Onyx Marketplace is operated by Sapphire Virtual Network Limited and 4 Core Integrated Services Limited, Nigerian Companies committed to safeguarding personal information in compliance with the Nigeria Data Protection Act (NDPA) 2023.
Effective Date: [To be determined] | Last Updated: [To be determined]
This Privacy Policy explains how we collect, use, store, share, protect, and manage personal information belonging to Buyers, Vendors, prospective customers, and users of the Onyx platform.
By accessing or using Onyx (website, mobile application, Vendor Dashboard, or APIs), you consent to the practices outlined in this Policy.
This Privacy Policy applies to all individuals and entities that access or interact with the Onyx Marketplace platform, including:
This Policy governs all categories of personal and business data collected through Onyx' digital infrastructure, including account registration, payment transactions, vendor verification, product transactions, customer support, and automated data collection technologies.
Onyx collects and processes personal and business information necessary to operate the marketplace, verify user identities, fulfill transactions, and comply with legal obligations:
Full legal name, mobile phone number, email address, date of birth, residential or delivery address, and gender (optional).
Registered business name, CAC registration or RC number, Tax Identification Number (TIN), business addresses, corporate contact details, identity documents of directors, and product certifications (NAFDAC, SONCAP, etc.).
Tokenized payment card details, bank account details for Vendor payouts, wallet activity, transaction records including payments, refunds, disputes, and BNPL repayment records.
Bank Verification Number (BVN) when necessary, credit profile, income estimates, employment details, KYC documentation, and risk assessments.
IP address, geolocation, device identifiers, browser type and version, operating system, mobile app activity, crash logs, cookies, and tracking pixels.
Search queries, purchase history, user preferences, engagement logs, time spent on pages, and clickstream data.
Call recordings, chat transcripts, emails, complaint submissions, resolution logs, and public feedback or ratings.
Onyx processes personal data for lawful, specific, and legitimate purposes:
Account creation and management, order processing, delivery and logistics operations, vendor settlements, and platform display functionality.
KYC/KYB verification, product and vendor compliance checks, and regulatory obligations under Nigerian law.
Credit eligibility assessment, lender interaction facilitation, repayment management, and fraud and identity protection.
Homepage and interface personalization, product recommendations, platform analytics, and performance and security optimization.
Promotional messages, surveys and feedback requests, and targeted advertising. Users may opt out at any time via account settings.
Fraud detection and monitoring, user protection, vendor monitoring and enforcement, and policy and legal enforcement.
Onyx processes personal data in accordance with the Nigeria Data Protection Act (NDPA), the Nigeria Data Protection Regulation (NDPR), and applicable laws:
For marketing communications, cookies and similar technologies, and optional data fields. Users may withdraw consent at any time.
Processing necessary to fulfill contractual obligations including account management, order processing, payments, delivery, vendor settlements, and BNPL financing.
Compliance with NDPA, FCCPA, AML/CFT, Cybercrime laws, tax reporting, vendor verification, lawful government requests, and anti-fraud obligations.
Platform safety and integrity, improving functionality, conducting analytics, preventing financial loss, and protecting users from security risks.
Processing required for public safety, fraud investigations, or responding to lawful government directives.
Onyx does not sell or trade personal data. Data may only be shared with trusted third parties where necessary, with all parties bound by strict confidentiality obligations and NDPA-compliant processing terms:
Limited personal and financial information shared for credit evaluation, repayment management, fraud detection, and regulatory compliance.
Customer name, delivery address, phone number, and order details necessary for delivery operations only.
Limited Buyer information to fulfill orders, process deliveries, provide post-purchase support, and handle warranties. Vendors are prohibited from contacting customers outside Onyx-approved channels.
Secure, NDPA-compliant payment processors manage card transactions, direct debit mandates, wallet operations, and settlements. Full card details are tokenized and never stored on Onyx servers.
Disclosures made where required by law, including NDPA, FCCPC, SON, NAFDAC, AML/CFT legislation, and valid court orders.
Cloud hosting, server and database providers, cybersecurity systems, analytics tools, and customer support technologies. These providers may only process data on Onyx' behalf.
Onyx uses cookies, pixels, tags, and similar tracking technologies to enhance user experience and optimize platform performance:
Users can accept all cookies, reject non-essential cookies, or manage categories via the Cookie Preference Center. Note that disabling certain cookies may affect platform functionality.
Personal data is stored only as long as necessary to meet legitimate business, legal, and regulatory purposes in compliance with NDPR, Money Laundering (Prohibition) Act, FCCPA, and applicable laws:
| Data Category | Retention Period | Notes |
|---|---|---|
| Financial & transactional records | Minimum 5 years | Tax, AML, regulatory requirements |
| Vendor & Buyer account information | Active period + 2 years | Extended if required by law or disputes |
| Customer support & complaints | Resolution + 2 years | Defense against claims or disputes |
| BNPL/Installment financing data | Agreement + regulatory period | Credit risk and repayment history |
| Cookies & analytics data | Up to 12 months | Platform optimization and personalization |
Upon reaching the end of retention periods, data is securely deleted, anonymized, or archived with restricted access.
Onyx adopts a multi-layered security framework aligned with global best practices, NDPR requirements, and industry standards:
TLS 1.2/1.3 protocols for in-transit encryption, strong encryption algorithms for data at rest, payment tokenization, and data masking and pseudonymization.
Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), Principle of Least Privilege, and regular access reviews.
Continuous monitoring, audit logging, threat intelligence, and AI-driven threat detection systems.
Formalized Incident Response Plan, breach notification to affected parties and NITDA, post-incident analysis, and user support.
Onyx may transfer personal data outside Nigeria for cloud hosting, analytics, payment processing, and BNPL financing. All transfers are governed by NDPR 2023 and include:
Under the Nigeria Data Protection Act (NDPA 2023), all users are entitled to:
Onyx is committed to protecting the privacy and safety of minors:
In the event of a data breach, Onyx will:
Onyx may provide links to external websites or third-party services. Key points:
Onyx reserves the right to revise, amend, or update this Privacy Policy at any time:
For questions, concerns, or requests related to this Privacy Policy or data protection matters, contact us through:
Onyx is committed to acknowledging all privacy-related inquiries promptly. Data rights requests will be processed in accordance with NDPA timelines and regulatory requirements.
Platform Operated By: Sapphire Virtual Network Limited and 4 Core Integrated Services Limited
By using the Onyx platform, you acknowledge that you have read, understood, and consented to the practices outlined in this Privacy Policy. Your continued use constitutes ongoing acceptance of these privacy practices.