Help us improve Paymarka

Allow anonymous usage analytics so we can understand which pages and actions are useful.

Privacy Notice

Last updated 15 July 2026

Read this first

This notice explains how personal data is handled through Paymarka, including the public website, account and workspace application, client portals, notifications, billing features, and support routes. It is written for the product currently implemented in this repository and does not replace a data processing agreement, a workspace customer's own privacy notice, or legal advice.

Controller identity: Paymarka is operated by [LEGAL ENTITY NAME], with its registered office at [REGISTERED ADDRESS, COUNTRY]. The legal entity, privacy inbox, and Data Protection Officer details must be completed before publication: [PRIVACY CONTACT EMAIL] and [DPO NAME / DPO EMAIL, OR “NO DPO APPOINTED”].

Who decides how data is processed?

For an account, workspace administration, subscriptions, product security, support, service analytics, abuse prevention, and legal compliance, Paymarka generally decides the purposes and means of its own processing and acts as a data controller.

A business using Paymarka (the workspace customer) normally decides why its client, proposal, contract, invoice, payment-proof, and portal data is collected and how it is used. For that processing, Paymarka normally acts as the workspace customer's processor or service provider, subject to the parties' written agreement. The workspace customer remains responsible for its instructions, lawful basis, notices to its clients and team members, data accuracy, and responding to requests about its records. The exact controller and processor allocation must be confirmed in the applicable contract or data processing agreement for each use case.

What we receive and where it comes from

We receive information directly from account holders, workspace teams, clients and signers, from the workspace customer that enters client information, from authentication and payment providers, and from devices and browsers that connect to the service.

  • Account and identity: name, email, password hash, email-verification state, Google account identifier and avatar when Google sign-in is enabled, workspace memberships, roles, and invitations.
  • Workspace profile: workspace name, country, address, contact email and phone, custom-domain information, logo, reusable signature image, signature type and hash, payment and notification settings, and branding preferences.
  • Client and commercial records: client name, email, phone, company, address, notes and WhatsApp opt-out; deal titles, descriptions, industry, tags, dates, value, currency, payment structure, milestones, negotiations, proposals, contracts, clauses, invoices, line items, disputes, ratings and feedback.
  • Signatures and evidence: signer name and email, typed or drawn signature data, signing consent and version, contract and signature hashes, signing time, IP address, user agent, accepted-proposal IP address, snapshots, audit events, generated PDFs, uploaded documents and payment-proof files.
  • Payment and subscription data: payment method, payment and gateway references, offline-payment references, proof and receipt URLs, verification state, webhook payloads, subscription identifiers and billing status. Workspace bank details and Paystack configuration may be stored for the workspace. Paymarka does not hold client payment funds; the configured payment provider or workspace bank handles the underlying funds movement.
  • Communications: email and WhatsApp destinations, notification preferences, message subjects and delivery status, support or sales enquiries, and information included in the messages or attachments we are asked to send.
  • Technical and security data: request IDs, URLs and routes, status and duration, IP address, user agent, authentication and portal-token events, error information, and platform audit records.
  • AI and analytics context: where those features are enabled, deal and proposal context, milestones, contract clauses, and limited identifiers or event metadata used to provide AI drafting and product analytics.

Why we use it and our Nigerian lawful bases

The Nigeria Data Protection Act 2023 recognises consent, contract, legal obligation, vital interests, public interest or official authority, and legitimate interests where those interests do not override fundamental rights. We use the basis that actually applies to the processing, and do not treat consent as a substitute for a necessary contract or legal obligation.

  • Provide Paymarka: create and secure accounts, authenticate users, create workspaces, apply roles and permissions, show client portals, generate documents and receipts, and support the deal workflow (contract and legitimate interests; sometimes consent for optional features).
  • Communicate: send verification, invitation, password-reset, proposal, contract, invoice, payment, receipt, reminder and service messages (contract, legitimate interests, or consent where marketing or another law requires it).
  • Billing and payments: create subscriptions, reconcile billing, record payment evidence and receipts, and prevent or investigate fraud (contract, legitimate interests and legal obligations).
  • Security and accountability: enforce tenant isolation and permissions, rotate and revoke sessions, rate-limit or investigate misuse, maintain audit and evidence trails, respond to incidents, and comply with lawful requests (legitimate interests and legal obligations).
  • Improve the service: understand feature use and reliability through conditional server-side analytics and operational diagnostics (legitimate interests, or consent where required). We do not use AI drafts to make solely automated legal or similarly significant decisions about people.
  • Marketing: only where separately permitted and consented to where required. You can object to direct marketing at any time.

Providers and disclosures

We disclose only what is needed for the relevant purpose, under contracts, instructions and safeguards that must be verified by the business. The repository identifies these conditional integrations; the final provider register must confirm their current account, locations, sub-processors, retention terms and transfer safeguards.

