← ClubOps

Privacy Policy

Last updated: August 13, 2026

1. What we collect

CategoryExamplesWhy
Account dataName, username, email, phone, roleAuthentication, account management
Club/business dataClub name, address, products, prices, inventoryOperating the Service
Transaction dataSales, tabs, tips, procurement, payrollPOS/accounting functionality
Payment dataSubscription payment records, plan, billing statusBilling (card details are held by Paystack, never by us; see §4)
Biometric dataFacial-recognition descriptor (an encoded numeric representation, not a photo)Optional entry-logging feature (see §3)
Usage/security dataLogin timestamps, IP address, audit log of admin actionsSecurity, fraud prevention, lockout protection

2. Legal basis for processing

Under the NDPA 2023, we process account and transaction data on the basis of contractual necessity (you can't use a POS system without us processing sales data) and legitimate interest (security logging, fraud prevention). Biometric data is processed only on the basis of explicit consent (see §3).

3. Biometric data specifically

Facial-recognition data is classified as sensitive personal data under NDPA 2023 §2(f) / §30, with stricter consent and retention rules than ordinary personal data.
  • This feature is optional: a Club chooses whether to enable it.
  • Where enabled, the Club (as the party with the direct relationship to the individual being enrolled, whether staff or patron) is responsible for obtaining explicit, informed, opt-in consent before capture, and for being able to demonstrate that consent was given.
  • The individual has the right to withdraw consent and have their biometric data deleted; the Club is responsible for actioning that request in the system.
  • We store the mathematical descriptor only, not the source image, and do not use it for any purpose beyond the entry-logging feature the Club has enabled.

4. Third parties we share data with

PartyWhat they receivePurpose
PaystackPayment details for subscription billingPayment processing (we never see or store full card numbers)
ResendEmail address, transactional email contentSending account/welcome emails
ProStack NGAll application data (as the hosting infrastructure)Hosting the database and application

We do not sell personal data to third parties, and do not share it beyond what's needed to run the Service.

5. Data retention

  • Account and operational data is retained for as long as your Club's account is active.
  • On account closure, data is retained for 30 days to allow export and dispute resolution, then deleted.
  • Biometric data is deleted on request, or when the associated Club account closes, whichever is sooner.
  • Audit logs (admin actions) are retained separately for security purposes for a defined period.

6. Your rights (NDPA 2023)

Subject to verification of identity, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion; withdraw consent (for biometric data specifically); and lodge a complaint with the Nigeria Data Protection Commission (NDPC).

7. Security

Passwords are hashed, never stored in plaintext. Access to Club data is restricted by role. Administrative actions are logged. Data in transit is encrypted (HTTPS/TLS).

8. Children's privacy

The Service is intended for business use by nightclub staff and management, not for use by children. We do not knowingly collect personal data from anyone under 18.

9. Changes to this policy

We may update this policy from time to time. Material changes, especially anything affecting biometric data handling, will be communicated by email or in-app notice.

10. Contact

Privacy questions or data-subject requests: support@clubops.ng

ClubOps, a ProStackNG platform