Legal

Privacy Policy.

What personal data we collect, why we hold it, how long we keep it, and what you can ask us to do with it.

Effective 28 March 2026Last updated 10 June 2026

Effective Date: 28.03.2026 · Last Updated: 10.06.2026

1. About This Privacy Policy

This Privacy Policy explains how Node Union Data Solutions (BVI) Ltd, a company incorporated in the British Virgin Islands under company number BVIBC 6650239 (incorporated 28 March 2026), with its registered office at OMC Chambers, Wickhams Cay 1, Road Town, Tortola, British Virgin Islands (“Company”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal data.

We operate nodeunion.io (the “Platform”) and act as the data controller for the personal data described in this Privacy Policy.

This Privacy Policy applies to visitors, registered users, customers, reward programme participants and other individuals who interact with the Platform, including individuals located in Nigeria.

Our privacy contact details are:

Privacy/Data Protection Contact: Legal department

Email: legal@nodeunion.io

Address: OMC Chambers, Wickhams Cay 1, Road Town, Tortola, British Virgin Islands

If we appoint a Data Protection Officer, the officer may be contacted at legal@nodeunion.io.

2. Applicable Law

We process personal data in accordance with the British Virgin Islands Data Protection Act 2021.

Where our processing relates to individuals in Nigeria or where the Platform offers or targets services to individuals in Nigeria, we also process personal data in accordance with the Nigeria Data Protection Act 2023, the Nigeria Data Protection Act General Application and Implementation Directive, and other applicable Nigerian data protection, consumer protection, financial, tax and regulatory requirements.

We follow the principles of fairness, lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability and duty of care.

3. Personal Data We Collect

Depending on how you use the Platform, we may collect the following categories of personal data.

3.1 Identity and contact information

This may include:

  • Full name
  • Email address
  • Telephone number
  • Residential, billing or delivery address
  • Username or account identifier
  • Date of birth or age confirmation, where required.

3.2 Account and profile information

This may include:

  • Login and account information
  • Account preferences
  • Communication preferences
  • Reward programme membership information
  • Information submitted through your profile.

Passwords are stored in protected form and are not visible to our personnel.

3.3 Purchase and transaction information

This may include:

  • Products or services ordered
  • Order amount, currency, date and status
  • Delivery, refund and cancellation information
  • Billing information
  • Payment method
  • Transaction and payment reference numbers
  • Limited payment information supplied by the payment provider selected by you during checkout, such as the card type and last four digits of a payment card.

Purchase payments are processed directly by the payment provider selected by you during the checkout process. We do not intentionally store complete payment card numbers, card security codes or CVV/CVC values on our systems.

3.4 Reward and payout information

To calculate, administer and pay rewards, commissions, cashback, referral payments or other amounts owed to you, we may collect:

  • Reward balance and transaction history
  • Eligibility and calculation information
  • Account holder or beneficiary name
  • Bank name
  • Bank account number
  • Bank or branch code
  • Mobile money or digital wallet details
  • Payout amount, date, reference and status
  • Tax or regulatory information, where required by law.

Reward payouts are processed through the bank or payment provider selected by you when requesting the payout.

You must only provide payout details belonging to you or details that you are legally authorised to provide.

3.5 Identity verification and compliance information

Where verification is required by law, by your selected payment or payout provider, or to prevent fraud, we or an authorised verification provider may request:

  • Date of birth
  • Residential address
  • National Identification Number, Bank Verification Number or other government-issued identifier
  • Copy or details of an identification document
  • Photograph or selfie used for identity verification
  • Information required for anti-fraud, know-your-customer, tax or anti-money-laundering checks.

We will only request this information where it is necessary and lawful.

3.6 Technical and usage information

When you use the Platform, we may automatically collect:

  • Internet Protocol address
  • Device type and operating system
  • Browser type
  • Language and time-zone settings
  • Device or advertising identifiers, where permitted
  • Login, access and security logs
  • Pages viewed and actions performed
  • Referring website or campaign
  • Cookie and similar technology information.

3.7 Communications and support information

We collect information contained in enquiries, complaints, reviews, survey responses and communications with our customer support or privacy teams.

