Privacy Policy
How Raire collects, uses, shares and protects personal data
Effective date
1 August 2026
Operator
RAIRE LIMITED (RC 8806106), Lagos, Nigeria
RAIRE LIMITED (“Raire”, “we”, “us” or “our”) respects your privacy. This Privacy Policy explains how we process personal data when you use the Raire mobile application, raireapp.com, and related marketplace, payment, verification, authentication, delivery, communication and support services (the “Platform”).
1. Who we are
RAIRE LIMITED (RC 8806106), Lagos, Nigeria, is the data controller for personal data processed for Raire’s own purposes. Some providers, including payment, identity-verification, social-login, courier and authentication providers, may also act as independent controllers for their own legal and operational purposes.
Privacy questions and rights requests: support@raireapp.com or +234 (0) 913 680 9841.
2. Scope
This Policy applies to buyers, sellers, website visitors, waitlist members, support contacts and other Platform users. It does not govern a third party’s independent website, app or service, even if linked from Raire. Their notices apply to their processing.
3. Personal data we collect
3.1 Account and profile data
We may collect your name, username, email address, telephone number, password or authentication credentials, profile photograph, biography, city, state, account role, preferences, followers/following, likes and public profile information.
3.2 Seller identity, compliance and payout data
For sellers, we may collect legal name, date of birth, business or shop information, pickup information, bank name and account number, account-name verification, National Identification Number (NIN), Bank Verification Number (BVN), government identity-document information, selfie, liveness or facial-verification data, verification status, risk indicators and related metadata.
Smile ID, Paystack, banks or other verification providers may collect identity images, numbers and biometric or liveness information directly. Depending on the integration, Raire may receive verification results, reference numbers, risk signals and limited identity metadata rather than full source documents. Biometric and identity data is sensitive and is used only for verification, security, fraud prevention, payments and legal compliance.
3.3 Listings, content and communications
We collect listing photographs and videos, descriptions, size, measurements, brand, condition, price, quantity, production time, drafts, comments, questions, messages, reports, reviews, dispute evidence, and communications with Raire. Messages are not public, but Raire may access them where necessary for service delivery, safety, fraud prevention, support, disputes and enforcement.
3.4 Transaction and delivery data
We collect cart and order contents, offer history, item and delivery prices, commission, authentication selection, payment status, Paystack transaction references, refunds, chargebacks, payout records, bank payout status, pickup and delivery addresses, recipient name and telephone number, courier events, Hub inspection status, proof of delivery and dispute outcomes.
Payment providers process card details, bank-transfer information and other payment credentials. Raire does not intend to store full payment-card numbers, CVV codes or online-banking passwords.
3.5 Device, app and usage data
We may collect IP address, device type, operating system, app version, language, time zone, device or installation identifiers, push-notification token, login and session information, crash and diagnostic logs, security events, pages or screens viewed, searches, clicks, feature use and approximate location inferred from IP or delivery information. We do not currently request precise device location for map services.
3.6 Permissions and information from your device
With your device permission, Raire may access:
camera and photographs, so you can create listings, add a profile image, submit evidence or scan permitted content;
contacts, so you can discover people you may know on Raire; contact matching may compare telephone numbers or email addresses, including through hashed or otherwise protected identifiers, and does not authorise Raire to message contacts without a separate instruction; and
notifications, so Raire can send order, message, security, offer and account alerts.
You can change permissions in device settings, although some features may stop working. Raire should request access only when needed and should not access unrelated files or contacts.
3.7 Social sign-in data
If you sign in with Google, Apple or Facebook, we receive the information that provider permits you to share, such as a provider user identifier, name, email address and profile image. Apple may provide a relay email address. We do not receive your social-provider password.
3.8 Website, waitlist and marketing data
On raireapp.com, we may collect waitlist or newsletter details, campaign source, form submissions, consent choices, cookie identifiers, browser type, pages visited and interactions. Brevo is used for website waitlist and email campaigns; it is not used as the app’s primary messaging system.
3.9 Information from other sources
We may receive information from sellers and buyers, couriers, authenticators, Paystack, Smile ID, banks, social-login providers, fraud and security services, public sources, regulators, law enforcement, and people who report content or transactions. We may combine it with information already held to verify transactions and protect the Platform.
