Legal
Privacy Policy
Last updated September 6, 2026
1. What this policy covers
This Privacy Policy explains what data ZenithPro collects through its Android application, web admin portal, and terminal hardware, why we collect it, and how it is stored, shared, and protected. It applies to registered businesses, their staff, and, where relevant, their customers whose transaction records are stored in the system.
2. Data we collect
- Business & staff data: business name, address, phone, staff names, roles, login credentials, and branch assignments.
- Transaction data: sales, sale items, payment method, amounts, customer debt records, and expense entries recorded through the app.
- Payment metadata: virtual account references and webhook confirmations from Nomba. ZenithPro receives confirmation that a payment occurred, not access to the underlying bank account or card details.
- Device & usage data: device identifiers, crash reports, and app analytics collected via Firebase Crashlytics and Analytics, used to diagnose issues and improve reliability.
- Customer records entered by merchants: names, phone numbers, and purchase history that a business chooses to record for its own customers.
3. How we use this data
We use the data described above to:
- Operate core features — sales processing, inventory, debt tracking, and reporting;
- Reconcile payments confirmed through Nomba's webhook notifications;
- Send push notifications for payment confirmations, low stock, and sync status;
- Diagnose crashes and improve app stability and performance;
- Meet legal, tax, or regulatory obligations where applicable.
4. Where data lives, including offline
ZenithPro is offline-first: records are written to a local database on the terminal first, so the app keeps working without a connection. This means transaction data may exist on the physical device before it syncs to our servers. Terminals should be kept reasonably secure, since locally stored data is only as protected as the device itself until it syncs. Once synced, data is stored on our backend infrastructure (Supabase, hosted on its underlying cloud provider) with access controls scoped per business.
5. Who we share data with
We do not sell business or customer data. We share data only with service providers necessary to run ZenithPro:
- Nomba — to process payments and provision virtual accounts. ZenithPro never holds the underlying funds.
- Supabase — our database, authentication, and backend infrastructure provider.
- Firebase (Google) — crash reporting, analytics, and push notification delivery.
We may also disclose data if required by law or to protect the rights, safety, or property of ZenithPro, its merchants, or others.
6. Data retention
We retain business and transaction data for as long as an account is active, and for a reasonable period after termination to comply with tax, accounting, or legal obligations, or to allow a business to export its records. You may request deletion of your business's data subject to those obligations.
7. Your rights
Depending on applicable law, including the Nigeria Data Protection Act 2023, you may have the right to access, correct, export, or request deletion of personal data held about you or your business. Requests can be made through the contact details below.
8. Security
We use role-based access control, row-level security on our database, and encrypted connections between the app and our servers. No system is perfectly secure, and we encourage businesses to use strong staff credentials and report any suspected unauthorized access immediately.
9. Children's privacy
ZenithPro is a business tool and is not directed at children. We do not knowingly collect personal data from individuals under 18 acting in a personal capacity.
10. Changes to this policy
As ZenithPro moves from pilot to general availability, this policy may be updated. Material changes will be communicated through the app or admin portal.
11. Contact
Questions or data requests can be sent to the contact address listed in the ZenithPro app or admin portal.