Skip to content
Duka

Privacy Policy

Effective August 25, 2026

This policy explains what data Duka collects, why, and the rights you and your customers have over it, under the Nigeria Data Protection Act 2023 and, where applicable, the GDPR.

1. Who we are

Duka is operated by StiltTech, registered in Nigeria. For the account and business data you give us directly, we are the "data controller" under the Nigeria Data Protection Act 2023 (NDPA) and, where it applies, the EU/UK GDPR. For data your own customers give you through your storefront or POS, you are the controller and we process it only on your instructions — see Section 5.

2. Data we collect

  • Account & business data — your name, business name, email, phone number, and any tax or billing details you provide.
  • Catalogue & sales data — products, prices, stock levels, orders, and sales you or your staff enter.
  • Your customers' data — names, contact details, delivery addresses, and order history that your storefront or POS customers give you at checkout.
  • Payment data — transaction references, amounts, and status from Paystack, Flutterwave, or Opay. We never see or store full card or bank account numbers; the processor you choose handles that directly.
  • Usage & security data — IP address, login timestamps, device/browser information, and the security audit log (who did what, when).
  • Cookies — a single httpOnly session cookie that keeps you signed in. No advertising or analytics cookies are set today.

3. How we use it

  • Run the service: authenticate you, keep your catalogue and orders in sync between the storefront and POS, process payments.
  • Secure the service: enforce two-factor authentication on admin roles, log security-relevant actions, detect abuse.
  • Communicate with you: billing notices, order confirmations, and service updates.
  • Meet legal obligations: tax, financial, and regulatory record-keeping.

4. Legal basis for processing

We process account and business data because it's necessary to perform our contract with you (running your store), because we have a legitimate interest in keeping the platform secure and reliable, or because the law requires us to keep certain records (for example, transaction records for tax purposes). Where we ever rely on consent, such as for optional marketing email, you can withdraw it at any time.

5. Controller vs. processor

Duka is multi-tenant: every store's data is isolated from every other store at the database level (Postgres Row-Level Security). When it comes to your own customers' data, you decide what to collect and why — you're the controller, and we're the processor acting on your instructions. If one of your customers wants to exercise a data-protection right, they should contact you first; if you need our help fulfilling that request, email us.

6. Who we share data with

  • Payment processors — Paystack, Flutterwave, or Opay, whichever you enable, to process orders and your subscription.
  • Infrastructure providers — cloud hosting and object storage (for product images and files) that keep the service running.
  • Law enforcement or regulators — only when we're legally required to disclose information.

We do not sell your data or your customers' data, to anyone, ever.

7. International transfers

Our infrastructure and storage providers may process data outside Nigeria, including in the EU. Where that happens, we rely on the provider's standard safeguards (such as standard contractual clauses) to keep your data protected to the same standard as under this policy.

8. Data retention

We keep your data for as long as your account is active. If you close your account or ask us to delete your data, we purge it within 30 days of a verified request — except records that Nigerian tax and financial regulations require us to keep longer, such as transaction and invoice records, which we retain only for that purpose.

9. How we protect your data

  • Each store's data is isolated from every other store at the database level, not just in application code.
  • Data in transit is encrypted (TLS).
  • Passwords are hashed, never stored in plain text.
  • Two-factor authentication is mandatory for every admin-level role.
  • Security-relevant actions are recorded in an audit log.
  • Access to data is scoped by role, so staff only see what their job requires.

10. Your rights

Under the NDPA and, where it applies, the GDPR, you can ask us to: give you access to your data, correct it, delete it, restrict or object to our processing, or receive a copy in a portable format. To exercise any of these, email us below. If you're not satisfied with our response, you can lodge a complaint with the Nigeria Data Protection Commission (NDPC) or, for EU/UK residents, your local data protection authority.

11. Children

Duka is a business tool. It isn't directed at children, and we don't knowingly collect data from anyone under 18.

12. Changes to this policy

If we make a material change to how we handle your data, we'll update the effective date above and notify you by email or an in-app notice before it takes effect.

13. Contact us

Questions or requests about this policy: email privacy@duka.stilttech.com. We're StiltTech, operating in Nigeria.