Legal
Your records belong to you.
What MyKanti collects, why we collect it, who else ever sees it, and how to get it all back or have it deleted. Written to be read by the person who owns the shop.
The short version
We do not sell your data, and we do not give your figures to tax authorities. Your books leave our systems only when you tell them to, when a provider needs them to send your message or take your payment, or when a court orders it.
You can take everything with you. Export to PDF or Excel whenever you like, and ask us to delete your account and we will, within 30 days.
Your customers’ details are your responsibility. You are the controller of that data; we only hold it and send the reminders you approved.
This summary is here to be read. It is not a substitute for the clauses below, which are what actually applies.
01
Who we are
MyKanti is operated by MyKanti Technologies Ltd. (RC 0000000), a company registered in Nigeria with its registered office at [Registered office address], Lagos, Nigeria. In this policy “we”, “us” and “MyKanti” mean that company, and “you” means the person using the app or this website.
For the records you keep about your own business, we are the data controller — we decide why they are processed. For the details you enter about your customers, the position is different and important; section 06 sets it out.
You can reach our data protection officer at dpo@mykanti.com, or the whole team at hello@mykanti.com and on WhatsApp at 0800 000 0000.
02
What we collect
Everything below is either something you typed, something you chose, or something your phone reports so the app can run. We do not buy data about you from anyone, and we do not build a profile of you from outside sources.
Your phone number and PIN
There is no password in MyKanti. You sign in with your number and a 4-digit PIN, and we send a one-time code to confirm the number belongs to you. PINs are stored only as a cryptographic hash — we cannot read yours back, and nor can our staff.
Your shop
Shop name, street and area, and the phone number you want customers to see on receipts. If you run more than one shop, the same details for each.
Business papers — only if you offer them
CAC registration type, registered name and TIN. This step is skippable and the app says so. If you skip it, we never ask again unless you go looking for it.
What you record
Your daily book — money in, money out, notes on what you spent it on — plus stock, cash counts, and any correction you make to a day you had already closed, including what it said before.
People who owe you
The name you enter for a customer, their phone number if you want reminders sent, what they took, what they have paid, and any credit limit you set for them.
Staff you invite
Their name, phone number, their own PIN, and the limits you place on them. Every entry in the book records who made it and when — that trail is the point of staff logins, and it cannot be switched off.
Payment details
Which plan you are on, when you paid, and what for. Card details go directly to our payment processor and never reach our servers — we see only the last four digits, the card type, and whether the charge succeeded.
Where your reports go
Your choice of weekly or monthly summary, and any additional address you nominate — for example your accountant's email.
Technical information
Device model, operating system version, app version, preferred language, crash reports and rough connection quality. We use this to work out why the app is slow or broken on the phones people actually own.
What we deliberately do not collect
We do not ask for your BVN or NIN. We do not read your contacts, your photos, your SMS inbox or your WhatsApp messages. We do not track your location in the background. The app asks for a permission only at the moment it needs it — for example the camera, if you choose to attach a photo of a receipt — and refusing simply turns that one feature off.
03
Why we use it, and on what lawful basis
Section 25 of the Nigeria Data Protection Act 2023 requires a lawful basis for every use. Ours are these:
- To run the service you asked for — keeping your book, calculating what you kept, tracking credit, sending your weekly summary, syncing between your phones. Basis: performance of our contract with you.
- To confirm it is really you — the one-time code, the PIN, and signing a lost device out when you tell us to. Basis: contract, and our legitimate interest in security.
- To take payment and keep the receipts that go with it. Basis: contract, and legal obligation for tax records.
- To send reminders to your customers, in your shop’s name and in wording you approved. Basis: your instruction to us as processor — see section 06.
- To support you when you message us, which means a support agent may need to look at the specific record you are asking about. Basis: legitimate interest in answering you properly.
- To keep the app working — crash reports, aggregate counts of which screens are used, and diagnosing sync failures. Basis: legitimate interest in a product that functions.
- To meet the law where we are compelled to, and to investigate fraud or abuse of the service. Basis: legal obligation and legitimate interest.
Where we rely on consent — an optional marketing message, or sharing a summary with a lender you are applying to — you can withdraw it at any time, and withdrawing it never costs you access to the book itself.
04
Your sales figures stay yours
This is the question shop owners actually ask, so we will answer it directly. We do not pass your records to tax authorities. We do not send them to banks, lenders, cooperatives, landlords, competitors, or anybody else, and we do not sell data to anyone, ever.
There are exactly three circumstances in which your figures leave our systems:
- You tell us to. If you apply for a loan through a partner and choose to share a business summary, you approve that specific share, for that specific recipient, and you can revoke it afterwards.
- A sub-processor needs it to do its job — the company that sends your SMS cannot send it without the number and the message. Section 08 names them.
- A court or a regulator with jurisdiction compels us under Nigerian law. Where we are legally permitted to tell you this has happened, we will.
If we are ever bought or merged, your records move with the service under this same policy, and we will tell you before anything changes.
05
What your staff can and cannot see
A staff login is deliberately narrower than yours. An attendant can add sales and record credit. They cannot see your profit, cannot delete records, cannot change prices, and cannot see the shop’s overall position unless you grant it.
You are the one who decides those limits, and you can change or remove a staff login at any time. Because every entry is stamped with who made it, your staff should know that their activity in the app is visible to you — that is a normal part of the job, and telling them plainly is both fairer and what the NDPA expects of you as their employer.
06
Your customers' details — you are the controller
When you write down that Yakubu took goods worth ₦23,000 and save his phone number so he can be reminded, you are recording personal data about someone who is not a MyKanti user. This matters legally, and we would rather you understood it than discovered it later.
For that data you are the data controller and we are your data processor. We hold and send it on your instructions, we do not use it for our own purposes, we do not market to your customers, and we do not add them to any list.
What that means for you
- Record what the credit relationship actually needs — a name, a number, what is owed. You do not need anything more, and collecting more creates an obligation you did not have to take on.
- Tell your customers you keep a written record and that reminders may come by SMS or WhatsApp. Saying it at the counter, once, is enough and it prevents the argument later.
- If a customer asks you to stop messaging them, stop — remove the number from their record. The debt survives; the messaging does not.
- If a customer asks you what you hold about them, you can show them their ledger from the app in a few seconds.
What that means for us
We process customer data only to carry out the instruction you gave — storing the ledger and delivering the reminder. We apply the same security to it as to your own records, we tell you without undue delay if it is ever breached, and when you delete a customer or close your account it goes with the rest of your data on the timetable in section 09.
07
How reminders are sent
Reminders go out in your shop’s name, using wording you approve once before the first one is ever sent. You choose the schedule — for example weekly until the balance is cleared — and you can stop it for one customer or for all of them at any time.
Delivery is by WhatsApp where the number supports it, and by SMS otherwise. That means the message, the number and your shop name pass through the relevant messaging provider, which will handle them under its own terms. Message delivery is the one part of MyKanti that cannot work offline.
Reminders are transactional messages about a debt the customer incurred — they are not marketing, and we will not let them be used as marketing.
08
Who else touches your data
We keep this list short on purpose. Each of these is bound by a written agreement, may use your data only to provide its service to us, and may not use it for its own purposes.
- Payment processing — to take card, transfer and USSD payments, and to store your card safely if you ask us to keep it for renewals. They receive your name, phone number, email if you gave one, and the amount. We never receive your full card number.
- Messaging providers — to deliver reminders, one-time codes and your weekly summary over SMS and WhatsApp.
- Cloud hosting and backup — to store the synced copy of your records, encrypted.
- Crash and performance reporting — to tell us which screen broke, on which model of phone.
- Customer support tooling — to keep track of your conversation with us so you do not have to repeat yourself.
A current, named list of these providers is available on request from privacy@mykanti.com. We will update this page when a provider is added or replaced.
09
Where it is kept, and for how long
On your phone
MyKanti is offline-first: what you enter is written to your phone straight away and syncs when signal returns. That local copy is protected by your device lock and your PIN. If you lose the phone, tell us and we will sign that device out; the records themselves are safe on the synced copy and appear when you sign in on a new phone.
On our servers
Data is encrypted in transit and at rest. Access by our staff is restricted to the people who need it, is logged, and is limited to what is required to answer a support request or fix a fault. Our primary storage is in Nigeria. Where a sub-processor operates outside Nigeria, the transfer is made under the safeguards required by Part IX of the NDPA.
How long
- While your account is open — your books, credit list and stock stay as long as you want them. They are your business history and we do not thin them out.
- After you ask us to delete your account — we remove your records within 30 days, including from routine backups within a further 90 days.
- After a period of dormancy — if an account is unused for 24 months we will contact you before deleting anything.
- Payment and tax records — kept for 6 years, because Nigerian tax law requires it. This is the one category we cannot delete on request.
10
Your rights, and how to use them
Under the Nigeria Data Protection Act 2023 you have the right to:
- ask what we hold about you, and get a copy;
- have anything wrong corrected;
- have your data deleted, subject to the tax-record exception above;
- ask us to restrict or stop a particular use;
- object to processing we base on legitimate interests;
- take your records elsewhere in a portable format — the app exports to PDF and Excel, and you do not need our permission to use it;
- withdraw a consent you previously gave;
- not be subject to a decision made purely by automated means that has a legal or similarly significant effect on you. MyKanti does not make such decisions.
Ask on WhatsApp at 0800 000 0000 or write to privacy@mykanti.com. We will respond within 30 days, and we will not charge you for it. We may need to confirm it is you before we hand over records — that check protects you, not us.
If we get it wrong, you can complain to the Nigeria Data Protection Commission. We would rather you told us first, but it is your right either way.
11
If something goes wrong
If personal data we hold is breached in a way that risks harm, we will report it to the Nigeria Data Protection Commission within 72 hours of becoming aware, as the NDPA requires, and we will tell the people affected — including you, and where the breach involves your customers, so that you can tell them. We will say what happened, what it means, and what we are doing about it, in plain language.
12
Children
MyKanti is a tool for running a business and is not intended for anyone under 18. We do not knowingly create accounts for children. If you believe a child has an account, tell us and we will remove it. This does not stop an older child helping a parent set the app up — that is common and welcome — but the account belongs to the adult who owns the business.
13
Changes to this policy
When we change something that affects you materially — a new sub-processor, a new use of your data, a change to retention — we will tell you in the app and by message before it takes effect, not afterwards. Minor corrections are made here with the date at the top updated. Every version is dated, and we will send you the previous wording on request.
14
Contact
Data protection officer: dpo@mykanti.com
Privacy requests: privacy@mykanti.com
General: hello@mykanti.com · WhatsApp 0800 000 0000
Post: MyKanti Technologies Ltd., [Registered office address], Lagos, Nigeria
See also our Terms of service, and the help centre if you would rather just ask someone.