Privacy Policy
Your money data is sensitive, so we are precise about what we collect, why we need it and who ever sees it.
Last updated: 8 August 2026
1. Who we are
Giva is a crypto off-ramp and payments app built for Nigerians, operated from Lekki Phase 1, Lagos, Nigeria. This Privacy Policy explains what personal data we collect when you use the Giva app or usegiva.com, why we collect it, who we share it with and what rights you have.
We process personal data in line with the Nigeria Data Protection Act 2023 and applicable financial-services regulations. You accept this policy when you create a Giva account.
2. Data we collect
Identity and verification data: your full name, date of birth, gender, nationality, residential address, BVN or NIN, government-issued ID, selfie or liveness capture, and, where required, proof of address or source of funds.
Contact data: your email address and phone number.
Financial and transaction data: your Naira and digital-asset balances, deposit addresses, bank account details, saved beneficiaries, transaction history, bill payments, quotes accepted and receipts.
Technical data: device model and operating system, app version, IP address, approximate location derived from IP, push tokens, crash logs and security events such as sign-in attempts.
Support data: the messages, screenshots and call notes you share with our team.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Why we use your data
- To create and operate your account and to deliver the features you request — deposits, buys, conversions, transfers, bank withdrawals and bill payments.
- To verify your identity and meet our KYC, CFT and AML obligations, including sanctions and PEP screening and transaction monitoring.
- To detect, investigate and prevent fraud, account takeover and other illegal activity.
- To provide customer support and resolve disputes and chargebacks.
- To keep records required by Nigerian law and to respond to lawful requests from regulators, law enforcement and courts.
- To improve reliability and product quality using aggregated or de-identified usage data.
- To send service messages about transactions, security and material changes to our terms. Marketing messages are only sent with your consent and you can opt out at any time.
Our legal bases are performance of our contract with you, compliance with legal obligations, our legitimate interest in keeping the platform safe, and your consent where required.
5. International transfers
Some of our providers operate outside Nigeria. Where personal data is transferred abroad, we rely on adequacy decisions, contractual safeguards or your explicit consent, and we require the recipient to protect your data to a standard comparable with Nigerian law.
6. How long we keep it
We keep identity, transaction and compliance records for at least five years after your account is closed or your last transaction, whichever is later, because financial-services and AML rules require it. Support records are kept for as long as needed to resolve your case and defend legal claims. After that, data is deleted or irreversibly anonymised.
7. How we protect your data
We use encryption in transit and at rest, strict access controls with least-privilege permissions, device-level protections such as PIN and biometrics, monitoring of security events, and regular review of our infrastructure and partners.
No system is perfectly secure. Please use a strong, unique password, keep your device software current, and never share your PIN, password or one-time codes — Giva staff will never ask for them.
8. Your rights
Subject to Nigerian law, you can ask us to:
- access a copy of the personal data we hold about you;
- correct data that is inaccurate or incomplete — much of this you can do yourself in Settings;
- delete data we no longer have a legal reason to keep;
- restrict or object to certain processing;
- receive your data in a portable format; and
- withdraw consent for marketing at any time.
Email hello@usegiva.com to exercise any of these rights. We will respond within 30 days. Some requests cannot be fulfilled where AML record-keeping obligations apply. If you are unhappy with our response, you may complain to the Nigeria Data Protection Commission.
10. Children and changes
Giva is not for anyone under 18 and we do not knowingly collect data from children. If we learn that we have, we will delete it.
We may update this policy as our product and obligations evolve. Material changes will be notified in the app or by email before they take effect, and the date at the top of this page will always show the current version.
Questions about this policy?
Our team reads every message. Reach us and we'll get back to you as quickly as we can.
hello@usegiva.com