Legal

Privacy Policy

How we collect, use, share and protect personal data across the OhShip platform, and the rights the Nigeria Data Protection Act 2023 gives you over that data.

Last updated 5 August 2026

1. Scope and controller

This policy explains how Nextplace Technologies Limited (RC 1813382) ("Nextplace", "we", "us") handles personal data in connection with the OhShip platform and the ohship.africa website. Our registered address is 33 Ina Obasi, Ogudu, Ojota, Lagos State, Nigeria and we can be reached at support@ohship.africa.

It is written primarily under the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 issued by the Nigeria Data Protection Commission (NDPC).

2. Our two roles

We hold two different positions depending on whose data is involved. This distinction determines who you should approach about your data.

DataOur roleWhat it means for you
Data about our own users — logistics providers, their staff, demo requesters, and visitors to ohship.africaControllerWe decide why and how this data is processed. Exercise your rights directly with us.
Data about end customers who book shipments on a provider-branded site — senders, recipients, addresses, parcel detailsProcessorThe logistics provider is the controller and decides how this data is used. We process it only on that provider’s instructions. Direct your requests to the brand you booked with; we will assist them.
alt_route

If you booked a shipment

The brand whose website you used is the controller of your data and your first point of contact. We hold that data on their behalf. If you contact us directly we will forward your request to them and support them in answering it.

3. Data we collect

Account and business data

Name, email address, phone number, password (stored only as a cryptographic hash), role and permissions, business name, business address, and the brand configuration a provider sets up.

Verification (KYC) data

Where a provider must be verified before settlement, we collect identity and business-registration details and any documents submitted, together with the result returned by our verification partners. We collect only what verification requires.

Shipment data

Sender and recipient names, addresses, phone numbers and email addresses; parcel contents descriptions, weights and dimensions; pickup and delivery instructions; waybill and tracking numbers; and shipment status history. Most of this is end-customer data for which we act as processor.

Payment and billing data

Transaction amounts, references, status, wallet balances, invoices, settlement account details and bank account numbers used for payouts.

Card details are entered on the payment provider's secure checkout. We never receive or store a full card number or CVV. Where a card is saved for reuse, we store only the reusable token issued by the payment provider, the masked card number showing the last digits, the expiry date and the card brand — enough to display the saved card and charge it again through the provider, and not enough to reconstruct the card.

Technical and usage data

IP address, browser and device type, pages and features used, timestamps, request logs, API usage, and error diagnostics captured when something breaks.

Communications

Demo requests, support emails, notification delivery records, and correspondence you send us.

4. Why we use it, and our lawful basis

PurposeLawful basis under the NDPA
Creating and administering accounts; providing the platform, dashboards and APIsPerformance of a contract
Booking, pricing, generating waybills for and tracking shipments; passing details to the carrier that will deliver the parcelPerformance of a contract
Processing payments, invoicing, and settling funds to providersPerformance of a contract; legal obligation
Identity and business verification (KYC), fraud prevention, and platform securityLegal obligation; legitimate interest in preventing fraud and abuse
Sending transactional notifications — booking confirmations, status updates, invoices, security alertsPerformance of a contract
Error monitoring, debugging, analytics and improving the platformLegitimate interest in operating a reliable service
Responding to demo requests and business enquiries you send usConsent; steps taken at your request before entering a contract
Marketing emails to business contactsConsent — withdrawable at any time via the unsubscribe link or by emailing us
Keeping accounting, tax and compliance records; responding to lawful requestsLegal obligation

We do not sell personal data. We do not use end-customer data for our own marketing, and we do not share one provider's data with another provider.

5. Who we share data with

We share personal data only with the service providers we need to run the platform, and only for the purposes below. Each is bound by contractual confidentiality and security obligations.

