Privacy & Cookie Policy
Last updated: August 28, 2026
This policy explains how Eleo handles personal data across its websites, applications, business software, marketplace and Eleo-powered storefronts. A merchant may separately control customer, supplier and staff data it enters into Eleo; our Data Processing Agreement applies when Eleo processes that data for the merchant.
1. Data we collect
Depending on how you use Eleo, we collect account and contact details; business, store, listing and team information; identity-verification and settlement details; order, payment-reference and transaction records; customer, supplier, selected device-contact and communications data; in-app messages and searches; photos, audio, files and other business content you choose to upload; support and account-deletion requests; Apple subscription and purchase status; and user, store, device, IP, browser, cookie, crash, performance and product-usage identifiers. Payment providers receive card or bank data needed to process payments; Eleo does not receive full card numbers from hosted payment forms.
2. Why we use it
We use personal data to provide accounts, stores, orders, payments, fulfilment connections, messaging and support; verify identity and settlement details; secure and improve Eleo; prevent fraud; keep legal and accounting records; communicate service updates; and send marketing where permitted. Our legal bases include contract, legal obligation, legitimate interests and consent, as applicable.
3. Who receives data
We share only what is reasonably needed with marketplace buyers and merchants, payment and identity-verification providers, delivery or integration partners you select, professional advisers, authorities, and vendors that host, secure, analyse or communicate the Services. These include Firebase for authentication, messaging, analytics, crash and performance diagnostics; RevenueCat and Apple for in-app subscriptions; and payment, banking and identity-verification providers such as Stripe or the locally available provider selected for a transaction. Our current Service Providers and Subprocessors page identifies core processing vendors. Payment providers generally handle payment data as independent controllers under their own notices. We require processors to protect personal data consistently with this policy, our instructions and applicable law.
4. Cookies and analytics
Essential cookies keep the Services secure, remember settings and maintain sessions. With your choice where required, website analytics may include PostHog or Google Analytics. Eleo mobile applications use Firebase analytics, crash and performance tools and Eleo analytics. These services may receive linked user, store and device identifiers so Eleo can diagnose a problem and measure product use. Eleo does not sell personal data or share it for cross-context behavioural advertising, and the Eleo Suite iOS app does not use data for tracking. Use the cookie banner or available privacy settings to change optional choices. You may also object to non-essential analytics by contacting us. Browser controls may block cookies, although essential features may then fail.
5. Retention, security and transfers
We keep account and profile data while an account is active and for the period needed to complete a deletion, dispute or security review. We retain merchant business and transaction records, deletion-request receipts and financial, tax, payment, accounting or KYC records only for the service, audit, legal-hold and statutory periods that apply to them. Security logs and backup copies follow defined operational schedules; backup copies are isolated from normal use and expire through the backup cycle. When a purpose and required period end, we delete or de-identify the data. You may ask us for the period or criteria applicable to a category. We use access controls, encryption in transit, monitoring and other proportionate safeguards, but no system is completely secure. Vendors may process data outside Nigeria; where required, we use contractual transfer safeguards and supplementary security measures.
6. Your choices and rights
Subject to law, you may ask to know or access, correct, erase, restrict or port your data; object to certain processing; withdraw consent; or limit eligible uses of sensitive data. Eleo does not sell personal data or share it for cross-context behavioural advertising, so there is no such sale or sharing to opt out of. We do not discriminate against people for exercising privacy rights. You can unsubscribe from marketing using the message link. We may need to verify your identity and may retain data where law, a legal hold or another person's rights require it. We respond within the period required by applicable law. You may complain to the Nigeria Data Protection Commission or another competent local authority.
Signed-in Eleo Suite users can submit an authenticated deletion request in Settings. After verification and review, Eleo deletes or de-identifies the account identity and associated personal data that it is not required to retain. Store, organisation and transaction records controlled by a merchant may remain available to that merchant, and retained records are restricted to their lawful purpose. If you cannot sign in, contact support so we can verify the request safely.
7. Children and third parties
Eleo business accounts are intended for adults. Marketplace purchases by minors require any consent and supervision required by law, and age-restricted goods require lawful age checks. Third-party sites, merchants and integrations have their own privacy practices.
8. Updates and contact
We may update this policy as Eleo, law or our vendors change and will provide additional notice where reasonably required. Privacy requests: [email protected]. General questions: [email protected].
