Legal Document
Privacy Policy

This Privacy Policy explains how Cloverr Technologies Limited collects, uses, stores, and protects your personal information when you use the Cloverr platform and services.

Effective: June 29, 2025
~12 min read
NDPR Compliant
Our Commitment

Cloverr is committed to protecting your privacy and handling your personal data in accordance with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023. This policy is written in plain language — we tell you exactly what we collect and why.

1 Who We Are & Data Controller

Cloverr Technologies Limited is the Data Controller responsible for your personal data collected through the Cloverr Platform. We are registered under Nigerian law and our principal place of business is Lagos, Nigeria.

Our Data Protection Officer (DPO) can be reached at privacy@cloverr.ng. We have registered with the Nigeria Data Protection Commission (NDPC) as required by the NDPA 2023.


2 Information We Collect

2.1 Information You Provide

CategoryData CollectedPurpose
Account RegistrationFull name, email address, phone number, date of birthAccount creation, identity verification, communications
Bank & Payment DetailsBank name, account number, account name, BVN (where required for KYC)Processing withdrawals, fraud prevention, regulatory compliance
Social Media AccountsUsernames, profile URLs, account IDs for linked platforms (Instagram, TikTok, YouTube, Twitter/X)Task verification, order matching, fraud detection
Identity VerificationGovernment-issued ID (NIN, driver's licence, international passport), selfie photoKYC compliance, fraud prevention
CommunicationsMessages sent to support, survey responses, feedbackCustomer service, platform improvement

2.2 Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers, mobile network information, and browser type.
  • Log Data: IP address, access times, pages viewed, links clicked, referring URLs, and session duration.
  • Location Data: Approximate location derived from IP address. We do not collect precise GPS location unless you explicitly grant permission for a location-sensitive feature.
  • Usage Data: How you interact with tasks, your task acceptance rate, task completion speed, verification outcomes, and transaction history.
  • Cookie & Tracking Data: See Section 7 (Cookies) for full details.

2.3 Information from Third Parties

  • Social media platforms (where you grant us permission) — profile verification data and public account metrics.
  • Identity verification service providers — document authentication results.
  • Payment processors and banks — transaction confirmation data.
  • Fraud prevention services — risk scores and flagging signals.

3 How We Use Your Information

We process your personal data only where we have a lawful basis to do so. The table below summarises our processing activities:

PurposeLawful Basis
Creating and managing your accountContract performance
Processing task completions and paymentsContract performance
Verifying your identity (KYC)Legal obligation (NDPR, CBN guidelines)
Detecting and preventing fraudLegitimate interest / Legal obligation
Communicating service updates and important noticesContract performance / Legitimate interest
Sending marketing communications (where opted in)Consent
Improving and personalising the PlatformLegitimate interest
Complying with legal and regulatory requirementsLegal obligation
Resolving disputes and enforcing TermsLegitimate interest / Legal obligation
Analytics and product researchLegitimate interest

4 Sharing Your Information

Cloverr does not sell your personal data. We share your data only in the following circumstances:

4.1 Service Providers

We work with carefully selected third-party service providers who process data on our behalf under strict data processing agreements. These include:

  • Cloud hosting and infrastructure providers (servers located within Nigeria and the EU).
  • Payment processors and financial institutions for withdrawal processing.
  • Identity verification and KYC service providers.
  • Fraud detection and cybersecurity services.
  • Customer support and communication platforms.
  • Analytics and crash reporting services.

4.2 Legal Requirements

We may disclose your information to government agencies, law enforcement, regulators, or courts where we are legally required to do so, or where we believe disclosure is necessary to protect the rights, property, or safety of Cloverr, our Users, or the public.

4.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of Cloverr's assets, your personal data may be transferred to the acquiring entity. We will notify you via email and a prominent Platform notice at least 30 days before any such transfer, and the acquiring entity will be bound by this Privacy Policy.

We Do Not Sell Your Data

Cloverr does not sell, rent, or lease your personal data to advertisers, data brokers, or any other third parties for commercial purposes.