4. How We Collect Personal Data

We may collect personal data:

  • Directly from you when you register, place an order, request a payout, complete a form or contact us
  • Automatically through the Platform, cookies, logs and similar technologies
  • From the payment provider, bank or payout provider selected by you
  • From merchants, delivery providers or commercial partners involved in fulfilling a transaction
  • From identity verification and fraud-prevention providers
  • From referral or reward programme partners
  • From public or official sources, where lawful.

If we receive your personal data from another source, we will provide the information required by applicable law unless you already have that information or an applicable legal exception applies.

5. Why We Process Personal Data

We process personal data only where we have an appropriate lawful basis.

PurposeCategories of dataLawful basis
Creating and administering an accountIdentity, contact and account dataPerformance of a contract or steps requested before entering a contract
Processing purchases, payments, refunds and deliveriesContact, order, transaction and limited payment dataPerformance of a contract
Verifying identity and payout detailsIdentity, verification and payout dataContract, legal obligation and, where applicable, legitimate interests
Calculating and paying rewards, commissions or cashbackIdentity, reward, payout and transaction dataPerformance of a contract
Preventing fraud, abuse and unauthorised transactionsIdentity, transaction, device and security dataLegal obligation and legitimate interests in protecting users and the Platform
Operating, maintaining and securing the PlatformTechnical, account, device and security dataLegitimate interests in providing a reliable and secure service
Providing customer support and handling complaintsContact, account, transaction and communication dataContract and legitimate interests
Sending promotional email or SMS messagesName, email address, telephone number and preferencesConsent
Using analytics, advertising or other non-essential cookiesDevice, usage and cookie informationConsent
Keeping accounting, tax and transaction recordsTransaction, payment and payout recordsLegal obligation
Complying with lawful requests from authoritiesInformation covered by the lawful requestLegal obligation
Establishing, exercising or defending legal claimsRelevant account, transaction and communication dataLegitimate interests and legal obligation

Where we rely on legitimate interests, we consider the necessity of the processing, its impact on you and the safeguards available to protect your rights.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out lawfully before consent was withdrawn.

You are not required to provide optional information. However, if you do not provide information necessary for an account, purchase, verification or payout, we may be unable to provide the relevant service.

6. Payments and Reward Payouts

Purchase payments are processed by the payment provider selected by you during the checkout process.

When requesting a reward, commission, cashback, referral payment or other payout, you may select an available bank or payment provider through which you wish to receive the funds.

The selected provider may receive the personal data necessary to:

  • Authorise and settle a purchase payment
  • Send funds to your nominated account
  • Process refunds
  • Verify your identity or account ownership
  • Prevent fraud and unauthorised transactions
  • Meet financial and regulatory obligations
  • Resolve transaction disputes.

The Platform may receive transaction status information, reference numbers and limited payment details from the selected provider in order to confirm the purchase or payout.

The payment provider or bank selected by you may process personal data under its own privacy policy and legal obligations. You should review the provider’s privacy notice before completing a purchase or requesting a payout.

We will never ask you to send a payment card security code, account password, PIN or one-time password through ordinary email, social media or customer support chat.

7. When We Share Personal Data

We may share personal data with:

  • The payment provider selected by you during checkout
  • The bank or payment provider selected by you when requesting a payout
  • Acquiring banks and card networks involved in processing a selected payment method
  • Identity verification, fraud-prevention and security providers
  • Cloud hosting, database, email and technology providers
  • Customer support and communication service providers
  • Analytics and advertising providers, where you have given the required consent
  • Merchants, suppliers and delivery providers involved in fulfilling an order
  • Professional advisers, including lawyers, accountants, auditors and insurers
  • Companies involved in a proposed merger, financing, acquisition or transfer of business, subject to appropriate confidentiality safeguards
  • Courts, regulators, law enforcement agencies and other public authorities where disclosure is required or permitted by law.

Service providers acting on our instructions may only use personal data for the agreed purposes and must apply appropriate security and confidentiality measures.

Payment providers, banks and other financial institutions selected by you may act as independent data controllers for processing carried out under their own legal and regulatory obligations.

We do not sell personal data for money.

8. International Data Transfers

The Company is incorporated in the British Virgin Islands. Personal data collected from individuals in Nigeria may therefore be transferred to, stored in or accessed from the British Virgin Islands.

