Artilance
Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how Artilance Home Services Limited (RC 9571550) (“Artilance”, “we”, “us”, “our”) collects, uses, shares, and protects your personal data when you use the Artilance mobile application and website (together, the “Platform”).
Artilance operates a marketplace that connects customers who need home and personal services with independent service providers. We are the data controller responsible for the personal data described in this Policy, and we process it in accordance with the Nigeria Data Protection Act 2023 (NDPA) and other applicable law.
If you have any questions about this Policy or how we handle your data, contact us at hello@artilance.com.
1. Who this Policy applies to
This Policy applies to everyone who uses the Platform, including customers who request services and providers who offer them. You must be at least 18 years old to use Artilance. We do not knowingly collect data from anyone under 18.
At launch, Artilance operates in Lagos, Nigeria. We may expand to other locations, including outside Nigeria, in future; where we do, we will comply with the data protection laws that apply.
2. The personal data we collect
Account and profile data
- First and last name
- Email address
- Phone number
- Date of birth
- Gender
- Profile photo (if you add one)
- Short bio (providers)
Identity verification data (providers, and where required)
- National Identification Number (NIN)
- A verification selfie / liveness check
- Date of birth used to confirm your identity
See section 5 for exactly how this data is handled — importantly, we do not store your NIN in readable form, and in our standard verification flow your verification selfie is processed by our verification partner and is not stored by us.
Location data
- The service address and state you provide
- Approximate coordinates (latitude/longitude) associated with a service request or booking, used to match you with nearby providers and to describe where a service is to be performed
We use address autocomplete to help you enter locations; we do not continuously track your device’s GPS location in the background.
Financial data (providers)
- Bank account name, number, bank name, and bank code, used to pay out your earnings
Service and transaction data
- Service requests, bookings, quotes, and their status
- Photos and descriptions you attach to a request, booking, or portfolio
- Payment and payout records, including escrow transaction references and amounts
Communications
- Messages and images you exchange with other users through in-app chat
- Reviews and ratings you submit
Device and technical data
- A push-notification token (FCM token) so we can send you notifications
- Basic technical information necessary to operate the app
Analytics (planned)
- We intend to introduce product analytics (using Mixpanel) to understand how the Platform is used and to improve it. This is not yet active. When we enable it, we will update this Policy and, where the law requires, ask for your consent.
3. How we collect your data
- Directly from you — when you register, complete your profile, verify your identity, create or accept a request, chat, or contact support.
- Automatically — such as your push-notification token and technical data needed to run the app.
- From our identity-verification partner — the result of a NIN and face verification check (see section 5).
4. How we use your data, and our legal bases
We process your personal data for the following purposes. Under the NDPA, each purpose relies on one or more legal bases: performance of a contract with you, compliance with a legal obligation, your consent, or our legitimate interests in operating and securing the Platform.
| Purpose | Legal basis |
|---|---|
| Create and manage your account | Contract |
| Verify provider identity (NIN + face) to build trust and reduce fraud | Legal obligation / legitimate interest / consent |
| Match customers with providers and enable bookings | Contract |
| Process payments, escrow, and provider payouts | Contract / legal obligation |
| Enable in-app chat between matched users | Contract |
| Send you service, transaction, and security notifications | Contract / legitimate interest |
| Handle disputes, refunds, and safety reports | Contract / legitimate interest |
| Prevent fraud, abuse, and prohibited activity, and enforce our Terms | Legitimate interest / legal obligation |
| Comply with legal, regulatory, and financial-record obligations | Legal obligation |
| Improve the Platform (including future analytics) | Legitimate interest / consent |
We do not send marketing emails. We only send messages that relate to your account, your transactions, and the security of your account. If we introduce marketing communications in future, we will ask for your opt-in and give you a way to unsubscribe.
5. Identity verification — how we handle your NIN and selfie
Trust and safety are central to Artilance, so we verify provider identities using the National Identification Number (NIN) together with a face (liveness) check. This verification is performed through a licensed third-party identity-verification partner (Prembly).
- Your NIN is sent to our verification partner to confirm your identity. We do not store your NIN in readable (plaintext) form. We retain only a one-way cryptographic reference (a hash) used to confirm that an identity has been verified and to prevent one identity being used for multiple accounts, together with the verification result (verified / not verified, a match score, and a partner reference).
- In our standard verification flow, your verification selfie is transmitted to our verification partner and is not stored by Artilance — we keep only the verification result, not the image.
- Your verification partner processes this data to return a verification result and handles it under its own terms and privacy practices.
Because a NIN is a sensitive national identifier, we treat it with particular care and apply access controls to the systems that handle verification data.
