Privacy Policy
We believe privacy is a right, not a feature. This policy explains exactly what we collect, why we collect it, who we share it with, and how you can control your data.
Introduction
Nobevra is a cross-platform business productivity and financial management platform operated by The Noble's Technology Services, a company registered with the Corporate Affairs Commission (CAC) in Nigeria.
This Privacy Policy applies whenever you visit our website, create an account, use our web or mobile applications, interact with our AI features, scan a QR code, or contact us.
Who Controls Your Data
What We Collect
We collect different categories of information depending on how you use Nobevra. Here is a transparent breakdown of every category.
- Full name & username
- Email address & phone number
- Country & language preference
- Profile photograph
- Password (hashed โ never stored in plain text)
- Business name, address & tax details
- Logo, brand colors & invoice preferences
- Team workspace & role information
- API keys (hashed)
- Custom domain configuration
- IP address & approximate location
- Device type & operating system
- Browser & app version
- Session tokens (encrypted on device)
- Crash & performance data
- Invoice amounts, line items & currencies
- Payment status & transaction references
- Card token (last 4 digits, brand, expiry โ no full card numbers)
- Payout bank account details
- Wallet balance & transaction history
AI Features
Nobevra uses AI to power the AI assistant, receipt/OCR scanning, and report insights. All AI features use Google Gemini (via the Generative Language API).
QR Codes & Analytics
When someone (e.g. your customer) scans a QR code you created with Nobevra, our systems collect data about that third party's device, even though they may have no relationship with Nobevra. As the QR code owner, you are responsible for ensuring this is consistent with applicable privacy laws and providing appropriate notice to those individuals.
Data collected on each QR scan:
- Raw IP address of the scanning device
- User-Agent string (browser/device type and version)
- Accept-Language header (language/locale preference)
- Referer header
- City and country โ derived from IP via Cloudflare geo-detection (Supabase infrastructure)
- Timestamp and QR code identifier
Contract Signatures
When a contract is electronically signed through Nobevra, we capture the signer's IP address and User-Agent at the moment of signing to create a legally valid audit trail. A SHA-256 cryptographic hash is generated and retained as part of the binding legal record.
Subprocessors
This table reflects the verified, production state of the Nobevra platform. We update it when providers change.
| Provider | Region | Purpose |
|---|---|---|
| Supabase | US | Database, Auth, Storage, Edge Functions |
| Vercel | US | Web hosting & edge delivery |
| Google Gemini API | US | AI assistant, receipt OCR, report insights |
| Google Analytics 4 | US | Web analytics (consent-gated only) |
| Google OAuth / FCM | US | Sign in with Google, push notifications |
| Flutterwave | Nigeria | Payment processing, card tokenization, payouts |
| LinkedIn API | US | Social media posting (if connected) |
| Twitter / X API | US | Social media posting (if connected) |
| Self-hosted SMTP | Nigeria | Transactional email delivery |
| ip-api.com | EU | IP geolocation (mobile โ currency detection) |
| ipapi.co | US | IP geolocation (web โ currency detection) |
| FormSubmit.co | US | Contact form handling |
Your Rights
Depending on your jurisdiction, you have the following rights. We honour these rights regardless of where you live.
The Nigeria Data Protection Commission (NDPC) is the relevant supervisory authority. Nobevra processes personal data in accordance with the Nigeria Data Protection Act 2023 and applicable NDPC regulations.
You may lodge a complaint with your local data protection authority. For UK users, this is the ICO. For EEA users, contact your national supervisory authority.
California residents have rights to access, delete, correct, and opt-out of the sale/sharing of personal information. Nobevra does not sell personal information.
Security & Contact
Effective Date: August 8, 2026. We may update this policy periodically. Material changes will be notified via in-app notification or email. This policy is interpreted in accordance with applicable Nigerian, European, and international data-protection law. Governing law: Lagos, Nigeria.
