Privacy Policy
Version: v2-2026-09-19
1. What this policy covers
How GadVerify collects, stores, uses, and shares information from three groups of people: anonymous visitors using the device check, individuals who register a public account to report a device, register ownership, or track a case, and business accounts and their staff who subscribe to the business platform.
2. Information we collect
- Device check: the IMEI or serial number you enter, and standard request metadata (IP address, timestamp) kept briefly for rate limiting and abuse prevention. No account or personal details are required.
- Public account or device report: name, email or phone, the device details you report (IMEI, IMEI2, serial, brand and model, storage, color), the state and local government area where the device was lost/stolen, an incident description, and optional contact details for follow up.
- Business account: business name and registration details, owner and employee names, emails, and phone numbers, role and permission assignments, inventory and device identifiers, sales and customer transaction records, supplier and pricing data, payroll records for staff you employ, and subscription and billing metadata (not full card numbers; payment is handled by our payment provider).
- Authentication: password (stored hashed, never in plain text), one time codes sent to your email or phone for login and security verification, and, if you choose to use them:
- Sign-in with Google: your name, email address, and Google account identifier, used only to create or sign in to your account. We never receive or store your Google password.
- Passkeys: a cryptographic public key tied to your device's own fingerprint, face, or screen-lock sensor. We never receive, see, or store your actual fingerprint, face data, or device PIN — that stays on your device; we only ever hold the public key half of the pair, which is useless without the device that created it.
3. How we use it
To operate the verification and reporting service; to let a business run its inventory, sales, staff, and payroll operations; to detect and prevent fraud, stolen device circulation, and abuse; to send account, security, and subscription related notifications where applicable; and to maintain the audit trail described below.
4. What a device check reveals, and what it never reveals
A device check returns only a confidence tiered result: whether the device matches an active report, and how strong that match is. It never reveals the identity, contact information, or any other private detail of the person or business that filed the report. A business's own sales amounts, customer data, and inventory are never visible to another business; the only thing that ever crosses the boundary between businesses is a redacted stolen device match.
5. Cookies and similar technologies
We use a small number of strictly necessary cookies and browser storage entries to keep you signed in, protect your session, and remember basic preferences (such as which branch you're viewing in the business dashboard). We do not use third-party advertising or cross-site tracking cookies. Where your browser supports it, a passkey's public key is stored by your device or browser, not by us, using the WebAuthn standard.
6. Audit logging
Security relevant and stolen device relevant actions (who flagged a device, who checked one, who changed a permission, login attempts) are recorded in an audit log with the acting user, timestamp, and action, kept to investigate disputes, fraud, and account security, and available to platform administrators and, for a business's own activity, that business's owner.
7. Sharing
We do not sell personal data. Data is shared only: with our payment provider to process subscription payments; with our email and SMS providers solely to deliver account and one time code messages; with Google, solely to confirm your identity if you choose "Continue with Google"; in redacted form through the stolen device check described above; and where required by law or a valid legal request.
8. International hosting
GadVerify's infrastructure may be hosted on servers located outside Nigeria. Where this applies, we take reasonable steps to ensure any such transfer is protected to a standard consistent with Nigerian data protection law.
9. Retention
Account data is kept while your account is active. Transaction, sales, and payroll records are retained after account closure as required for financial recordkeeping and to preserve the historical accuracy of past receipts and reports (changing a price or setting later never rewrites what a past receipt or report actually said). Device reports remain checkable by reference number even without an account, so that a device's status stays verifiable regardless of what happens to the reporting account.
10. Your rights
Subject to the Nigeria Data Protection Act 2023 and other applicable law, you may request a copy of the personal data we hold about you, ask us to correct inaccurate data, object to certain processing, request a portable copy of your data, or request deletion of your account, subject to what must be retained for the legal, financial, and dispute resolution reasons described above (for example, a stolen device report already relied on by other users is not silently deleted). Use the contact details on our Contact page to make these requests.
11. Security
Passwords are hashed, not stored in plain text; sensitive actions require re-authentication or a second factor where enabled; business data is isolated at the database query level, so one business's data is never returned by another business's requests; and we take reasonable technical and organizational measures to protect your information. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
12. Children
GadVerify is intended for business use and for adults managing their own devices, and is not directed at, or knowingly used to collect data from, anyone below the minimum age stated in our Terms & Conditions.
13. Changes to this policy
We may update this policy from time to time. Accepting it at registration is recorded against your account, tied to the version shown above. If this policy changes in a way that matters, a new version will require accepting it again.
14. Governing law
This policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023 and other applicable data protection legislation.
This document is a working draft prepared for internal review and has not yet been reviewed or approved by a licensed attorney. It should not be treated as final or legally binding until that review is complete.