4. How we use personal data
create, authenticate, secure and manage accounts;
verify sellers, bank accounts and identity and prevent duplicate, fraudulent or unsafe accounts;
publish profiles and listings and personalise discovery, search, recommendations and social features;
enable carts, offers, orders, payments, commissions, refunds, chargebacks and seller payouts;
coordinate pickup, Hub inspection, delivery, tracking, failed delivery, returns and optional authentication;
enable messages, questions, reviews, notifications and customer support;
investigate disputes, prohibited goods, counterfeit concerns, abuse, security incidents and legal claims;
measure, troubleshoot, protect, develop and improve the Platform;
send essential service, legal, transaction and security communications;
send marketing where permitted and honour unsubscribe or objection requests;
comply with tax, accounting, consumer, data-protection, law-enforcement, court, payment and regulatory obligations; and
create aggregated or de-identified statistics that do not reasonably identify an individual.
5. Legal bases for processing
Under the Nigeria Data Protection Act 2023 and other applicable law, we rely on one or more of the following:
Contract: processing needed to create an account, provide requested features, complete orders, coordinate delivery, resolve transaction issues and pay sellers;
Legal obligation: processing needed for legal, tax, accounting, regulatory, fraud, payment, court or law-enforcement duties;
Legitimate interests: protecting users and Raire, preventing fraud, enforcing rules, improving the Platform, keeping records, securing systems and marketing similar services, where those interests are not overridden by your rights;
Consent: optional device permissions, certain sensitive-data processing, non-essential cookies, direct marketing, and other processing where consent is requested; and
Establishment, exercise or defence of legal claims and other grounds permitted for sensitive personal data.
Where we rely on consent, you may withdraw it at any time without affecting processing already lawfully carried out. Refusing information required for a contract or legal obligation may prevent account creation, selling, payout, delivery or another requested feature.
6. When we share personal data
We share only what is reasonably necessary with the following recipients:
Other users: public profile and listing information, reviews, order status, and limited transaction information needed to communicate or resolve an order. For Raire delivery, sellers do not receive the buyer’s full delivery address;
Paystack, banks and payment networks: identity, transaction, bank, refund, chargeback, fraud and payout information;
Smile ID and identity providers: seller identity, document, NIN/BVN, selfie, liveness and verification information;
Couriers and the Raire Hub: recipient, contact, address, item, pickup, delivery, evidence and return information;
Authenticators: item information, photographs, order reference and other data needed for an authentication selected at checkout;
Technology providers: Firebase services for authentication, notifications, security or diagnostics; MongoDB or other cloud database and hosting infrastructure; email, security, storage and development providers;
Google, Apple and Meta: information needed for social sign-in and their security and account functions;
Brevo: website waitlist, newsletter, campaign and consent information;
Professional advisers, insurers, auditors and contractors: information reasonably needed for their services and confidentiality duties;
Regulators, courts, law enforcement and public authorities: where required or permitted by law or necessary to protect rights, safety and Platform integrity; and
Corporate transaction participants: under appropriate safeguards in connection with financing, restructuring, merger, acquisition, sale or transfer of all or part of the business.
We do not sell personal data. We do not permit service providers to use Raire-controlled data for their own unrelated advertising merely because they process it for us.
7. Public information and visibility
Usernames, profile photographs, biographies, public follower relationships, listings, seller status, sold indicators and reviews may be visible to other users or the public. Search engines may index public website content. Do not post information you want to keep private. Messages, exact delivery addresses, KYC information, payment credentials and bank details are not intended to be public.
8. Cookies and similar technologies
Raire’s website and app may use cookies, software development kits, local storage, pixels and similar technologies for login, security, preferences, performance, analytics and—only where permitted—marketing. Essential technologies are necessary for requested services. Non-essential analytics or marketing technologies should operate according to the choices in the Privacy Preference Center or device settings.
You can adjust browser cookies, device permissions and marketing choices. Blocking essential technology may prevent parts of the Platform from working. Raire does not intend to access an advertising identifier or track users across unrelated apps for targeted advertising without any consent required by law or platform rules.
9. Direct marketing
We may send product updates, seller opportunities, recommendations, launch news and offers where you have consented or where otherwise permitted. You can unsubscribe using the message link or contact support@raireapp.com. Transaction, security, legal and service messages are not marketing and may continue while you have an account or open transaction.
If you object to direct marketing, we will stop using your personal data for that purpose and may retain minimal suppression information so we do not contact you again unintentionally.
10. International transfers
Some providers or their infrastructure may process data outside Nigeria, including where global cloud, payment, identity, social-login, email or support services operate. Where personal data is transferred internationally, Raire will use a lawful transfer basis and appropriate safeguards under the Nigeria Data Protection Act, such as an adequacy determination, contractual protections, consent where appropriate, or another permitted mechanism. We also assess the nature of the data and require reasonable security measures.
11. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described, including account operation, transactions, fraud prevention, disputes, tax and accounting, legal claims and regulatory duties. Typical retention is:
Data category
Typical retention approach
Account and profile
While the account is active; ordinary account data is scheduled for deletion or de-identification within about 30 days after a valid deletion request, subject to open transactions and exceptions below.
Transactions, tax and payouts
Generally at least six years after the relevant year or transaction, or longer where law, audit, fraud, chargeback or litigation requires.
Seller KYC and verification
For the seller relationship and thereafter for the period required by law, payment or fraud obligations, generally up to six years unless a longer lawful hold applies. Providers may apply their own legal retention.
Disputes, support and enforcement
For the life of the account and generally up to six years after closure of the matter where needed for claims, safety and consistency.
Technical and security logs
Usually up to 12 months, but longer where connected to a security incident, fraud investigation or legal claim.
Marketing records
Until you unsubscribe, object, or the campaign purpose ends; minimal suppression data may be retained to honour your choice.
Backups
Deleted data may remain in protected backups for up to 90 days before routine overwrite, unless a lawful hold applies.
These are operational targets, not promises to keep data for the maximum period. We may delete or de-identify earlier where lawful and no longer needed, and retain longer where required for fraud, safety, a court order, regulatory inquiry, legal claim or statutory recordkeeping.
12. Account deletion
You may request account deletion through the app. We will authenticate the request and may first require completion of open orders, payouts, returns, disputes or chargebacks. Account access and public profile content may be removed promptly, while ordinary backend data is scheduled for deletion or de-identification within about 30 days.
Deletion does not require us to erase transaction, tax, KYC, fraud, security, dispute or legal records that must or may lawfully be retained. Some content may remain where another user has an independent record, where it was incorporated into a completed transaction, or in protected backups until overwritten. We will restrict retained data to the applicable purpose.
13. Your rights
Subject to the Nigeria Data Protection Act 2023 and applicable exceptions, you may have the right to:
receive information about our processing and request access to your personal data;
correct inaccurate or incomplete data;
request deletion of data that is no longer required or unlawfully processed;
restrict or object to certain processing, including objecting at any time to direct marketing;
withdraw consent without affecting prior lawful processing;
receive certain data in a structured, commonly used, machine-readable format and request portability where applicable;
object to a decision based solely on automated processing that produces legal or similarly significant effects, and request human review where the law provides; and
lodge a complaint with the Nigeria Data Protection Commission or seek another available remedy.
Send requests to support@raireapp.com. Describe the request and the account involved. We may verify identity and authority before responding and may refuse or charge only where law permits, such as for manifestly unfounded or excessive requests. We will respond within the period required by law.
14. Automated tools and fraud decisions
Raire and its providers may use rules, risk indicators or automated tools to flag unusual logins, identity mismatches, payment risk, duplicate accounts, prohibited content or transaction abuse. Significant actions should include appropriate human review where required by law. You may contact support to challenge an account or transaction decision.
15. Security
We use technical and organisational measures appropriate to the nature and risk of the data, including access controls, authentication, encryption in transit where supported, environment and role separation, logging, backups, provider due diligence and incident procedures. No internet or storage system is completely secure, so we cannot guarantee absolute security.
Protect your password, verification codes and devices; do not send payment credentials through messages; and report suspected compromise to support@raireapp.com. Where a personal-data breach triggers legal notification duties, Raire will notify the Nigeria Data Protection Commission and affected individuals as required.
16. Children
Raire is for people aged 18 and older. We do not knowingly permit children to create accounts or sell or buy through the Platform. If you believe a person under 18 has provided personal data, contact us so we can investigate and take appropriate action.
17. Changes to this Policy
We may update this Policy to reflect legal, product, provider or operational changes. We will update the effective date and give reasonable notice of material changes through the app, website, email or another appropriate method. Where required, we will request fresh consent rather than relying only on continued use.
18. Complaints and contact
Contact RAIRE LIMITED first so we can investigate:
RAIRE LIMITED (RC 8806106)
Lagos, Nigeria
Email: support@raireapp.com
Telephone: +234 (0) 913 680 9841
You may also complain to the Nigeria Data Protection Commission (NDPC) through its official website at https://ndpc.gov.ng or use any other remedy available under law.
19. Legal framework
This Policy is intended to be read consistently with the Nigeria Data Protection Act 2023, applicable guidance issued by the Nigeria Data Protection Commission, the Federal Competition and Consumer Protection Act 2018, and other applicable Nigerian law.