  • Resend: email recipients, sender/reply-to details, subject, message content, attachments and delivery identifiers when email is configured.
  • Twilio WhatsApp: WhatsApp numbers, message content and delivery information when WhatsApp notifications are enabled.
  • Paystack and banks: subscription or transaction references and payment state when the corresponding payment or billing flow is enabled. Paystack and the relevant bank process payment data under their own notices and terms.
  • Cloudinary: uploaded logos, signatures, PDFs, contracts, receipts and payment-proof assets when file storage is configured.
  • OpenAI: deal, proposal and contract context sent to the configured OpenAI model for enabled AI drafting or contract summarisation. Do not submit information to AI features unless the workspace customer is authorised to do so. AI output requires human review and is not legal advice.
  • Google: identity-token information needed for Google sign-in when the Google client is enabled.
  • PostHog: lifecycle and feature-event metadata, which can include workspace, user and deal identifiers, when the server-side analytics key is configured.
  • Infrastructure providers: database, cache, hosting, email, file-storage, logging and security vendors may process data as subprocessors. Their names and locations are not fully discoverable from this repository and must be listed in the approved vendor register before publication.

Cookies and browser storage

The application uses a refresh-token cookie namedrefreshToken for authentication. It is configured as HTTP-only, is normally secure in production, and has a maximum age of 30 days. Short-lived access tokens (currently 15 minutes) are also stored in browser local storage by the web application. Browser storage may additionally contain theme preferences, workspace selection state, client-portal display state, and a Public One-Off draft. Clearing it can sign you out and removes the locally saved One-Off draft.

No advertising-cookie library was identified in the reviewed frontend. PostHog is server-side and conditional on configuration. If non-essential cookies or tracking tools are introduced, Paymarka must provide a conspicuous notice, explain each purpose, offer a clear accept or decline choice where consent is required, and make withdrawal as easy as giving consent. The current product should not imply that optional analytics consent is already managed unless that control is implemented.

International and cross-border processing

Some providers may process data outside Nigeria. We will not infer a country, adequacy decision, standard contractual clause, binding corporate rule, Commission-approved instrument, or other safeguard from a vendor name alone. Before enabling each transfer, the business must document the recipient country, transfer basis, adequacy or safeguards, onward-transfer terms, and how data-subject rights can be enforced. Where the NDPC GAID requires consent for a transfer to a non-adequate country, that consent must be obtained and recorded.

If Paymarka targets or monitors people in the EEA or United Kingdom, the business must separately confirm whether the GDPR or UK GDPR applies, identify any representative or DPO requirement, provide the applicable lawful bases and rights, and use the required international transfer safeguards. Those requirements are conditional and do not replace Nigerian law.

Your rights and how to exercise them

Subject to lawful limitations, you may ask for confirmation and access, a copy in a commonly used electronic format, correction, erasure, restriction, objection, withdrawal of consent, data portability where applicable, and human review or an explanation of a solely automated decision. You may object to direct marketing at any time. Paymarka does not currently use AI to make solely automated decisions with legal or similarly significant effects.

For client, deal, proposal, contract, invoice or payment records, start with the workspace customer shown in the relevant portal or document. For Paymarka account, security, billing, analytics or provider processing, contact [PRIVACY CONTACT EMAIL]or use the Paymarka contact routeand mark the request “Privacy rights request”. We may verify identity, protect other people's data, and ask for the relevant workspace or record. We aim to respond without undue delay and will explain any lawful reason we cannot fully comply.

You may also complain to the Nigeria Data Protection Commission. Its current contact route is available at ndpc.gov.ng/contact.

Security and personal-data incidents

The product implements workspace-scoped access checks and role-based permissions, password hashing, short-lived access tokens, an HTTP-only refresh cookie, session revocation, rate limiting, audit events, request identifiers, signature and contract hashes, and Cloudinary asset isolation checks. These are safeguards, not a guarantee that a service is immune from compromise. Deployment encryption, backups, secrets management, vulnerability management, staff access controls and independent testing must be verified by the operator.

We investigate suspected personal-data incidents, contain and remediate them, keep the records required by law, notify the NDPC within 72 hours where the NDP Act threshold is met, and communicate high-risk incidents to affected people in plain language as required. Report a suspected incident through [SECURITY INCIDENT EMAIL] or the contact route.

Deletion, retention and legal holds

Workspace owners can start account deletion from Settings → Workspace. The current flow requires the owner, a reason and the exact confirmation text, removes workspace records from the product, cancels recurring Paystack billing where applicable, and queues Paymarka-owned Cloudinary assets for a 30-day purge period. Some deletion-request, billing, platform-audit, legal, fraud, backup or third-party records may remain for the period stated in the Data Retention Policy or until the relevant obligation ends.

Deletion cannot erase data that the workspace customer, another signer, a payment provider, a regulator or a third party is required or entitled to retain. We will restrict use where appropriate and record corrections instead of rewriting evidence that must remain reliable.

Children and sensitive information

Paymarka is a business workflow and is not intended for children. Do not enter sensitive personal data or a child's data unless the workspace customer has a lawful, documented need and has put the required safeguards and notices in place. Contact us if you believe such data was submitted without a lawful basis.

Changes and legal references

We will update this notice when processing, providers, safeguards or law changes, and will identify the effective date above. The notice is intended to support compliance with the Nigeria Data Protection Act 2023 and the NDPC's General Application and Implementation Directive (GAID) 2025. It is not a promise of immunity from liability and should be reviewed and approved by Nigerian privacy counsel and the operator before production use.