Privacy Policy
Effective date: 18 August 2026
1. Scope and Roles
This Privacy Policy explains how FlyMyAds Digital Services (trading as "FlyMySMS", "we", "us", or "our") handles personal data in connection with the FlyMySMS platform (the "Service"). It should be read together with our Terms and Conditions.
The Service handles two different kinds of personal data, and our role differs for each:
- Account Data - your own name, email address, and organisation details. For this data, we are the data controller: we decide why and how it's processed, as described in this policy.
- Contact Data - the recipient phone numbers, names, and message content you upload to send campaigns. For this data, you (or your organisation) are the data controller, and FlyMySMS is a data processor acting only on your instructions. You are responsible for having a lawful basis (e.g. the recipient's consent) to hold and message that data - see Section 4 of the Terms and Conditions ("Acceptable Use").
2. Information We Collect
We collect:
- Account Data you provide at signup and afterwards: name, email address, password (stored as a salted hash, never in plain text), and organisation/business name.
- Contact Data you upload: recipient phone numbers, optional names/emails, and the message content of campaigns and test sends you create.
- Payment Data: wallet top-up amounts and status. Card and bank details are entered directly with our payment processor, Paystack - we never receive or store your full card number.
- Usage and Log Data: sign-in timestamps, IP address (used for rate-limiting to prevent abuse - see our architecture notes on Postgres-backed rate limiting), and an audit trail of account actions (e.g. campaign created, wallet topped up) for security and support purposes.
3. How We Use Information
We use the information above to:
- provide the Service - create your account, let you build and send campaigns, process wallet top-ups, and deliver the messages you send;
- secure the Service - detect and rate-limit abusive login/signup/password-reset attempts, and maintain an audit trail;
- communicate with you - password reset and email verification messages, and operational notices about your account; and
- comply with legal obligations, including responding to lawful requests from regulators or law enforcement.
We do not sell personal data, and we do not use Contact Data for our own marketing purposes.
4. Legal Basis for Processing
Where the Nigeria Data Protection Act 2023 and its regulations (NDPR) apply, we process Account Data on the basis of performing our contract with you (providing the Service you signed up for) and our legitimate interest in keeping the Service secure. Contact Data is processed on your instructions, as our customer and its data controller - it is your responsibility to establish a lawful basis (typically consent) for messaging your recipients.
5. Sharing With Third-Party Service Providers
We share personal data only with the service providers that help us operate the Service, under agreements that restrict them to using it solely to provide that service to us:
- Paystack - processes wallet top-up payments.
- Zoho ZeptoMail - delivers transactional emails (password reset, email verification).
- our SMS gateway provider - delivers the messages you send; recipient phone numbers and message content are shared with them for that purpose only.
- our database and hosting infrastructure providers, who store data on our behalf.
We do not otherwise share personal data with third parties, except where required by law or with your consent.
6. Data Retention
We retain Account Data for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or dispute-resolution obligations. We retain Contact Data for as long as you keep it in your account; deleting a contact or your account removes it from active use, though it may persist briefly in backups until they age out.
7. Your Rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data, subject to our legitimate need to retain some records (e.g. financial/audit records);
- object to or restrict certain processing; and
- withdraw consent where processing is based on consent.
To exercise any of these rights, contact us using the details in Section 12. If your recipients want to exercise rights over data your organisation holds about them (as opposed to us), that request should go to you, as the data controller for Contact Data - we will assist you in responding to it.
8. Data Security
We use industry-standard measures to protect personal data, including encrypted connections (HTTPS), salted password hashing, rate limiting on authentication endpoints, and role-based access controls restricting cross-organisation data access. No system is perfectly secure, and we cannot guarantee absolute security.
9. International Data Transfers
Some of our service providers (Section 5) may process data outside Nigeria. Where that happens, we require those providers to maintain protections consistent with NDPR requirements for cross-border transfers.
10. Children's Privacy
The Service is not directed at, and we do not knowingly collect Account Data from, anyone under 18.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will make a reasonable effort to notify you (e.g. by email or an in-app notice) before they take effect.
12. Contact Us
Questions about this policy, or requests to exercise your data rights, can be sent to admin@flymyads.com.