HIPPO PAY PRIVACY POLICY

1. INTRODUCTION

Welcome to Hippo Pay.

Hippo Pay is a digital payment and financial technology platform that provides users with convenient access to services including airtime purchases, data subscriptions, electricity payments, cable TV subscriptions, SMS services, gift cards and other related digital payment services.

This Privacy Policy explains how Hippo Pay collects, uses, stores, protects, and shares your personal information when you use our website, mobile application, wallet, payment services, customer support channels, and other services operated by Hippo Pay.

We respect your privacy and are committed to protecting your personal information in accordance with applicable Nigerian data protection laws, including the Nigeria Data Protection Act, 2023 (NDP Act) and applicable guidance issued by the Nigeria Data Protection Commission (NDPC).

By creating an account or using Hippo Pay, you acknowledge that you have read and understood this Privacy Policy.


2. WHO WE ARE

For applicable data protection laws, Hippo Technologies Ltd may act as a data controller in relation to personal information for which we determine the purposes and means of processing.

Throughout this Privacy Policy, “Hippo Pay”, “we”, “us” or “our” refers to the Hippo Pay platform and the entity responsible for operating the service.

Website: https://www.hippopay.app
Email: hello@hippopay.app
Telephone: +234 704 408 0555

Where required by applicable law, Hippo Pay may appoint or designate a Data Protection Officer or appropriate privacy contact to oversee data protection matters.


3. INFORMATION WE COLLECT

We may collect different categories of personal information depending on how you interact with Hippo Pay.

3.1 Information You Provide Directly

When you create or use an account, we may collect:

  • Full name
  • Email address
  • Telephone/mobile number
  • Residential or contact address
  • Date of birth where required
  • Username or account information
  • Password and authentication information
  • Transaction PIN information
  • Profile information
  • Identification information
  • BVN or NIN information where required for verification
  • Bank account information
  • Other information required to provide or secure our services

We will only request information that is reasonably necessary for the relevant purpose.

3.2 Transaction Information

When you use Hippo Pay, we may collect information relating to your transactions, including:

  • Transaction type
  • Transaction amount
  • Transaction date and time
  • Transaction reference
  • Recipient or beneficiary information
  • Payment method
  • Wallet balance and wallet activity
  • Gift card creation, redemption or cancellation information
  • Airtime, data, electricity and cable TV transaction information
  • Service provider information
  • Transaction status and related records

We may retain transaction records where necessary to provide our services, prevent fraud, comply with legal obligations, resolve disputes and maintain accurate financial records.

3.3 Device and Technical Information

When you access Hippo Pay, we may automatically collect certain technical information, including:

  • IP address
  • Device type
  • Device model
  • Operating system
  • Browser type
  • Browser version
  • Application version
  • Device identifiers where permitted
  • Internet/network information
  • Login information
  • Date and time of access
  • Pages or features accessed
  • Security and authentication events

This information may be used to secure your account, detect suspicious activity, troubleshoot technical issues and improve our services.

3.4 Security and Account Activity Information

For security and fraud prevention, we may record:

  • Login attempts
  • Successful and unsuccessful authentication attempts
  • Password or PIN changes
  • Account profile changes
  • KYC information changes
  • Security settings changes
  • Device information associated with account activity
  • IP address associated with relevant activity
  • Date and time of account activity

This information helps us investigate unauthorised access, fraud, account compromise and other security incidents.


4. VERIFICATION AND KYC INFORMATION

Depending on the services you use and applicable legal or regulatory requirements, Hippo Pay may require identity verification.

This may include the collection or verification of:

  • BVN
  • NIN
  • Government-issued identification
  • Date of birth
  • Name
  • Phone number
  • Bank account information
  • Other information necessary to establish or verify your identity

KYC information may be processed for purposes including:

  • Identity verification
  • Fraud prevention
  • Account security
  • Regulatory compliance
  • Anti-money laundering and related compliance obligations
  • Prevention of impersonation and unauthorised account use
  • Meeting requirements imposed by financial institutions, payment processors or other authorised service providers

Where verification is performed through a third-party provider, your information may be securely transmitted to that provider for the relevant verification purpose.


5. HOW WE USE YOUR INFORMATION

We may use your personal information to:

  1. Create and manage your Hippo Pay account.
  2. Provide our payment and digital services.
  3. Process wallet transactions.
  4. Process airtime, data, electricity and cable TV payments.
  5. Provide SMS-related services.
  6. Create, manage, redeem and cancel gift cards.
  7. Verify your identity.
  8. Complete KYC and compliance procedures.
  9. Authenticate your account.
  10. Send OTPs and security notifications.
  11. Detect, prevent and investigate fraud.
  12. Protect users and the Hippo Pay platform.
  13. Respond to customer support requests.
  14. Process refunds, reversals and transaction disputes.
  15. Maintain transaction and financial records.
  16. Improve our website, application and services.
  17. Monitor system performance and reliability.
  18. Communicate important service information.
  19. Send promotional communications where permitted by law and, where required, with your consent.
  20. Comply with applicable laws, regulations and lawful requests from competent authorities.
  21. Enforce our Terms and Conditions.
  22. Protect our rights, property, users and systems.

