Privacy Policy
Effective: August 2026 ยท Compliant with NDPA 2023 & NDPR
zero2v is operated by an INDEPENDENT, PRIVATE entity. We are NOT a government portal, nor are we associated with or endorsed by the National Identity Management Commission (NIMC) or the Central Bank of Nigeria (CBN).
Official identity records and National Identity Numbers (NINs) are managed strictly by NIMC. To interact directly with government infrastructure, visit nimc.gov.ng.
1Our Role & Lawful Basis
Under the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR), zero2v operates as a data processor facilitating self-service retrieval and verification on behalf of authenticated users who either possess lawful title to their own records or hold explicit, documented consent from the data subject.
2Information We Process
We process the following categories of information strictly to fulfill your requested lookups and transactions:
- Account Credentials: Full name, email address, password hashes (bcrypt/argon2), and phone number;
- Billing & Wallet Data: Transaction references, deposit amounts, and balance histories via Paystack;
- Verification Query Inputs: NIN numbers, tracking IDs, phone numbers, or demographic query parameters submitted by you;
- Audit & Compliance Logs: IP address, timestamp, device user agent, and consent confirmation status for every API call.
3Strict Consent Verification
Before any verification request is executed through our server proxies, the requesting user must positively confirm that they have obtained the data subject's explicit consent.
๐ Every consent acknowledgment is timestamped and cryptographically bound to the audit trail.
๐ซ Performing unauthorized searches on third parties without lawful consent is illegal and will result in immediate account termination and reporting to regulatory authorities.
4Data Security & Transmission
All communications between your device, our servers, and upstream verification APIs are encrypted using industry-standard Transport Layer Security (TLS 1.3 / HTTPS).
- Server-side API keys and credentials are fully isolated in secure server environments and never exposed to the client browser.
- Row Level Security (RLS) is strictly enforced on all database layers to ensure users can only ever access their own audit history and records.
- We will NEVER contact you requesting your account password, PIN, or one-time passcode (OTP).
5Data Subject Rights
Under the Nigeria Data Protection Act 2023, you have the right to request access to your transaction records, rectification of your profile details, and permanent deletion of your account data, subject to legal audit retention requirements.