Privacy Policy
NDPR-aligned data notice
Last updated: 25 June 2026
Romera Serve ("we", "us") respects your privacy. This Privacy Policy explains how we collect, use, store, and share personal data when you use romeraserve.com and our apps, in line with the Nigeria Data Protection Regulation (NDPR) and applicable guidance from the Nigeria Data Protection Commission (NDPC).
1. Data controller
Romera is the data controller for personal data processed through Serve. Contact: privacy@romeraserve.com
2. Data we collect
- Account data: name, email, phone, password hash, role (client/vendor)
- Profile & business data: business name, address, city/state, verification documents for vendors
- Transaction data: bookings, inquiries, messages, payment references from Paystack (not full card numbers)
- Location data: optional coordinates or city to show nearby services
- Technical data: device type, IP address, logs, cookies (see Cookie Policy)
3. Lawful bases & purposes
We process data to:
- Provide the marketplace (contract performance)
- Verify vendors and prevent fraud (legitimate interests / legal obligation)
- Send service notifications and support replies (contract / consent where required)
- Improve reliability and comply with law (legitimate interests / legal obligation)
4. Sharing
We share data with:
- Vendors or clients you interact with (e.g. booking details, inquiry messages)
- Processors: Supabase (hosting/database), Vercel (hosting), Paystack (payments), Resend (email alerts)
- Authorities when required by valid legal process
We do not sell personal data.
5. International transfers
Some processors may store data outside Nigeria. Where this occurs, we use appropriate safeguards consistent with NDPR requirements.
6. Retention
We retain data while your account is active and as needed for disputes, fraud prevention, tax, and legal obligations. Some booking and payment records may be kept after account deletion where required by law.
7. Your rights (NDPR)
Subject to verification, you may request:
- Access to your personal data
- Correction of inaccurate data
- Deletion (see Account deletion)
- Restriction or objection to certain processing
- Data portability where technically feasible
Submit requests to privacy@romeraserve.com. You may lodge a complaint with the NDPC.
8. Security
We use encryption in transit, access controls, row-level security on our database, and moderation tooling. No system is perfectly secure — report suspected breaches to privacy@romeraserve.com promptly.
9. Children
Serve is not directed at children under 18. We do not knowingly collect their data.
10. Changes
We will update this policy when practices change and revise the "Last updated" date.