Privacy Policy
Last Updated: July 2, 2026
Effective Date: July 2, 2026
1. Introduction
Ajo ("we," "our," or "us") is a digital thrift-collection (esusu/ajo) platform that enables users to create or join savings groups, contribute in rotating cycles, and manage payments through our mobile application and web services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
We are committed to protecting your privacy and ensuring the security of your personal information. This policy applies to all users of our services, including:
- ajo-mobile: Our member-facing mobile application
- ajo-server: Our backend API services
- ajo-admin-web: Our internal platform administration console
2. Information We Collect
2.1 Personal Information
Account Information:
- Phone Number: Your primary identifier (required, stored in E.164 format)
- Email Address: Optional, used for account recovery and notifications
- Full Name: Optional, used for personalization
- Password: Only for platform administrators (hashed, never stored in plaintext)
Authentication Data:
- One-Time Passwords (OTPs): Generated for login verification, hashed and auto-expired
- JWT Tokens: Session tokens with minimal payload (user ID, role, phone, email)
- Device Tokens: Firebase Cloud Messaging (FCM) tokens for push notifications
3. How We Use Your Information
We use your information to provide and improve our services:
- Authentication & Account Management: Verify your identity, create and manage your account, maintain secure sessions
- Payment Processing: Process wallet funding, automate contributions, initiate payouts
- Group Management: Create and administer savings groups, send invitations, track contributions
- Notifications: Send push notifications, SMS alerts, and in-app notifications
- Security: Authenticate requests, detect unauthorized access, prevent fraud
- Service Improvement: Debug issues, analyze usage patterns, test new features
4. Third-Party Services
We use trusted third-party services to operate our platform:
Payment Processing (Paystack)
We use Paystack for payment processing. Paystack collects payment card details and processes transactions. Their privacy policy governs their data collection.
SMS Services (Termii)
We use Termii for SMS delivery of OTPs and notifications. Termii sends SMS messages to your phone number.
Push Notifications (Firebase Cloud Messaging)
We use Firebase Cloud Messaging for push notifications. FCM delivers notifications to your device.
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: All API communications use HTTPS/TLS, JWT tokens are signed and verified
- Access Controls: Role-based access, group-level permissions, JWT re-verification on every request
- Data Storage: MongoDB with Mongoose schemas, OTP codes hashed with bcrypt and TTL indexes
- Token Storage: Mobile app uses secure storage, admin web uses httpOnly cookies
6. Your Rights and Choices
- Access and Update: View and update your profile information via the app
- Account Deletion: Contact us to request account deletion within 30 days
- Notification Preferences: Manage push notification permissions in device settings
- Data Portability: Request a copy of your personal data in JSON format
- Opt-Out: Opt out of non-essential notifications or request data deletion
7. Data Retention
- Account data retained for the duration of your account activity
- Financial transaction records retained for 7 years (legal requirement)
- Notification history retained for 90 days
- OTP records auto-deleted after 15 minutes
- Personal data deleted within 30 days of account deletion request
8. Contact Information
For privacy-related inquiries, requests, or complaints:
Data Protection Officer
Ajo Platform
Email: privacy@ajo.app
Phone: +234-XXX-XXXX-XXX
Lagos, Nigeria
We aim to respond to all privacy requests within 30 days.