Privacy Policy
How VendStack handles personal data — both our merchants' and the customers who buy through their channels.
Last updated 24 August 2026
The short version. VendStack is middleware. Merchants run the wallets and do the vending; we carry the conversation between their customers and their backend. We keep the least we can to make that work and to prove what happened. We never store transaction PINs — they pass through to the merchant and are masked everywhere we log.
1. Who this covers
This policy applies to Cloudence Limited (“VendStack”, “we”, “us”) and to vendstack.com.ng, our merchant dashboard, and the USSD, WhatsApp, Telegram and SMS channels we operate on behalf of merchants.
It describes two different relationships, and the difference matters:
- Merchants. When you sign up for VendStack, we are the data controller for your account. We decide what we collect about your business and why.
- Your customers. When someone dials your USSD code or messages your WhatsApp, Telegram or SMS channel, they are your customer. You are the data controller; we are your data processor, acting on your instructions. If one of your customers asks about their data, they should ask you — and we will help you answer.
2. What we collect
From merchants
- Account details: name, business name, email address, password (hashed, never readable), and email-verification status.
- Website and channel configuration: brand names, product selections, keywords, sub-codes, and the credentials you give us for your own channels (WhatsApp tokens, Telegram bot tokens, Merchant API secrets). Secrets are encrypted at rest and never displayed back to you.
- Billing records: subscriptions, wallet balance and transactions, virtual account details issued to you for funding, referral earnings.
- Usage: dashboard sign-in times, actions taken, and support correspondence.
From your customers, on your behalf
- Their phone number, and on Telegram their chat ID, which we map to a phone number so the merchant API stays keyed the same way on every channel.
- The content of messages they send to your channel, and the replies we send back.
- Transaction metadata: what was bought, the amount, the recipient number or meter/smartcard number, the reference, and whether it succeeded.
- Names and addresses returned by a biller when we verify a meter or smartcard, so a customer can confirm they are paying the right account.
- Voice notes sent to a channel, transcribed to text so the assistant can read them.
- For channels running the AI assistant: the message text and the structured intent the model produced, logged for auditing every decision that touched money.
What we never store
- Transaction PINs. A PIN is passed straight to your backend for validation and is never written to a session, a log or a database. Where a raw channel payload is kept — USSD callbacks and SMS messages — PIN segments are replaced with
[pin]before the record is written. - Card details or bank credentials. We never ask for them and never touch them.
- Customer wallet balances. We display what your backend returns; we don't keep our own copy.
3. Why we process it
| Purpose | Lawful basis |
|---|---|
| Running the channels a merchant has enabled, and completing the transactions their customers ask for | Performance of a contract |
| Fraud, velocity and abuse controls — blocking a number, capping daily spend | Legitimate interest, and legal obligation where it applies |
| Keeping an audit trail of every action that moved money | Legal obligation and legitimate interest |
| Billing merchants, and preventing non-payment | Performance of a contract |
| Support: answering "did my customer's message reach you?" | Legitimate interest |
| Service emails to merchants — receipts, low balance, expiry warnings | Performance of a contract |
We do not sell personal data, we do not use it for advertising, and we do not profile customers for marketing.
4. Who we share it with
Only with the parties needed to deliver the service, and only what they need:
| Recipient | What they receive | Why |
|---|---|---|
| The merchant whose channel was used | Everything relating to their own customers' transactions | It's their customer and their sale |
| Meta Platforms (WhatsApp Business Cloud API) | Phone numbers and message content on WhatsApp | To deliver WhatsApp messages |
| Telegram | Chat IDs and message content on Telegram | To deliver Telegram messages |
| Africa's Talking | Phone numbers and USSD session input | To run the USSD shortcode |
| SMS Gate, on handsets we operate | Phone numbers and message text on SMS | To send and receive text messages |
| Anthropic (Claude) | The text of a customer's message, on AI-enabled channels only | To work out what the customer is asking for. Not used to train models. |
| Billers and verification providers | A meter or smartcard number | To confirm the account before a payment is made |
| Payment providers issuing merchant virtual accounts | Merchant business details | To let merchants fund their VendStack wallet |
| Hosting and infrastructure providers | Data at rest and in transit | To run the platform |
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over a merchant's data, we will tell that merchant unless we are legally barred from doing so.
5. Where data is held
Our infrastructure is hosted with providers who may store or process data outside Nigeria. Where that happens we rely on the transfer mechanisms permitted under the Nigeria Data Protection Act 2023 — including contractual safeguards with each provider. Messaging platforms (Meta, Telegram) operate their own global infrastructure and process message content under their own terms.
6. How long we keep it
| Record | Kept for |
|---|---|
| Merchant account and billing records | The life of the account, then as long as tax and company law requires |
| Transaction audit records | The life of the merchant's account — they are the record of what happened to someone's money |
| Raw USSD callbacks and SMS message logs | 30 days by default, then automatically deleted |
| AI decision logs | Retained for auditing decisions that touched money, and deleted with the merchant's account |
| Conversation sessions in progress | Minutes — they expire on their own and are deleted when a transaction ends |
| Voice notes | Not retained; transcribed and discarded |
7. Security
- All traffic runs over TLS.
- Merchant API secrets, channel tokens and gateway credentials are encrypted at rest.
- Passwords are hashed with bcrypt; nobody at VendStack can read them.
- Calls to a merchant's backend are signed with HMAC so the merchant can verify the request genuinely came from us. Inbound webhooks are signature-verified and replay-protected.
- Access to production data is limited to the people who need it, and administrative actions are recorded in an audit log.
- Every action that moves money requires an explicit confirmation and a PIN validated by the merchant — never by us, and never by the AI.
No system is perfectly secure. If a breach affects personal data we will notify the NDPC and affected merchants without undue delay, and give merchants what they need to notify their own customers.
8. Rights
Under the Nigeria Data Protection Act 2023 you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You may also complain to the Nigeria Data Protection Commission.
If you are a merchant, write to privacy@cloudence.com.ng and we will respond within 30 days.
If you are a customer of one of our merchants, your request belongs with that merchant — they decide what happens to their customer data. Send it to them; if you're not sure who they are, we can point you in the right direction. Where a merchant instructs us to delete or export a customer's data, we act on it.
9. Cookies
The dashboard uses only what it needs to function: a session cookie to keep you signed in, a CSRF token to protect forms, and a “remember me” cookie if you ask for one. There are no advertising or third-party tracking cookies on the dashboard. Clearing them signs you out.
10. Children
VendStack is a service for businesses and is not directed at children. Merchants should not knowingly enable their channels for anyone under 18.
11. Changes
We will update this page when our practices change, and change the date at the top. If a change materially affects how we handle personal data, we will email merchants before it takes effect.
12. Contact
Privacy questions and data requests: privacy@cloudence.com.ng
Anything else: support@cloudence.com.ng
Cloudence Limited
14 Justice Bode-Vivour Cresent, Jahi