Privacy Policy

Privacy Policy for Arvices

Last Updated: May 31, 2026

Arvices ("we", "our", "us", or the "Platform") is committed to protecting your privacy and safeguarding your personal data. This Privacy Policy outlines our rigorous practices regarding the collection, use, processing, storage, disclosure, and protection of your data when you interact with the Arvices ecosystem—including our mobile applications, web platforms, browser interfaces, and automated WhatsApp conversational integrations (collectively, the "Service").

By accessing or using the Service, you explicitly consent to the data practices described in this Privacy Policy, which is structured in strict compliance with the Nigeria Data Protection Act (NDPA) and other applicable consumer protection frameworks.


1. Data Controller and Statutory Authority

For the purposes of applicable data protection legislation, the data controller is Arvices. We process all personal data lawfully, fairly, and transparently based on explicit user consent, contractual necessity, legal obligations, or legitimate business interests.


2. Information We Collect and Process

To deliver an automated, conversational service and commerce marketplace, we must ingest several streams of data. The types of information we collect depend entirely on how you interact with our platform (whether as a consumer seeking services/products or as an onboarded Service Provider/Vendor).

2.1 Information You Provide Directly to Us

  • Account Identity Data: Full legal name, verified mobile phone number, secondary contact lines, and email address collected during registration.
  • Conversational & AI Interaction Data: Complete text inputs, voice prompts, structured messages, media attachments, and intent queries provided to the Arvices AI concierge engine across all channels (Web, Mobile, and WhatsApp).
  • Financial & Wallet Data: While credit/debit card numbers are handled externally, we collect and retain internal wallet balances, withdrawal history, payout bank account details, and localized transaction ledger data.
  • Provider Verification Data (Service Providers & Vendors Only): To protect the physical and financial safety of our ecosystem, we collect government-issued identification (e.g., National Identification Number [NIN], Driver’s License, or International Passport). *Note: Identification data is strictly utilized via secure, authorized third-party APIs for identity confirmation and fraud prevention; *

2.2 Automated Information & Infrastructure Logging

  • Precise Geographical Location Data: We collect precise real-time latitude and longitude coordinates from your mobile device or IP address. This data is mandatory to power our automated proximity matching engine, calculate dynamic distance metrics, and facilitate local commerce delivery logistics.
  • Technical Device Data: IP addresses, device hardware models, operating system versions, push notification tokens, unique device identifiers, and system crash logs used for performance optimization.
  • Webhook & Communication Metadata: Timestamps, message delivery statuses, and routing identifiers stemming from our integrations with external conversational gateways (e.g., Meta/WhatsApp API frameworks).

2.3 User-Generated Content (UGC)

  • Public portfolio images, workspace photographs, item catalogs, service descriptions, pricing tables, public ratings, and written reviews posted to our "Showcase" or "Explore" feeds.

3. Detailed Mechanisms of Data Utilization

Arvices utilizes your personal data to execute core platform logic, optimize AI performance, and fulfill statutory legal mandates. Specifically, your data is used for:

  • Automated Matching & Service Fulfillment: Utilizing precise location data and conversational prompts to connect consumers with nearby artisans, mechanics, or merchants in real time.
  • Conversational AI Optimization: Passing anonymized or structured textual queries to our AI sub-processors to interpret intent, generate live offers, and automate appointment bookings seamlessly.
  • External Network Outreach: Using our infinite fulfillment loop to convert natural language queries into automated outreach templates that can communicate with independent local providers to fulfill unique user requests.
  • Regulatory Compliance & Invoice Generation: Structuring transaction details to format legal documents and comply with active electronic invoicing directives issued by the Federal Inland Revenue Service (FIRS) and other state-level tax boards.
  • Trust, Safety, and Security: Executing automated risk profiles, scanning chat logs for platform circumvention or fraudulent behavior, verifying provider backgrounds, and mitigating cybersecurity threats.

