CardTap
Privacy Policy
Your privacy matters to us. This Privacy Policy explains how Lony Tech Solutions Limited collects, uses, protects and manages personal data when you use CardTap.
Effective Date: 7 October 2026
This Privacy Policy applies to CardTap, including the CardTap website, applications, application programming interfaces (APIs), merchant and partner interfaces, terminal-related services and other services provided as part of the CardTap platform.
CardTap is a product of Lony Tech Solutions Limited ("Lony Tech", "we", "us" or "our"). Lony Tech is responsible for determining how personal data is processed for the CardTap services where we act as the data controller.
By using CardTap, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will obtain it before processing your personal data on that basis.
1. Information We Collect
We collect only information that is reasonably necessary to operate, secure and improve CardTap and to meet applicable legal and regulatory obligations.
1.1 Account and Business Information
Where you create or manage a CardTap account, we may collect information such as:
- Full name and business or organisation name;
- Email address and telephone number;
- Business identification and registration information;
- Account credentials and authentication information;
- Business, merchant or partner identifiers;
- Terminal and device identifiers; and
- Other information required to establish and maintain your CardTap account.
1.2 Transaction Information
When CardTap is used to initiate or process a payment, we may process transaction-related information such as:
- Transaction reference or payment reference;
- Transaction amount and currency;
- Date and time of the transaction;
- Merchant, partner or terminal identifier;
- Transaction status and response information;
- Payment routing information; and
- Other information necessary to reconcile, investigate, secure or complete a transaction.
CardTap is designed to minimise the exposure of sensitive payment information. We do not intentionally collect or store complete card credentials, such as a card PIN, unless a particular payment integration expressly requires the processing of such information and the processing is lawful and appropriately protected.
1.3 NFC and Terminal Information
CardTap may interact with NFC-enabled cards, devices or payment terminals as part of a payment flow. Depending on the payment integration, the information processed may include technical identifiers, tokenised payment information, transaction references or other data required to initiate or authenticate a transaction.
CardTap does not use NFC functionality to access unrelated information stored on a user's device or card. NFC access is used only for functionality supported by the CardTap payment flow and permitted by the applicable device and payment integration.
1.4 Technical and Usage Information
We may automatically collect limited technical information when you use CardTap, including:
- IP address;
- Browser and device type;
- Operating system;
- Application or platform version;
- Device and terminal identifiers;
- Login and authentication events;
- Error and diagnostic information; and
- Security and fraud-prevention events.
2. How We Use Personal Data
We may use personal data for the following purposes:
- Creating and managing CardTap accounts and partner relationships;
- Processing and routing payment transactions;
- Generating and reconciling transaction records;
- Operating terminals and payment integrations;
- Authenticating users and securing accounts;
- Detecting, preventing and investigating fraud, abuse and unauthorised activity;
- Providing customer and technical support;
- Monitoring system performance and reliability;
- Improving CardTap products and services;
- Maintaining audit and security records;
- Complying with applicable laws and regulatory requirements;
- Responding to lawful requests from competent authorities; and
- Establishing, exercising or defending legal claims where necessary.
3. Lawful Basis for Processing
Depending on the circumstances, we may process personal data on one or more lawful bases recognised under applicable data protection law, including:
- Performance of a contract — where processing is necessary to provide CardTap services requested by you;
- Legal obligation — where processing is required by applicable law or regulation;
- Legitimate interests — where processing is necessary for legitimate business, security, fraud prevention or service-improvement purposes and those interests do not override applicable privacy rights; and
- Consent — where applicable law requires consent or where we otherwise choose to rely on consent.
4. Payment and Infrastructure Providers
CardTap may integrate with payment processors, banks, payment networks, technology providers and other infrastructure providers to enable payment processing and related services.
Where a transaction is processed through third-party payment infrastructure, relevant transaction information may be transmitted to the applicable provider for purposes such as payment authorisation, routing, settlement, reconciliation, fraud monitoring and regulatory compliance.
These providers may process personal data independently or on our behalf depending on the nature of the service and the applicable contractual and legal relationship.
5. Service Providers and Data Processors
We may engage trusted third-party service providers to support CardTap operations. These providers may provide services such as:
- Cloud hosting and infrastructure;
- Database and storage services;
- Application monitoring and security;
- Communication and notification services;
- Customer support;
- Payment processing and financial infrastructure; and
- Fraud prevention and security services.
