VilliQ
PrivacyTermsCookiesRefunds

Privacy Policy

Last updated: September 2, 2026

1. Who This Policy Is About

This policy covers information VilliQ ("VilliQ", "we", "us") collects about you if you are a VilliQ account holder — an organization owner or a team member they have invited. It also covers information your organization enters about occupants (tenants, lessees, short-let guests, buyers): for that information, your organization decides what is collected and why, and VilliQ processes it on your organization's instructions, acting as a data processor for that data. If you are an occupant and want to know what your landlord or agent has entered about you in VilliQ, that request goes to them, not to VilliQ directly, though we will help route it. Your organization is responsible for having a lawful basis to provide us with information about occupants and other individuals. VilliQ does not become the owner of that information merely because we store or process it on your organization's behalf.

2. Information We Collect

  • To create your account: name, email address, phone number, and a password — or a Google sign-in, in which case we never see your password.
  • About your organization: business name, address, phone, email, tax and registration numbers if you provide them, and any branding (logo, colors) you upload.
  • About occupants, entered by your organization: name, email, phone, date of birth, gender, ID type and number, employer and income, emergency contact details, and any free-text notes your team adds. Only name, email, and phone are required by the platform — everything else is optional and entered at your organization's discretion.
  • About payments: amount, method, reference number, and — for card and bank-processed payments — the response returned by the payment processor.
  • Documents and photos: property photos, maintenance-ticket photos, expense receipts, and the PDF receipts VilliQ generates for you.
  • Device, browser, and usage information: IP address and browser/device information, logged against sign-ins and against anyone who opens a shared receipt or invoice link, for security and fraud-prevention purposes.
  • Communications: messages you send through the in-app support form, and the content of receipts, reminders, and notifications VilliQ sends by email, SMS, or WhatsApp on your organization's behalf.

3. Why We Process This Information

To provide the service you have signed up for — creating your account, storing your property and occupant records, generating invoices and receipts, processing payments, and sending the notifications your organization has configured. To secure the platform — detecting suspicious sign-ins and preventing abuse. To communicate with you about your account, billing, and support requests. To comply with our own legal, tax, and regulatory obligations. We do not sell personal information, and we do not use it for advertising.

4. Who We Share Information With

VilliQ uses trusted service providers to operate and deliver the Service. Depending on how you use VilliQ, these providers may process information on our behalf, including:

  • Paystack and Flutterwave — payment processing.
  • Resend and our email infrastructure provider — service-related email, including account verification and password resets.
  • Supabase — database, authentication, and file-storage infrastructure.
  • Technical service providers — security, error detection, and service operation, where necessary to keep VilliQ running reliably.

We may also disclose information where required by law, to enforce our agreements, to prevent fraud or abuse, or to protect the rights, property, security, or safety of VilliQ, our users, or others. We do not sell personal information.

5. Where Information Is Stored

VilliQ's database and file storage run on Supabase's infrastructure. As part of delivering the Service, information may be processed or stored outside Nigeria. Where that happens, we take reasonable steps, consistent with the Nigeria Data Protection Act 2023, to ensure the information continues to receive an appropriate level of protection.

6. How Long We Keep Information

We do not run a fixed automatic-deletion schedule. We retain information for as long as your account or organization remains active, plus any additional period reasonably needed to comply with our legal, tax, accounting, or dispute-resolution obligations. When you delete your account or organization, we delete the associated data from our active systems as described in Section 10, except where we are required or permitted by law to keep it longer. Routine backups may retain a copy of deleted information for a limited additional period until that backup is naturally cycled out, rather than being edited on demand.

7. Keeping Information Secure

We implement reasonable technical and organizational measures designed to protect the information we hold. Receipts and invoices are stored in a private file store and only ever served through short-lived, single-purpose links — they are not publicly browsable. Sign-in is handled by Supabase Auth. Property, maintenance, and expense photos are stored in a store that is not access-restricted the same way, since they do not carry the same sensitivity as a financial document. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim a specific security certification or standard we have not actually obtained — if that changes, we will say so here specifically.

8. Who Can See Information Inside Your Organization

As the Service is built today, every team role your organization invites — Property Manager, Agent, or Maintenance Staff — can see the same occupant and payment records; only team-management actions, like inviting, removing, or changing the role of a team member, are restricted to the owner and other Property Managers. If you need to limit which team members can see certain records, do not invite them, or contact us to discuss your requirements.

9. Your Rights Under the Nigeria Data Protection Act 2023

You have the right to know what personal information we hold about you, to correct it if it is wrong, to ask us to delete it, to object to or restrict certain processing, to receive a copy of it in a portable format where feasible, and to withdraw any consent you have given. In practice: you can update your own profile directly in Settings; occupant records are corrected or removed by the organization that manages them, since that is who entered the information; and you can delete your account or organization entirely as described below. To exercise any of these rights directly with VilliQ, write to support@villiq.com. You can also complain to the Nigeria Data Protection Commission (NDPC) if you believe your rights have not been respected. Nothing in this policy limits any rights you have that cannot lawfully be excluded under applicable law.

10. Access, Correction, and Deletion in Practice

Deleting your VilliQ account removes your organization (if you are its sole owner) and everything in it — properties, units, occupant records, tenancies, invoices, payments — from our active systems immediately; see Section 6 for how routine backups are handled afterward. Deleting an organization directly works the same way and requires typing its name to confirm. Two things this does not do: it does not cancel an active Paystack or Flutterwave subscription on its own, and it does not remove photos or receipts already uploaded to file storage. If either of those matters to you, handle them before deleting.

11. Children's Information

VilliQ is built for property management businesses and is not directed at children. We do not knowingly collect information about anyone under 18 in the account-holder role. Occupant records may relate to any age where relevant to a tenancy or lease, entered by the organization managing that relationship.

12. Cookies and Similar Technologies

See our Cookie Policy for what VilliQ stores in your browser and why.

13. Business Transfers

If VilliQ is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require any successor to continue to honor the commitments made in this policy with respect to previously collected information.

14. Changes to This Policy

We will update the date at the top of this page when this policy changes, and post the update here before it takes effect.

15. Contact Us

Questions or requests about your information can be sent to support@villiq.com.

© 2026 VilliQ. All rights reserved.