Privacy Policy
Last updated: May 2025
1. Who We Are
Fifitox is a Nigerian gifting platform operated from Lagos, Nigeria. This Privacy Policy explains how we collect, use, and protect your personal information when you use our platform.
2. Information We Collect
- Phone number — required to create an account and for delivery coordination
- Name and email — optional, collected if you provide them
- Delivery addresses — collected when you place an order
- Recipient information — name and phone number of gift recipients
- Payment data — we do not store card details; payment is handled by Paystack
- AI conversation data — your chats with Fifi are processed to generate gift recommendations
- Usage data — pages visited, device type, IP address, for analytics and security
3. How We Use Your Information
- To fulfil your orders and coordinate delivery
- To send order status updates via SMS and WhatsApp
- To power Fifi’s AI gift recommendations
- To prevent fraud and abuse
- To improve the platform and our products
- To communicate platform updates (you can opt out)
4. Third Parties We Share Data With
- Paystack — payment processing
- Termii — SMS OTP delivery
- Meta (WhatsApp) — order update messages
- Anthropic — AI model powering Fifi (conversation data is processed per Anthropic’s privacy policy)
- Supabase — database and file storage infrastructure
- Delivery couriers — name, phone, and address of recipient for delivery
We do not sell your personal data to third parties.
5. Data Retention
We retain your account data for as long as your account is active. Order records are retained for 7 years for tax and legal compliance. You may request deletion of your account and associated data at any time (subject to legal retention requirements).
6. Security
We use industry-standard measures to protect your data, including TLS encryption in transit, hashed tokens, and access controls. However, no system is completely secure. We will notify you promptly if we become aware of a breach affecting your data.
7. Your Rights
Under Nigerian data protection law (NDPR), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to processing of your data for marketing purposes
To exercise any of these rights, contact us at privacy@fifitox.com.
8. Cookies
We use minimal cookies for authentication (JWT tokens stored in localStorage). We do not use tracking cookies or third-party advertising cookies.
9. Children
Fifitox is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with data, please contact us immediately.
10. Changes
We may update this policy periodically. We will notify you of material changes via SMS. Continued use of the platform after changes constitutes acceptance.
11. Contact
Data controller: Fifitox, Lagos, Nigeria.
Email: privacy@fifitox.com