6. Who we share your data with
We do not sell your personal data. We share it only as needed to run the Platform, with the following categories of recipients (service providers who process data on our behalf, or partners who provide a specific function):
| Recipient | Purpose | Location |
|---|---|---|
| Supabase | Database and backend hosting | European Union (Ireland) |
| Prembly | NIN + face identity verification | Nigeria |
| Payscrow | Escrow, payment collection, settlement, and disputes | Nigeria |
| Flutterwave | Bank-account name confirmation and bank list (no money is moved by this partner) | Nigeria |
| Cloudinary | Hosting of images (profile, portfolio, service, and chat images) | United States |
| Google (Firebase Cloud Messaging) | Push notifications | United States |
| Resend | Sending transactional and security emails (e.g. one-time codes) | United States |
| Google (Places) | Address autocomplete | United States |
We also share data with other users of the Platform to the extent necessary for a service to happen — for example, a provider and customer who are matched will see each other’s relevant profile details, chat messages, and service location.
We may disclose data where required by law, regulation, legal process, or a lawful request by a public authority, or to protect the rights, safety, and property of Artilance, our users, or others.
Images note: Images you upload (profile, portfolio, service-request, and chat images) are stored with our image host and are accessible to anyone who has the image link. Please avoid including sensitive information in images you upload.
7. International transfers
Some of our service providers are located outside Nigeria. In particular, our database is hosted in the European Union (Ireland), and some partners are located in the United States. This means your personal data may be transferred to, and processed in, countries outside Nigeria.
Where we transfer personal data outside Nigeria, we do so in accordance with the NDPA — relying on an adequacy determination, appropriate safeguards, or another lawful transfer mechanism — and we take steps to ensure your data continues to be protected.
8. How long we keep your data
We keep your personal data for as long as your account is active and for as long as we need it for the purposes described in this Policy.
- Account, profile, and service data are retained while your account is active.
- Financial and transaction records (payments, escrow, payouts) are retained for as long as necessary to meet our legal, tax, accounting, and regulatory obligations, even after your account is closed.
- Communications (chat messages, reviews) are retained to maintain a record of the service relationship and to help resolve disputes.
When you delete your account (see section 9), we anonymise your profile and identity data. We retain transaction and financial records, reviews, chat messages, and an internal deletion record where we are required or permitted to do so — in particular to comply with the law and to resolve disputes.
9. Your rights, and how to exercise them
Under the NDPA, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”), subject to the retention limits above
- Restrict or object to certain processing
- Data portability — receive your data in a usable format
- Withdraw consent at any time, where we rely on consent
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC)
Deleting your account. You can delete your account yourself in the app. For security, we email you a one-time code to confirm the request; once you confirm, deletion is immediate and irreversible.
You cannot delete your account while you have an active booking, a pending payout, or an open dispute — you will need to complete or resolve these first.
When you confirm deletion, we immediately anonymise your profile and identity data: your name, phone number, profile photo, bio, location, device token, and NIN reference are removed, and your email address is replaced with a non-identifying value (so the same email can be used to register again in future). Your provider profile is deactivated, and any open requests or quotes are cancelled or withdrawn.
Some data is retained after deletion, because we are required or permitted to keep it: transaction, booking, and payout records (to meet legal, tax, and accounting obligations); reviews and chat messages (which remain, associated with a “Deleted User” rather than with you); and an internal deletion record noting your original email address and the reason you gave, kept as an audit log. See section 8 for the principles we apply.
To exercise any of these rights, email hello@artilance.com. We may need to verify your identity before acting on a request.
10. How we protect your data
We take reasonable technical and organisational measures to protect your personal data, including access controls, encryption in transit, hashing of sensitive identifiers such as your NIN, and restricting access to systems that handle verification and financial data.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to affect you, we will notify you and the NDPC as required by the NDPA.
11. Children
The Platform is intended only for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us at hello@artilance.com and we will take steps to remove it.
12. Our website and cookies
Our marketing website (artilance.com) is an informational site. In its current form, it:
- Does not set any cookies and does not use analytics or advertising trackers.
- Loads web fonts from Google Fonts. When your browser loads these fonts, your IP address and browser information are sent to Google. This is the only third-party service the website contacts. You can learn more from Google’s Privacy Policy.
If we introduce cookies, analytics, or other tracking on the website or in the app in future, we will update this Policy and, where required, ask for your consent.
13. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the app or by email. Your continued use of the Platform after an update means you accept the revised Policy.
14. Contact us
For any privacy question, request, or complaint:
Artilance Home Services Limited (RC 9571550)
Email: hello@artilance.com
You also have the right to contact the Nigeria Data Protection Commission (NDPC) if you believe we have not handled your data lawfully.