Privacy Policy
Last updated 20 Sept 2026
Last updated: 6 September 2026
GiftCardNigeria is an independent editorial publication that tests and reviews gift card trading platforms serving Nigerian users. This Privacy Policy explains what personal data we collect, why we use it, who may process it for us, how long we keep it and the choices available to you.
This policy applies to visitors, newsletter subscribers, authors, researchers, fact-checkers, administrators and anyone who contacts us about our content or their privacy.
GiftCardNigeria is the data controller for the personal data covered by this policy. Questions and requests can be sent to admin@giftcardnigeria.com.
1. The principles we follow
We handle personal data in line with the Nigeria Data Protection Act 2023. We collect data for clear purposes, limit collection to what we need, keep information accurate where necessary, restrict access and retain it only for as long as there is a valid reason.
We do not sell personal data. We do not use newsletter addresses for advertising by other companies. GiftCardNigeria does not currently use advertising pixels or non-essential analytics trackers.
2. Personal data we collect
The information we hold depends on how you interact with GiftCardNigeria.
Website visitors
When you visit the website, our hosting and security systems may automatically process limited technical information. This may include your IP address, browser and device type, requested pages, access time, referral page, approximate location derived from an IP address, and security or error logs.
We use this information to deliver the website, prevent abuse, diagnose faults and maintain security. We do not currently use it to build advertising profiles.
Newsletter subscribers
When you subscribe to the monthly rates report, we collect your email address, subscription status and the time of your subscription. We may also record information needed to manage delivery, such as whether an email was delivered or whether you unsubscribed.
Submitting the newsletter form gives us permission to send the report to the address provided. Every newsletter email includes a way to unsubscribe.
Authors, researchers and fact-checkers
We collect the information needed to identify editorial contributors and document their work. Depending on the person’s role, this may include:
Name, work email address and role.
Profile photograph and published biography.
Links to published work.
Research assignments and testing-cycle identifiers.
Test notes, form responses, timestamps and evidence-folder links.
Internal editorial comments, fact-check records and approval history.
Account and access information for authorised CMS users.
Published author profiles contain only the details approved for public display. Internal contact, account and research information is restricted to authorised users.
Platform-testing records
A platform test may produce screenshots, transaction times, rates, payout information, correspondence with support and researcher notes. Evidence can incidentally contain personal data such as a name, email address, phone number, bank name, partial account information or a platform username.
We restrict access to the original evidence. Before publishing selected evidence, we remove gift card codes and PINs, bank and account details, private transaction identifiers, login information and unnecessary personal data.
Enquiries, corrections and complaints
If you email us about a correction, complaint, editorial question or privacy request, we receive the information you provide. This usually includes your email address, your name if supplied, the page or issue concerned, your message and any supporting links or attachments.
Please do not send gift card codes, passwords, full bank details or other information that is not needed to assess your request.
Administrative accounts
Authorised CMS users provide information needed to create and secure an account, including an email address, name, password credentials handled by our authentication provider, role, permissions and activity records. Audit logs may record actions such as publishing, editing, restoring or deleting content.
3. Why we use personal data
Purpose | Typical data | Lawful basis |
|---|---|---|
Delivering and securing the website | Device, server, access, security and error information | Legitimate interests in operating a secure and reliable publication |
Sending the monthly rates report | Email address and subscription status | Consent |
Managing authors and editorial contributors | Name, role, contact information, profile and work records | Contractual necessity or legitimate interests, depending on the relationship |
Testing and reviewing platforms | Research forms, notes, timestamps, screenshots and transaction evidence | Legitimate interests in producing accurate and accountable editorial work |
Operating the CMS | Account, permission, login and audit information | Contractual necessity and legitimate interests in access control and accountability |
Handling corrections, complaints and privacy requests | Identity, contact details, correspondence and supporting evidence | Legitimate interests and legal obligations |
Establishing or responding to legal claims | Relevant correspondence, audit records and evidence | Legal obligations and legitimate interests |
Where we rely on consent, you can withdraw it. Withdrawal does not make earlier processing unlawful. Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights outweigh our reason for using the data.
4. Newsletter choices
The newsletter is optional. We use the email address supplied through the subscription form to send the monthly rates report and necessary messages about that subscription.
You can unsubscribe through the link in a newsletter email or by contacting admin@giftcardnigeria.com. After you unsubscribe, we stop sending the newsletter. We may retain the minimum information needed to record and honour the opt-out.
GiftCardNigeria currently stores newsletter subscriptions in Supabase. No separate newsletter-delivery platform is connected at the date shown above. If that changes, we will assess the provider and update this policy where necessary.
5. Cookies, local storage and similar technology
GiftCardNigeria does not currently use advertising cookies or non-essential analytics trackers.
The website may use essential cookies or local storage to provide security, maintain authorised admin sessions, remember necessary settings and support basic site functions. Blocking essential technology may prevent parts of the website or CMS from working properly.
