Privacy policy

Last updated 25 September 2026

This policy explains what Vanari does with personal data. It covers two different groups of people, and the difference matters, so it is stated first.

Businesses and their staff hold accounts with us. Hotspot customers do not: they buy a voucher and get online, and almost nothing about them reaches us. Where a section applies to only one group, it says so.

What we collect from hotspot customers

Getting online with a voucher requires the code and nothing else. No name, no email, no phone number, no identity document, and there is no field on the page to put one in.

What we collect from businesses and staff

Payments

Card and bank details are collected by Paystack on their own pages and never pass through Vanari. We receive a confirmation that a payment succeeded, its amount, and a reference. We do not see, store, or have any means of retrieving a card number.

Why we hold it

How long

Session and usage records are kept for the retention period configured for that business, which defaults to two years and can be shortened on request. Financial records are kept for as long as Nigerian law requires them, which is longer, and this takes precedence over a shorter setting.

Records of significant actions are append-only by design. They cannot be edited or deleted, including by us, because a record that can be quietly changed is not a record.

Who else sees it

Your rights under the Nigeria Data Protection Act

You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. We will respond within 30 days. A copy and a deletion can be produced directly by the business running the network you used, or by us; a correction is handled by us by hand, so tell us what is wrong and what it should say.

Deletion has one limit worth stating honestly rather than in small print: we cannot delete a financial record or an action log we are required to keep. Where that applies we remove or mask the personal details within the record instead of destroying the record, and we will tell you which parts were kept and why.

Security

Traffic to this site and to our service is encrypted. Router credentials and second-factor secrets are encrypted where they are stored. The service runs under a database role that cannot alter or remove financial and audit records, which is a limitation we impose on ourselves deliberately.

Contacting us

Use the contact details in the footer of this page. If you are a hotspot customer and your question is about a specific network, the business running that network is usually the faster route, and we will pass a request on to them where it is properly theirs to answer.