Overcast privacy

Privacy Notice

This is a product-policy draft, not legal advice. Complete a Nigeria Data Protection Act review before public launch.

Data we use

Depending on the feature, Overcast stores account identity, contact details, pickup location, vendor bank-verification details, listings, orders, messages, evidence exports, payment references, ledger events, and support/moderation records.

Why we use it

We use this data to authenticate users, show listings, verify vendors, process escrow payments, coordinate orders, prevent fraud, resolve disputes, provide support, and meet legal/accounting obligations.

Service providers

Supabase provides authentication/database/storage and Paystack provides payment and bank-account verification services. Configure contracts, transfer safeguards, retention, and access controls before production.

Your choices

Provide a support route for access, correction, deletion, objection, and breach questions. Define what must be retained for financial, fraud, or dispute records and for how long.

Security

Use HTTPS, least privilege, private storage, audit logs, secret rotation, backups, and an incident-response process. Never send passwords, payment secrets, or private encryption keys through support chat.

Contact and effective date

Replace this placeholder with the registered controller name, privacy contact/DPO route, effective date, retention schedule, and complaint escalation path.