Personal data may also be processed in other countries where our hosting, technology, support, fraud-prevention or other authorised service providers operate.

The payment provider or bank selected by you may process personal data in the countries identified in that provider’s privacy notice. The identity of the selected provider will be displayed during the purchase or payout process before you confirm the transaction.

Our current core hosting, operational and support locations are:

British Virgin Islands, Germany, Hong Kong, Singapore, UAE

Where personal data is transferred from Nigeria, the British Virgin Islands or another jurisdiction, we will only make the transfer where it is permitted by applicable data protection law.

Depending on the transfer, safeguards may include:

  • Transfer to a country recognised as providing an adequate level of data protection
  • Contractual obligations requiring the recipient to protect personal data
  • Standard contractual clauses or other approved contractual instruments
  • Binding corporate rules, where applicable
  • Consent, where consent is a lawful and appropriate transfer basis and relevant risks have been explained
  • Transfer necessary for the performance of a contract with you, including processing a purchase or payout; or
  • Another transfer mechanism or statutory exception permitted by applicable law.

We will take reasonable steps to ensure that recipients protect personal data to a standard consistent with this Privacy Policy and applicable law.

You may contact us at legal@nodeunion.io to request additional information about the safeguards used for a particular international transfer.

9. Data Retention

We retain personal data only for as long as necessary for the stated purpose and applicable legal obligations.

Our standard retention periods are:

Data categoryStandard retention period
Account and core contact informationWhile the account is active and for 24 months after closure
Purchase, refund, payment, reward and payout recordsSix years from the relevant transaction or the end of the applicable financial year
Identity or KYC verification records, if collectedWhile the relationship is active and for five years after it ends, unless a different period is legally required
Customer support and complaint recordsThree years after the matter is closed
Security and technical logsUp to 12 months, unless required for an investigation
Marketing consent and preferencesUntil consent is withdrawn; an opt-out record may be retained for three years to respect the request
Non-essential cookie identifiersFor the period stated in Cookie Settings and normally no longer than 12 months without renewed consent

We may retain relevant information for longer where necessary to comply with a legal obligation, investigate fraud, resolve a dispute, enforce an agreement or establish, exercise or defend a legal claim.

When personal data is no longer required, we will delete it, anonymise it or securely restrict access to it.

10. Data Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, destruction, unauthorised disclosure or access.

Depending on the nature of the processing, these measures may include:

  • Encryption during transmission
  • Restricted and role-based access
  • Secure password storage
  • Multi-factor authentication for administrative access
  • System monitoring and security logging
  • Staff and contractor confidentiality obligations
  • Vendor security assessments
  • Backups and recovery procedures
  • Incident response procedures.

No internet-based service can guarantee absolute security. You are responsible for keeping your password, PIN and one-time verification codes confidential.

Where a personal data breach creates a risk to individuals in Nigeria, we will notify the Nigeria Data Protection Commission within the period required by Nigerian law.

Where notification to the BVI Information Commissioner or another competent authority is required, we will make the applicable notification in accordance with the relevant law.

Where a breach is likely to create a high risk to you, we will notify you without undue delay and provide appropriate protective guidance.

11. Cookies and Similar Technologies

The Platform may use cookies, pixels, local storage and similar technologies.

Necessary cookies

Necessary cookies support essential functions such as security, authentication, network management, accessibility, shopping baskets and transaction processing. These cookies do not require optional consent where their use complies with applicable law.

Optional cookies

With your consent, we may use:

  • Analytics cookies to understand how the Platform is used
  • Preference cookies to remember optional settings
  • Advertising cookies to measure or personalise advertising
  • Social media or third-party integration cookies.

The cookie banner will provide clear options to accept or reject optional cookies. Rejecting optional cookies will not prevent access to the Platform’s essential functions.

You may change or withdraw your cookie consent at any time through Cookie Settings. Additional information about individual cookies, providers and durations should be displayed in the Platform’s cookie management tool.

  • Browser-level cookie blocking may affect some Platform functions.

12. Direct Marketing

We will send promotional email or SMS messages only where we have the required consent or another lawful basis expressly permitted by law.

