1. Who we are
Trovah App ("Trovah", "we", "us", or "our") operates hyper-local marketplace services engineered by Jaflah Software Development Company (https://jaflah.dev).
For privacy questions or NDPR data subject requests, contact support@trovah.app with the subject line "Privacy Request".
2. Scope
This Policy applies to buyers, merchants (vendors), delivery partners, logistics partners, website visitors, and applicants who interact with Trovah websites, apps, APIs, and support channels.
It covers account data, order data, device data, marketing communications, and wallet-related transaction metadata processed to operate the platform.
3. Personal data we collect
Depending on how you use Trovah, we may process the following categories of personal data:
- Identity and contact data: name, phone number, email address, business name, and delivery or store address.
- Account and profile data: login credentials (hashed), preferences, city or LGA, store category, and support history.
- Order and commerce data: cart contents, order status, delivery instructions, ratings, and dispute records.
- Wallet and payment metadata: funding references, transfer references, withdrawal requests, ledger entries, and Paystack transaction identifiers. We do not store full card PAN data on Trovah servers when payments are handled by licensed processors.
- Device and usage data: IP address, device identifiers, app version, approximate location needed for delivery matching, cookies or similar technologies, and diagnostic logs.
- Application data: vendor, rider, and logistics application forms submitted through our marketing or onboarding portals.
4. Lawful bases (NDPR)
Under the NDPR, we process personal data only where a lawful basis applies. Common bases for Trovah processing include:
- Contract: to create accounts, fulfill orders, settle merchant payouts, and provide customer support.
- Consent: for optional marketing messages, certain device permissions, and non-essential cookies where required.
- Legitimate interest: to secure the platform, prevent fraud, improve reliability, and understand marketplace performance - balanced against your rights.
- Legal obligation: to meet regulatory, tax, accounting, AML/CFT-related, or lawful disclosure requirements applicable in Nigeria.
5. How we use personal data
- Operate marketplace discovery, ordering, dispatch, and fulfillment.
- Authenticate users, protect accounts, and detect abusive or fraudulent activity.
- Process wallet funding, peer transfers where enabled, order settlement, refunds, and withdrawals via payment partners.
- Communicate transactional notices (order updates, receipts, security alerts) and, where permitted, product updates.
- Support merchants with catalog, commission, and payout operations.
- Improve product quality, reliability, and city-level availability through aggregated analytics.
- Comply with applicable laws and respond to lawful requests from competent authorities.
6. Wallet transactions and financial data
Trovah wallet features may allow funding, holding a balance for marketplace activity, settling orders, and withdrawing to bank accounts through Paystack or other licensed payment service providers.
We process wallet ledger entries, status codes, and reference IDs necessary to keep balances accurate and auditable. Payment card collection and authorization are performed by our payment processor under their own security controls and policies.
You are responsible for safeguarding your login credentials and device. Report suspected unauthorized wallet activity immediately to support.
8. Cross-border transfers
Some processors may store or process data outside Nigeria. Where transfers occur, we take steps consistent with NDPR expectations - including contractual safeguards and diligence on security - so personal data remains protected to an appropriate standard.
9. Retention
We retain personal data only for as long as needed for the purposes described in this Policy, including providing the service, resolving disputes, enforcing agreements, and meeting legal, tax, and audit requirements.
Wallet ledgers and order records may be retained longer where required for financial integrity, chargeback defense, or statutory retention periods. When retention ends, we delete or irreversibly anonymize data where feasible.
10. Security measures
We apply administrative, technical, and organizational measures appropriate to the risk, including access controls, encrypted transport (TLS), hashed credentials, webhook verification for payment events, and monitoring for suspicious activity.
No method of transmission or storage is perfectly secure. You should use strong unique passwords and enable available device security features.
11. Your NDPR rights
Subject to NDPR conditions and applicable exceptions, you may request to access, correct, delete, or receive personal data we hold about you; withdraw consent where processing is consent-based; and object to or restrict certain processing.
To exercise these rights, email support@trovah.app with enough detail for us to verify your identity and locate your records. We will respond within a reasonable period consistent with NDPR expectations.
- Access personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Delete personal data in certain circumstances.
- Withdraw consent where processing is consent-based.
- Object to or restrict certain processing.
- Receive information about processing in a portable format where applicable.
12. Children
Trovah marketplace services are intended for users who can form a binding contract under applicable Nigerian law. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact us and we will take appropriate steps.
14. Changes to this Policy
We may update this Policy to reflect product, legal, or operational changes. We will post the revised version with an updated effective date and, where changes are material, provide additional notice through the apps or email where appropriate.
15. Contact
Privacy and NDPR requests: support@trovah.app
Engineering and corporate owner: Jaflah Software Development Company - https://jaflah.dev
You may also use our Contact page for general support routing.