1. Data Ownership Principle
This platform operates under strict data separation:
Platform Owns
The software system, infrastructure, logic, templates, and deployment architecture.
Tenant Owns
Their private business data — customers, transactions, records, and operational content.
2. Data We Collect
We may collect the following types of data:
- Account information: Principal ID, email (if provided), role, registration date
- Usage data: Pages visited, features accessed, session duration
- Payment information: Transaction references, payment status, provider used (processed via third-party providers — we do not store card details)
- Agreement records: Acceptance timestamps, checkbox states, IP address, device info
- System activity logs: Access events, admin actions, subscription changes
3. Tenant Data Privacy
Tenant private business data — including customer records, order data, financial records, and operational content — is:
- NOT accessed by the platform owner by default
- NOT shared across tenants or between platform users
- Logically isolated per tenant at the data layer
- Under the tenant's full control during active lease
4. Data Access Policy
Platform administrators (Chief Admin) do NOT access tenant private data except in the following strictly limited circumstances:
Tenant-Granted Support Access
When a tenant explicitly grants support access, the action is logged with timestamp and admin ID. Access is limited to the scope granted and revoked when resolved.
Legal / Security Investigation
When required by law, court order, or legitimate security investigation. All such access is audit-logged with reason and authority.
Fraud / Abuse / Breach
When there is credible evidence of fraud, abuse, illegal activity, or material breach of the Terms. Access is limited to what is necessary for the investigation.
All data access events by platform administrators are recorded in the audit log with timestamp, actor, reason, and scope.
5. Data Storage & Security
Your data is stored with the following protections:
- Data is stored securely on the Internet Computer protocol
- Tenant environments are logically isolated — one tenant cannot access another's data
- Security measures enforced at all levels: authentication, RBAC, input validation, rate limiting, and encryption
- No sensitive keys or credentials are exposed to the frontend
6. Data Retention
Data retention follows the lease lifecycle:
7. Data Export
Tenants may export their business data at any time during the following states:
- Active subscription
- Grace period
- Restricted mode (limited to allowed data types)
- Offboarding period
Export formats may include CSV, PDF, or ZIP depending on data type and app configuration. Export capability is removed after the offboarding period ends.
8. Payment Data
Payment processing is handled by third-party providers (Stripe, Paystack, Flutterwave, etc.). We do not store sensitive financial credentials such as card numbers, CVVs, or bank PINs. We store:
- Payment reference IDs and transaction status
- Payment amount and provider used
- Admin approval records for manual payments
9. Security Measures
We implement the following security protections:
10. Your Rights
You have the right to:
- Access your account data at any time
- Request an export of your business data
- Request deletion of your data (subject to retention policy and active subscription status)
- Correct inaccurate account information
- Withdraw support access previously granted
We may update this policy periodically. Continued use of the platform after updates constitutes acceptance of the revised policy.