Wisemonie Mobile Application · Effective Date: June 2026 This Privacy Policy explains how Wisemonie Digital Technologies Limited ("Wisemonie", "we", "our", or "us") collects, uses, stores, shares, and protects your personal information when you use the Wisemonie mobile application, website, or any associated services. By downloading, registering, funding a wallet, creating an envelope, scheduling a release, or using any Wisemonie service, you consent to the practices described in this Privacy Policy.
1. Who We Are
- Company Name: Wisemonie Digital Technologies Limited
- RC Number: 9578392
- Registered Address: Ashi-Bodija, Ibadan, Oyo State, Nigeria
- Support Email: wisemoniehelpdesk@gmail.com
- Data Protection Officer: wisemoniehelpdesk@gmail.com
We operate Wisemonie, a personal financial-discipline platform offering envelope-based money allocation, scheduled releases, spending controls, optional hard-locked envelopes, automated transfers, bill payments, and digital wallet functions. We are not a bank and do not hold deposits. All wallet balances are maintained by our licensed banking partner.
Our Service Providers
We deliver our services through licensed financial institutions and authorised third-party processors:
- Rubies Microfinance Bank Limited — Licensed Microfinance Bank providing Banking-as-a-Service (BaaS) infrastructure: virtual account creation, wallet balance custody, fund transfers, BVN verification, NIN validation, and settlement. Wisemonie operates under a Strategic Partnership Agreement with Rubies. RC Number: 166231.
- Bill Payment Aggregator — Licensed third-party provider for airtime, data, utility, and TV-subscription payments PayeeLord VTU.
- Cloud Hosting Provider — Backend application infrastructure and database hosting Render.
- Authentication Service — Secure login and session management and custom JWT.
- Push Notification Provider — Firebase Cloud Messaging (FCM) for mobile alerts.
- Email Service Provider — Transactional and notification email delivery Brevo.
Regulatory Compliance
We are committed to protecting your personal information in compliance with:
- The Nigeria Data Protection Act 2023 (NDPA) and Nigeria Data Protection Regulation (NDPR)
- Central Bank of Nigeria (CBN) regulations on KYC, AML, and consumer financial services
- Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended)
- Other applicable Nigerian laws and regulations
2. Information We Collect
We collect only information strictly required to operate the Wisemonie platform safely and lawfully.
a. Personal Information You Provide
Identity & KYC Data:
- Bank Verification Number (BVN)
- Date of birth and gender
- Selfie photographs for identity verification
- Verification timestamps and status
Account Information:
- Full name, phone number, and email address
- Username and profile image
- Transaction PIN (stored as a cryptographic hash only — never in plaintext)
Financial Data:
- Wallet balance and complete transaction history
- Envelope configurations, allocations, and spending patterns
- Scheduled release rules (timing, frequency, recurrence) and commitment notes
- Hard-lock configurations and unlock conditions
- Automation schedules and execution history
- Bill payment history and saved recipients
- Linked bank account details and Dedicated Virtual Account (DVA) information
- Shared-envelope memberships and permissions
Security Credentials:
- Login credentials
- Multi-factor authentication data
- App-lock and biometric authentication preferences
b. Information Automatically Collected
- Device information (model, operating system, platform, app version)
- Session logs, login attempts, and usage analytics
- Error logs and crash reports
- In-app navigation events, features used, and screen views
- Notification interactions and delivery status
- Envelope activity, scheduled-release events, and spending triggers
c. Information from Third Parties
- Rubies Microfinance Bank: BVN and NIN verification results, bank account validation, transfer outcomes, settlement reports, virtual-account event data.
- Bill Payment Aggregator: Service verification (phone number validation), bill payment results.
- Authentication Service: Authentication status, session metadata, and registration confirmations.
d. Biometric Data
We support biometric authentication (Face ID, fingerprint) for app access and transaction approval. Biometric data is processed and stored solely on your device using your device's secure enclave (iOS Keychain or Android Keystore). We do not have access to, transmit, or store your biometric data on our servers.
e. Device Contacts
With your explicit permission, we may access your device contacts to facilitate quick recipient selection for transfers and bill payments (such as airtime and internet subscription purchases). Contact data is used locally on your device and is not stored on our servers or shared with third parties.
