Legal
Privacy Policy
Last updated 15 August 2026
Notiza never asks for your internet banking password, PIN or OTP, and cannot move money. It reads the alerts your bank already sends you, and nothing else.
Your team sees only the fields you allow them. Account balances are removed before an alert reaches anyone you have not granted them to — removed, not hidden behind a blur.
Who this covers
This policy applies to the Notiza mobile app, the collector app, this website and the service behind them. It is written for the Nigeria Data Protection Act 2023, and the controller is Notiza.
If you use Notiza because your employer invited you, your employer decides what you can see. This policy still describes what we do with your data, but questions about your permissions are theirs to answer.
What we collect
Your account
The email address and name your identity provider gives us when you sign in with Google. We never receive or store a password.
Your business
The workspace name, branch and business type you enter, and the names and roles of the people you invite.
Your bank accounts
The account number and bank you add, and the account name the bank returns when we verify that number. Account numbers are shown in full only to the workspace owner.
Payment alerts
The contents of the bank alerts you route to us: amount, direction, the counterparty the bank names, the reference, the time, the bank’s own narration, and the balance where the alert carries one.
Devices and sessions
A device label and platform your app reports at sign-in, and the IP address that sign-in came from. We use these to tell you when your account is used somewhere new.
Notification tokens
A push token per device, so alerts can reach your phone.
We do not collect internet banking credentials, card numbers, PINs or OTPs. There is nowhere in Notiza to enter them, and no feature that would use them.
How alerts reach us
You can forward bank alerts to an address we generate for your workspace, or connect a Gmail account. Where you connect Gmail, we ask only for permission to read messages — never to send, delete or modify them — and we read only messages from the bank senders your workspace has added. You can withdraw that permission at any time from your Google account.
We verify that each alert genuinely came from your bank before recording it. Mail that fails that check is refused rather than stored, so a forged alert cannot become a payment in your records.
SMS
If you pair an Android phone as a collector, it reads bank alert SMS on that device and reports them to us. It reads messages from the senders your workspace has added and does not read your other messages.
Why we hold it
To perform the contract you signed up for: to confirm that a payment someone claims to have made actually arrived, to route that confirmation to the people you have chosen, and to show you what came in. Alerts that cannot be attributed to one of your accounts are kept so you can see that they arrived and were not silently dropped.
We also hold a small amount of data to keep the account secure — the device and sign-in records above — on the basis of our legitimate interest in telling you about access you may not have authorised.
Who else sees it
We do not sell your data, and we do not use it for advertising. It is processed by the providers who run the service:
- Amazon Web Services — hosting, storage, sign-in and outbound email, in the Europe (Ireland) region.
- Google — sign-in, and the Gmail API where you have connected a mailbox.
- Expo — delivery of push notifications to your phone.
- Supabase — a mirror of transaction records used for reporting.
- Paystack — confirming the name on a bank account when you add one.
- WhatsApp and Telegram — only where you have chosen to have alerts delivered there, and only the alert content you configured.
Some of these process data outside Nigeria. Where they do, that transfer is covered by the provider’s own contractual safeguards.
What your team sees
Each person you invite has their own grant, and it is applied when the alert is read rather than when it was stored — so tightening someone’s access changes what they can see immediately, including for alerts that already exist. A grant can limit which accounts a person sees, which direction of payment, a minimum amount, and whether the balance is included at all. Where the balance is excluded it is removed from the record they receive, not obscured in it.
If you are on a paid plan
Which plan a workspace is on is stored with the workspace, along with a record of when it changed and who changed it. That record is what lets us answer questions about your account months later, so it is kept for as long as the workspace exists.
Billing details — the business name and address an invoice is made out to, and any tax identifier you give us — are not stored alongside your payment alerts. They are held in our accounting records, kept for as long as Nigerian tax law requires, and are not visible to anyone you invite to your workspace.
We do not store card details. Paid plans are invoiced, and no card is held on file.
How long we keep it
Payment records
Kept for as long as your workspace exists, because they are the record you check a disputed payment against.
In-app notifications
90 days.
Alerts we could not read
30 days, so a parsing failure can be diagnosed and then forgotten.
Known devices
A year after their last sign-in.
Plan history
As long as the workspace exists — it is the record of what you were entitled to and when.
Billing and invoices
Held in our accounting records for as long as tax law requires, which is longer than anything above and separate from your alerts.
Everything else
Deleted when you delete the workspace.
Deleting a workspace removes its accounts, recipients, connections and payment records. It cannot be undone.
Your rights
Under the Nigeria Data Protection Act you may ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Write to privacy@notiza.ng and we will respond within 30 days.
You can also complain to the Nigeria Data Protection Commission if you think we have handled your data wrongly.
Security
Data is encrypted in transit and at rest. Mailbox tokens are wrapped with a dedicated key. Sign-in is handled by a managed identity provider rather than by us, so we never hold your password. Access to production data is limited to the people who operate the service.
No system is perfect. If we discover a breach affecting your data we will tell you and the Commission as the Act requires.
Children
Notiza is a tool for businesses and is not directed at anyone under 18.
Changes
If we change this policy in a way that materially affects you, we will say so in the app before the change takes effect. The date at the top is the last time the text itself changed.