4. Disclosures and Sharing of Personal Data

We do not sell, rent, or lease your personal information to third-party data brokers. Your data is shared exclusively with the following categories of recipients to fulfill contractual workflows:

  • Payment Infrastructure Partners: All payment processing is managed securely via Paystack (a PCIDSS-compliant gateway). We share transaction metadata with Paystack to complete secure checkouts and process merchant payouts.
  • AI Infrastructure Sub-processors: To power our conversational automation features, textual prompts and intent blocks are securely transmitted to advanced large language model APIs (such as Google Gemini). These models process contextual text prompts strictly under data protection agreements that prohibit them from using your personal data to train public baseline models.
  • Communication Network Providers: Message payloads, media files, and notification statuses are securely processed through Meta/WhatsApp API endpoints if you choose to run your service requests through our WhatsApp messenger integrations.
  • Marketplace Counterparties: Your profile name, specific service address, and telephone number are shared with a Service Provider or Vendor only after a booking or purchase is explicitly confirmed, accepted, and cleared by our matching loop.

5. Data Security & Infrastructure Guardrails

Arvices implements strict technical and organizational safeguards to prevent accidental loss, unauthorized access, alteration, or disclosure of your data:

  • Data in Transit: All web traffic, API calls, and webhook communications are encrypted using modern Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols.
  • Data at Rest: Critical data strings, authentication hashes, and personal profiles are shielded using industry-standard AES-256 database encryption.
  • DevOps Best Practices: We employ secure, isolated container architectures, automated dependency scanning, strict environment-variable isolation, and restricted microservice communication paths.
  • User Responsibility: While we maintain strict firewalls, you are solely responsible for securing your personal device, app login credentials, and WhatsApp account verification codes.

6. Retention and Deletion Frameworks

6.1 User-Initiated Deletion

You have the right to request the complete deletion of your Arvices account at any time through our native in-app settings menu or by reaching out to our privacy compliance desk.

6.2 Regulatory Retention Mandates

Please note that certain core data segments cannot be instantly wiped upon account termination. Pursuant to Nigerian financial regulations, anti-money laundering (AML) acts, and national tax accounting laws, all transaction records, fiscal logs, electronic invoicing histories, and related identity verification strings will be retained in our secure archives for a period of up to seven (7) years following account closure before permanent disposal.


7. Your Statutory Rights Under the NDPA

As a data subject interacting within the Federal Republic of Nigeria, you possess extensive statutory rights regarding your personal information. These include:

  • Right of Access and Portability: You may request a clean, machine-readable export of all personal data we hold about your profile.
  • Right to Rectification: You can update or correct inaccurate, outdated, or incomplete account records at any time.
  • Right to Object to Automated Decision-Making: You have the right to challenge, question, or request a human review of automated matching choices or algorithmic scoring rules if they significantly affect your account standing.
  • Right to Erasure ("Right to be Forgotten"): You can request the removal of data assets where there is no overriding legal or regulatory reason to keep processing them.
  • Right to Withdraw Consent: You can pull back your processing consent at any time. Note that doing so will limit your ability to use our conversational AI pipelines.

To exercise any of these statutory rights, please submit a formal data subject request to our Data Protection Compliance Team.


8. Third-Party Links & Cross-Platform Boundaries

Our Service may dynamically display maps, contain hyperlinks to external merchant storefronts, or route your queries to public business listings. We do not control, manage, or audit the privacy frameworks of these external platforms. We highly recommend reviewing the individual privacy policies of any external website or service you choose to engage with through Arvices.


9. Revisions to this Privacy Policy

Arvices reserves the right to adjust, update, or rewrite this Privacy Policy at our sole discretion. When significant operational adjustments occur, we will post the changes here, update the "Last Updated" timestamp at the top of this document, and issue a direct notification through our mobile app channels or via WhatsApp. Continued interaction with the Platform following an update serves as binding acceptance of the revised privacy terms.


10. Contact Information & Redress

For any questions, data deletion requests, or compliance inquiries regarding this policy, please contact us:

  • Email: [email protected]
  • Response Time: Our privacy desk reviews and responds to all valid data protection inquiries within forty-eight (48) business hours.