3. How We Use Your Information
a. Core Financial Services
- Create and manage your digital wallet account
- Process wallet funding, withdrawals, and transfers
- Provide Dedicated Virtual Accounts (DVAs) for funding
- Execute transactions through Rubies Microfinance Bank's BaaS infrastructure
- Facilitate Wisemonie-to-Wisemonie identity-based transfers
- Process bill payments through our licensed payment aggregator
b. Envelopes, Releases & Locks
- Create, fund, and enforce envelope allocations and spending boundaries
- Process and execute scheduled envelope releases (daily, weekly, monthly, emergency funds or custom rules)
- Enforce hard-locked envelopes until their unlock conditions are met
- Store commitment notes you create when configuring locked envelopes
- Enable shared-envelope access with users you designate
c. Automations & Recurring Transactions
- Schedule and execute recurring transfers and bill payments
- Validate balance, schedule conditions, and recipient details before execution
- Send reminders and notifications for scheduled releases and payments
- Process end-of-cycle envelope behaviour according to the rules you have set
d. Identity Verification (KYC) & Security
- Verify your identity using BVN, NIN, and government-issued documents
- Process selfie verification for identity confirmation
- Detect and prevent fraud, money laundering, and other financial crime
- Maintain regulatory compliance with CBN and Nigerian AML requirements
e. Communications & Notifications
- Push notifications (transaction alerts, envelope release events, scheduled-payment reminders)
- Email notifications (confirmations, alerts, account-status updates)
- In-app messages (envelope thresholds, release status, system updates)
- Occasional phone calls to the number you registered with, made solely to provide customer support, resolve account issues, or gather feedback about the app; never for marketing When we contact you by phone, we will never ask for your transaction PIN, passcode, one-time passwords (OTPs), full card details, or any other sensitive security credentials. Our staff will never request this information, and you should never share it with anyone claiming to represent Wisemonie. If you receive a call asking for such details, please end the call and report it to wisemoniehelpdesk@gmail.com.
f. Analytics & Platform Improvement
- Monitor application performance and detect defects
- Improve envelope and release algorithms and user experience
- Analyse usage trends to enhance features
- Maintain platform reliability and security
We do not sell or rent your personal data.
4. Legal Basis for Processing
We process your data under the following lawful bases as permitted by the NDPA and NDPR:
- Consent — Provided when you register, grant specific permissions, or activate features such as hard-locked envelopes and shared access
- Contractual Necessity — Required to provide the wallet, envelope, and payment services you have requested
- Legal Obligations — NDPA, NDPR, CBN regulations, AML and KYC laws, and tax requirements
- Legitimate Interests — Fraud prevention, platform security, and service improvement
5. Sharing Your Information
We share data only as required for service delivery and legal compliance. All third-party processors are bound by confidentiality and data protection obligations no less stringent than those imposed under this Privacy Policy.
a. Banking & Payment Partner
- Rubies Microfinance Bank: Identity verification, virtual account creation, wallet operations, transfers, reconciliations, and KYC processing under our Banking-as-a-Service Strategic Partnership Agreement.
b. Bill Payment Provider
- Bill Payment Aggregator: Customer verification and service fulfilment for airtime, data, utility, and TV-subscription payments PayeeLord VTU.
c. Technology & Communication Providers
- Cloud Hosting Provider: Secure backend storage and processing of user data Render.
- Authentication Service: Login and session management.
- Push Notification Provider: Delivery of mobile notifications (Firebase Cloud Messaging).
- Email Service Provider: Transactional email delivery Brevo.
d. Regulators & Law Enforcement
We may disclose your information to the following authorities as required by law:
- Central Bank of Nigeria (CBN)
- Nigeria Financial Intelligence Unit (NFIU)
- Economic and Financial Crimes Commission (EFCC)
- Nigeria Data Protection Commission (NDPC)
- Other government agencies as required by applicable law
6. Cross-Border Data Transfers
Some of our service providers process data outside Nigeria. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent measures recognised by relevant data protection authorities. Cross-border transfers are conducted in compliance with the NDPA requirements for international data transfers. Specific providers that host data outside Nigeria, e.g, Render Frankfurt, Firebase US etc.
