Privacy Notice
Effective date: 1 January 2025
This Privacy Notice explains how Subsi Limited collects, uses, stores, and shares your personal information when you use our platform. We are committed to protecting your privacy and processing your data lawfully and transparently.
1. Who We Are
Subsi Limited ("Subsi", "we", "our", or "us") operates the Subsi e-commerce platform accessible at subsi.com and through our mobile applications. We are the data controller responsible for your personal information collected via our platform.
If you have any privacy-related queries, contact us at: privacy@subsi.com
2. Information We Collect
We collect different types of information depending on how you use our platform:
Account information: Name, email address, phone number, and password when you register.
Profile information: Delivery address, profile picture, and account preferences.
Transaction data: Orders placed, items purchased, payment method (we do not store full card numbers), and delivery details.
Seller information: Business name, bank account details, store profile, product listings, and sales data.
Usage data: Pages visited, search queries, clicks, session duration, device type, browser, and IP address.
Communications: Messages with sellers, support tickets, and emails sent to us.
Cookies: See our Cookie section below.
3. How We Use Your Information
We use your personal information to:
• Create and manage your account • Process and fulfil your orders • Send order confirmations, updates, and delivery notifications • Process payments and prevent fraud • Provide customer support • Personalise your shopping experience and recommend products • Send marketing communications (where you have opted in) • Comply with legal obligations • Improve and develop our platform through analytics
Our legal bases for processing are: contract performance, legitimate interests, legal obligation, and consent (where applicable).
4. Sharing Your Information
We share your information only as necessary:
Sellers: We share your name, delivery address, and order details with the relevant seller so they can fulfil your order.
Logistics partners: Delivery companies receive your name, address, and phone number to deliver your orders.
Payment processors: Payment data is handled by our PCI-DSS-compliant payment partners (e.g., Paystack). We receive confirmation of payment but not full card details.
Service providers: We use third-party tools for email delivery, analytics, customer support, and cloud hosting. These providers process data on our behalf under strict data processing agreements.
Legal compliance: We may disclose information if required by law, court order, or to protect the rights and safety of Subsi, our users, or the public.
We do not sell your personal information to any third party.
5. Cookies & Tracking
We use cookies and similar tracking technologies to:
• Keep you logged in across sessions • Remember your cart and preferences • Analyse site usage and performance • Deliver relevant advertising (where applicable)
Essential cookies are required for the platform to function. Analytics and marketing cookies are optional — you can manage your preferences in your browser settings or through our cookie banner.
By continuing to use Subsi, you consent to our use of essential cookies.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Specifically:
• Account data is retained for the lifetime of your account plus 2 years after closure • Transaction records are retained for 7 years for legal and tax compliance • Support communications are retained for 2 years • Marketing preferences are kept until you unsubscribe
You may request deletion of your account and data at any time (see Your Rights below). Some data may be retained longer if required by law.
7. Your Rights
Under applicable data protection law, you have the right to:
Access: Request a copy of the personal data we hold about you. Correction: Ask us to correct inaccurate or incomplete data. Deletion: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations. Portability: Receive your data in a structured, machine-readable format. Objection: Object to processing based on legitimate interests, including direct marketing. Restriction: Request that we limit how we use your data in certain circumstances.
To exercise any of these rights, contact us at privacy@subsi.com. We will respond within 30 days. We may need to verify your identity before processing your request.
8. Children's Privacy
Our platform is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal information, please contact us immediately at privacy@subsi.com and we will delete the information.
9. Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction. These measures include encryption in transit (HTTPS), secure password storage, and access controls.
No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately.
10. Changes to This Notice
We may update this Privacy Notice from time to time. When we make material changes, we will notify you via email or a prominent notice on the platform before the changes take effect. The "Effective date" at the top of this page will always reflect the most recent update.
11. Contact Us
For any privacy-related questions or to exercise your rights, contact our Data Protection Officer:
Email: privacy@subsi.com Address: Subsi Limited, Victoria Island, Lagos, Nigeria
Last updated: 1 January 2025