etral

Privacy notice

Last updated 28 August 2026

This notice explains what Xetral collects about you, why, how long it is kept and what you can ask us to do with it. It is written to match what the system actually does — the retention table below is generated from the same configuration the deletion job reads.

Who we are

Xetral is operated by [registered company name], [registered address]. We are the data controller for the information described here. Our data protection officer can be reached at [dpo@ address], and we are registered with the Nigeria Data Protection Commission under [NDPC registration reference].

What we collect, and why

  • Who you are. Your name, date of birth, address, phone number, email and the identity document you upload. We are required to collect and verify these before you can hold money, receive an account number or be issued a card. We cannot offer those services without them.
  • What you do with your money. Every transfer, purchase, deposit, card payment and currency conversion. This is the record of what we owe you, so it exists for as long as your account does.
  • How you sign in. The devices you use, when they were used and the network address they connected from. This is what makes it possible to tell you that somebody else has signed in, and to let you sign them out.
  • What breaks. When something fails we record the error and the page it happened on — not who you are. Error records are deliberately grouped by the fault rather than by the customer.

We do not use your data for advertising, we do not sell it, and we do not profile you for anything other than fraud prevention and the legal obligations described below.

What we deliberately do not hold

  • Your card number. There is no place in our database that can hold one. When you tap to see your card details we fetch them from the card issuer, show them to you and drop them. We record that it happened, never what it showed.
  • Your transaction PIN or password. Both are stored as one-way hashes. Nobody at Xetral can read them, and we cannot recover one for you — we can only help you set a new one.
  • Your fingerprint or face. If you unlock the app with biometrics, that happens entirely on your phone. Your device tells us only that it agreed to release your PIN; we never see the biometric data itself.

How long we keep it

Two rules pull in opposite directions here, and both are law. Nigeria's anti-money-laundering rules require records of a customer relationship to be kept for five years after it ends. The Nigeria Data Protection Act requires that personal data is not kept for longer than it is needed. So different things have different answers:

WhatHow longWhy
Your account, transactions and balancesWhile you are a customer, and five years afterNigerian anti-money-laundering rules require records of a customer relationship to be kept for five years after it ends. Your ledger is also the only record of what we owe you, so it is never deleted.
Your identity documentsWhile you are a customer, and five years afterThe same rule. Deleting them while you still bank with us would destroy the proof that you were ever verified, and every card and account number depends on it.
Sign-in sessions and devicesWhile you are a customerSo you can see which devices are signed in and sign out the ones you do not recognise. This is the screen you would use if somebody else got into your account.
Expired sign-in and password reset tokens90 daysThese are one-way hashes of credentials that no longer work. Kept briefly so a security incident can be investigated, then deleted.
Emails we sent you180 daysThe contents are erased the moment a message is delivered — a password reset email contains a live link, and the safest place for a spent one is nowhere. What remains is that we wrote to you on a given day.
Declined card payments365 daysUsed to spot fraud on your card. It is also a record of where you shop, which is why it does not stay longer.
Technical error records180 daysWhat broke, not who it happened to: the address of the page rather than your identity. Kept until the fault is fixed, then deleted.
A record of when card details were shownKeptThat a card number was revealed, and to whom — never the number itself, which we do not store at all. This record is deliberately permanent: a log that a scheduled job can delete from is one an intruder can prune.

Who else sees it

We share the minimum necessary with the companies that actually move your money and deliver what you buy: Bitnob (account numbers, cards, crypto and currency conversion), VTpass (airtime, data and bills), Airalo (eSIMs), Twilio (phone numbers) and Resend (email). Each receives only what its part of the transaction requires. We also disclose information to the Central Bank of Nigeria, the NFIU and law enforcement where we are legally required to.

Where it is held

Your data is stored on servers in the European Union, with encrypted backups held off those servers. Some of the providers listed above process data outside Nigeria; where they do, that transfer relies on the contractual protections the NDPA requires.

What you can ask for

  • A copy of the personal data we hold about you.
  • A correction, if something is wrong.
  • Deletion — though not of the records we are legally required to keep. We will tell you plainly which is which rather than refusing the whole request.
  • To object, or to withdraw consent where we relied on it. Some services cannot continue without the data they need.
  • To complain to the Nigeria Data Protection Commission if you are not satisfied with our answer.

You can do the first two yourself, now: Settings → Your data downloads a copy of everything we hold, and the same page asks us to erase it. An erasure request is answered by a person, and the answer names what was deleted and what we are required to keep — with the date it stops being kept.

For anything else, write to [dpo@ address]. We answer every request within 30 days, and we record when it was made and when it was answered so that we can show we did.

Keeping it safe

Sensitive values are encrypted with keys that can be rotated. Access to customer records requires a second factor, and every privileged action is written to a log that cannot be edited or deleted, including by us. Sign-in sessions rotate their credentials on every use, and a credential presented twice is treated as stolen and revoked everywhere.

Changes

When this notice changes we will tell you in the app before the change takes effect. The date at the top is the last time it was updated.

PrivacyTermsSign in