Full Legal Privacy Policy
NOBEVRA PRIVACY POLICY
Effective Date: August 8, 2026
Last Updated: August 8, 2026
1. INTRODUCTION
Welcome to Nobevra. Nobevra is a cross-platform business productivity and financial management platform operated by The Noble's Technology Services, a company duly registered with the Corporate Affairs Commission (CAC) in Nigeria. Nobevra provides tools and services including invoicing, quotations and estimates, client relationship management, expenses and receipt management, products and services management, inventory management, payment functionality, digital business cards, QR-code generation, digital identity tools, productivity tools, analytics, team collaboration, AI-assisted functionality and related business-management services.
Our website is: Nobevra
This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal information when you:
- visit our website;
- create a Nobevra account;
- use our web application;
- use our Android or iOS applications;
- use our business, invoicing or productivity features;
- communicate with us;
- contact customer support;
- subscribe to paid services;
- interact with our public QR codes, digital business cards or public-facing pages; or
- otherwise interact with Nobevra.
By using Nobevra, you acknowledge that you have read and understood this Privacy Policy.
2. WHO IS RESPONSIBLE FOR YOUR INFORMATION?
For purposes of applicable data-protection laws, the relevant Nobevra entity is: The Noble's Technology Services A company registered with the Corporate Affairs Commission (CAC), Nigeria. Nobevra is the product/platform operated by The Noble's Technology Services.
Contact
General privacy contact: invoice@noblesworld.com.ng
Data Protection Officer / Privacy Contact: privacy@noblesworld.com.ng
Website: nobevra.noblesworld.com.ng
3. OUR ROLE: DATA CONTROLLER AND DATA PROCESSOR
Depending on the circumstances, Nobevra may act as either a data controller or a data processor/service provider.
3.1 When Nobevra acts as a controller
We may act as a controller when we determine why and how personal information is processed for purposes such as:
- creating and administering user accounts;
- authentication;
- account security;
- subscription management;
- billing;
- customer support;
- fraud prevention;
- platform security;
- product analytics;
- service improvement;
- communications;
- legal compliance;
- abuse prevention;
- marketing where permitted;
- maintaining business records.
3.2 When Nobevra acts as a processor/service provider
If you use Nobevra as a business customer to store or manage information relating to your own customers, employees, contractors, suppliers or other individuals, you may determine the purposes for which that information is processed. In those circumstances, you may be the controller/business responsible for that information, while Nobevra may process the information on your instructions to provide the service. For example, if an agency stores its clients' names, email addresses and invoice information inside Nobevra, the agency may remain responsible for determining why that client information is processed. Where legally required or commercially appropriate, Nobevra may enter into a Data Processing Addendum (DPA) with business customers.
4. INFORMATION WE COLLECT
We collect information necessary to provide, secure, improve and administer Nobevra. The exact information collected depends on how you use the platform.
4.1 Account information
This may include:
- full name;
- username;
- email address;
- telephone number;
- country;
- preferred language;
- password credentials or authentication identifiers;
- profile photograph;
- account identifiers;
- authentication information;
- security settings. We do not intentionally store your plain-text password.
5. BUSINESS AND ORGANIZATION INFORMATION
When you create or configure a business workspace, we may collect:
- business name;
- trading name;
- registered business name;
- business address;
- business email;
- business telephone number;
- website;
- business category;
- industry;
- tax identification information;
- registration information;
- business logo;
- brand colors;
- invoice preferences;
- currency;
- tax settings;
- payment information;
- business descriptions;
- digital identity information.
6. INVOICE AND FINANCIAL INFORMATION
Nobevra may process information contained in business records created by you, including:
- invoice numbers;
- invoice dates;
- due dates;
- invoice amounts;
- currencies;
- products;
- services;
- quantities;
- prices;
- discounts;
- taxes;
- payment status;
- payment references;
- customer information;
- billing addresses;
- shipping information;
- notes;
- quotations;
- estimates;
- recurring invoice information;
- receipts;
- transaction records;
- expense records;
- financial reports;
- account balances;
- wallet information;
- payment-link information.
Nobevra is not a bank merely because the platform provides wallet or payment-related functionality. Payment transactions may be processed by third-party payment providers.
