Legal
Privacy Policy
Subnivo is preparing for public launch. This policy describes what we actually do today. Two things are still being finalised and are marked as such below: the exact retention period for community messages, and the precise post-closure period for account records. Both will be published here, as a new version, once the retention schedule is approved.
1. Who is responsible
Subnivo is the data controller for the personal data described here. Subnivo is a subscription-management and paid-membership platform operating in Nigeria, and this policy is written to the Nigeria Data Protection Act 2023 (NDPA).
For anything in this policy, write to privacy@subnivo.com.
One thing worth being clear about up front: when you join a creator's Hub, the creator sees information about you: your username, display name, profile image, what you posted in their community, and your membership and payment status with them. The creator is responsible for how they use that. Your email address is not shown to creators.
2. What we collect, and why
Not all of this applies to everyone. A member who joins a free community gives us very little; a creator who charges money goes through identity verification and gives us considerably more.
Account and identity
Your name, public username, email address, password (stored only as a hash), whether your email is verified, your profile image, your login sessions, and (if you turn it on) two-factor authentication secrets and backup codes. Used to create and secure your account.
Device and network
The IP address and browser or app user agent attached to your sessions, and counters keyed to your IP or account used for rate limiting. Used to keep accounts secure, detect abuse and keep the service stable.
Business, Hub and plan information
If you run a community: your business profile and type, your Hub's name, tagline, description, images and accent colour, and the plans and prices you publish. Used to deliver the service you signed up for.
Creator verification (only if you charge money)
Your declared name, representative name and date of birth, your Bank Verification Number (BVN), your bank account number and bank code, the details our payment provider returns when we check them, and the outcome of comparing the two. Also the identity or business documents you upload.
This is the most sensitive data we hold, so how it is handled matters: documents are stored in private object storage and are never public; staff access requires an active case, a named reason, and recent multi-factor re-authentication, and every access is logged; your BVN is retained so staff can resolve payment disputes against it, and is never returned to any client application in full. Verification is not requested from members, and not from creators running free communities.
Membership, payment and financial records
Your checkouts, subscriptions, invoices, refunds, disputes, double-entry ledger records and settlement records, together with the policy text you accepted at checkout. Also the email address our payment provider holds for you, which is kept as the provider recorded it and does not follow later changes to your Subnivo email.
We never receive your full card details. Card data is entered with Paystack and stays with them.
Community content
Messages you post, threads, replies, reactions, mentions, files you attach, pins, which channels you have read, and presence and typing indicators. Used to run the community you joined.
Safety and moderation
Reports you make about a message, moderation actions taken and the reason given, and timeouts or bans including who applied and lifted them. Used for community safety and to keep enforcement accountable.
Connected Discord and Telegram
Your user ID and username on those platforms once you link them, plus the record of access we granted or removed and any failed attempts. Used to provision and revoke the access that comes with a membership.
Support
Support cases you open, the messages in them and any files you attach. Used to help you, and as evidence in refund and dispute decisions.
Email and preferences
The emails we send you, delivery results, and your notification preferences for renewals, grace periods and community mentions.
Analytics and service telemetry
Product analytics events, application logs, performance metrics and traces. We also use Microsoft Clarity for behavioural analytics and session replay. Section 4 explains what it does and does not capture.
3. Our lawful bases
| What we do | Lawful basis under the NDPA |
|---|---|
| Create and run your account; deliver Hubs, memberships and access; take payment | Performance of our contract with you |
| Keep financial and tax records; verify creators; respond to lawful requests | Compliance with a legal obligation |
| Secure accounts, prevent fraud and abuse, moderate for safety, keep the service reliable, and understand how the product is used | Our legitimate interests, balanced against your rights |
| Anything we ask your permission for, including where consent is legally required | Consent, which you can withdraw at any time |
4. Cookies and analytics
Subnivo sets very few cookies, and none of them are advertising cookies.
- Session cookies: these keep you signed in. They are HTTP-only, sent only over HTTPS, restricted to the site that set them, and strictly necessary.
- A layout preference: remembers whether you collapsed the sidebar. Expires after seven days.
- Microsoft Clarity: sets its own cookies and identifiers to measure how the application is used.
On Clarity, specifically: the interior of the application is masked, so the text of member details, community messages, billing information and verification data is excluded from session recordings. What is collected is interaction and device data: clicks, scrolling, navigation, viewport, approximate location from IP, and error signals. We use it to find where the product confuses people.
Subnivo does not currently present a cookie consent banner. If a consent mechanism is required for behavioural analytics under the NDPA, we will add one and update this policy. If you would rather not be included in Clarity measurement in the meantime, write to privacy@subnivo.com and we will exclude you.
This marketing site does not run analytics or set cookies at all.
