Owelet does not sell personal data, run third-party advertising, or use customer debt records for marketing. We use data to provide accounts, sync records, verify purchases, send requested reminders, secure the service and diagnose faults. You can export your records and delete your account from the app.
1. Scope and privacy roles
This Privacy Policy applies to the Owelet mobile application, the website at www.owelet.ng, and related support and launch communications (together, the “Service”). In this policy, “Owelet”, “we”, “us” and “our” refer to the Owelet business responsible for the Service.
Owelet is the data controller for account, support, subscription and diagnostic information used to operate the Service. When a business user enters personal information about a customer or debtor, that business user decides why the information is recorded and is responsible for using it lawfully. Owelet processes that customer information to provide the app and cloud-sync service to the user.
We aim to handle personal data in accordance with the Nigeria Data Protection Act 2023 (“NDPA”), the NDP Act General Application and Implementation Directive 2025 (“GAID”), and other applicable laws.
2. Data we handle
The data we handle depends on how you use Owelet. You are not required to provide optional business branding or contact-book access.
| Category | Examples | How we receive it |
|---|---|---|
| Account and identity | Name, email address, sign-in provider, account identifier, verification and session status | From you, Supabase, Google or Apple when you create or access an account |
| Business profile | Business name, phone number, address and receipt branding you choose to add | From you |
| Sales and customer records | Customer name and phone number, items, sale value, debt amount, due date, payments, currency, notes and receipt details | From records you create or import |
| Products and reports | Saved products, quantities, prices and summaries calculated from your records | From you and calculations performed in the app |
| Subscription information | Plan, billing source, payment reference or transaction identifier, price, currency, status and expiry | From Apple, Paystack and our verification services |
| Technical diagnostics | App version, device/OS context, error type, sanitised stack trace, performance traces and sync operation name | Automatically when a fault or sampled performance event occurs |
| Support and launch requests | Your email address and the content of messages you send us | From your email to us |
Data we do not intentionally collect
Owelet does not intentionally collect precise location, advertising identifiers, your full address book, card number, CVV, online banking credentials, or the passwords you use with Google or Apple. The app does not include Firebase Analytics or an advertising SDK.
Website data
The current website uses local page assets and does not set advertising or analytics cookies. Standard web-server logs may record an IP address, browser information, requested page, time and security events. If we later introduce analytics or non-essential cookies, we will update this policy and provide any consent controls required by law.
3. Why we use data and our legal bases
- Provide the Service and perform our contract: create and secure accounts; store, sync and restore records; generate receipts and reports; provide exports; verify subscriptions; and respond to support requests.
- Your consent: access a contact you select, schedule notifications you enable, send a requested launch alert, or process another optional action that clearly asks for permission. You may withdraw consent at any time.
- Legitimate interests: prevent fraud and account abuse, maintain reliable sync, protect the Service, and diagnose faults, after considering the impact on users.
- Legal obligation: comply with valid legal requests, tax or accounting obligations, consumer-protection duties and data-protection requirements.
No advertising use: we do not use your sales, customer or debt records to profile people for advertising, sell data to brokers, or decide whether a person should receive credit.
4. Information about your customers
Owelet is designed for a business user to record information about customers and transactions. Before entering, importing or contacting a customer, you must have a lawful reason to use their information and give any notice required by applicable law.
You should record only information relevant to a genuine business transaction, keep it accurate, restrict access to your device and account, and remove it when no longer needed. You must not use Owelet to create false debt records, harass people, make unlawful lending decisions, or send unsolicited communications.
5. Contact access and reminders
Optional contact selection
If you choose “Import from Contacts”, the app asks your device for permission and lets you select a contact. Owelet uses the selected name and phone number to fill the customer fields. It does not upload or retain your full address book. You may type the details manually instead and revoke permission in your device settings.
Notifications
With your permission, Owelet schedules local notifications on your device for reminders you choose. You can disable reminders in Owelet or revoke notification permission in device settings.
Sharing
When you choose to share a receipt or message, your device opens the selected third-party app. The content you decide to share is then handled under that service’s privacy terms. Owelet does not silently send messages to customers.
6. Subscription and payment data
On iPhone and iPad, Apple processes in-app purchases. On Android, Paystack processes subscription checkout. These providers may collect payment and billing information directly under their own privacy policies. Owelet does not receive or store your full card number, CVV or online-banking credentials.
Owelet receives and stores the limited information needed to verify and manage Pro access, such as a plan or product identifier, transaction/reference identifier, amount, currency, purchase status, billing source and subscription expiry. Our server checks purchase information before granting access.
7. Service providers and disclosures
We disclose data only as needed to operate Owelet, comply with law, protect people or the Service, complete a business transfer, or carry out an action you request.
- Supabase: authentication, database, cloud sync and protected server functions. Privacy information.
- Sentry: privacy-limited crash diagnostics and sampled performance traces. Screenshots, view hierarchies and default personal identifiers are disabled, and Owelet sanitises sync errors before reporting. Privacy information.
- Google/Firebase: configuration needed for Google sign-in and identity verification. Owelet does not use Firebase Analytics. Google Privacy Policy.
- Apple: Sign in with Apple and in-app purchases on Apple devices. Apple Privacy Policy.
- Paystack: Android payment checkout, payment verification and subscription events. Paystack Privacy Policy.
