Privacy Policy
How Nura Mustapha Technologies Limited collects, processes, stores, and protects your retail business data — in plain language.
Privacy Policy
Last Updated: 23 July 2026 — Version 2.0This Privacy Policy explains how Nura Mustapha Technologies Limited (“we”, “us”, “our”, “SwiftPOS”) collects, uses, stores, and discloses information about you and your retail business when you access or use the SwiftPOS platform at swiftpos.ng and app.swiftpos.ng. We are committed to protecting your personal data in accordance with the Nigeria Data Protection Regulation 2019 (NDPR) and its Implementation Framework.
1 Who We Are
SwiftPOS is a cloud-based Point of Sale and retail management software platform developed and operated by Nura Mustapha Technologies Limited, a company registered in the Federal Republic of Nigeria under the Corporate Affairs Commission with registration number RC 9679645.
For the purposes of the Nigeria Data Protection Regulation (NDPR), Nura Mustapha Technologies Limited is the Data Controller of personal data processed through the SwiftPOS platform. Where we process personal data on your instructions (for example, your employees’ and customers’ data stored in your tenant environment), we also act as a Data Processor on your behalf, and you remain the Data Controller for that data.
2 Scope of this Policy
This Policy applies to:
- Business owners, administrators, and managers who register and maintain a SwiftPOS account (“Merchants”);
- Cashiers, store employees, and other staff users added to a Merchant’s tenant environment (“Staff Users”);
- End customers of Merchants whose personal details (name, phone number, credit balances) are recorded in SwiftPOS;
- Visitors to the SwiftPOS marketing website at swiftpos.ng.
This Policy does not govern the privacy practices of third-party websites or services that may be linked from our platform.
3 Personal Data We Collect
3.1 Merchant Account & Registration Data
When you create a SwiftPOS account, we collect:
- Full legal name of the account holder;
- Business name and company type;
- Email address and phone number;
- Hashed account password (we never store passwords in plain text);
- Company URL slug (unique identifier used to access your tenant environment);
- Physical store address(es) and branch locations;
- Business registration number (CAC number), if provided voluntarily;
- Subscription plan tier and billing cycle preference;
- Payment transaction reference IDs from our payment processors.
3.2 Staff & Cashier Data
When a Merchant creates staff accounts, we collect for each staff member:
- Full name and assigned username;
- Contact email address or phone number;
- Role designation (Administrator, Manager, Cashier, or custom roles);
- Role-based permission settings and custom capability overrides;
- Hashed cashier transaction PIN (used for sales authorization and pricing overrides);
- Login timestamps and session history;
- IP addresses and device information associated with each login session.
3.3 Product & Inventory Data
To provide inventory management services, we store:
- Product names, SKUs, barcodes, and category assignments;
- Retail selling prices, wholesale cost prices, and VAT/tax configurations;
- Stock quantity levels across single and multiple branches;
- Supplier information (name, contact, payment terms);
- Purchase order records, received quantities, and stock adjustment histories;
- Product images and descriptions uploaded by the Merchant.
3.4 Sales & Transaction Data
- All sales transactions processed through Classic POS, Smart Grid POS, and Barcode POS interfaces;
- Items sold, quantities, unit prices, applicable discounts, and VAT amounts;
- Payment methods (cash, bank transfer, QR code, card, or split payment);
- Receipt data including QR code identifiers;
- Transaction timestamps, cashier identifier, and POS terminal session ID;
- Order reversals, voids, and adjustment records;
- End-of-Day (EOD) cash reconciliation records and variance reports.
3.5 Customer (End-Customer) Data
Merchants may record their own customers’ information in SwiftPOS for the purpose of credit sales and customer loyalty management. This may include:
- Customer name and phone number;
- Outstanding credit balances and credit sale histories;
- Payment receipt logs associated with a named customer.
Merchants are solely responsible for obtaining any required consent from their end-customers before recording personal data in SwiftPOS.
3.6 Audit Trail & System Event Data
To protect Merchants against internal theft and unauthorized activity, SwiftPOS records an immutable audit log capturing 24 distinct system event types, including:
- Login and logout events with IP addresses and timestamps;
- Product price modifications and bulk price changes;
- Stock adjustment, stock addition, and write-off events;
- Transaction override requests, discount approvals, and PIN verifications;
- Sales deletion, order cancellation, and transaction reversal events;
- Account configuration changes (plan upgrades, branch additions, receipt customizations);
- Export and data download activities.
