Subject to identity checks and lawful limits, you may request access, correction, erasure, restriction, objection (including to marketing), portability where applicable, withdrawal of consent, and review of certain automated outcomes.
Erasure does not override mandatory KYC/AML, tax, fraud, audit, outstanding-loan, or litigation holds.
Email MoniBoatCustomerService@gmail.com. We will respond within statutory timelines and explain any lawful refusal. You may also complain to the Nigeria Data Protection Commission.
14Closing Your Account
Use Delete Account in MoniBoat, or email us about closure.
We may verify identity first. Outstanding balances must normally be cleared before closure completes.
After approval, access ends and data that is no longer needed is deleted or irreversibly de-identified. Records required for legal, regulatory, fraud, financial, or dispute purposes may remain for the applicable period.
15Security
We apply organisational and technical controls aimed at reducing unauthorised access, loss, alteration, or misuse. Measures may include TLS for transit, AES-256 (or equivalent) for sensitive storage, least-privilege access, MFA for staff, monitoring, vendor diligence, and incident response.
No online system is perfectly safe. Please use strong credentials, protect OTP codes, keep your device updated, and tell us quickly if you suspect misuse.
16If a Breach Occurs
We will investigate, contain, document, and remediate incidents affecting personal data. Where the legal threshold is met, we will notify the NDPC and affected users in the manner and time the law requires.
17Age Limit
MoniBoat is for users aged 18 or older. We do not knowingly serve children. If we learn an under-18 account exists, we will disable it and delete related data except where a short legal or fraud hold is required.
18Changes to this Notice
We may update this Notice when products, permissions, security practices, or laws change. The date at the top shows the current version. Material changes may be highlighted in the app, by email, or another clear channel.
19Language
If translations exist and conflict with the English text, the English version controls to the extent permitted by law.
20Contact
For privacy questions, data requests, deletion help, or security concerns:
Do not email passwords, PINs, or OTP codes. If you remain unhappy with our reply, you may escalate to the Nigeria Data Protection Commission or another competent authority.
© 2026 MoniBoat Digital Technologies Ltd. All rights reserved.