How we collect, use, and protect your information — clearly explained.
On This Page
1. Who We Are 2. What We Collect 3. How We Use It 4. Who We Share With 5. Cookies & Tracking 6. Referral Tracking 7. WhatsApp & SMS 8. API & Webhooks 9. Data Retention 10. Security 11. Your Rights 12. Children's Privacy 13. Third-Party Links 14. International Users 15. NDPR Compliance 16. Policy Changes 17. Contact DPOKredo, operated by Ifeony Innovations (RC: 2984583, Victoria Island, Lagos, Nigeria), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard information when you use our platform, in compliance with Nigeria's National Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023.
Kredo is a business management SaaS platform operated by:
As a data controller, we determine the purposes and means of processing your personal data. Where you store your customers' data on Kredo, we act as a data processor on your behalf.
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Full name, business name, profile photo | You (registration / profile) |
| Contact Data | Email address, phone number, business address | You (registration / profile) |
| Authentication Data | Hashed password, Google/LinkedIn OAuth tokens | You (registration) / OAuth providers |
| Financial Data | Revenue figures, invoice amounts, expense records | You (business activity) |
| Transaction Data | Payment references, subscription records, billing cycle | You + Paystack |
| Technical Data | IP address, browser type, device info, session ID | Automatic (platform logs) |
| Usage Data | Pages visited, features used, actions, timestamps | Automatic |
| Customer Data | Your customers' names, emails, phone numbers, purchase history | You (CRM input) |
| Staff Data | Staff names, roles, contact info, HRM records | You (staff management) |
| Communications | Support ticket content, messages sent to us | You |
| Referral Data | Referral / affiliate code, referring partner ID | URL parameter + cookie |
| API Usage Data | API keys generated, webhook endpoints, request logs | You (API configuration) |
We do not collect special categories of sensitive data (health information, biometrics, political opinions, or religious beliefs). We do not knowingly collect data from individuals under 18 years of age.
We process your data under the following legal bases:
Specific uses include:
We do not sell your personal data. We share data only in the following circumstances, and only to the extent necessary:
All third-party processors are bound by appropriate data processing agreements. We do not share your data with advertisers.
Kredo uses only the following types of cookies and local storage:
kredo_ref): Store an affiliate/referral code (if you arrived via a referral link) for up to 30 days to attribute registrations to the correct partner. See Section 6 below.We do not use advertising cookies, cross-site tracking cookies, Google Analytics, Facebook Pixel, or any third-party analytics or remarketing scripts on our platform.
If you visit any Kredo page via a referral link (e.g., trykredo.com?ref=PARTNERCODE), the referral code is:
kredo_ref) on your device for up to 30 daysThis cookie is used solely to attribute any account registration you complete within 30 days to the referring affiliate partner, so they receive appropriate commission. No personal data is shared with affiliate partners as part of this tracking — only an anonymized commission event is recorded on our end.
You may clear your cookies at any time to remove referral tracking.
When you use Kredo to send WhatsApp messages or SMS notifications to your customers, the following applies:
If you use the Kredo Developer API (Growth and Business plans):
We retain your data for as long as your account is active, plus the additional periods required by law:
We implement robust technical and organizational measures to protect your data:
HttpOnly, SameSite=Lax, and Secure (HTTPS-only)X-Frame-Options, X-Content-Type-Options, HSTS)Under Nigeria's National Data Protection Regulation (NDPR) and the Nigeria Data Protection Act (NDPA) 2023, you have the following rights regarding your personal data:
To exercise any of these rights, email hello@trykredo.com with the subject line “Data Rights Request”. We will acknowledge your request within 5 business days and respond fully within 30 days.
Kredo is strictly a business management tool intended for adults aged 18 and over. We do not knowingly collect, solicit, or process personal data from anyone under 18 years of age. If we become aware that we have inadvertently collected data from a minor, we will delete it immediately and notify the relevant guardian where required.
The Kredo platform may contain links to or integrations with third-party websites and services, including Paystack, WhatsApp, Google, LinkedIn, and WooCommerce. We are not responsible for the privacy practices, content, or security of these external sites. We encourage you to review their respective privacy policies before sharing any personal information with them.
Kredo is primarily designed for Nigerian and African businesses. If you access our platform from outside Nigeria, please be aware that your data will be transferred to and processed in Nigeria. By using our Service, you consent to this transfer. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy regardless of where it is processed.
Kredo operates in full compliance with:
We have appointed a Data Protection Officer (DPO) who can be reached at hello@trykredo.com. We conduct regular Data Protection Impact Assessments (DPIAs) for high-risk processing activities. Our data processing activities are documented and available for regulatory inspection upon lawful request.
You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng if you believe your rights under Nigerian data protection law have been violated.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or platform features. For material changes, we will notify you via email to your registered address at least 14 days before the changes take effect. Minor updates will be reflected in the “Last Updated” date above.
We encourage you to review this page periodically. Your continued use of Kredo after the effective date of a revised Privacy Policy constitutes acceptance of the changes.
For any privacy-related queries, data rights requests, or to report a suspected breach: