Privacy Policy

Last updated [TO CONFIRM — date of review]

Draft — under legal review

This document describes how Quira Ledger is built to work, but it hasn't yet been reviewed by our legal advisers. If anything here matters to a decision you're making, please ask us rather than relying on it.

This policy explains what Quira Ledger collects, why, and what you can ask us to do about it. It covers the marketing site, the billing area, and the application itself.

Quira Ledger is operated by Quira Resource Tech [TO CONFIRM — full registered name, RC number and registered address]. For anything in this policy, contact [TO CONFIRM — privacy contact address].

Two kinds of data

The distinction matters throughout this document. Account data is about you and your organization — it's how we know who you are and what you're paying for. Business data is what you put into the system: your sales, stock, customers, suppliers and staff records. That data is yours. We hold it so the service can work, and we don't use it for anything else.

What we collect

When you create an account

  • Your name and email address
  • Your business name, country and contact details
  • A password, stored only as a cryptographic hash — we can't read it

When you use the application

  • The business records you create: sales, inventory, invoices, journal entries
  • Records about people you employ, where you use the payroll features
  • An audit trail of significant actions and who performed them

Automatically

  • IP address, browser and device type, and pages visited
  • Error and performance logs, which may contain the URL that failed
  • Cookies strictly necessary for signing in and keeping you signed in

What we never hold

We do not store card numbers, CVVs or bank credentials. Payments happen on Paystack's or Flutterwave's own pages, and what comes back to us is a reference, an amount and a status.

Why we hold it

  • To provide the service — the core of our contract with you
  • To bill you — issuing invoices, taking payment, chasing what's overdue
  • To support you — answering questions, diagnosing faults
  • To keep the service secure — detecting abuse, investigating incidents
  • To meet legal obligations — tax and accounting records we're required to retain

We do not sell your data, we do not share it with advertisers, and we do not use your business data to build products for anyone else.

Who else processes it

We use a small number of providers to run the service. Each has access only to what their job requires.

  • Paystack — payment processing for customers billed in naira
  • Flutterwave — payment processing for customers billed in US dollars
  • [TO CONFIRM — hosting provider and region] — where the application and database run
  • [TO CONFIRM — email provider] — sending invoices, receipts and account emails

We may also disclose data where the law requires it, or to establish or defend a legal claim. Where we can lawfully tell you first, we will.

Where it's held

Our infrastructure is located in [TO CONFIRM — region]. Where data is transferred outside Nigeria, we rely on [TO CONFIRM — transfer mechanism] and take the steps required by the Nigeria Data Protection Act 2023.

How long we keep it

  • Your business data — for as long as your account is open. After you close it, we keep it for [TO CONFIRM — e.g. 30 days] so you can change your mind or export it, then delete it.
  • Billing records — retained for [TO CONFIRM — statutory retention period] because tax law requires it, even after an account closes.
  • Technical logs — [TO CONFIRM — e.g. 90 days].

Your rights

Under the Nigeria Data Protection Act 2023, you can ask us to:

  • Tell you what we hold about you, and give you a copy
  • Correct anything that's wrong
  • Delete data we no longer have a reason to keep
  • Stop or limit a particular use
  • Provide your data in a portable format

Write to [TO CONFIRM — privacy contact address]. We'll respond within [TO CONFIRM — response window]. If you're not satisfied, you can complain to the Nigeria Data Protection Commission.

One note on scope: where you hold data about your own staff or customers inside Quira Ledger, you are the controller of that data and we act on your instructions. Requests from those individuals should go to you, and we'll help you answer them.

Security

Data is encrypted in transit. Passwords are hashed. Access to production systems is restricted to staff who need it, and significant actions leave an audit trail. No system is perfect, and we won't claim otherwise — if a breach affects you, we'll tell you and the regulator as the law requires.

Cookies

We use cookies that are necessary for the service to function: keeping you signed in, remembering which organisation you're working in, and protecting forms against cross-site request forgery. [TO CONFIRM — whether any analytics are in use. If yes, they need naming here and a consent banner.]

Children

Quira Ledger is a business tool and isn't intended for anyone under 18. We don't knowingly collect data from children.

Changes

If we change this policy in a way that materially affects you, we'll email the account owner before it takes effect. The date at the top always reflects the current version.