3.7 AI Assistant Interaction Data
For Merchants on plans with access to the SwiftPOS AI Business Assistant:
- User prompt inputs submitted to the AI assistant;
- AI-generated responses and tool call outputs;
- Daily token usage counts and rate-limit tracking data;
- Session identifiers linking conversations to authenticated user sessions.
AI interaction data is retained solely for rate-limit enforcement and session continuity. It is not used for training external AI models.
3.8 Website & Analytics Data
When you visit swiftpos.ng, we collect standard web analytics information including IP address, browser type, referring URL, pages visited, and session duration through Google Analytics (GA4). This data is processed in aggregate and is used solely for improving our marketing website and product.
4 How We Use Your Data
| Purpose | Data Used |
|---|---|
| Providing & operating the SwiftPOS platform | Account data, inventory data, transaction data, staff credentials |
| Processing sales & managing POS sessions | Product data, cashier credentials, transaction data |
| Generating reports & business intelligence | Sales data, profit/loss data, stock data |
| Delivering daily operational email summaries | Sales summaries, cash variance, profit margin digests |
| Detecting & flagging suspicious activity | Audit log data, transaction patterns, discount frequencies |
| Sending low-stock & credit-owing notifications | Inventory levels, customer credit data, contact information |
| Billing & subscription management | Account data, payment references, plan tier data |
| AI assistant operations | Prompt data, session data, inventory/financial data queried |
| Security & fraud prevention | IP addresses, login history, audit trail data |
| Legal compliance & regulatory obligations | Account data, transaction records, as required by Nigerian law |
| Product improvement & analytics | Aggregated, anonymized usage data |
5 Legal Basis for Processing
Under the NDPR, we process personal data on the following legal grounds:
- Contractual necessity: Processing required to deliver the SwiftPOS service under your subscription agreement (account management, transaction processing, reporting).
- Legitimate interests: Fraud detection, internal security monitoring, audit logging, and platform analytics — where these interests are not overridden by your fundamental rights.
- Legal obligation: Compliance with applicable Nigerian laws, including the NDPR, FIRS tax regulations, and any court orders.
- Consent: Where you have given specific, informed consent for a processing activity (e.g., marketing communications). You may withdraw consent at any time.
6 Third-Party Data Processors
We engage the following categories of third-party processors who may access your data solely to perform services on our behalf:
| Processor / Category | Purpose | Data Shared |
|---|---|---|
| Monnify (Moniepoint) | Subscription billing & payment processing | Merchant name, email, payment amounts |
| Email SMTP Provider | Transactional emails, daily report delivery | Email address, report content |
| SMS Gateway | Customer credit notifications, security alerts | Phone number, notification content |
| Google Analytics (GA4) | Website analytics | Anonymized browsing data, IP address |
| Cloud Hosting Provider | Server infrastructure & data storage | All platform data (encrypted at rest) |
We do not sell, rent, or trade your personal or business data to any third party for marketing or commercial purposes.
7 Offline Mode & PWA Data Storage
SwiftPOS operates as a Progressive Web App (PWA) with offline-first capabilities. When you use SwiftPOS in an environment without internet connectivity:
- Product catalogs, pricing data, and active shopping carts are cached locally on your device using browser Service Workers and IndexedDB;
- Transactions processed offline are stored temporarily on the local device with a unique
client_idUUID to prevent duplication; - Upon reconnection, offline transactions automatically synchronize with our cloud servers;
- Locally cached data on your device is subject to your browser's storage settings. SwiftPOS is not responsible for data loss caused by manually clearing browser storage, device resets, or browser cache purges before synchronization is complete.
8 Data Retention
| Data Category | Retention Period |
|---|---|
| Active account & merchant data | Duration of subscription + 90 days after cancellation |
| Sales & transaction records | 7 years (in accordance with Nigerian tax regulations — FIRS requirements) |
| Audit log records | 5 years from creation date |
| Staff credentials & login history | Duration of account + 90 days |
| Customer credit records | Duration of Merchant account + 90 days |
| AI assistant prompt logs | 90 days (for rate-limit enforcement only) |
| Website analytics data | 14 months (Google Analytics standard retention) |
Upon expiry of the applicable retention period, data is securely deleted or anonymized using industry-standard methods.
9 Your Rights Under the NDPR
As a data subject under the Nigeria Data Protection Regulation, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data where no legitimate grounds exist for continued processing, subject to legal retention obligations.
- Right to Data Portability: Receive your data in a structured, machine-readable format (CSV export). This is accessible directly in the SwiftPOS Export Center.
- Right to Restriction: Request that we limit the processing of your data in certain circumstances.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, submit a written request to compliance@swiftpos.ng. We will respond within 30 days of receiving your request.
10 Security Measures
We implement multiple layers of technical and organizational security controls to protect your data:
- Encryption in Transit: All connections to SwiftPOS are encrypted using HTTPS/TLS 1.2 or higher. HSTS (HTTP Strict Transport Security) headers are enforced on all live servers.
- Encryption at Rest: Sensitive database fields and backup data are encrypted at rest on our cloud infrastructure.
- Password Hashing: All account passwords are hashed using industry-standard algorithms (bcrypt/PBKDF2). Raw passwords are never stored or logged.
- Cashier PIN Hashing: Cashier verification PINs are stored as salted hashes. No plaintext PINs are ever accessible by SwiftPOS staff.
- Multi-Tenant Isolation: Each Merchant operates within a strictly isolated tenant environment. Database queries are scoped by
company_slugat the application level, preventing cross-tenant data access. - Role-Based Access Control (RBAC): All system endpoints enforce role-level permission checks. Cashiers, Managers, and Admins have different access scopes.
- Immutable Audit Logs: System event logs cannot be deleted or modified by any user, including administrators. Only authorized SwiftPOS system processes can write to audit logs.
- Anomaly Detection: Our suspicious activity engine continuously monitors for unusual patterns (e.g., excessive discounts, high-volume voids, rapid price changes) and flags them for Merchant review.
- Regular Security Reviews: We conduct periodic code security reviews, dependency audits, and server hardening assessments.
11 Cookies
The SwiftPOS marketing website (swiftpos.ng) uses the following types of cookies:
- Strictly Necessary Cookies: Session management and CSRF protection for the marketing website. These cannot be disabled without affecting site functionality.
- Analytics Cookies: Google Analytics 4 collects anonymized browsing data to help us understand how visitors engage with our website. You may opt out by adjusting your browser settings or using Google’s opt-out tools.
The SwiftPOS application (app.swiftpos.ng) uses browser storage (cookies and IndexedDB) for authentication session management and offline POS caching. These are required for the platform to function correctly.
12 Children’s Privacy
The SwiftPOS platform is a business software product intended for use by registered business operators. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has registered an account, please contact us immediately at compliance@swiftpos.ng so we can investigate and take appropriate action.
13 International & Cross-Border Data Transfers
Your data is primarily stored and processed on servers located within or accessible from Nigeria. Where data may be transferred to or processed by third-party service providers operating in other jurisdictions (such as Google Analytics servers), we ensure that such transfers are subject to adequate data protection standards, including contractual protections consistent with the NDPR’s requirements for cross-border transfers.
14 Complaints & Regulatory Authority
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the supervisory authority for data protection in Nigeria.
Nigeria Data Protection Commission
Website: ndpc.gov.ng
Email: info@ndpb.gov.ng
We would, however, appreciate the opportunity to address your concerns first. Please contact us at compliance@swiftpos.ng before filing a formal complaint.
15 Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our platform features, legal requirements, or business practices. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page;
- Display an in-app notification to all logged-in Merchant administrators;
- Send an email notification to primary account holders where changes are significant.
Your continued use of SwiftPOS after the effective date of any updated Policy constitutes acceptance of the revised terms.
16 Contact Us
For all privacy and data protection enquiries, please contact our compliance team:
- Data Controller: Nura Mustapha Technologies Limited (RC 9679645)
- Email: compliance@swiftpos.ng
- General Support: contact@swiftpos.ng
- Phone / WhatsApp: +234 916 460 1810
- Office: Kano, Federal Republic of Nigeria