Last updated: August 6, 2026. This Privacy Policy describes how Scripe Technologies Ltd collects, uses, and shares your personal information when you use our platform, in compliance with the Nigeria Data Protection Regulation (NDPR).
Welcome to Scripe(“we,” “our,” or “us”). Scripe Technologies Ltd is the Data Controller responsible for your personal data under the Nigeria Data Protection Regulation (NDPR), enforced by the Nigeria Information Technology Development Agency (NITDA).
When you visit https://scripe.app(the “Website”), use our mobile application, or use any of our services (the “Services”), we appreciate that you are trusting us with your personal information. This Privacy Policy explains what information we collect, why we collect it, how long we keep it, who we share it with, and what rights you have.
If you have any questions about this policy or our data practices, contact our Data Protection Officer at privacy@scripe.app.
We collect personal data that you voluntarily provide when you create an account, make a purchase, subscribe to a newsletter, attend an event, or contact support. We also collect certain data automatically when you use our Services.
Under the NDPR, we must have a lawful basis for each type of processing. The table below summarises the purposes for which we use your data and the legal basis we rely on.
| Purpose | Legal basis |
|---|---|
| Account creation and authentication | Performance of contract |
| Processing payments and fulfilling orders | Performance of contract |
| Sending transactional emails (receipts, tickets, booking confirmations) | Performance of contract |
| Sending marketing and newsletter emails | Consent |
| Analytics and product improvement | Consent (cookie banner) |
| Fraud prevention and platform security | Legitimate interest |
| Compliance with legal obligations (e.g. financial records) | Legal obligation |
| AI-assisted content generation (when you use AI features) | Consent |
We share your personal data with the following categories of third-party service providers, each of whom processes data on our behalf under contractual obligations that protect your privacy.
| Provider | Purpose | Data shared |
|---|---|---|
| Paystack | Payment processing | Email, name, payment amount, transaction reference |
| Supabase | Database and authentication | All account and content data |
| Cloudflare R2 | File storage (images, documents, media) | Uploaded files |
| Plunk | Transactional and marketing emails | Email, name |
| Termii / Twilio | SMS and WhatsApp notifications | Phone number, message content |
| PostHog | Product analytics (only with consent) | Anonymised usage events, device info |
| Google Generative AI | AI-assisted features (content drafts, summaries) | Text prompts you submit to AI features |
We do not sell, rent, or trade your personal data to any third party for their marketing purposes.
Some of our third-party processors operate outside Nigeria. When your data is transferred internationally, we ensure that adequate safeguards are in place through contractual data processing agreements that meet NDPR requirements.
Our primary database is hosted by Supabase in the United States. File storage is provided by Cloudflare, which replicates data across edge locations globally. In all cases, we require processors to maintain security standards equivalent to or exceeding NDPR requirements.
We retain personal data only for as long as necessary for the purpose it was collected. The specific retention periods are:
When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised.
We implement the following technical and organisational measures:
While we take every reasonable precaution, no system is completely immune to security threats. If you suspect unauthorised access to your account, contact us immediately at support@scripe.app.
Under the NDPR, you have the following rights over your personal data. You can exercise all of these directly from your account — no need to email us.
To exercise these rights, go to Settings → Privacy → Your Data. We respond to all requests within 30 days.
If you believe your data protection rights have been violated, you may lodge a complaint with the Nigeria Information Technology Development Agency (NITDA) at nitda.gov.ng.
When a business (merchant) uses Scripe to sell products, manage events, or run a community, the merchant acts as a Data Controller for the personal data of their customers. Scripe processes this data on behalf of the merchant.
Merchants are responsible for:
Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at privacy@scripe.app, and we will take steps to delete that information.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on our Website before the change becomes effective. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
The version of this policy you consented to at signup is recorded in your account. If a future version materially changes how we process your data, we may ask you to re-consent.
If you have questions about this Privacy Policy or want to exercise your data rights, you can reach us through: