KinwardBack to home
Data protection

Privacy Policy

This Policy explains what personal data Kinward collects, why we use it, who receives it, how long we retain it and the choices available to you.

Effective and last updated: 17 August 2026

01

Who controls your data

Kinward Merchant LTD (RC12533791), of 235 Ayetoro-Itele Road, Ado-Odo/Ota, Ogun State, Nigeria, is the data controller responsible for personal data processed through mykinward.com and Kinward member services (“Kinward”, “we”, “us” or “our”).

This Policy is issued under the Nigeria Data Protection Act 2023 and other applicable Nigerian privacy, consumer protection and electronic communications requirements.

02

Scope of this Policy

This Policy applies to visitors, invitation requesters, invitees, members, former members and people who contact Kinward. It covers data collected through our website, account registration, authentication, profile, invitations, product transactions, payouts, support and related communications.

03

Personal data we collect

Depending on how you use Kinward, we may collect:

  • Contact and authentication data: phone number, password credentials handled by our authentication provider, OTP events, monthly login-OTP usage and applicable charges, recovery email and communication preferences.
  • Identity and eligibility data: first, middle and last name, date of birth, confirmation that you are at least 18, and verification information.
  • Profile data: residential address, state, city or LGA, education level, institution and profile-completion status.
  • Invitation and referral data: referrer identifiers, invitation codes, inviter relationship, issue, expiry, redemption, email-delivery outcome and reward progress.
  • Bank and transaction data: selected bank name and code, account number, the account-holder name returned by our verification provider, verification provider and timestamp, and purchase, reinvestment, sale-back, withdrawal, fee, principal, dividend and payout records.
  • Technical and security data: IP address, browser and device information, authentication cookies, timestamps, error, fraud-prevention and security logs.
  • Communications: invitation requests, support messages, complaints, confirmations and other correspondence.

Please do not provide information we have not requested. We do not seek access to your phone contacts, photos, videos, precise location, call logs or unrelated device files.

04

Where data comes from

We receive personal data:

  • directly from you when you request an invitation, register, complete a profile or transact;
  • from the member who invites you, limited to the invitation and referral relationship;
  • from authentication, SMS, banking, payment and verification providers, including bank and account-holder details returned by Monnify Name Enquiry;
  • automatically from your browser, device and use of the platform; and
  • from regulators, advisers, public records or fraud-prevention sources where lawful and necessary.
05

Why we process personal data

We use personal data to:

  • receive and assess invitation requests;
  • create, authenticate, secure and recover member accounts, enforce active-membership access to login OTPs and calculate monthly login-OTP usage;
  • validate invitations, prevent self-referral and administer referral rewards;
  • verify eligibility, identity and age, and confirm that a payout account name matches the immutable legal name in the member profile;
  • process purchases, reinvestments, dividends, fees, withdrawals and sale-back requests;
  • operate, troubleshoot, improve and secure the platform;
  • provide support and communicate account, security, legal and transaction notices;
  • detect fraud, abuse, money laundering and other unlawful conduct;
  • keep accounting, audit, tax, compliance and dispute records; and
  • comply with court orders, regulators and applicable law.
06

Our lawful bases

Depending on the processing, we rely on one or more of:

  • Contract: processing needed to create and operate your membership and perform requested transactions.
  • Legal obligation: accounting, tax, regulatory, fraud-prevention, court and compliance requirements.
  • Legitimate interests: securing Kinward, preventing abuse, improving services and managing claims, balanced against your rights.
  • Consent: where consent is appropriate, including optional marketing or non-essential technologies. You may withdraw consent without affecting earlier lawful processing.
  • Other lawful grounds: where necessary to protect vital interests, perform a task in the public interest or establish, exercise or defend legal claims.
07

Service providers and data sharing

We do not sell personal data. We disclose only what is reasonably necessary to providers and recipients supporting a stated purpose, including:

  • Supabase: account authentication, session management, database and application infrastructure.
  • Twilio: SMS delivery, including verification and login OTPs, when enabled.
  • Monnify: product-purchase payment processing, the supported Nigerian bank directory and payout-account Name Enquiry. For a product purchase, Kinward sends the member name, payment email address, amount, payment reference, purchase description and limited order metadata needed to initialise and verify the transaction. Monnify returns payment references, status, payment method, paid and settlement amounts and, where bank transfer is selected, the temporary receiving bank, account name, account number and expiry. For Name Enquiry, Kinward sends the selected bank code and 10-digit account number and receives the associated account number, account-holder name, bank code and bank name. Kinward does not send your profile legal name to Monnify for the Name Enquiry lookup; that comparison is performed within Kinward’s controlled systems.
  • Resend: transactional invitation email delivery and delivery, delay, bounce, complaint, failure and suppression reporting.
  • Hosting, security and communications providers: website delivery, monitoring and operational support.
  • Banks and payment partners: receiving funds, verifying payout details and completing authorised transactions.
  • Professional advisers and authorities: auditors, lawyers, accountants, insurers, courts, regulators and law-enforcement bodies where lawful.

Providers may process data only for agreed services, their lawful independent obligations or as otherwise disclosed to you. If Kinward is reorganised, financed, sold or transferred, data may be shared with advisers and a successor subject to appropriate safeguards.

Monnify’s processing is also governed by its applicable privacy notice. Kinward remains responsible for how we select, send, use and retain the personal data described in this Policy. Listing a bank or obtaining a successful Name Enquiry does not guarantee that the bank or Monnify will remain available or that a later payout will succeed.

08

International data transfers

Some technology providers may store or process data outside Nigeria. Where personal data is transferred internationally, we will use a lawful transfer mechanism and reasonable contractual, organisational and technical safeguards required by the Nigeria Data Protection Act. You may contact us for information about safeguards relevant to your data.

09

Automated checks and decisions

Kinward automatically validates phone formats, invitation status, one-time codes, profile requirements, referral relationships and some transaction rules. We may also use automated signals to identify suspicious activity. These checks protect the platform and apply the rules consistently.

For payout accounts, Kinward automatically compares the account-holder name returned by Monnify with the legal name in your profile. The check ignores word order, letter case, punctuation and accents, but requires all name parts to match. A mismatch prevents the account from being saved or used for payouts. You may correct the bank details or contact us to request an explanation and appropriate human review.

Where an automated decision produces a significant adverse result, you may contact us to request an explanation and appropriate human review, subject to legal and security limitations.

10

How long we keep data

We retain data only for a defined operational or lawful purpose:

  • Rejected or unused invitations: related personal data and individual email-event history is deleted or irreversibly de-identified within seven days after rejection or expiry. We may retain anonymous daily outcome counts that cannot identify the invitee, unless a security incident, dispute or legal hold requires limited retention.
  • Closed accounts: general account data may be retained for up to 180 days for investigation, fraud prevention, security and closure administration.
  • Payout-account verification attempts: a restricted abuse-prevention record containing only the member identifier and attempt timestamp is retained for up to 30 days. It does not contain the submitted account number or Monnify response.
  • Identity and financial records: retained after account closure for the period required for accounting, audit, tax, anti-fraud, regulatory, dispute-resolution and other legal obligations. These records are restricted and are not kept for unrelated marketing.
  • Login OTP records: individual request outcomes support abuse prevention and monthly calculation. Monthly totals and related charges may be retained as financial records for accounting, audit, dispute and legal purposes.
  • Security and support records: retained for the period reasonably necessary to investigate incidents, answer requests and defend claims.
  • Backups: removed through our scheduled backup-rotation process, subject to secure isolation and legal holds.

When retention ends, data is deleted, anonymised or securely isolated. A legal hold, court order or regulatory investigation may extend a period, and we will retain only what is necessary for that purpose.

11

Your privacy rights

Subject to applicable law, you may ask us to:

  • confirm whether we process your data and provide access to it;
  • correct incomplete or inaccurate data;
  • delete data that no longer has a lawful retention basis;
  • restrict or object to particular processing;
  • provide portable data where the right applies;
  • withdraw consent for future consent-based processing; and
  • request review of a significant automated decision.

We may verify your identity before fulfilling a request. Some rights are subject to lawful exceptions, including financial record-keeping, fraud prevention, active disputes and the rights of other people. A legal name locked in the profile can still be challenged through support where it is inaccurate.

12

Cookies and similar technologies

Kinward uses essential cookies and similar storage to authenticate members, maintain sessions, protect forms, remember necessary state and operate the website. These are required for the requested service. If we introduce non-essential analytics, advertising or preference cookies, we will provide any notice and choice required by law before using them.

13

Data security and incidents

We use access controls, encrypted connections, authentication, row-level database controls, monitoring, provider safeguards and operational procedures designed to protect personal data. No online system is completely secure, so members must also protect passwords, OTPs, recovery email and devices.

Monnify credentials are held server-side and are not sent to your browser. Kinward stores the limited payment, temporary transfer-account, payout-account and verification metadata needed to operate your account, rather than retaining full provider responses.

We investigate suspected personal-data breaches and will notify the Nigeria Data Protection Commission and affected people where and within the time required by applicable law.

14

Children

Kinward membership is restricted to people aged 18 or older. We do not knowingly create member accounts for children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

15

Requests and complaints

Send a privacy request or complaint to hello@mykinward.com. Please describe your request and the account or contact information needed to locate your data. We will acknowledge and respond within the period required by applicable law.

You also have the right to complain to the Nigeria Data Protection Commission if you believe your data-protection rights have been violated.

16

Changes to this Policy

We may update this Policy when our services, providers, retention practices or legal obligations change. We will publish the revised date and provide additional notice where a change materially affects your rights or requires a new choice.

17

Contact details

Kinward Merchant LTD
RC12533791
235 Ayetoro-Itele Road, Ado-Odo/Ota, Ogun State, Nigeria
hello@mykinward.com