Privacy Policy

In force from 9 October 2026.

1. Who we are

SabiLedger ("we", "us") is an online bookkeeping service for businesses. This policy explains what personal information we handle, why, and the choices you have, in line with Nigeria's Data Protection Act 2023.

We handle personal information in two ways:

  • For our own account holders - the people who sign in to SabiLedger. Here we decide how the information is used (we are the "controller").
  • On behalf of the businesses that use us - the records a business keeps about its own customers, students, parents, staff and suppliers. The business decides what is recorded and why (it is the controller); we keep and process it for them, only on their instructions (we are their "processor").

2. What we collect

  • About people who sign in: name, email address, phone number if given, a scrambled form of your password (never the password itself), sign-in times, and the sign-in codes we email you.
  • About each business: its name, type, address, logo and contact phone.
  • A business's records: whatever it records in SabiLedger - for example customers' and students' names and contact details, parents' details, sales, payments and debts. Some businesses also record ID numbers (NIN), vehicle details, passport photos and guarantor details, for example from applications sent through their own website.
  • Technical details: your device's internet address and the pages requested, kept briefly by our hosting provider for security and to stop abuse.

3. Why we use it

  • To provide SabiLedger: signing you in, keeping your business's records and doing what you ask (this is needed to perform our agreement with your business).
  • To keep accounts safe: sign-in codes, limits on repeated attempts, and an activity log (our legitimate interest in security, and yours).
  • To email you about your account, such as sign-in codes, approvals and password resets.
  • To meet legal obligations.

We do not sell personal information, show advertising, or use your business's records for our own marketing.

4. ID numbers, photos and other sensitive details

NINs and passport photos are encrypted before they're stored. Lists show only the last four digits of a NIN; the full number is shown only to people the business has allowed to see it, and every time someone views it, it's logged. Photos are only shown to people signed in to that business.

5. Who else handles it

We use a small number of trusted providers to run SabiLedger. Each only gets what it needs for its job:

  • Railway - hosts SabiLedger and its database, in a data centre in the Netherlands.
  • Resend - sends our emails (based in the United States).
  • Cloudflare - runs our web addresses, and the security check on forms sent from a business's own website.
  • Google Fonts - supplies the fonts our pages use; your browser asks Google for them, so Google sees your internet address.
  • Termii - only if a business switches on text messages: the business's texts go through its own Termii account.

We may also share information if the law requires it, or to protect people's safety.

6. Information stored outside Nigeria

Because our hosting is in the Netherlands and some providers are in the United States, information is stored and handled outside Nigeria. We only use providers that protect it to a standard at least as high as Nigerian law requires, under written agreements.

7. How long we keep it

  • Account and business records are kept while the business uses SabiLedger.
  • When a business's account is closed and deleted, its records are removed from SabiLedger straight away. They remain in our backups until those age out - backups are kept for up to 3 months - and are then gone.
  • A business can ask us to delete particular records sooner, for example applications it turned down.
  • Short-lived security records, such as sign-in attempt limits, are kept for hours or days.

8. How we protect it

  • Every connection is encrypted (HTTPS), and passwords are stored scrambled.
  • Two-step sign-in with a code by email or an authenticator app.
  • Each business's records are kept apart; nobody can see another business's records.
  • The business chooses what each of its people can do, and changes are logged.
  • Daily backups, with weekly and monthly copies.

9. Your rights

You can ask to see the personal information held about you, have it corrected or deleted, restrict or object to how it's used, get a copy to take elsewhere, and withdraw consent you've given. You can also complain to the Nigeria Data Protection Commission.

If a business using SabiLedger holds your details (for example a shop you buy from, or your child's school), please contact that business first - it decides what it records. We'll help it respond.

10. Cookies and your device

SabiLedger uses one cookie, to keep you signed in. It's needed for the service to work, so there's nothing to turn on or off. Your browser also remembers a few of your choices on your device, such as dark mode and how many rows a list shows. We don't use tracking or advertising cookies.

11. Children

People who sign in to SabiLedger must be 18 or older. Schools may record students' details; the school is responsible for having parents' permission to do so.

12. If something goes wrong

If personal information is ever exposed, we'll tell the businesses affected without delay and report it to the Nigeria Data Protection Commission within 72 hours, as the law requires.

13. Changes

If we change this policy, we'll update the date at the top and tell account owners about important changes before they apply.

14. Contact

Questions about privacy, or to use your rights: WhatsApp 0807 335 3405.