5. Who else processes your data
We do not sell personal data and we do not share it for advertising. We use the following processors and platforms to run the service:
| Provider | What they do for us | What reaches them |
|---|---|---|
| Cloudflare | Hosting, DNS, edge delivery, private file storage, staff access control | Request metadata, and the files you upload |
| Neon | The main product database and the separate staff database | Account, membership, verification and financial records |
| MongoDB Atlas | Community chat storage | Messages, threads, reactions and chat metadata |
| Managed Valkey / Redis | Realtime state and the background job queue | Short-lived session and job data |
| Paystack | Payment processing, bank account and BVN resolution, creator subaccounts | Payment and customer details, and verification inputs |
| Resend | Transactional email | Your email address and delivery metadata |
| Discord | Connected community access | Your Discord identity and the roles we manage |
| Telegram | Connected community access | Your Telegram identity and group membership |
| Microsoft Clarity | Behavioural analytics and session replay | Interaction and device data, as described in section 4 |
We may also disclose data where the law requires it, to establish or defend legal claims, to protect someone's safety, or to a buyer if the business is ever transferred, in which case this policy continues to apply until you are told otherwise.
6. International transfers
Several providers above operate infrastructure outside Nigeria, so your data may be processed abroad. Where that happens we rely on the transfer safeguards available under the NDPA, including contractual protections with each provider. You can ask us which providers hold data for a given category by writing to privacy@subnivo.com.
7. How long we keep things
We keep personal data only while there is a reason to. The principles we apply are below; where an exact figure is still being set, this says so rather than quoting a number we could not honour.
| Category | How long |
|---|---|
| Account, identity and sessions | While your account is active, then a limited post-closure period for security and dispute purposes. Exact period being finalised. |
| Membership, invoice, refund, dispute and ledger records | Retained as immutable financial evidence for the statutory accounting, tax and dispute period that applies in Nigeria. These survive account closure. |
| Creator verification data and documents | Retained while needed for eligibility, fraud prevention and provider obligations. The lifecycle is under review and will be narrowed to a defined period. |
| Community messages and attachments | Exact period being finalised. Deleting a message removes it from the community immediately; the underlying deletion, backup expiry and legal-hold behaviour is being defined before it is automated. |
| Connected platform identity and access records | While the account is linked and access is needed, then minimal records of what was granted or removed. |
| Support cases | For the period in which a related dispute or claim could still be raised. |
| Logs, metrics, traces and rate-limit counters | The shortest operationally useful window. |
8. Your rights
Under the NDPA you can ask us to:
- give you access to the personal data we hold about you;
- correct anything inaccurate;
- delete your data;
- restrict how we use it, or object to a use based on legitimate interests;
- give you a copy in a portable, machine-readable form; and
- withdraw consent where consent is what we relied on.
Write to privacy@subnivo.com. We will verify that the request is really yours, normally through your signed-in session, and otherwise by a proportionate check that asks for no more identity data than the request needs. We respond within 30 days.
Some limits apply, and it is fairer to state them plainly. We may not be able to erase records we are legally required to keep, financial and tax records in particular, or records held for an active dispute, fraud investigation, safety matter or legal hold. Where that happens we will tell you which data we have kept and why. Deleting your account also does not remove your messages from other people's copies of a conversation where those are held under the same legal basis.
9. How we protect data
- Member accounts and staff accounts are entirely separate systems, with separate databases, credentials and sessions. Staff cannot sign in as you.
- Staff access is least-privilege and permission-gated. Privileged work requires multi-factor step-up re-authentication, a linked case and a written reason, and is recorded in an append-only audit log.
- Uploaded files are held in private storage and served only through short-lived signed links. Nothing is publicly addressable.
- Files are scanned before other members can open them.
- Payment webhooks are cryptographically verified before they are acted on, so a forged payment notification cannot grant access.
- Passwords are stored only as hashes. Two-factor authentication is available on your account.
- Data is encrypted in transit, and at rest by our infrastructure providers.
No system is completely secure. If a breach affects your personal data we will notify you and the Nigeria Data Protection Commission as the NDPA requires. To report a vulnerability or a suspected breach, write to privacy@subnivo.com.
10. Automated decisions
We do not make decisions about you that are both solely automated and significantly consequential. Automated checks do run, comparing your declared details with what the payment provider returns during verification, screening uploads and applying risk thresholds, but a member of staff reviews and decides verification outcomes, refunds and enforcement. You can ask for a decision to be looked at again.
11. Children
Subnivo is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, tell us at privacy@subnivo.com and we will remove it.
12. Changes to this policy
We will update this policy as the service develops, in particular when the retention periods marked above are settled. Each version carries its own version number and effective date. For material changes we will give notice through the service or by email.
Version history
| Version | Effective | Change |
|---|---|---|
| 2026-07-26 | 26 July 2026 | First published version. |
13. Contact and complaints
- Privacy, data requests, breach reports: privacy@subnivo.com
- Everything else: support@subnivo.com
If you are unhappy with how we have handled your data you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng). We would rather hear from you first, but that right is yours regardless.
Related: Terms of Use.