7. Data Retention
We retain your information for the periods necessary to fulfil the purposes outlined in this Privacy Policy, subject to legal requirements:
- Data Type: Retention Period
- Transaction records (wallet, envelope releases, transfers): 7 years (CBN requirement)
- KYC / identity verification documents: 7 years after account closure
- Account information (profile, settings, envelope configurations): Duration of account + 7 years
- Usage analytics, navigation logs, session logs: 2 years
- Marketing preferences: Until consent is withdrawn
- Audit logs and security incident records: 7 years (regulatory compliance)
When retention periods expire, data is securely deleted or permanently anonymised. All customer data, transaction records, and account histories generated through Wisemonie's platform remain the property of Wisemonie. Upon termination of our Banking-as-a-Service partnership with Rubies Microfinance Bank, Rubies is contractually obligated to provide Wisemonie with a full machine-readable export of all such data within thirty (30) days and to provide continued data access for ninety (90) days to facilitate migration.
8. Your Rights
Under the Nigeria Data Protection Act 2023 (NDPA) and NDPR, you have the following rights regarding your personal information:
- Right of Access: Obtain confirmation of whether we process your personal data, access to that data, and information about how we process it.
- Right to Rectification: Request correction of inaccurate or incomplete personal information we hold about you.
- Right to Erasure: In certain circumstances, request deletion of your personal information. Some data must be retained for regulatory compliance (e.g. transaction records for 7 years).
- Right to Restriction: Request that we limit how we process your personal information in certain circumstances.
- Right to Data Portability: Receive a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests. You may object to marketing communications at any time.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, please contact our Data Protection Officer at wisemoniehelpdesk@gmail.com We will respond to your request within 30 days. If you are unsatisfied with our response, you may file a complaint with the Nigeria Data Protection Commission (NDPC).
9. Data Security
We implement industry-standard security measures to protect your personal information:
Technical Safeguards:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Transaction PIN hashed using a strong, salted cryptographic algorithm
- Session tokens stored in device secure storage (iOS Keychain / Android Keystore)
- Secure API handling with authentication and authorisation controls
- Regular vulnerability monitoring and patching
Organisational Safeguards:
- Access controls and role-based permissions
- Continuous monitoring for anomalies
- Periodic security assessments and penetration testing
- Staff training on data protection and information security Your Responsibilities: You are responsible for keeping your devices secure, protecting your login credentials and transaction PIN, and enabling device-level security features such as screen lock and biometric authentication.
10. Cookies & Tracking Technologies
We use cookies and similar technologies on our website and supporting web surfaces for:
- Authentication and session management
- Performance analytics and error tracking
- User preference storage You may disable cookies in your browser settings, but this may affect some functionality.
11. Third-Party Links
The App and our website may contain links to external services operated by third parties. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party services before providing your personal information.
12. Marketing & Communications
- We send promotional messages only with your opt-in consent
- You may unsubscribe from marketing communications at any time
- Transactional notifications (transaction alerts, security alerts, scheduled-release notices) cannot be disabled as they are essential to the service
- We may occasionally call you on your registered phone number for customer support, to resolve account issues, or to gather feedback about the app. These calls are not marketing, and we will never ask for your PIN, OTPs, or other sensitive credentials during them
13. Children's Privacy
Wisemonie is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected information from a minor, please contact us at wisemoniehelpdesk@gmail.com and we will take prompt steps to delete such information.
14. Changes to This Policy
We may modify this Privacy Policy from time to time to reflect:
- New or changed regulatory requirements
- New features or changes to existing services
- Updates to our data processors
- Improvements to our security practices Material changes will be notified via in-app notification or email. The updated policy will indicate the effective date. Continued use of Wisemonie after changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us
For questions, concerns, or to exercise your data protection rights, contact us at:
Wisemonie Digital Technologies Limited
Ashi-Bodija, Ibadan, Oyo State, Nigeria General Support: wisemoniehelpdesk@gmail.com Data Protection Officer: wisemoniehelpdesk@gmail.com Website: www.wisemonie.app
16. Consent Acknowledgement
By using Wisemonie, you confirm that:
- You have read and understood this Privacy Policy
- You agree to the collection, use, and processing of your personal data as described herein
- You understand your rights, the data retention periods, and the lawful basis for processing
- You acknowledge that some of your data may be transferred outside Nigeria with appropriate safeguards
- You understand that certain data must be retained for regulatory compliance even after account closure — End of Privacy Policy —