Privacy Policy
Last Updated: September 16, 2026
1. Who We Are
This Privacy Policy explains how Subin Pass Ltd ("Subin", "we", "us", "our"), registered at East West Road, Choba, Port Harcourt, Rivers State, Nigeria, collects, uses, shares, and protects personal data when you use the Subin platform (subinpass.com, app.subinpass.com, and related services, the "Platform"), whether as a customer, vendor, or vendor staff member.
We are the data controller for the personal data described in this policy, unless stated otherwise.
2. Data We Collect
2.1 Account and profile data (all users)
Name, email address, phone number, password (stored hashed, never in plain text), profile photo, and, where provided, state/country of residence.
2.2 Customer-specific data
- Subscription and redemption history (which vendor, which plan, when, and how much value/credit was used).
- Household/family sharing data: who you've invited, and what access you've granted them.
- Referral data: your referral code and who signed up using it.
- Reviews you post, including their content and the redemption they're linked to.
- Location data you provide to find nearby vendors (approximate, and only when you use the location/discovery feature).
2.3 Vendor-specific data
- Business details: business name, category, description, address, coordinates, contact details, and any social/website links you provide.
- KYC compliance documents: a business registration certificate, a representative's identification document, and proof of storefront/address, submitted for verification. These are stored in a private, access-restricted storage bucket separate from public storefront media, and are never made public.
- Bank account details for payout (bank name, account number), used to route your settlement.
- Storefront media: photos and videos you upload for your public listing.
- Staff records: names and hashed PIN codes for staff/attendant accounts you create; we do not store staff PINs in plain text.
2.4 Payment data
Card and payment details are collected and processed directly by our payment processor (Paystack); Subin does not receive or store your full card number, CVV, or expiry date. We do receive and store transaction metadata: amount, currency, a payment reference, timestamp, and status.
2.5 Technical data
IP address, device/browser information, and standard web server logs, collected automatically for security, fraud prevention, and diagnosing issues.
3. How We Use Personal Data
- To create and manage your account and provide the Platform's core functionality (subscriptions, redemptions, payouts, staff management, household sharing).
- To process payments and payouts through our payment processor.
- To verify vendor identity and business legitimacy (KYC) before allowing a storefront to go live.
- To send transactional communications: welcome emails, redemption alerts, KYC status updates, payout notices, wallet top-up confirmations, referral notifications, and similar account activity.
- To detect and prevent fraud, abuse, and security incidents, including monitoring for unauthorized access attempts.
- To improve the Platform and understand usage patterns, in aggregate or de-identified form where possible.
- To comply with legal obligations, including tax, anti-money-laundering, and law enforcement requests where legally required.
We do not sell personal data to third parties.
4. Legal Basis for Processing
Where applicable data protection law requires a stated legal basis, we rely on: performance of a contract with you (providing the Platform you signed up for), our legitimate interests (fraud prevention, service improvement, security), your consent (where explicitly requested, for example optional marketing communications), and compliance with legal obligations (KYC, tax, and financial recordkeeping requirements).
5. Who We Share Data With
- Payment processor (Paystack): to process subscription payments, wallet top-ups, and vendor payouts.
- Cloud infrastructure and storage providers (currently Cloudflare R2 for file storage, and our hosting provider): to store uploaded files (KYC documents in a private bucket, storefront media in a public bucket) and run the Platform.
- Email delivery provider: to send transactional emails.
- Vendors, limited to what's needed to fulfill a subscription: your name, and information reasonably needed to verify and process a redemption. Vendors do not receive your payment card details, password, or other account data beyond what's needed for the transaction.
- Law enforcement or regulators, where required by law, court order, or to protect Subin's or others' rights, safety, or property.
- Professional advisors (lawyers, auditors, accountants) under confidentiality obligations, where necessary.
We do not share KYC compliance documents with anyone other than authorized Subin personnel reviewing vendor verification, except as required by law.
6. International Transfers
Where personal data is processed or stored outside your country (for example, on cloud infrastructure located outside Nigeria), we take reasonable steps to ensure it receives an equivalent standard of protection, consistent with applicable data protection law, including using providers with appropriate security certifications and, where required, standard contractual safeguards.
7. Data Retention
- Account data is retained while your account is active, and for a reasonable period after closure to meet legal, accounting, tax, and fraud-prevention obligations.
- Transaction and redemption records are retained as required by applicable financial recordkeeping law.
- KYC documents are retained for as long as required by applicable law and our KYC/compliance obligations, then securely deleted.
- You may request deletion of your account; some data may be retained where law requires it, as described above.
8. Your Rights
Subject to applicable law, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; object to or restrict certain processing; request a portable copy of your data; and withdraw consent where processing is based on consent. To exercise these rights, contact us at hi@subinpass.com. We may need to verify your identity before acting on a request.
9. Security
We use technical and organizational measures appropriate to the sensitivity of the data involved, including encrypted storage credentials, hashed passwords and staff PINs, access-restricted private storage for KYC documents (never publicly reachable, only via short-lived signed links for authorized review), and rate-limiting on public-facing endpoints. No system is completely secure, and we cannot guarantee absolute security, but we take these obligations seriously and continually review and harden the Platform.
10. Children
The Platform is not directed at, and not intended for use by, individuals under 18. We do not knowingly collect personal data from children.
11. Cookies and Similar Technologies
The Platform currently uses only essential browser local storage, to keep you logged in and to remember a referral code you arrived with. It does not currently use analytics or advertising cookies. If that changes, this policy will be updated and, where required, a cookie consent banner will be added before any non-essential cookies are used.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app or by email before they take effect.
13. Contact
Questions about this policy, or to exercise your data rights, can be sent to hi@subinpass.com.