Emisi

Privacy Policy

How Emisi handles your data

Last updated: 1 September 2026

1. Who we are

Emisi (“we”, “us”, “our”) operates a marketplace connecting buyers with independent sourcing agents (“OGs”) who source and deliver goods on request. This policy explains what personal data we collect, why, and what rights you have over it, in line with the Nigeria Data Protection Act/NDPR.

Data controller: Olatoye Dhikrullah Kayode, trading as Emisi, of Coral Court Hub, Lekki, Lagos, Nigeria

Contact for privacy matters: graphwellintellect@gmail.com

2. What we collect

If you're a buyer

  • Email address, phone number (account creation/login)
  • Delivery address and delivery instructions, per order
  • Order history and items requested

If you're an OG (sourcing agent)

  • Email address, phone number
  • Display name and profile information you provide (bio, primary market)
  • Identity verification documents: a government-issued ID, a selfie, and (optionally) a proof of address - required once, to verify you're a real, accountable person before you can fulfil orders. These are stored privately and are only ever viewed by Emisi admins for verification purposes, never made public, and every admin view is logged.

For everyone

  • Password (stored as an irreversible cryptographic hash - we never see or store your actual password)
  • Session information (a login cookie, expires automatically after 7 days)
  • Standard technical/log data our hosting provider collects for any web request (IP address, browser type) - used for security and abuse prevention, not for tracking you across other sites

Payment-related

Emisi's current payment method is manual bank transfer: you transfer funds to Emisi's own bank account and report the transfer; an admin manually verifies it against our bank statement. We do not collect or store your own bank account details - only Emisi's own account information (shown to you at checkout) and a reference number you provide.

3. Why we collect it

  • To create and manage your account, and let you use the marketplace (contract necessity).
  • To match buyers with OGs, process orders, and arrange delivery.
  • To verify an OG's identity before they can accept real orders - a trust and safety requirement central to how the marketplace works.
  • To detect and prevent fraud, abuse, and unauthorized access (e.g. rate-limiting login attempts).
  • To resolve disputes between buyers and OGs, with a full record of what happened.
  • Where required, to comply with our legal obligations.

4. Who we share it with

We don't sell your data. We share it only with:

  • The other party to your transaction, in a limited way: a buyer sees their assigned OG's display name and public profile info, never their phone/email. An OG sees a buyer's delivery address and order details needed to fulfil the order, never the buyer's account email/phone directly.
  • Service providers who help us run Emisi (all under their own data protection obligations):
    • Neon (database hosting) - stores all the data described above
    • Cloudflare R2 (file storage) - stores OG verification documents, privately, never publicly accessible
    • Vercel (application hosting)
    • Sentry (error monitoring) - may incidentally capture technical details when something breaks, to help us fix it
    • Upstash (rate limiting) - briefly processes IP addresses to prevent login abuse
  • Law enforcement or regulators, only if legally required to.

5. How long we keep it

We keep your account and order data for as long as your account is active, and for 7 years after account closure or your last transaction, to meet financial and tax record-keeping obligations. After that period, we will delete or anonymize it. At this stage this is a manual process an admin performs on request, not yet an automated one.

6. Your rights

Under Nigerian data protection law, you can:

  • Ask what personal data we hold about you
  • Ask us to correct inaccurate data
  • Ask us to delete your data (subject to legal retention requirements)
  • Object to certain uses of your data

To exercise any of these, contact us at graphwellintellect@gmail.com. At this stage, requests are handled manually by an admin.

7. Security

We take reasonable technical measures to protect your data: passwords are hashed, not stored in plain text; identity documents are stored privately with access logged; connections to the site are encrypted (HTTPS); administrative actions are recorded in an audit trail. No system is perfectly secure, but we take this seriously.

8. Changes to this policy

We may update this policy as Emisi evolves. Material changes will be reflected by updating the “Last updated” date above - we don't currently send a separate notification for each change, given our small scale, but you're welcome to check back periodically.

9. Contact

graphwellintellect@gmail.com