Skip to content
Kpali
  • Services
  • App
  • Business
  • Contact

Draft — under legal review. Bracketed items marked [to be completed before launch] are placeholders, not omissions by accident. Everything else on this page describes what the software actually does today.

Legal

Privacy Policy

Last updated: 5 September 2026 · Draft

This policy says what Kpali collects, why, who else sees it, where it is kept and how to have it removed. It describes the app as built, not as planned — where something is not built yet, it says so.

1 · Who we are

Kpali is operated by [company legal entity and registration — to be completed before launch]. In this policy, "Kpali", "we" and "us" mean that company, and "you" means the person using the service. That company is the data controller for the information described here.

2 · What we collect

Only what the service needs to work. In full:

  • Your phone number. Given at sign-up. It identifies your account and is the number a receipt or a support reply refers to.
  • An email address, if you give one. Optional. Used for receipts and account mail, and to match a store-credit purchase made on our website to your account — nothing else.
  • A device key. Your device generates a secret and keeps it in the phone's own secure hardware storage. We store only a one-way hash of it — enough to recognise your device, never enough to reconstruct the key or use it elsewhere.
  • Session records. Which devices are signed in, when they enrolled, failed unlock attempts, and any lockout — so a lost phone can be locked out.
  • People you save. If you save someone to pay again, we keep the name you chose for them, the country, the provider, and the account, meter or phone number being paid. The full number is stored so the payment can be made; it is masked whenever it is displayed or sent back to your app.
  • Your orders. What was bought, the amount and currency, the category, when it was placed, what the provider answered, and any adjustment or rerouting we disclosed to you at the time.
  • Your balance ledger. Every credit and debit against your store credit. This is an append-only financial record.

3 · What we do not collect

Stated plainly, because absence is worth as much as disclosure:

  • No analytics, advertising or tracking software. The app contains no analytics SDK, no advertising SDK and no third-party tracker. We do not profile you and we do not build an advertising identity.
  • No location data. The app never asks for your location.
  • No access to your contacts. People you save are typed in by you.
  • No identity documents. There is no identity-verification flow in the app today. When one is added it will use a BVN — a number checked against your bank account — and not a photographed document. This policy will be updated before that ships.
  • We never sell your data. Not to anyone, for any purpose.

4 · Permissions the app asks for

  • Face ID / fingerprint. Checked by your phone, on your phone. The result never leaves the device and we never receive your biometric data.
  • Camera and photos. Requested only if you sell a gift card, so you can attach a picture of it. Nothing is read from your photo library unless you pick it.

Both are asked for at the moment they are needed, and the app works without granting them.

5 · Who else sees your data

To deliver what you buy, the details of that purchase go to the company that fulfils it — and only the details needed to fulfil it. Today those are:

  • vtu.ng — Nigerian airtime, data, television and electricity. Receives the number, meter or account being paid.
  • Bitrefill — gift cards and vouchers.
  • DT One — international airtime and data.
  • eSIM Access — eSIM plans.
  • Bitnob — deposit addresses, where deposits are enabled.
  • Our bank-transfer processor — naira bank transfers, in the app and on the website. It receives the amount, the payment reference and, for a purchase made on the website, the email address you typed into the form.
  • Resend — sends transactional email, and therefore handles your email address and the contents of receipts we send you.
  • Neon — hosts the database described in section 6.

We share the minimum each one needs, and we do not give any of them your data for their own marketing. We may also disclose information where the law requires it, or to investigate fraud against you or us.

6 · Where your data is kept

Your data is stored in Germany. The Kpali servers run in Nuremberg and the database is hosted in Frankfurt. If you are in Nigeria or elsewhere outside the European Union, this means your information is transferred to and processed in the EU, which applies data-protection standards at least equivalent to those you are entitled to at home.

Some providers listed in section 5 operate in other countries, so a purchase you make may be processed where that provider operates.

7 · How long we keep it

  • Your account and orders — for as long as your account exists, and afterwards for as long as financial-record and anti-fraud rules require us to keep them.
  • The balance ledger — it is append-only and is not edited or deleted, because it is the record of money moving. Closing your account does not erase it.
  • Sessions — until they expire or you sign the device out.
  • People you save — until you delete them.

8 · Your rights

You can ask us to show you what we hold about you, correct anything wrong, delete what we are not legally required to keep, or send you a copy of your data. Write to privacy@kpali.app and we will answer within 30 days.

Where a financial record must legally be retained, we will tell you which parts we cannot delete and why, rather than refusing the whole request.

If you are in Nigeria you may also complain to the Nigeria Data Protection Commission. If you are in the EU or UK, to your local data-protection authority. [regulatory registrations and representative details — to be completed before launch]

9 · How we protect it

  • Everything between your phone and our servers travels over an encrypted connection (HTTPS/TLS). The app talks to no other host.
  • Your device key lives in your phone's hardware-backed secure storage, marked so that it is readable only while the phone is unlocked and never migrated to another device in a backup or restore.
  • We store only a hash of that key, never the key.
  • Account numbers are masked everywhere they are shown or returned to the app.
  • Repeated failed unlock attempts lock the device out.

No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator, without waiting to be asked.

10 · Children

Kpali is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has an account, write to us and we will remove it.

11 · Changes to this policy

If we change what we collect or who we share it with, we will update this page and change the date at the top. Where the change is significant we will tell you in the app before it takes effect, rather than relying on you to re-read this page.

12 · Contact

Questions about privacy, or to make a request under section 8: privacy@kpali.app. General enquiries: contact@kpali.app. [postal address of the operating company — to be completed before launch]

© 2026 Kpali. Draft — under legal review. See also the Terms & Conditions.