Legal
Privacy policy
What BuildLink collects about you, why, who else sees it, and what you can require us to do about it.
Pre-launch draft
This policy describes what the system actually does, but it has not yet been reviewed by a data protection lawyer. It will be, before the marketplace opens to the public.
The short version
- We collect what an account, an order or a vendor application needs — nothing else.
- The vendor fulfilling your order gets your name, address and phone number. They have to.
- Your card details never reach us; the payment provider holds them.
- Three cookies, all of them the sign-in itself. No advertising or analytics trackers.
- You can ask for a copy of your data, or its correction or deletion, at any time.
A summary for reading, not the policy. The numbered clauses below are what applies.
1.Who this covers
BuildLink operates the BuildLink marketplace and is the data controller for the personal data described here. It applies to customers, to vendors, and to anyone who contacts us.
It is written under the Nigeria Data Protection Act 2023 and explains what we collect, why, who else sees it, and what you can require us to do about it.
A vendor you buy from is a separate controller of the data they receive to fulfil your order — clause 4 sets out exactly what reaches them.
2.What we collect
Only what an order, an account, or a vendor application actually needs:
- Account details
- Your name, email address, phone number and password. The password is stored only as a hash — we cannot read it, and neither can anyone who reaches the database.
- Delivery addresses
- The addresses you save, with the state and any landmark or access note you add for the driver.
- Orders
- What you bought, from which vendor, for how much, where it went, and the status of each fulfilment.
- Payment records
- Amount, currency, method, status, the provider’s reference, and the fee. Not your card number — see clause 5.
- Vendor documents
- For sellers only: business name and registration number, tax identification, identity and registration documents, and the settlement bank account.
- Messages you send us
- Support emails and calls, and anything you attach to them.
- Technical data
- IP address, browser and device type, and the pages requested — used to keep the site up and to spot fraud and abuse.
We do not ask for, and do not want, health data, biometrics, political or religious affiliation, or anything else in the sensitive categories.
3.Why we use it
Each use below has a lawful basis under the NDPA, and we have named it rather than left it implied:
- Running your orders
- Taking payment, holding it, passing the order to the vendor, arranging delivery, and refunding you. Basis: performance of your contract.
- Your account
- Signing you in, keeping you signed in, letting you change your details. Basis: performance of your contract.
- Order and account notifications
- Confirmations, dispatch and delivery updates, refund notices, password and security emails. Basis: performance of your contract. These are not marketing and cannot be switched off while an order is live.
- Verifying vendors
- Checking registration, identity and settlement accounts before a seller can list. Basis: legal obligation and our legitimate interest in a marketplace that is not a fraud vector.
- Fraud, abuse and security
- Detecting stolen cards, fake listings and account takeover, and keeping records of administrative actions. Basis: legitimate interests.
- Support
- Answering you, and looking into what went wrong. Basis: legitimate interests.
- Legal and tax records
- Keeping transaction records we are required to keep. Basis: legal obligation.
We do not sell your personal data, and we do not share it for anyone else’s advertising.
5.Card details and payment data
Card details are entered with our payment provider, not with us. Your card number, expiry and CVV never reach our servers and are never stored in our database.
What we keep against a payment is what is needed to explain it: the amount, currency, method, status, the provider’s reference, the provider’s fee and the timestamps.
When the provider sends us an event about a payment, we do not store what they send. We copy nine named fields out of it and drop the rest unread — an allowlist rather than a blocklist, so anything a provider adds later is discarded by default. The card BIN, the last four digits, the card type, the account name and the reusable authorisation code are all in the part that is dropped.
Bank account details belong to vendors, not customers, and exist so payouts can be made. They are shown masked everywhere in the product, including to our own staff.
7.How long we keep it
- Account details: while your account is open, and then a short period after closure in case an order or a refund is still running.
- Orders, payments and refunds: kept for as long as tax and financial record-keeping law requires, whether or not the account is closed. These are the records that prove a payment was held, released or returned.
- Vendor verification documents: for the life of the vendor account and the retention period that applies to the checks afterwards.
- Support correspondence: normally two years.
- Technical logs: short-lived, and kept longer only where an incident is being investigated.
When something no longer has a purpose or a legal reason to exist, it is deleted or anonymised.
8.Your rights
Under the NDPA you can require us to:
- tell you what personal data we hold about you, and give you a copy
- correct anything inaccurate — most of it you can correct yourself from your account
- delete data we no longer have a reason to keep
- restrict or object to a use that rests on our legitimate interests
- give you your data in a portable form, or send it to another controller
- withdraw a consent you gave, without affecting what was done before you withdrew it
Some of this has limits. We cannot delete the record of an order you placed while tax law requires us to keep it, and we cannot delete a vendor’s verification file while the account is trading. Where we refuse, we tell you why.
Ask by writing to support@buildlink.ng with "Data protection request" in the subject. We reply within 30 days, and we may ask you to confirm who you are first — the request itself must not become the way somebody else obtains your data.
9.How it is protected
- Passwords are stored only as hashes, never in a form anyone can read.
- Sessions use HTTP-only cookies, so a script injected into a page cannot steal them, and the refresh token is scoped to the sign-in routes alone.
- Card details never reach us — clause 5.
- Bank account numbers are masked everywhere they are displayed, including in our own admin console.
- Administrative actions are written to an append-only log.
- Access to production data is limited to the people who need it to run the marketplace.
No system is perfectly secure. If a breach affects you, we will tell you and notify the Nigeria Data Protection Commission as the NDPA requires.
10.Where it is processed
The marketplace serves Nigeria and the data is processed here. Some of the services we rely on — hosting, email delivery, payment processing — operate outside Nigeria, so some data is processed abroad.
Where that happens we use providers under contractual terms that hold them to the standard the NDPA requires, and we send them only what the service needs.
11.Children
The marketplace is not for under-18s and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.
12.Changes to this policy
The version in force is the one on this page, effective 28 August 2026.
If we change how we use your data in a way that materially affects you, we will tell you by email before the change takes effect rather than leaving you to notice a new date at the top.
13.Contact and complaints
Email support@buildlink.ng, or call 0803 123 4567 during support hours (8am–8pm, Monday to Saturday).
By post: BuildLink, 12 Adeola Odeku Street, Victoria Island, Lagos.
If you are not satisfied with how we have handled your data or your request, you can complain to the Nigeria Data Protection Commission. Complaining to us first is usually faster, but it is not a condition of going to them.
Want a copy of your data, or something removed?
Write to us with “Data protection request” in the subject and we will reply within 30 days.
