Privacy policy
Last updated 28 September 2026
What we hold, why we hold it, and who else ever sees it.
The short version
We hold what you need us to hold to run your shop, and nothing else. We do not sell it, we do not advertise against it, we use no third-party analytics or advertising trackers, and we do not look at your books unless you ask us to help.
Who is responsible for it
OPTISALE is responsible (the “controller”) for the personal data about you and your staff described here. To contact us about it, write to chukwuebuka@optisale.app.
For the records you keep about your own customers, you are responsible, and we process them on your behalf — see “Your customers’ details” below.
We are based in Nigeria. We do not offer OPTISALE to businesses in the European Union or the United Kingdom, and we have not appointed a representative in either. If you are there anyway — travelling, or a customer of a shop that uses us — write to us directly at chukwuebuka@optisale.app: every request is answered by us, the same way and in the same time, wherever it comes from, and you keep your right to complain to your own supervisory authority.
What we collect
About you: your name, email address, phone number, and the business details you enter — including what you give us to verify your business: your CAC certificate and registration number, and the owner's name as it is printed on it. We do not ask for a NIN or any other personal ID number.
About your business: the products, sales, customers, debtors, expenses and reports you record.
About your use of the app: sign-in times, the device and browser you used, and an audit log of changes made inside your company. This is what lets you see who changed what.
Your agreement: when you accepted the Terms and this policy and confirmed your age, which version you accepted, and the network address and browser it came from.
How new shops get on: we count, from records the app keeps anyway, how many new shops go on to add a product, record a sale and pay — and, if a shop first reached us through a link such as a referral, which kind of link. If you answer the one question we ask on your second day about how your first day went, we keep your answer.
We do not store card numbers. Payments go to Paystack or Flutterwave, who handle the card and tell us only whether it worked.
On your device
The app keeps your sign-in, a few preferences such as the theme and language, and any sales waiting to be sent while you are offline, in your browser’s storage or the phone app’s storage.
Our website also remembers for 30 days how you first reached it, so that a sign-up can be credited to the shop that referred it.
All of this is needed to give you the service you asked for, and none of it tracks you across other websites or is used for advertising — so, under the EU ePrivacy Directive and the UK’s PECR, it does not need a cookie banner. We use no advertising or analytics cookies.
Why we hold it, and why we are allowed to
To run the service you signed up for — showing your records, generating your documents, sending the messages you ask us to send and taking your payment. The legal basis is our contract with you (GDPR Article 6(1)(b)).
To keep accounts secure and prevent fraud — sign-in checks, two-factor codes, the audit log and the record of your agreement. The legal basis is our legitimate interest in a service people can trust (Article 6(1)(f)); you can object, and we will stop unless we have a compelling reason to continue.
To keep billing and tax records, because the law requires them (Article 6(1)(c)).
To reach you about your account: confirmation codes, billing notices and replies to your support messages (our contract with you).
Your answer to the second-day question, only because you chose to give it (your consent, Article 6(1)(a)). You can ask us to delete it at any time.
We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not profile you.
The laws we follow
Wherever you are: the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation, where we are based.
In the European Union and the European Economic Area: the General Data Protection Regulation (EU) 2016/679 and the ePrivacy Directive 2002/58/EC. In the United Kingdom: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.
In Africa beyond Nigeria: South Africa’s Protection of Personal Information Act 2013 (POPIA), Kenya’s Data Protection Act 2019, Ghana’s Data Protection Act 2012, and the equivalent law of any other country where you use OPTISALE.
In the United States: the California Consumer Privacy Act as amended by the California Privacy Rights Act, and similar state laws where they apply.
Where these differ, you get the protection of whichever applies to you.
Who else sees it
People you have added to your own company, limited by the permissions you gave them.
The services that make features work — our sub-processors — each seeing only what its job needs: Paystack and Flutterwave (payments), ZeptoMail by Zoho (email), Termii (SMS), Google (signing in with Google, and push notifications to the phone app through Firebase Cloud Messaging), Dojah (CAC registry checks, only when you verify your business that way), Render (hosting the service), and our database and file-storage providers.
Our support staff, when you ask for help. That access is read-only, time-limited, recorded, and you are told when it happens.
Anyone the law requires us to tell, if we are properly compelled.
Data that leaves your country
Some of those providers store or process data outside the country you are in, including outside Africa. When personal data from the European Economic Area, the United Kingdom, Nigeria, South Africa, Kenya or another country that restricts transfers goes somewhere its law does not already treat as adequate, we rely on the safeguards that law recognises — such as the European Commission’s Standard Contractual Clauses and the UK’s International Data Transfer Addendum — and you can ask us for a copy.
Your customers’ details
When you record a customer, you are the one deciding to hold their details and you are responsible for having the right to. We hold them on your behalf and use them only to provide the service — for example, to send the message you asked us to send.
Nobody under 18
OPTISALE is not for anyone under 18, and we do not knowingly collect their data. Everyone confirms their age when they create an account. If you believe someone under 18 has one, tell us and we will close it.
How long we keep it
For as long as your account is open.
Delete your account and your name, email address and phone number are removed at once; sales you made for a shop stay in that shop’s books under the name printed on them, as bookkeeping requires. Close a shop and its records are deleted 30 days later.
We keep payment and invoice records for as long as tax law requires, and the record of when you accepted these terms for as long as a legal claim about them could be brought. Nothing else is kept.
Export your data before you close the account if you want to keep it.
What you can ask for
To see the data we hold about you, and a copy of it in a common, machine-readable form — you can export your shop’s records yourself at any time from inside the app.
To have it corrected if it is wrong, or deleted — you can delete your account yourself: Settings → Account & Security → Delete account.
To restrict how we use it, or object to our using it, and to withdraw a consent you gave, at any time and without affecting what was done before.
Not to be subject to a decision made only by automated means that significantly affects you — we make none.
If you are in California: to know what we collect and why, to delete and correct it, and not to be treated differently for asking. We do not sell your personal information or share it for advertising, and never have.
Write to chukwuebuka@optisale.app and we will answer within a month. If you are not happy with our answer, you can complain to the data protection authority where you live — among others, the Nigeria Data Protection Commission, your country’s supervisory authority in the EU, the UK Information Commissioner’s Office, South Africa’s Information Regulator, Kenya’s Office of the Data Protection Commissioner or Ghana’s Data Protection Commission.
Keeping it safe
Traffic is encrypted in transit. Passwords are hashed, never stored as you typed them. Every query is scoped to your company, and verification documents are held where no public link can reach them.
No system is perfect. If something happens that affects your data, we will tell you without undue delay, and the regulator within the time the law sets — 72 hours under the GDPR and the Nigeria Data Protection Act.
Something here unclear? Ask us — we would rather explain it than have you guess.