6. LAWFUL BASIS FOR PROCESSING

Hippo Pay processes personal data only where there is an appropriate lawful basis under applicable data protection law.

Depending on the circumstances, this may include:

Contract

We may process information necessary to create your account and provide services you have requested.

Legal Obligation

We may process information where necessary to comply with legal, regulatory, tax, financial, anti-fraud or other applicable obligations.

Consent

Where consent is required, we will request your consent before processing your information for the relevant purpose.

You may withdraw consent where applicable. Withdrawal of consent will not affect processing that was lawfully carried out before withdrawal.

Legitimate Interests

We may process information where necessary for legitimate business interests, including platform security, fraud prevention, service improvement and protection of our users, provided those interests do not override your applicable privacy rights.


7. OTP, PASSWORD AND TRANSACTION PIN INFORMATION

Hippo Pay may use one-time passwords (OTPs), passwords and transaction PINs to protect your account.

We may process your telephone number and related authentication information to:

  • Verify ownership of your telephone number.
  • Authenticate account access.
  • Confirm sensitive account activity.
  • Authorise transactions.
  • Detect suspicious activity.
  • Protect your account from unauthorised access.

Your transaction PIN should never be shared with another person.

Hippo Pay personnel will not request your complete password, transaction PIN or OTP through unsolicited messages.


8. HOW WE SHARE YOUR INFORMATION

Hippo Pay does not sell your personal information.

However, we may share information with trusted third parties where reasonably necessary to provide our services, fulfil legal obligations or protect our users and platform.

These parties may include:

  • Payment processors
  • Banks and financial institutions
  • Airtime and telecommunications providers
  • Data service providers
  • Electricity distribution/service providers
  • Cable TV providers
  • SMS service providers
  • Identity verification and KYC providers
  • Fraud prevention providers
  • Technology and cloud service providers
  • Customer support providers
  • Professional advisers
  • Regulators and government authorities
  • Law enforcement agencies where legally required

Third parties processing personal information on our behalf may be required to maintain appropriate confidentiality and security safeguards.


9. PAYMENT INFORMATION

Payments made through Hippo Pay may be processed through third-party payment processors, banks or other authorised financial service providers.

Where payment processing is handled by a third party, that provider may process payment information in accordance with its own privacy policy and applicable legal requirements.

Hippo Pay does not intend to store complete payment-card information unless necessary and lawfully permitted for the relevant service.

Where possible, authorised payment service providers process sensitive payment information directly.


10. DATA SECURITY

We take reasonable technical and organisational measures designed to protect personal information against:

  • Unauthorised access
  • Unauthorised disclosure
  • Loss
  • Destruction
  • Alteration
  • Misuse
  • Fraud
  • Unlawful processing

Security measures may include authentication controls, access controls, encryption or secure transmission technologies, monitoring, logging, security testing and other appropriate safeguards.

However, no internet-based system can be guaranteed to be completely secure.

You are responsible for maintaining the confidentiality of your account credentials, password, transaction PIN and OTP.

If you believe your account has been compromised, you should contact Hippo Pay immediately.


11. ACCOUNT ACTIVITY AND SECURITY LOGS

To protect users and maintain platform security, Hippo Pay may maintain records of significant account activity.

These records may include:

  • Date and time
  • IP address
  • Device information
  • Login information
  • Security events
  • Account changes
  • Previous and updated account information where necessary for audit or security purposes
  • Transaction activity

Such records may be used to investigate fraud, unauthorised access, disputes, security incidents and suspicious activity.


12. DATA RETENTION

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • The type of information
  • The purpose for which it was collected
  • The nature of our relationship with you
  • Transaction and financial recordkeeping requirements
  • Regulatory requirements
  • Fraud prevention requirements
  • Dispute resolution
  • Legal proceedings
  • Security and audit requirements

When personal information is no longer required, we may securely delete, anonymise or otherwise dispose of it in accordance with our applicable retention procedures.


13. YOUR DATA PROTECTION RIGHTS

Subject to applicable law and relevant exceptions, you may have rights including:

  • The right to be informed about how your personal information is processed.
  • The right to request access to personal information we hold about you.
  • The right to request correction of inaccurate or incomplete information.
  • The right to request deletion of personal information where legally applicable.
  • The right to object to certain processing.
  • The right to request restriction of processing in appropriate circumstances.
  • The right to data portability where applicable.
  • The right to withdraw consent where processing is based on consent.
  • The right to object to certain automated decision-making where applicable.
  • The right to lodge a complaint with the appropriate data protection authority.

These rights are subject to applicable legal limitations. For example, we may be required to retain certain transaction, identity or regulatory information even after an account closure request.

The NDPC identifies data-subject rights including access, rectification, objection, restriction, portability, erasure and rights relating to automated decision-making.


