Privacy policy
Last updated 25 September 2026
This policy explains what Vanari does with personal data. It covers two different groups of people, and the difference matters, so it is stated first.
Businesses and their staff hold accounts with us. Hotspot customers do not: they buy a voucher and get online, and almost nothing about them reaches us. Where a section applies to only one group, it says so.
What we collect from hotspot customers
Getting online with a voucher requires the code and nothing else. No name, no email, no phone number, no identity document, and there is no field on the page to put one in.
- The voucher code, which is the credential itself. It is checked by the business's router against our authentication service.
- Session records written by the router while the voucher is in use: the device network address, the device hardware address, start and stop times, and how much data was transferred. This is what makes a time or data limit enforceable and what a business's usage reporting is built from.
- The devices connected to a business's network, as its router reports them: each device's hardware address, the name the device itself reports (which is often its owner's name), its network address, whether it was logged in, which of the router's ports or its own Wi-Fi it came in through, and the kind of device it is (such as an Android phone or a Windows laptop), worked out from what the device announces and kept only as that kind. The business sees this to know who is on its network, and it is deleted after seven days, or sooner if the business keeps its records for less. Because most devices belong to nobody we can identify, this history expires on its own rather than waiting for a request.
- A phone number, only if it is typed in, and only to send a receipt for a purchase made on the payment page. It is optional, it is labelled as optional, and the purchase completes without it.
What we collect from businesses and staff
- Name, email address, and phone number for each account.
- Business details supplied at sign-up, including a registration number where the business has one.
- Records of significant actions taken in the dashboard, so a business can see who changed what.
- Router and site details needed to configure the service.
Payments
Card and bank details are collected by Paystack on their own pages and never pass through Vanari. We receive a confirmation that a payment succeeded, its amount, and a reference. We do not see, store, or have any means of retrieving a card number.
Why we hold it
- To authenticate a voucher and enforce the plan that was bought.
- To bill a business correctly and to let them reconcile what their resellers owe.
- To keep a record of money movements, which we are obliged to retain.
- To investigate abuse of a network, when a business asks us to.
How long
Session and usage records are kept for the retention period configured for that business, which defaults to two years and can be shortened on request. Financial records are kept for as long as Nigerian law requires them, which is longer, and this takes precedence over a shorter setting.
Records of significant actions are append-only by design. They cannot be edited or deleted, including by us, because a record that can be quietly changed is not a record.
Who else sees it
- The business running the hotspot you used. They see the usage on their own sites and nothing from any other business. Businesses are isolated from each other at the database level, not by convention.
- Paystack, for payments.
- Google Cloud, which hosts the service.
- Nobody else. We do not sell personal data, we do not share it for advertising, and there is no advertising or analytics code on the page a hotspot customer sees.
Your rights under the Nigeria Data Protection Act
You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. We will respond within 30 days. A copy and a deletion can be produced directly by the business running the network you used, or by us; a correction is handled by us by hand, so tell us what is wrong and what it should say.
Deletion has one limit worth stating honestly rather than in small print: we cannot delete a financial record or an action log we are required to keep. Where that applies we remove or mask the personal details within the record instead of destroying the record, and we will tell you which parts were kept and why.
Security
Traffic to this site and to our service is encrypted. Router credentials and second-factor secrets are encrypted where they are stored. The service runs under a database role that cannot alter or remove financial and audit records, which is a limitation we impose on ourselves deliberately.
Contacting us
Use the contact details in the footer of this page. If you are a hotspot customer and your question is about a specific network, the business running that network is usually the faster route, and we will pass a request on to them where it is properly theirs to answer.