RecipientPurposeLocation
Paystack Payments LimitedCard and bank payment processing, settlement splits, and dedicated virtual accountsNigeria
Monnify (Moniepoint Inc.)Alternative payment processing and bank account verificationNigeria
Smile IdentityIdentity and document verification (KYC) checksNigeria and United States
Amazon Web ServicesCloud hosting, database storage, file storage and content deliveryOutside Nigeria
NovuDelivery of transactional notifications (in-app and email)Outside Nigeria
SentryApplication error monitoring and diagnosticsOutside Nigeria
Carrier partnersFulfilment of shipments — pickup, transport, customs clearance and delivery. Includes DHL, FedEx, UPS, Aramex, Fez Delivery and Terminal Africa, depending on the carriers your provider has enabled.Varies by carrier and route

We also disclose personal data:

  • to the logistics provider whose branded site you used, where you are an end customer — they are the controller of that data;
  • where required by law, court order, or a lawful request from a regulator or law-enforcement authority; and
  • to a successor entity in connection with a merger, acquisition or reorganisation, subject to this policy continuing to apply.

6. International transfers

Some of our sub-processors — notably cloud hosting, notification and error-monitoring providers — operate outside Nigeria, so personal data may be transferred and stored abroad. Where that happens we rely on the transfer conditions in Part VIII of the NDPA, including contractual safeguards with the recipient requiring an adequate level of protection and processing restricted to our documented instructions.

7. How long we keep data

  • Account data — for as long as the account is active, and for up to 12 months after closure to handle wind-down, disputes and final billing.
  • Shipment and transaction records — retained while needed to provide the service and thereafter for the period required by Nigerian accounting, tax and anti-money-laundering rules, generally 6 years.
  • KYC and verification records — for the retention period required of regulated verification, generally 5 years after the relationship ends.
  • Technical logs and error diagnostics — typically 30 to 90 days.
  • Marketing contact data — until you withdraw consent.

A logistics provider may request deletion of its data at any time. After deletion from our live systems, residual copies may persist in routine backups until those backups cycle out on our ordinary schedule.

8. Security

  • Encryption of data in transit using TLS.
  • Passwords stored only as salted cryptographic hashes, never in readable form.
  • Strict tenant isolation, so one provider cannot access another provider's data.
  • Role-based access control, with staff access limited to what a role requires.
  • Full card numbers and CVVs are never stored — a saved card is held only as a payment-provider token alongside a masked number, expiry and brand.
  • Continuous error and security monitoring, with logging of administrative actions.

If a personal data breach occurs, we will notify the NDPC and affected controllers or data subjects as required by the NDPA — including notifying the NDPC within 72 hours where we are the controller, and notifying the controller without undue delay where we are the processor.

9. Your rights

Under the NDPA you have the right to:

  • be informed about how your personal data is used;
  • access the personal data held about you;
  • have inaccurate or incomplete data corrected;
  • request deletion where the data is no longer necessary or was processed unlawfully;
  • restrict processing in certain circumstances;
  • receive your data in a structured, commonly used, machine-readable format and have it ported;
  • object to processing based on legitimate interest, and to direct marketing at any time;
  • withdraw consent at any time, without affecting processing already carried out; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise a right, email support@ohship.africa. We respond within 30 days. We may ask you to verify your identity first. If your request concerns data held on behalf of a logistics provider, we will refer it to that provider as controller and tell you we have done so.

10. Cookies and local storage

We keep you signed in using browser storage rather than tracking cookies, and we do not run advertising trackers. The detail is set out in our Cookies & Local Storage policy.

11. Children

The platform is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user. Where a child's details appear as a shipment recipient, that data is provided by the sender and processed only to complete the delivery. If you believe we hold a child's data inappropriately, contact us and we will delete it.

12. Changes to this policy

We update this policy as the platform, our sub-processors and the law change. The date at the top of this page shows when the current version took effect. Material changes will be notified by email or in the dashboard before they take effect.

13. Contact and complaints

For any privacy question or request, contact support@ohship.africa or write to Nextplace Technologies Limited (RC 1813382), 33 Ina Obasi, Ogudu, Ojota, Lagos State, Nigeria.

If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).