Aparte Technologies Limited (RC 0000000), of Lagos, Nigeria, is the data controller for personal data processed through the Aparte website and mobile applications (the Platform). This policy explains how we handle that data under the Nigeria Data Protection Act 2023 (NDPA) and other applicable law.
The short version
We collect what we need to run bookings safely — who you are, what you booked, and what you paid. We never see or store your card number. We do not sell your personal data. You can ask us for a copy of your data, or ask us to delete it, at any time.
1.What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, phone number, password (stored only as a hash), profile photo, role (Guest, Host or Admin). | You, at sign-up. |
| Verification data | Government-issued ID document (NIN, international passport, driver's licence or voter's card) and a selfie, from both Guests and Hosts. Address, business registration and bank account details, from Hosts. | You — Guests before their first booking, Hosts during onboarding. |
| Listing and vehicle data | Property address, photographs, description, pricing, availability, vehicle registration and particulars. | Hosts. |
| Booking data | Dates, guest counts, prices and fee breakdown, booking status, check-in codes, caution deposit records, cancellations and refunds. | Generated as you use the Platform. |
| Payment data | Transaction reference, amount, status, payment method type, last four digits of the card, and payout bank details for Hosts. | Our payment processor. We never receive or store full card numbers or CVVs. |
| Communications | Messages between Guests and Hosts, support conversations, and the notifications we send you. | You and other users. |
| Device and usage data | IP address, device model and operating system, app version, login sessions and known devices, pages and screens viewed, crash and error reports. | Collected automatically. |
| Location data | Approximate location from your IP address, and — on mobile, only if you grant permission — device location used to show nearby listings and to power map search. | Your device. |
We do not deliberately collect special-category data such as health or religious belief. Please do not include it in messages or listing descriptions.
2.Why we use it, and our lawful basis
| Purpose | Lawful basis under the NDPA |
|---|---|
| Create and maintain your account; authenticate you; send one-time codes. | Performance of a contract with you. |
| Take bookings, collect payment, calculate fees, hold and release caution deposits, pay Hosts. | Performance of a contract with you. |
| Share the details a Guest and Host need to complete a booking. | Performance of a contract with you. |
| Verify the identity of Guests and Hosts before a booking is made, screen for fraud, investigate misuse, and keep the Platform safe. | Legitimate interest in a safe marketplace, and legal obligation. |
| Provide customer support and resolve disputes. | Performance of a contract, and legitimate interest. |
| Diagnose crashes, measure how features are used, and improve the product. | Legitimate interest, and consent where required for analytics cookies. |
| Send service messages about your bookings. | Performance of a contract with you. |
| Send marketing about new features or offers. | Consent. You can withdraw it at any time. |
| Meet accounting, tax, anti-money-laundering and other legal obligations. | Legal obligation. |
3.Payment information
Card payments are processed by Paystack, a licensed payment service provider. When you pay, your card details are entered directly into Paystack's secure form and transmitted to them — they do not pass through Aparte servers and we do not store them.
We receive and keep only what we need to reconcile a booking: the transaction reference, amount, currency, status, method type and the last four digits of the card. Paystack processes your card data as an independent controller under its own privacy policy.
For Hosts, we store the bank account number, bank code and verified account name needed to send payouts.
5.International transfers
Some of our providers store or process data outside Nigeria. Where that happens we rely on the transfer mechanisms permitted by the NDPA — an adequacy decision by the Nigeria Data Protection Commission, or contractual safeguards obliging the recipient to protect the data to an equivalent standard. You can ask us for details of the safeguards that apply to a particular transfer.
6.How long we keep it
- Account data — for as long as your account is open, and up to 24 months after closure so we can handle disputes and repeat sign-up abuse.
- Booking, payment and payout records — at least 6 years after the booking, to meet accounting and tax obligations.
- Identity verification documents — the ID image and selfie are deleted 14 days after your check is approved. We keep only a record that the check happened: the type of document, who reviewed it and when. A submission that was not accepted is deleted 90 days after the decision, so you have time to query it. This applies to Guests and Hosts alike.
- Messages — for as long as the account is open, and for the duration of any dispute.
- Caution deposit records — kept with the booking record. The deposit itself is held only until release, 72 hours after the stay ends unless a claim is raised.
- Analytics and crash data — typically 12 months.
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.
7.Your rights
Under the NDPA you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your data, where we have no overriding legal reason to keep it.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimate interest is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interest, and to direct marketing at any time.
- Withdraw consent — where processing relies on consent, withdraw it without affecting what was done beforehand.
To exercise any of these, email privacy@stayaparte.com. We will respond within 30 days. We may ask you to verify your identity first — that check protects your data from someone impersonating you.
If you are unhappy with our response you may complain to the Nigeria Data Protection Commission (NDPC).
8.How we protect it
- Data is encrypted in transit with TLS, and at rest in our database and file storage.
- Passwords are stored only as salted hashes. Nobody at Aparte can read your password.
- Access to the Platform uses short-lived access tokens with separate refresh tokens, and we track known devices and active sessions so you can end one you do not recognise.
- Uploaded files — identity documents, listing photographs — are stored in private storage and served only through short-lived signed links.
- Administrative access is role-based and limited to staff who need it, and admin actions are recorded in an audit log.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the NDPC and affected users as the NDPA requires.
10.Children
The Platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact privacy@stayaparte.com and we will delete it.
11.Changes to this policy
We update this policy as the Platform and the law change. The revised version is posted here with a new effective date, and where a change materially affects how we use your data we will notify you by email or in the app before it takes effect.
12.Contact us
For any question about this policy or your personal data:
- Privacy and data requests — privacy@stayaparte.com
- General support — support@stayaparte.com
- Aparte Technologies Limited (RC 0000000), Lagos, Nigeria
See also our Terms and Conditions.