Where appropriate, we require service providers processing personal data on our behalf to maintain appropriate confidentiality, security and data protection obligations.
6. Data Sharing
We do not sell personal data.
We may disclose personal data where reasonably necessary to:
- Provide CardTap services;
- Process or reconcile transactions;
- Protect CardTap users and our systems;
- Comply with applicable legal, regulatory or court requirements;
- Respond to lawful government requests;
- Investigate suspected fraud, security incidents or misuse;
- Protect our rights, property, users or the public; or
- Facilitate a corporate transaction such as a merger, acquisition, restructuring or sale of assets, subject to applicable law.
7. International Data Transfers
Some CardTap infrastructure or service providers may process data outside Nigeria. Where personal data is transferred across borders, we will take reasonable steps to ensure that the transfer and subsequent processing are carried out in accordance with applicable data protection requirements.
Depending on the circumstances, appropriate contractual, technical or other safeguards may be used for international transfers.
8. Data Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, destruction or other unlawful processing.
Security measures may include:
- Encryption of data in transit;
- Access controls and authentication;
- Role-based access to systems and information;
- Monitoring and security logging;
- Infrastructure and application security controls;
- Backup and recovery mechanisms; and
- Security testing and incident-management procedures.
No internet-based service can guarantee absolute security. You are also responsible for protecting your account credentials, devices and authentication information.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing services, maintaining transaction records, resolving disputes, enforcing agreements, preventing fraud and complying with legal, regulatory and accounting obligations.
When personal data is no longer required, we may securely delete, anonymise or otherwise dispose of it in accordance with our retention procedures and applicable law.
10. Cookies and Similar Technologies
The CardTap website may use cookies or similar technologies that are necessary for website functionality, security, preferences, analytics or service improvement.
Where required, we will provide appropriate controls for managing non-essential cookies. Disabling certain cookies may affect some website functionality.
11. Your Data Protection Rights
Subject to applicable law and any lawful limitations, you may have rights relating to your personal data, including the right to:
- Be informed about the processing of your personal data;
- Request access to personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion or erasure of personal data where applicable;
- Request restriction of processing in applicable circumstances;
- Object to certain processing activities;
- Request data portability where applicable;
- Withdraw consent where processing relies on consent; and
- Lodge a complaint with the relevant data protection supervisory authority.
These rights are not absolute and may be subject to lawful exceptions, including circumstances where we are required to retain or process information to comply with legal or regulatory obligations.
12. How to Exercise Your Rights
To submit a privacy or data protection request, contact the CardTap privacy team through the official contact details published on the CardTap website.
To protect your account and personal information, we may need to verify your identity before processing certain requests.
We will handle valid requests within the period required by applicable law and will explain where a request cannot be fulfilled or is subject to a lawful restriction.
13. Children and Minors
CardTap is a business and payment technology platform and is not intended for individuals who are below the minimum age permitted to independently use the applicable service under applicable law.
We do not knowingly collect personal data from children for purposes unrelated to the provision of our services.
14. Third-Party Websites and Services
CardTap may contain links to websites or services operated by third parties. Those third parties may have their own privacy policies and terms.
We are not responsible for the privacy practices of third-party websites or services that we do not control. We recommend reviewing their privacy notices before providing personal information.
15. Data Breaches and Security Incidents
We maintain procedures for identifying, assessing, investigating and responding to suspected personal-data security incidents.
Where applicable law requires notification of a personal data breach to affected individuals or a regulatory authority, we will make the required notification within the applicable timeframe.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in CardTap, our processing activities, technology, legal requirements or regulatory guidance.
When we make material changes, we may provide additional notice through the CardTap website, application or other appropriate communication channel.
The "Effective Date" at the beginning of this Privacy Policy indicates when the current version became effective.
17. Contact Us
If you have questions about this Privacy Policy, want to exercise a data protection right, or have a privacy-related concern regarding CardTap, please contact Lony Tech Solutions Limited through the official contact information published on the CardTap website.
Privacy and Data Protection
CardTap is committed to responsible data handling and privacy-by-design principles. We aim to collect only the information necessary to provide secure and reliable payment services and to protect the confidentiality and integrity of the information entrusted to us.
© 2026 Lony Tech Solutions Limited. All rights reserved.