Privacy Policy

Last updated: June 2026

This Privacy Policy describes how Kovaus Technologies Ltd ([TODO RC number], [TODO registered address], “Kovaus”, “we”, “us”) collects, uses, shares, and protects personal data when you use the Kovaus platform - the websites at kovaus.com and its subdomains, and any services we provide through them.

We process personal data in accordance with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation (NDPR), and we are accountable to the Nigeria Data Protection Commission (NDPC). If you are accessing Kovaus from outside Nigeria, your data will be processed in Nigeria and in the locations of our service providers listed below.

1. Who this policy applies to

  • Guests - people who browse Kovaus, save listings, and make bookings.
  • Hosts - people who create listings and receive bookings on Kovaus.
  • Visitors - anyone who visits the site without an account.

2. What we collect

You give us directly:

  • Account data: name, email, phone, password (hashed), profile photo.
  • Host data: legal name, payout bank details (held by our payment processor), listing media and descriptions, property addresses.
  • Booking data: check-in / check-out dates, number of guests, communications with the host.
  • Verification data: any ID or document you supply during identity verification or host onboarding.
  • Support data: messages you send through our chat widget or support form.

We collect automatically:

  • Device and log data: IP address, browser type, OS, referrer, timestamps, pages viewed.
  • Approximate location derived from IP - we do not use device GPS.
  • Cookies and similar tracking technologies - subject to your consent. See our Cookie Policy.

We receive from third parties:

  • Payment confirmation and transaction status from Paystack.
  • Map and geocoding lookups from OpenStreetMap / Nominatim when you enter a property address.

3. Why we process it (lawful basis)

  • Contract - to provide the platform, process bookings, calculate commissions, and pay hosts.
  • Legal obligation - to keep transaction records, respond to lawful requests, and meet tax or anti-money-laundering rules.
  • Legitimate interest - to keep the platform secure, prevent fraud, improve features, and run aggregated analytics.
  • Consent - to send marketing emails and to load non-essential cookies. You can withdraw at any time.

4. Who we share it with (processors and third parties)

We do not sell your personal data. We share it with the following categories of recipient, only as necessary for the listed purpose:

RecipientPurposeLocation
PaystackPayment processing and host payoutsNigeria / South Africa
CloudinaryListing photo and 360 tour hostingUSA / EU
Cloudflare R2File storageGlobal edge network
ResendTransactional email delivery (OTPs, booking confirmations)USA
Tawk.toSupport chat (loaded only with marketing consent)USA
VercelWeb hosting, page-view analyticsUSA / EU
Google Analytics 4Aggregated usage measurement (consent-gated)USA
PostHogProduct funnels and diagnostics (consent-gated)USA / EU
Meta PlatformsAd attribution via Pixel and Conversions API (consent-gated)USA / EU
OpenStreetMap / NominatimGeocoding addresses to map coordinatesGermany

Where a recipient is outside Nigeria, transfers are made under safeguards permitted by the NDPA, which may include standard contractual clauses, the recipient's own adequacy decision, or your explicit consent. We will share the specific mechanism on request.

We also share data with hosts and guests as necessary for a booking - for example, a host sees the guest name and contact details after booking confirmation.

5. How long we keep it

  • Account data - while your account is active, and up to 12 months after closure for fraud-prevention and dispute purposes.
  • Booking and payment records - 7 years, to meet Nigerian tax and accounting obligations.
  • Verification documents - only for the duration of the tenancy or booking that required them, then deleted.
  • Audit logs - 24 months, then anonymised.
  • Marketing data - until you withdraw consent or unsubscribe.

6. Your rights

Under the NDPA you may:

  • Request access to the personal data we hold about you.
  • Ask us to correct inaccurate data, or complete incomplete data.
  • Ask us to delete your data (subject to our legal retention obligations above).
  • Object to processing based on legitimate interest, including for direct marketing.
  • Withdraw consent at any time, including by clicking “Reset preferences” on our cookie policy.
  • Request a copy of your data in a portable, machine-readable format.
  • Lodge a complaint with the Nigeria Data Protection Commission if you believe we have mishandled your data.

To exercise any of these rights, email privacy@kovaus.com. We will respond within 30 days.

7. Security

We protect personal data with measures appropriate to the risk: passwords are hashed with industry-standard algorithms, data is encrypted in transit, access is gated by role and permission, and changes to records are audit-logged. No system is perfectly secure - if a breach occurs that affects your personal data, we will notify you and the NDPC within 72 hours as required by the NDPA.

8. Children

Kovaus is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact privacy@kovaus.com and we will remove it.

9. Changes to this policy

We update this policy when our practices change. The “Last updated” date at the top reflects the most recent revision. For material changes we will notify registered users by email or in-app.

10. Contact

Data Protection Officer: privacy@kovaus.com
Registered office: [TODO registered address]
Or use our support page.