- Email and communications providers: delivery and storage of messages you send to info@owelet.ng.
Legal requests and safety
We may disclose information when reasonably necessary to comply with a valid legal process, protect a person from harm, investigate fraud or security abuse, enforce our Terms, or establish and defend legal claims. Where legally permitted and appropriate, we will notify the affected user.
Business transfer
If Owelet is reorganised, financed, acquired or sold, relevant data may transfer as part of that transaction subject to confidentiality, applicable law and notice of any material change in controller or policy.
8. Storage and security
On your device
Owelet stores working records in the app’s local files so core features can work offline. Those records rely on the protections of your phone and operating system; they are not separately encrypted by Owelet’s local database. The optional Owelet PIN is stored as a salted hash in the device’s Keychain or Keystore, but it does not replace a strong device passcode or device encryption.
In the cloud
For signed-in accounts, records are transmitted over encrypted HTTPS/TLS connections and stored through Supabase. Database row-level access rules and authenticated server functions are designed to isolate one account’s records from another. No security control can eliminate every risk, and we therefore avoid absolute guarantees.
Your responsibilities
Use a strong, unique password where enabled, protect your Google or Apple account, keep your device locked and updated, do not share sign-in credentials, and export important records periodically. Contact us promptly if you believe your account or data has been compromised.
Security incidents
We assess suspected personal-data breaches and will notify the Nigeria Data Protection Commission and affected individuals where the NDPA or another applicable law requires it.
9. International data transfers
Some service providers operate or support systems outside Nigeria. As a result, account, cloud, diagnostic or transaction information may be processed in another country. We use contractual, organisational and technical safeguards appropriate to the provider and transfer, and assess international transfers under the NDPA and GAID 2025.
Privacy laws in another country may differ from Nigerian law. You may contact us for more information about the categories of international recipients and safeguards relevant to your account.
10. How long we keep data
We keep identifiable data only for as long as reasonably necessary for the purpose described in this policy, including providing the Service, resolving disputes, preventing fraud, and meeting legal obligations.
- Account, cloud records and products: while the account is active, then removed through the account-deletion process, subject to limited legal or security exceptions.
- Local app records: until you delete them, clear the app, uninstall it, change to another account where the app clears prior-account data, or use account deletion.
- Purchase and subscription information: for the life of the entitlement and afterwards only as needed for reconciliation, fraud prevention, disputes and legal record-keeping. Apple and Paystack apply their own retention periods.
- Diagnostics and server logs: for a limited period set by our operational and security needs and provider configuration, then deleted or aggregated.
- Support and launch emails: until the request is completed and for a reasonable follow-up period, or until you ask us to delete the message, unless it must be retained for a legal claim or obligation.
- Backups: deleted data may remain temporarily in encrypted provider backups until those backups rotate, and is not restored to active use except for disaster recovery.
11. Your privacy rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- be informed about how your personal data is used;
- access personal data held about you;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- receive data you provided in a portable format where applicable;
- withdraw consent without affecting earlier lawful processing;
- not be subject to certain solely automated decisions with legal or similarly significant effects; and
- complain to the Nigeria Data Protection Commission.
Owelet does not use customer records for automated credit scoring or decisions about a person’s eligibility for lending. To exercise a right, email info@owelet.ng. We may verify your identity and will respond within the period required by applicable law. If a request concerns customer data entered by an Owelet business user, we may direct the request to that business user or assist them in responding.
12. Export and account deletion
Export
You can export debt records as CSV and create a JSON backup from Settings. Exported files are stored wherever you choose to save or share them and are not deleted when you later delete your Owelet account.
Delete your account in the app
Open Settings → Account → Delete Account, review the warning, type the requested confirmation and submit. A successful request permanently removes the Owelet authentication account and associated synced debts, payments, products, profile, referrals and Owelet subscription records, and clears Owelet’s local user data on that device.
Billing is separate: deleting Owelet does not itself cancel a recurring subscription controlled by Apple or Paystack. Cancel the subscription with the billing provider before deleting the account to avoid future charges. Apple purchases can be managed in Apple ID Subscriptions; contact info@owelet.ng for help with Paystack-billed subscriptions.
If in-app deletion fails, or if you cannot access the account, contact info@owelet.ng. We may ask for information needed to verify account ownership.
13. Children’s privacy
Owelet is a business record-keeping service intended for adults and is not directed to anyone under 18. We do not knowingly create accounts for or collect personal data directly from children. If you believe a child has created an account or provided data, contact us so we can investigate and take appropriate action.
14. Changes to this policy
We may update this policy when the Service, our providers or applicable law changes. We will publish the revised version and update the date above. For a material change, we will provide reasonable advance notice through the app, website or account email when practicable and required. If consent is required for a new use, we will request it rather than relying only on continued use.
15. Contact and complaints
For privacy questions, rights requests, deletion help or suspected data misuse, contact:
- Controller: Owelet
- Website: www.owelet.ng
- Email: info@owelet.ng
You also have the right to lodge a complaint with the Nigeria Data Protection Commission. We would appreciate the opportunity to address your concern first, but contacting us is not a condition of complaining to the Commission.
Need help with your data?
Tell us the account email and the type of request. Do not send your password, PIN or payment credentials.