6. Social-media and video embeds
Platform review pages may show third-party material from TikTok, YouTube, Instagram or X. These services can receive information about your device, browser, IP address and activity when their content loads.
GiftCardNigeria uses a click-to-load approach. The external post or video is not loaded merely because you opened the review page. If you choose to load it, your browser connects to that provider and its own privacy rules apply. You should review the provider’s policy before loading the content if you have concerns about its data practices.
A social-media post appearing on GiftCardNigeria does not mean that we endorse it.
7. Service providers and other recipients
We use trusted providers to operate the website and manage editorial work. They process information only for the relevant service and under their own contractual and security responsibilities.
These providers include:
Supabase, which provides database, storage and authentication services.
Website-hosting and delivery providers.
Form providers used to collect structured research responses.
Restricted file-storage providers used for screenshots and testing evidence.
Documentation and collaboration providers used for drafts, review and editorial records.
Email and communications providers used when someone contacts us.
We may disclose information when required by law, a valid court order or an authorised regulator. We may also disclose the minimum information necessary to investigate fraud, protect users, defend legal rights or respond to a serious security incident.
We do not give reviewed platforms access to a researcher’s private information merely because they disagree with a review.
8. Processing outside Nigeria
Some service providers may store or process data outside Nigeria. Where this happens, we assess the transfer and use safeguards required by applicable Nigerian data-protection law. The protection applied may depend on the destination, the provider and the type of information involved.
You can contact us if you want more information about an international transfer affecting your personal data.
9. How long we keep information
We apply different retention periods because the information serves different purposes.
Newsletter information is kept while you remain subscribed. After an opt-out, we retain only the minimum record needed to honour it.
Routine technical and security logs are kept only as long as needed for operation, troubleshooting, fraud prevention and security.
CMS account and audit information is kept while access is active and for an appropriate period afterwards to protect the publication and investigate misuse.
Correction, complaint and privacy correspondence is kept while the matter is handled and for a reasonable period afterwards where it may be needed for accountability or legal claims.
Editorial test records and evidence are retained as part of a restricted research archive while needed to support published findings, corrections, scoring history and fact-checking.
Personal information within archived evidence is removed, redacted or restricted when keeping it is no longer necessary.
Legal, regulatory, security or dispute-related requirements may sometimes require longer retention.
10. Security
We use access controls, authenticated admin accounts, restricted storage, audit records and redaction procedures to reduce the risk of unauthorised access, alteration, loss or disclosure.
No website or storage system can promise absolute security. Contributors and administrators are expected to protect their credentials and report suspected unauthorised access promptly.
If a personal-data breach occurs, we investigate it, limit further exposure and make any notifications required by Nigerian law.
11. Your rights
Subject to the Nigeria Data Protection Act and any lawful exceptions, you may ask us to:
Explain whether and how we process your personal data.
Give you access to personal data we hold about you.
Correct inaccurate or incomplete information.
Delete information that no longer has a lawful reason to be kept.
Restrict certain processing.
Provide eligible information in a portable format.
Stop processing based on legitimate interests where your circumstances justify an objection.
Stop direct marketing.
Withdraw consent.
Explain and request human review of a decision based solely on automated processing where applicable.
GiftCardNigeria does not currently use solely automated decisions that produce legal or similarly significant effects on public visitors or subscribers.
Some rights are not absolute. For example, we may need to retain information required by law, needed to protect another person’s rights or necessary to establish or defend a legal claim.
12. Making a privacy request
Send requests to admin@giftcardnigeria.com. Explain what you want us to do and identify the email address or interaction concerned.
We may request enough information to confirm your identity and prevent another person from gaining access to your data. We do not ask for more identification than is reasonably necessary.
We respond within the period required by applicable law. If a request is unusually complex or affects another person’s rights, we will explain any lawful extension or limitation.
13. Complaints
If you believe GiftCardNigeria has mishandled your personal data, contact admin@giftcardnigeria.com so we can investigate.
You may also complain to the Nigeria Data Protection Commission. Its current contact and complaint information is available at ndpc.gov.ng.
14. Children’s privacy
GiftCardNigeria is not directed at children and does not knowingly collect personal data from them. If you believe a child has submitted personal information to us, contact the editorial team so we can review and remove it where appropriate.
15. External websites
Our reviews and guides link to reviewed platforms, app stores, social networks and other external websites. Their privacy practices are separate from ours. GiftCardNigeria is not responsible for how another organisation collects or uses information after you leave our website or choose to load its content.
16. Changes to this policy
We update this Privacy Policy when our services, data practices or legal obligations change. The latest revision date appears at the top of the page. Where a change materially affects how we use existing personal data, we will provide an appropriate notice and seek fresh consent when required.
17. Contact
For questions, privacy requests or complaints, email admin@giftcardnigeria.com.