14. HOW TO EXERCISE YOUR RIGHTS

To exercise a privacy right or make a data protection request, contact us:

Email: hello@hippopay.app
Telephone: +234 704 408 0555

For security purposes, we may need to verify your identity before processing certain requests.

We will handle valid requests within the period required by applicable law.

If we cannot fulfil a request, we will provide an explanation where legally permitted.


15. COOKIES AND SIMILAR TECHNOLOGIES

Hippo Pay may use cookies and similar technologies on its website or application.

These technologies may be used to:

  • Keep you signed in
  • Maintain security
  • Remember preferences
  • Improve website functionality
  • Understand how users interact with our platform
  • Analyse performance
  • Detect suspicious activity
  • Improve our services

Some cookies may be essential for the operation and security of the platform.

Where required by law, we will provide appropriate cookie controls and allow you to manage applicable cookie preferences.


16. COMMUNICATIONS

We may contact you through:

  • Email
  • SMS
  • Telephone
  • In-app notifications
  • Website notifications
  • Other communication channels associated with your account

Some communications are necessary for providing the service and may include:

  • OTPs
  • Transaction confirmations
  • Security alerts
  • Account notifications
  • Service updates
  • Important changes to our Terms or Privacy Policy
  • Fraud or security warnings

Where legally required, you may be provided with the ability to opt out of marketing communications.

You may continue to receive essential service and security communications even if you opt out of marketing communications.


17. THIRD-PARTY LINKS AND SERVICES

Hippo Pay may contain links to third-party websites, applications or services.

We are not responsible for the privacy practices, security or content of third-party websites.

You should review the privacy policy of any third-party service before providing personal information to it.


18. INTERNATIONAL DATA TRANSFERS

Some of our technology providers, service providers or partners may process information outside Nigeria.

Where personal information is transferred or processed outside Nigeria, Hippo Pay will take reasonable steps to ensure that the transfer is carried out in accordance with applicable data protection requirements and appropriate safeguards.


19. CHILDREN’S PRIVACY

Hippo Pay is not intended to be used by persons who are not legally permitted to use our services.

We do not knowingly collect personal information from children in circumstances where such collection is prohibited by applicable law.

If you believe a child has provided personal information to Hippo Pay without appropriate authorisation, please contact us so that we can take appropriate action.


20. FRAUD PREVENTION AND ACCOUNT SECURITY

Hippo Pay may use personal and technical information to identify unusual transactions, suspicious account activity, attempted fraud, account takeover and other security threats.

We may temporarily restrict an account, transaction or service where we reasonably believe that doing so is necessary to protect the user, Hippo Pay or other parties.

Where appropriate, we may request additional information or verification before restoring access.


21. DATA BREACHES AND SECURITY INCIDENTS

If Hippo Pay becomes aware of a personal data breach, we will assess the incident and take appropriate steps in accordance with applicable law and our internal incident-response procedures.

Where notification to affected users, regulators or other parties is legally required, we will make such notifications within the applicable timeframe.


22. DATA ACCURACY

We take reasonable steps to ensure that personal information used by Hippo Pay is accurate and appropriate for the purposes for which it is processed.

You are responsible for ensuring that information provided to us is accurate and up to date.

You may update eligible account information through your Hippo Pay account or by contacting customer support.

Certain information may require additional verification before it can be changed.


23. ACCOUNT CLOSURE

You may request closure of your Hippo Pay account.

Closing your account does not necessarily result in the immediate deletion of all information associated with the account.

We may retain certain information where necessary to:

  • Comply with legal or regulatory requirements
  • Maintain transaction records
  • Prevent fraud
  • Resolve disputes
  • Enforce agreements
  • Protect our legal rights
  • Meet financial or accounting obligations

After the applicable retention period, information will be deleted, anonymised or securely disposed of as appropriate.


24. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect:

  • Changes to our services
  • Changes to technology
  • Changes to applicable laws
  • Changes to regulatory requirements
  • Changes to our data-processing practices
  • Improvements to our privacy and security practices

When we make material changes, we may provide notice through our website, application, email or another appropriate communication channel.

The updated version will display a revised “Last Updated” date.


25. CONTACT US

If you have questions, concerns or requests relating to this Privacy Policy or the handling of your personal information, please contact Hippo Pay.

HIPPO PAY

Website: https://www.hippopay.app
Email: hello@hippopay.app
Phone: +234 704 408 0555

For privacy or data protection requests, please include sufficient information to enable us to understand and respond to your request.


26. COMPLAINTS

If you believe that Hippo Pay has processed your personal information in a manner that violates applicable data protection law, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.

You may also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or another competent supervisory authority, subject to applicable law.


27. YOUR ACKNOWLEDGEMENT

By creating an account, accessing or using Hippo Pay, you acknowledge that you have had an opportunity to review this Privacy Policy and understand how Hippo Pay may process your personal information.

Where applicable law requires separate consent for a particular processing activity, Hippo Pay will request that consent separately.

© 2026 Hippo Pay. All Rights Reserved.