5 Data Retention
Data CategoryRetention PeriodReason
Account informationDuration of account + 5 yearsLegal obligation, dispute resolution
Transaction records7 years from transaction dateFIRS, CBN, and SCUML requirements
KYC documents5 years from account closureAML/CFT regulatory requirements
Task completion evidence12 months from task completionDispute resolution
Log and usage data12 monthsSecurity monitoring, fraud detection
Marketing consent recordsUntil consent withdrawn + 3 yearsCompliance evidence
Support communications3 years from last contactService quality, dispute resolution

After the applicable retention period, your data is securely deleted or anonymised in a manner that means it can no longer be attributed to you.


6 Your Rights

Under the NDPR 2019 and NDPA 2023, you have the following rights regarding your personal data. To exercise any right, contact privacy@cloverr.ng. We will respond within 30 days.

  • Right of Access — You may request a copy of the personal data we hold about you, along with information about how we use it.
  • Right to Rectification — You may request correction of any inaccurate or incomplete personal data we hold about you.
  • Right to Erasure — You may request deletion of your personal data where we no longer have a lawful basis to process it, subject to our legal retention obligations.
  • Right to Restrict Processing — You may request that we limit the way we use your data in certain circumstances, for example while a dispute is being resolved.
  • Right to Data Portability — You may request that we provide your personal data in a structured, machine-readable format so you can transfer it to another service.
  • Right to Object — You may object to processing based on legitimate interest, including direct marketing, at any time.
  • Right to Withdraw Consent — Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right to Lodge a Complaint — You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng if you believe we have not handled your data lawfully.

7 Cookies & Tracking

7.1 What We Use

Cookie TypePurposeDuration
Essential / Strictly NecessarySession management, authentication, security (CSRF tokens)Session / 30 days
FunctionalRemembering your preferences (language, notification settings)12 months
AnalyticsUnderstanding how users navigate the Platform (page views, session duration). Data is anonymised.13 months
Fraud PreventionDevice fingerprinting and risk scoring to detect fraudulent activity12 months

7.2 Managing Cookies

You can manage or disable non-essential cookies through your browser settings or our Cookie Preference Centre accessible from the footer of our Platform. Please note that disabling essential cookies will affect Platform functionality and your ability to log in.

We do not use advertising or third-party tracking cookies. We do not permit third-party advertisers to place cookies on the Platform.


8 Data Security

Cloverr implements appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage, including:

  • AES-256 encryption of data at rest and TLS 1.3 encryption of all data in transit.
  • Role-based access controls ensuring that employee access to personal data is limited to what is necessary for their role.
  • Regular security assessments, penetration testing, and vulnerability scanning.
  • Multi-factor authentication for all internal systems containing personal data.
  • Incident response procedures including mandatory breach notification to the NDPC within 72 hours of discovery where required.
  • Regular staff training on data protection and information security.
Important Notice

No method of data transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.


9 Children's Privacy

The Platform is not directed at children under the age of 18, and we do not knowingly collect personal data from anyone under 18 years of age. If we discover that we have inadvertently collected personal data from a person under 18, we will delete it immediately. If you believe a child under 18 has provided us with personal data, please contact us at privacy@cloverr.ng.


10 International Data Transfers

Your personal data is primarily processed and stored on servers located within Nigeria. Where we use third-party service providers that process data outside Nigeria, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the NDPC.
  • Transfer to countries that the NDPC has determined provide an adequate level of protection.
  • Binding corporate rules where the recipient is part of a group of companies.

You may request details of the safeguards in place for any specific international transfer by contacting our DPO at privacy@cloverr.ng.


11 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy.
  • Notify you by email at least 14 days before the changes take effect where the changes are material.
  • Display a prominent notice on the Platform.

We encourage you to review this Policy periodically. Your continued use of the Platform after the effective date of a revised Policy constitutes your acknowledgement of the changes.


12 Contact & Complaints

For any questions about this Privacy Policy, to exercise your data subject rights, or to report a concern about how we handle your data, please contact us:

Data Protection Officer
General Support
Regulatory Body
Nigeria Data Protection Commission
ndpc.gov.ng
Response Time
Within 30 days of receiving your request