Privacy Policy
Last updated: June 2026
MYGRO Market Ltd (“MYGRO”, “we”, “our”, “us”) respects your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have. We comply with the Nigeria Data Protection Act (NDPA), 2023 and the Nigeria Data Protection Regulation (NDPR).
1. Information We Collect
Account info: name, email, phone number, role (buyer / vendor / rider / admin), profile picture.
Order info: products purchased, delivery address, GPS coordinates, payment method, transaction references.
Vendor / Rider KYC: store name, market location, vehicle details, government ID (for verification).
Device info: IP address, browser, app version, approximate location — used for fraud prevention and analytics.
Communication: chat messages with vendors, AI assistant queries, support tickets.
2. How We Use Your Information
To process orders, assign riders, calculate accurate delivery fees, and route your delivery in real time.
To verify vendor and rider identity, enforce platform safety, and prevent fraud.
To personalize product recommendations using the MYGRO AI assistant (powered by OpenAI GPT-5.2).
To send transactional notifications (order confirmations, delivery updates) via email, SMS, or WhatsApp.
To send marketing messages — only with your explicit opt-in, and you may unsubscribe at any time.
3. Sharing & Third Parties
We share necessary order details with the assigned vendor and dispatch rider (your name, phone, delivery address).
Payment processors: Paystack handles card / USSD / bank transfer payments. We never store your full card number.
AI services: Anonymized queries are sent to OpenAI to power smart search and the chat assistant. No personal identifiers are forwarded.
Legal: We may disclose information when required by Nigerian law or to protect MYGRO and our users.
We do not sell your personal data to advertisers.
4. Cookies & Tracking
We use essential cookies to keep you logged in and remember your cart. Analytics cookies (anonymous) help us understand which features matter most. You can disable non-essential cookies in your browser settings.
5. Data Retention
Account and order records are retained for as long as your account is active, plus 7 years after closure to satisfy Nigerian tax and consumer-protection record-keeping requirements (FIRS, CBN).
Chat messages and support tickets are kept for 24 months. AI conversation history is kept for 90 days.
6. Your Rights (NDPA)
You have the right to: access your data, correct inaccurate data, request deletion, object to marketing, and request a copy of your data in a portable format.
To exercise any of these rights, email privacy@mygromarket.com. We respond within 30 days.
7. Security
Passwords are hashed with bcrypt. All traffic is encrypted in transit (TLS 1.3). Payment data is processed by PCI-DSS-compliant Paystack — we never see or store full card details. Access to production data is restricted to authorized engineering staff and logged for audit.
8. Children's Privacy
MYGRO is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has signed up, please contact us so we can remove the account.
9. International Transfers
Some processing partners (Paystack, OpenAI, cloud hosting) operate servers outside Nigeria. We rely on standard contractual clauses and provider compliance certifications to safeguard your data during such transfers, in line with the NDPA.
10. Changes to This Policy
We will notify you of material changes via in-app notice or email at least 7 days before they take effect.
11. Contact Us
Data Protection Officer: privacy@mygromarket.com
General support: support@mygromarket.com · WhatsApp +2348088140744
See also our Terms of Service.