NDPA 2023 · GDPR Aligned

Privacy Policy & Data Protection

Effective date: 9 June 2026. This policy explains how KoboSync collects, uses, and safeguards your information when you use our Service.

01

Who we are

KoboSync(“KoboSync”, “we”, “our”, “us”) operates the web application available at http://kobosync.com (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

KoboSync is registered and operated in the Federal Republic of Nigeria. We process data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and, where applicable, the General Data Protection Regulation (GDPR).

02

Information we collect

2.1 Information you provide

  • Account information: your name, email address, and phone number when you create an account.
  • Business information: bridge names, Google Sheet IDs, and payment gateway API keys (stored encrypted at rest using AES-256-GCM).
  • Financial configuration: VAT settings, account mappings for Xero/QuickBooks, and currency preferences.

2.2 Information received from third parties

  • Payment gateway webhooks: transaction references, amounts, customer emails, and metadata as sent to us by Paystack, Flutterwave, or Monnify on your behalf. We do not store full card numbers or bank account details.
  • Google OAuth & Merchant API: your Google account email and an OAuth refresh token that allows us to write to your Google Sheets and programmatically manage your Google Merchant Center account (Content API for Shopping) on your behalf. We request only the minimum scopes required to synchronize your inventory, product data, and pricing.
  • Bank feed providers (Mono/Okra): read-only transaction history from your connected bank account. We never receive your banking credentials — authentication is handled entirely by Mono or Okra.

2.3 Information collected automatically

  • Server logs including IP addresses, request timestamps, and HTTP status codes for security and debugging purposes. These are retained for a maximum of 90 days.
  • Error and performance telemetry via Sentry (anonymised where possible).
03

How we use your information

We use the information we collect to:

  • Provide, operate, and improve the Service.
  • Process incoming payment webhooks and write reconciled transaction data to your Google Sheets.
  • Synchronize inventory, product pricing, and margin intelligence labels securely with Google Merchant Center.
  • Send you operational notifications such as daily financial briefings, product intelligence alerts, and system health warnings that you have explicitly configured.
  • Synchronise transaction and expense data to accounting platforms (Xero, QuickBooks) where you have authorised this integration.
  • Verify your identity and prevent fraud or unauthorised access.
  • Comply with legal obligations, including tax record-keeping requirements under Nigerian law.

Google API Limited Use Compliance: KoboSync's use and transfer to any other app of information received from Google APIs will strictly adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google API data to develop, improve, or train generalized or personalized AI/ML models.

We do not sell your personal data to third parties. We do not use your financial transaction data for advertising purposes.

04

Legal basis for processing (NDPA / GDPR)

  • Contract performance: processing necessary to deliver the Service you have subscribed to.
  • Legitimate interests: security monitoring, fraud prevention, and service improvement.
  • Consent: sending marketing communications (you may withdraw consent at any time).
  • Legal obligation: retaining financial records as required by applicable Nigerian tax and accounting law.
05

Data retention

We retain your account data for as long as your account is active. Transaction records and financial data are retained for a minimum of 6 years in accordance with Nigerian tax record-keeping requirements.

Server logs are retained for 90 days. Webhook delivery logs are retained for 90 days. OAuth tokens and cached Google Merchant Center data are deleted immediately upon disconnecting an integration or upon explicit user request. You may revoke KoboSync's access at any time via your Google Account Security settings.

You may request deletion of your account and associated data at any time by emailing legal@kobosync.com. Financial records that we are legally required to retain will be anonymised rather than deleted.

06

Data sharing and disclosure

We share your data only with the following categories of third parties, strictly for the purposes of providing the Service:

  • Google LLC — to write data to your Google Sheets and synchronize catalogs with Google Merchant Center via Google APIs.
  • Supabase Inc. — database and authentication infrastructure.
  • Vercel Inc. — application hosting.
  • Resend Inc. — transactional email delivery.
  • Twilio Inc. — WhatsApp notification delivery (Pro plan only).
  • Xero Limited / Intuit Inc. — accounting data synchronisation (where you have enabled this integration).
  • Mono Technologies / Okra Technologies — bank feed data retrieval (where you have enabled this integration).
  • Sentry Inc. — error monitoring (anonymised data only).

We do not disclose your data to any other third party except where required by law or with your explicit written consent.

07

Security

We implement technical and organisational measures appropriate to the sensitivity of the data we process:

  • All API keys and OAuth tokens are encrypted at rest using AES-256-GCM before storage.
  • All data in transit is protected by TLS 1.2 or higher.
  • Webhook signatures are verified using HMAC-SHA512 before any data is processed.
  • Access to production systems is restricted to authorised personnel via multi-factor authentication.

No method of transmission over the internet is 100% secure. We will notify you without undue delay if we become aware of a breach that is likely to result in a risk to your rights and freedoms.

08

Your rights

Under the NDPA and, where applicable, GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate personal data.
  • Erase your personal data (subject to legal retention requirements).
  • Restrict or object to our processing.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email legal@kobosync.com. We will respond within 30 days.

09

Cookies, Children, Changes & Contact

Cookies

We use strictly necessary session cookies to maintain your authenticated session. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

Children

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.

Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email and by posting a notice on the Service at least 14 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

Contact our Data Protection Officer

KoboSync

Lagos, Nigeria

legal@kobosync.com

Your Rights at a Glance

Access: Request a copy of your data
Rectification: Correct inaccurate records
Erasure: Ask us to delete your data
Restriction: Limit how we process your data
Portability: Get your data in JSON/CSV
Withdraw consent: Opt out of marketing anytime
Email our DPO

We respond within 30 days

Key Data Processors

Google APIsSheets & GMC Sync
SupabaseDatabase & Auth
VercelApp Hosting
ResendEmail Delivery
TwilioWhatsApp (Pro)
SentryError Monitoring
RailwayBackground Workers