Privacy Policy
Last updated: July 31, 2026 | Effective Date: January 1, 2025
PhoneGuard ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully.
1. Information We Collect
We collect the following types of information:
- Personal Identification Information: Full name, email address, phone number, and National Identity Number (NIN) for KYC verification.
- Device Information: IMEI numbers, device brand, model, serial number, and device fingerprint data.
- Location Data: GPS coordinates and location history of registered devices (only when the app is actively in use or when device tracking is enabled by the owner).
- Account Credentials: Hashed passwords and authentication PINs (never stored in plain text).
- Transaction Data: Payment records, subscription plans, and receipts (no full card details are stored; payments are processed via Paystack).
- Usage Data: Log data, IP addresses, app interactions, and audit logs for security purposes.
- Push Notification Token: Firebase Cloud Messaging (FCM) token for sending alerts and notifications.
- Biometric/Photo Data: Passport photographs submitted for KYC verification purposes.
2. How We Use Your Information
We use the information we collect to:
- Verify your identity and prevent fraud through NIN-based KYC verification.
- Register, track, and protect your mobile devices.
- Process ownership transfers and generate official receipts.
- Send security alerts and push notifications about your registered devices.
- Process payments and manage your subscription.
- Provide stolen device reporting and recovery assistance.
- Maintain audit logs for security and compliance purposes.
- Improve the functionality and user experience of our app.
- Communicate with you regarding your account and our services.
- Comply with legal obligations and assist law enforcement where required.
3. Legal Basis for Processing (NDPR Compliance)
In accordance with Nigeria's National Data Protection Regulation (NDPR), we process your personal data on the following legal bases:
- Consent: You have given explicit consent during registration.
- Contract: Processing is necessary to provide the services you requested.
- Legal Obligation: Processing is required to comply with applicable laws.
- Legitimate Interest: Processing is necessary for fraud prevention and platform security.
4. Location Data
PhoneGuard collects precise device location data to enable the device tracking and anti-theft features. Location collection only occurs when:
- The device owner has enabled tracking on a registered device.
- A device has been reported stolen and tracking is activated.
- The app is in the foreground and you are actively using tracking features.
We do not share live location data with third parties except to assist law enforcement in recovering stolen devices upon proper legal request.
5. Sharing of Information
We do not sell, trade, or rent your personal information. We may share data with:
- NIN Slip API (ninslip.com): For identity verification purposes.
- Paystack: Our payment processor — subject to their privacy policy.
- Firebase (Google): For push notifications via FCM.
- Law Enforcement: When required by law or to assist in stolen device recovery.
- Authorized Dealers: Limited information necessary to process device sales and transfers.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Device records and audit logs may be retained for up to 7 years to comply with legal obligations. You may request deletion of your account and data at any time (see Section 10).
7. Data Security
We implement industry-standard security measures including:
- AES-256 encryption for data at rest and TLS for data in transit.
- Bcrypt hashing for all passwords and PINs.
- Role-based access controls for admin and dealer accounts.
- Regular security audits and activity monitoring.
- Two-factor verification for sensitive operations.
8. Children's Privacy
PhoneGuard is not directed to children under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us immediately.
9. Third-Party Links
Our app may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties and encourage you to review their privacy policies.
10. Your Rights
Under applicable data protection laws, you have the right to:
- Access: Request a copy of your personal data we hold.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Object: Object to processing based on legitimate interests.
To exercise these rights, contact us at privacy@phoneguard.ng.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification at least 30 days before the change takes effect. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact: