Home/Privacy Policy

Privacy Policy

This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights available to you when you interact with Taja.Shop.

Last updated: 8 November 2025

1
Who We Are and How to Reach Us

Taja Shop Technologies Limited (“Taja.Shop”, “we”, “us” or “our”) is the data controller responsible for personal data processed through the Taja.Shop marketplace. We comply with the Nigerian Data Protection Regulation 2019 (NDPR), the Nigeria Data Protection Act 2023, and—where applicable—the EU General Data Protection Regulation (GDPR).

Data Protection Officer: privacy@taja.shop
Office: Plot 5 Admiralty Road, Lekki Phase 1, Lagos, Nigeria
Telephone: +234 (0) 700 8252 7467

2
Personal Data We Collect

We collect personal data directly from you, automatically via your device, and from trusted partners (payment processors, identity verification vendors, logistics providers). This includes:

  • Identity & Contact Data: name, phone number, email, shipping/billing address, government-issued ID, BVN/NIN (for sellers), CAC filings (for corporate sellers).
  • Account & Profile Data: username, password hash, avatar, biography, saved preferences, notification settings.
  • Financial & Transaction Data: masked payment card, bank account, wallet balance, orders, refunds, payouts, taxes, dispute history.
  • Usage & Device Data: IP address, browser type, device identifiers, location (approximate), access logs, clickstream, crash reports.
  • Communications: messages exchanged via in-app chat, reviews, customer support tickets, recorded calls (where permitted), survey responses.

3
Legal Bases for Processing

  • Contractual necessity – to create your account, process orders, run escrow, settle payouts, provide support.
  • Legitimate interests – to secure the Platform, prevent fraud, personalise content, gain insights and improve services (balanced with your rights).
  • Consent – for marketing, optional cookies, biometric verification, and sharing with strategic partners when expressly authorised.
  • Legal obligation – to comply with AML/CFT, tax, regulatory and consumer protection requirements, respond to lawful requests and enforce policies.

4
How We Use Personal Data

Service delivery

  • Authenticate logins, manage profiles and maintain your account.
  • Enable product listings, carts, wishlists, order placement and escrow.
  • Facilitate Buyer–Seller messaging, ratings and dispute management.
  • Process payments, refunds, chargebacks and payouts.

Operations & compliance

  • Conduct KYC/KYB checks, sanctions screening and risk assessments.
  • Monitor transactions for fraud, AML/CFT and policy violations.
  • Generate invoices, receipts, tax and audit reports.
  • Respond to regulatory inquiries, court orders and lawful requests.

Product improvement & personalisation

  • Analyse behaviour to improve UX, reliability and security.
  • Train recommendation engines and tailor marketing offers.
  • Conduct surveys, testing and customer research.

5
Who We Share Data With

We do not sell personal data. We share limited information with trusted third parties under robust data processing agreements:

  • Payment gateways (Paystack, Flutterwave) to authenticate payments, manage escrow and mitigate fraud.
  • Logistics partners to arrange pickup, delivery and returns.
  • Identity & compliance vendors for KYC/KYB, sanctions, PEP, credit or fraud checks.
  • Customer support and communications tools (CRM, email, chat, telephony) to respond to enquiries.
  • Professional advisors & regulators (auditors, lawyers, tax authorities, law enforcement) where disclosure is required by law.
  • Corporate transactions (merger, acquisition, investment) subject to confidentiality safeguards.

6
International Transfers

Data is hosted in secure facilities in Nigeria and the European Union. When data is transferred outside Nigeria or the EU, we implement safeguards such as Standard Contractual Clauses, encryption in transit and at rest, strict RBAC, and continuous monitoring to ensure privacy standards equivalent to NDPR/GDPR.

7
Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, subject to legal, tax and regulatory requirements:

  • Account data – while your account is active and up to 7 years after closure.
  • Transaction records – minimum 7 years for statutory accounting and AML obligations.
  • Support logs – up to 3 years after resolution, unless extended for disputes.
  • Marketing consents – until you withdraw consent or opt out.
  • Aggregated analytics – retained indefinitely in anonymised form.

8
Data Security

We implement administrative, technical and physical controls to safeguard personal data, including:

  • TLS 1.2+ for all web and API traffic.
  • AES-256 encryption of sensitive data at rest.
  • Role-based access control, secret rotation and least privilege policies.
  • Continuous vulnerability scanning and third-party penetration testing.
  • 24/7 monitoring, SIEM alerts and incident response playbooks.
  • Employee background checks and mandatory privacy training.
  • Vendor due diligence and data processing agreements.
  • Redundancy, backups and disaster recovery drills.
  • Comprehensive audit logging for sensitive actions.

9
Your Privacy Rights

You may exercise the rights below by emailing privacy@taja.shop. We will respond within 30 days (or within statutory timelines):

Access – request confirmation and obtain copies of your personal data.

Portability – receive data in a structured, commonly used, machine-readable format.

Rectification – correct incomplete or inaccurate data.

Deletion – request erasure where data is no longer needed or consent withdrawn.

Restriction & objection – limit or object to processing based on legitimate interests or direct marketing.

Withdraw consent – revoke consent without affecting prior lawful processing.

You may lodge complaints with the Nigeria Data Protection Commission via https://ndpc.gov.ng or your local supervisory authority.

10
Cookies and Similar Technologies

We use first-party and third-party cookies, SDKs and pixels to remember preferences, keep you signed in, measure performance and deliver personalised advertising.

You can manage cookie preferences through browser settings or our on-site cookie banner. Essential cookies are required for core services (e.g. authentication, cart); disabling them may impair your experience.

11
Marketing Communications

We may send promotional emails, SMS or push notifications about products, offers and updates. You may opt out via the unsubscribe link, notification centre or by contacting us. You will continue to receive essential service messages (order updates, policy changes, security alerts).

12
Children’s Privacy

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has provided data, notify us immediately so we can delete it and close the account.

13
Updates to This Policy

We may revise this Privacy Policy to reflect regulatory changes, new features or operational needs. Material changes will be communicated via email, dashboard alerts or prominent notices at least 14 days before taking effect. The “Last updated” date will always indicate the latest version.

14
Contact & Escalation

If you have privacy questions, access requests or complaints, contact our Data Protection Officer. We will investigate and respond within statutory timelines.

Email: privacy@taja.shop
Postal: Data Protection Officer, Taja Shop Technologies Ltd, Plot 5 Admiralty Road, Lekki Phase 1, Lagos, Nigeria

By continuing, you acknowledge that you have read and understood this Privacy Policy.