Scripe
Pricing
Legal

Privacy Policy

Last updated: August 6, 2026. This Privacy Policy describes how Scripe Technologies Ltd collects, uses, and shares your personal information when you use our platform, in compliance with the Nigeria Data Protection Regulation (NDPR).

Table of Contents

1. Introduction2. Personal Data We Collect3. Legal Basis and Purpose4. Third-Party Processors5. International Transfers6. How Long We Keep Your Data7. How We Protect Your Data8. Your Data Rights9. Cookies and Analytics10. Merchant Responsibilities11. Children's Privacy12. Changes to This Policy13. Contact Us

1. Introduction

Welcome to Scripe(“we,” “our,” or “us”). Scripe Technologies Ltd is the Data Controller responsible for your personal data under the Nigeria Data Protection Regulation (NDPR), enforced by the Nigeria Information Technology Development Agency (NITDA).

When you visit https://scripe.app(the “Website”), use our mobile application, or use any of our services (the “Services”), we appreciate that you are trusting us with your personal information. This Privacy Policy explains what information we collect, why we collect it, how long we keep it, who we share it with, and what rights you have.

If you have any questions about this policy or our data practices, contact our Data Protection Officer at privacy@scripe.app.


2. Personal Data We Collect

We collect personal data that you voluntarily provide when you create an account, make a purchase, subscribe to a newsletter, attend an event, or contact support. We also collect certain data automatically when you use our Services.

Data you provide directly

  • Identity data: full name, username, profile photo.
  • Contact data: email address, phone number, billing/delivery address.
  • Authentication data: password (stored as a cryptographic hash, never in plain text).
  • Payment data: processed and stored by our payment processor, Paystack. We receive only a transaction reference and partial card details (last four digits and card type). We never store full card numbers.
  • Content data: posts, comments, event details, store products, circle/community content, and any files you upload.
  • Consent records: the date, IP address, and version of this policy you agreed to at signup.

Data collected automatically

  • Device and usage data: IP address, browser type, operating system, referring URL, pages visited, and timestamps. This data is collected via analytics cookies only with your consent (see Section 9).
  • Location data: approximate location derived from your IP address. We do not collect precise GPS location.

3. Legal Basis and Purpose

Under the NDPR, we must have a lawful basis for each type of processing. The table below summarises the purposes for which we use your data and the legal basis we rely on.

PurposeLegal basis
Account creation and authenticationPerformance of contract
Processing payments and fulfilling ordersPerformance of contract
Sending transactional emails (receipts, tickets, booking confirmations)Performance of contract
Sending marketing and newsletter emailsConsent
Analytics and product improvementConsent (cookie banner)
Fraud prevention and platform securityLegitimate interest
Compliance with legal obligations (e.g. financial records)Legal obligation
AI-assisted content generation (when you use AI features)Consent

4. Third-Party Processors

We share your personal data with the following categories of third-party service providers, each of whom processes data on our behalf under contractual obligations that protect your privacy.

ProviderPurposeData shared
PaystackPayment processingEmail, name, payment amount, transaction reference
SupabaseDatabase and authenticationAll account and content data
Cloudflare R2File storage (images, documents, media)Uploaded files
PlunkTransactional and marketing emailsEmail, name
Termii / TwilioSMS and WhatsApp notificationsPhone number, message content
PostHogProduct analytics (only with consent)Anonymised usage events, device info
Google Generative AIAI-assisted features (content drafts, summaries)Text prompts you submit to AI features

We do not sell, rent, or trade your personal data to any third party for their marketing purposes.


5. International Transfers

Some of our third-party processors operate outside Nigeria. When your data is transferred internationally, we ensure that adequate safeguards are in place through contractual data processing agreements that meet NDPR requirements.

Our primary database is hosted by Supabase in the United States. File storage is provided by Cloudflare, which replicates data across edge locations globally. In all cases, we require processors to maintain security standards equivalent to or exceeding NDPR requirements.


6. How Long We Keep Your Data

We retain personal data only for as long as necessary for the purpose it was collected. The specific retention periods are:

  • Active accounts: data is retained for as long as your account exists.
  • Deleted accounts: personal identifiers are anonymised immediately upon a verified deletion request. The anonymised record is retained for up to 2 years for fraud prevention and audit purposes.
  • Order and transaction records: 7 years after the transaction date, as required by Nigerian financial record-keeping regulations.
  • CRM contacts for deleted businesses: 90 days after business deletion.
  • Analytics data: aggregated and anonymised; individual session data is deleted after 90 days.

When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised.


7. How We Protect Your Data

We implement the following technical and organisational measures:

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Passwords are stored using bcrypt hashing with per-user salts.
  • Database access is restricted through role-based access controls and row-level security policies.
  • File uploads are stored in Cloudflare R2 with presigned URLs that expire after use.
  • Administrative actions are logged in an audit trail for accountability.

While we take every reasonable precaution, no system is completely immune to security threats. If you suspect unauthorised access to your account, contact us immediately at support@scripe.app.


8. Your Data Rights

Under the NDPR, you have the following rights over your personal data. You can exercise all of these directly from your account — no need to email us.

  • Right of access: request a copy of all personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete data via your profile settings.
  • Right to erasure: request deletion of your account and personal data. Your record is anonymised immediately; the anonymised stub is purged after 2 years.
  • Right to data portability: download your data in a machine-readable format (JSON).
  • Right to object: object to specific types of processing with a written explanation.

To exercise these rights, go to Settings → Privacy → Your Data. We respond to all requests within 30 days.

If you believe your data protection rights have been violated, you may lodge a complaint with the Nigeria Information Technology Development Agency (NITDA) at nitda.gov.ng.


9. Cookies and Analytics

We use the following categories of cookies:

  • Essential cookies: required for authentication and core functionality. These cannot be disabled without breaking the service. Legal basis: performance of contract.
  • Analytics cookies (PostHog):used to understand how visitors interact with the platform. These are only activated if you click “Accept” on the cookie consent banner. Legal basis: consent.

You can change your cookie preference at any time by clearing your browser's local storage for scripe.app. If you decline analytics cookies, all product analytics tracking is disabled and no usage data is sent to PostHog.


10. Merchant Responsibilities

When a business (merchant) uses Scripe to sell products, manage events, or run a community, the merchant acts as a Data Controller for the personal data of their customers. Scripe processes this data on behalf of the merchant.

Merchants are responsible for:

  • Obtaining appropriate consent from their customers before using marketing communications via Scripe (email campaigns, SMS, WhatsApp).
  • Responding to data requests from their own customers regarding data the merchant collected.
  • Complying with the NDPR as it applies to their own processing activities.

11. Children's Privacy

Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at privacy@scripe.app, and we will take steps to delete that information.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on our Website before the change becomes effective. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

The version of this policy you consented to at signup is recorded in your account. If a future version materially changes how we process your data, we may ask you to re-consent.


13. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, you can reach us through:

  • Data Protection Officer: privacy@scripe.app
  • General support: support@scripe.app
  • Self-service data requests: Settings → Privacy → Your Data

Still have questions?

We're happy to explain exactly how we handle your data.

Scripe

Talk to a product expert today.
For product inquiries, partnerships, or support,
please email us at support@scripe.app

Product

  • Store
  • Sessions
  • Workshops

Company

  • About us
  • Contact us

Resources

  • Scripe partner network
  • Blog
  • Terms of service
  • Privacy policy
  • Help center

© 2026 Scripe Inc. All rights reserved.