How Vine e-ID collects, uses, stores, and protects your personal data.
Last updated: 18 June 2026 · Effective date: 18 June 2026
Vine e-ID ("Vine", "we", "us", or "our") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our mobile application, website, APIs, and related services (collectively, the "Services").
We operate in accordance with the Nigeria Data Protection Regulation (NDPR) 2019, the Nigeria Data Protection Act 2023, and applicable international data protection frameworks including the EU General Data Protection Regulation (GDPR) where relevant to cross-border processing.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of our Services.
We collect only the data necessary to provide secure digital identity services. The categories of personal data we may process include:
We do not collect more data than is necessary for the purpose for which it is processed. Sensitive personal data, including biometric information, receives enhanced protection and is processed only with your explicit consent or as required by law.
We use your personal data for the following purposes:
We apply data minimisation and purpose limitation principles — your data is used only for the specific purposes described above and not for unrelated processing without your consent.
Under the NDPR and applicable law, we process your personal data on the following bases:
We do not sell your personal data. We may share your information only in the following circumstances:
All third-party processors are required to implement appropriate technical and organisational measures and process data only on our documented instructions.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements.
When data is no longer needed, we securely delete or anonymise it in accordance with our data retention and destruction policies.
As a data subject under the NDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete personal data.
Request deletion of your data where legally permitted.
Limit how we use your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or direct marketing.
Withdraw consent at any time where processing is consent-based.
File a complaint with NITDA or another supervisory authority.
To exercise any of these rights, contact our Data Protection Officer at privacy@vine-eid.ng. We will respond within 30 days as required by the NDPR.
Vine e-ID is incorporated in Nigeria and primarily processes data within Nigeria. Where we transfer personal data outside Nigeria — for example, to cloud infrastructure providers or international partners — we ensure appropriate safeguards are in place, including:
Our Services are not directed at children under the age of 18. We do not knowingly collect personal data from minors without verifiable parental or guardian consent. If you believe we have inadvertently collected data from a minor, please contact us at privacy@vine-eid.ng and we will take steps to delete such information promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email or in-app notification.
The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of our Services after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Our Data Protection team is available to help with access requests, data deletion, and any privacy-related concerns.