Legal
Privacy Policy
This page is maintained by MARTSAPP to answer common privacy questions about the MARTSAPP service. It describes the controls and practices we currently apply, and will be updated as the service evolves.
1. Who we are
MARTSAPP is a mobile-first commerce and business-management platform built for Nigerian merchants. This policy applies to merchants who create stores on MARTSAPP, their customers who place orders through MARTSAPP-hosted storefronts, and visitors to our marketing website.
Operator: MARTSAPP (operator contact details are listed in section 10).
2. What data we collect
- Merchant account data: name, email address, phone number, authentication credentials, store/tenant name, and branding assets.
- KYC and payout data: BVN, government ID images, proof-of-address documents, selfie/liveness media, and verified bank account details. These are collected only when a merchant chooses to unlock higher-tier payouts.
- Product and order data: product names, descriptions, images, prices, inventory levels, and order history — all tied to the merchant's tenant and isolated from other merchants by Row Level Security.
- Customer data: name, phone number, email, delivery address, and order history entered by shoppers at checkout. Merchants control this data for their own customers.
- Device and log data: push notification tokens, device type, IP address, and audit logs of financial actions (who, what, when, IP/device fingerprint).
3. How we use data
- To provide and operate the MARTSAPP storefront, order, inventory and payout services.
- To verify merchant identity and comply with tiered-KYC and anti-fraud requirements.
- To process payments and payouts through integrated payment providers.
- To send order, payout and low-stock notifications to merchants and customers.
- To improve the service, fix bugs, and detect abuse or unauthorized access.
4. Payment and payout data
MARTSAPP does not store raw card numbers, CVV or PINs. Card payments are handled through the payment provider's hosted fields or inline SDK. We store only the processor's transaction reference and, where supported, a token for repeat charges. Payout accounts are verified through the processor's account-name lookup before being saved; we store only the processor recipient/subaccount code.
5. Subprocessors and integrations
MARTSAPP relies on the following categories of service providers to operate the platform:
- Cloud backend and auth: Lovable Cloud (Supabase) for database, authentication, storage and edge functions.
- Payments: Paystack (primary) and Flutterwave (fallback) for card, bank transfer, USSD and QR payments.
- AI features: Lovable AI Gateway for optional product-title, description and sales-summary generation.
- Push notifications: Web Push protocol with VAPID keys managed by MARTSAPP.
We do not sell personal data to third parties.
6. Cookies and analytics
MARTSAPP uses essential cookies and local storage to keep you signed in and to cache storefront data for offline tolerance. We do not use third-party advertising cookies. Optional analytics may be added in the future; this policy will be updated if that happens.
7. Data retention and deletion
We keep account and transaction data for as long as necessary to provide the service and meet legal/tax obligations. Merchants can delete their account and store data from the in-app account-deletion flow; this removes tenant-scoped data from active tables and marks the account for eventual permanent deletion. Some records may be retained in immutable audit/ledger form where required for financial compliance.
8. Your privacy rights
You can access, correct or delete most of your data directly inside the MARTSAPP mobile or web app. For requests that cannot be handled in-app — such as data-export or complaints — contact us using the details in section 10. We will respond within a reasonable timeframe.
9. Security practices
MARTSAPP uses Row Level Security to isolate each merchant's data, HTTPS for all traffic, signed webhooks for payment events, idempotent payout requests, and step-up authentication for high-risk financial actions. Sensitive fields are encrypted at rest where supported by the backend provider.
Platform security is provided in part by Lovable Cloud infrastructure; MARTSAPP is responsible for application-level access controls, secure coding practices and prompt patching.
10. Contact us
Privacy and security contact
Email: privacy@martsapp.ng
Response target: within 30 days.
11. Changes to this policy
We may update this Privacy Policy as the service grows or as laws change. The latest version will always be available at this URL, and we will notify merchants of material changes through the app.
Last updated: 24 August 2026.