Legal
Privacy Policy
Last updated: June 12, 2026 · Compliant with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR).
The short version
ScanAcc helps businesses display their own bank account number through a scannable QR code. We do not process customer payments, do not see customer card numbers, BVNs, PINs, OTPs, transaction amounts, or any sensitive financial data. Money moves directly from a customer's bank app to the business's bank — never through ScanAcc.
What we collect from businesses
- Account credentials: email and password (passwords are hashed, never stored in plain text).
- Business profile: business name, optional phone number, public handle.
- Bank details for display: bank name, account name, account number. This information is the business's own publishable receiving details — the same information they would otherwise write on a wall or receipt.
What we collect from customers who scan
- Nothing personally identifying. We do not ask scanners to sign in, share contacts, or enter any details.
- Anonymous scan analytics: we record a one-way hashed session token (derived from IP + user agent + day) plus broad device type (Mobile/Desktop), browser family, and country — used solely to show the business their daily scan count. The raw IP address is never stored.
What we never have access to
- Customer card numbers, CVVs, PINs, OTPs or BVNs.
- Bank login credentials of any kind.
- Transaction amounts, references or settlement data.
- Customer names, phone numbers, addresses or contact lists.
Lawful basis (NDPA 2023, §25)
We process business data on the basis of contract (to provide the ScanAcc service the business signed up for) and legitimate interest (to keep the service secure and improve it). We rely on legitimate interest for anonymous scan analytics — no consent is required because no personal data is collected from scanners.
Your rights as a data subject
Under the NDPA you have the right to access, correct, delete, port and restrict processing of your data, and to object to processing. Exercise any of these rights by emailing nuuxperience@gmail.com. We respond within 30 days.
Data storage & security
All data is stored on secure managed infrastructure with encryption in transit (TLS 1.3) and at rest. Row-level security policies on our database ensure a business can only ever read or modify its own records. Service-role keys are server-side only and never exposed to browsers. We do not sell, rent or share business data with advertisers or data brokers.
Data retention
We keep business profile data for as long as the account is active, and for up to 90 days after deletion to allow recovery. Anonymous scan events are kept for up to 12 months for trend analytics, then permanently deleted.
Children
ScanAcc is intended for registered businesses and is not directed at children under 18.
Changes
If we materially change this policy we will notify account holders by email and update the "Last updated" date above.
Contact / Data Protection enquiries
Email nuuxperience@gmail.com. We reply within 24 hours.