You may stop direct marketing at any time by:

  • Selecting the unsubscribe link in an email
  • Following the opt-out instructions in an SMS
  • Changing your account communication settings; or
  • Contacting us at legal@nodeunion.io.

Service messages concerning purchases, security, payouts or important account information are not promotional messages and may still be sent where necessary.

13. Your Data Protection Rights

Subject to applicable law, you may have the right to:

  • Be informed about the processing of your personal data
  • Obtain confirmation that we process your personal data
  • Request access to and a copy of your personal data
  • Correct inaccurate, incomplete, outdated or misleading information
  • Request deletion of personal data that is no longer necessary or has no lawful basis
  • Request restriction of processing
  • Object to processing, including processing based on legitimate interests
  • Withdraw consent at any time
  • Request data portability in a commonly used electronic format
  • Object to and challenge qualifying automated decisions
  • Request human intervention in relation to qualifying automated decisions
  • Prevent or stop the use of personal data for direct marketing
  • Lodge a complaint with a competent data protection authority.

Some rights may be limited where processing is required by law, necessary to protect another person’s rights, or required for the establishment, exercise or defence of legal claims.

14. How to Exercise Your Rights

To exercise a data protection right, contact us at legal@nodeunion.io and describe your request.

We may request information reasonably necessary to confirm your identity and protect your account. We will not request more identification data than is proportionate to the request.

We will respond without unreasonable delay and normally within 30 days after receiving a complete request. If additional time is legally permitted and necessary, we will explain the reason for the delay.

Requests are normally handled without charge. We may request a reasonable fee only where this is permitted by law, including where fulfilling a request would impose unreasonable costs.

If you are dissatisfied with our response, you may ask us to reconsider the matter or lodge a complaint with the competent data protection authority.

15. Automated Decision-Making

We may use automated tools to identify suspicious logins, fraudulent payments, duplicate reward claims or unusual payout activity.

These tools may flag or temporarily pause an activity for review. We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects without providing the disclosures, safeguards and rights required by law.

Where such processing applies, you may request human review, provide additional information and challenge the decision by contacting legal@nodeunion.io.

16. Children’s Privacy

The Platform is intended for persons aged 18 or older. We do not knowingly allow children under 18 to create accounts, make purchases or participate in reward payouts.

If we learn that we have collected a child’s personal data without the consent or other lawful authority required by applicable law, we will take appropriate steps to delete or restrict that information.

A parent or legal guardian who believes that a child has provided personal data to us should contact legal@nodeunion.io.

If the Platform is changed to provide services to children, this Privacy Policy and the applicable age- and consent-verification procedures must be updated before children’s personal data is collected.

17. Third-Party Websites and Services

The Platform may contain links to or integrations with websites, payment providers, banks or other services operated by third parties.

We do not control the independent privacy practices of these third parties. You should review the privacy policy of the payment provider, bank or other service selected by you before providing personal data or completing a transaction.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to the Platform, our processing activities or applicable law.

The updated version will be published on the Platform with a new “Last Updated” date. Where a change materially affects your rights or how we use personal data, we will provide additional notice through the Platform, email or another appropriate method.

Where consent is required for a new purpose, we will request it before beginning that processing.

19. Contact and Complaints

Questions, requests and complaints should first be sent to:

Node Union Data Solutions (BVI) Ltd

Privacy/Data Protection Contact: Legal department

Email: legal@nodeunion.io

Address: OMC Chambers, Wickhams Cay 1, Road Town, Tortola, British Virgin Islands

We will review your complaint and take reasonable steps to resolve it promptly.

Complaints relating to individuals in Nigeria

If your complaint relates to the processing of personal data in Nigeria or your rights under Nigerian data protection law, you may lodge a complaint with:

Nigeria Data Protection Commission (NDPC)

No. 12 Dr Clement Isong Street, Abuja, Nigeria

Email: info@ndpc.gov.ng

Telephone: +234 (0) 916 061 5551

Website: https://ndpc.gov.ng

Complaints under British Virgin Islands law

You may also lodge a complaint with:

Office of the Information Commissioner

Government of the Virgin Islands

Road Town, Tortola, British Virgin Islands

Government website: https://gov.vg

The current official contact details for the Office of the Information Commissioner should be obtained from the Government of the Virgin Islands website before submitting a complaint.