7. CLIENT AND CRM INFORMATION
When you use our Client CRM, you may submit information about your customers, prospects or business contacts. This may include:
- name;
- email address;
- telephone number;
- company;
- job title;
- address;
- communication history;
- transaction history;
- invoice history;
- payment history;
- customer status;
- notes;
- tags;
- customer tier;
- relationship information.
You are responsible for ensuring that you have an appropriate legal basis and authorization to submit third-party personal information to Nobevra.
8. PRODUCTS, SERVICES AND INVENTORY INFORMATION
We may process information relating to:
- products;
- services;
- product names;
- descriptions;
- SKU numbers;
- prices;
- quantities;
- inventory levels;
- categories;
- product images;
- product metadata;
- product passports;
- Digital Product Passport information;
- suppliers;
- inventory transactions.
9. RECEIPTS, DOCUMENTS AND OCR
If you use receipt scanning or OCR functionality, you may upload:
- receipts;
- invoices;
- expense documents;
- photographs;
- PDFs;
- other business documents.
These documents may contain personal, financial or other information. Nobevra processes such information to provide the functionality requested by you. Where third-party OCR or AI services are used, applicable information may be processed by those providers as necessary to deliver the requested feature. Our current production integrations should be accurately listed in our Subprocessor List.
10. QR CODES AND DIGITAL BUSINESS CARDS
Nobevra provides QR-code and digital identity functionality. Depending on the QR-code type and configuration, a QR code may contain or redirect to information such as:
- website URLs;
- contact information;
- Wi-Fi configuration;
- telephone information;
- SMS information;
- email information;
- digital business cards;
- documents;
- payment information;
- public business profiles.
QR Scan Analytics โ Important Disclosure
When a third party (for example, your customer or a member of the public) scans a QR code you have created using Nobevra, our systems may automatically collect and store the following information about that scan event:
- IP address of the scanning device (raw, at point of collection);
- User-Agent string (browser/device type and version);
- Accept-Language header (language/locale preference);
- Referer header (the source from which the QR code was accessed);
- City and country, derived from the IP address using infrastructure-level geo-detection (via Cloudflare headers processed by Supabase's infrastructure);
- Timestamp;
- QR code identifier.
This information is collected to provide you with QR code scan analytics as part of the Nobevra platform. The individuals scanning your QR codes may not be Nobevra users, and they may have no direct relationship with Nobevra. If you create publicly accessible QR codes using Nobevra, you are responsible for ensuring that your use of QR scan analytics is consistent with applicable privacy laws and that you provide appropriate notice to the individuals whose QR scan data you collect and view through the platform.
You should not place highly sensitive personal information into a publicly accessible QR code unless you understand the risks.
11. DIGITAL BUSINESS CARDS
If you create a digital business card, you may provide:
- name;
- photograph;
- business name;
- job title;
- telephone number;
- email;
- website;
- social media links;
- business address;
- professional information;
- QR code;
- NFC-related information.
You understand that information intentionally published as a public digital identity may be accessible to anyone who receives or discovers the relevant link or QR code.
12. AI FEATURES
Nobevra may provide AI-assisted functionality including:
- AI voice-assisted invoice creation;
- business insights;
- productivity analysis;
- client intelligence;
- categorization;
- document/OCR processing (AI-powered receipt scanning);
- recommendations;
- business automation;
- other AI-assisted features introduced in the future.
AI functionality may process information you provide to generate the requested output.
Current AI Providers
Nobevra currently uses Google Gemini (via Google's Generative Language API) for AI-assisted features including the AI assistant, receipt/OCR scanning, and report insights. When you use an AI-assisted feature, relevant information (such as your message, financial metrics, or a receipt image) is transmitted to Google's Gemini API for processing.
Per Google's API usage terms and Google Cloud's data processing addendum, data submitted to the Gemini API is not used to train Google's general-purpose AI models. Google acts as a data processor with respect to the content you submit through the API. For details, refer to Google's Gemini API Terms of Service and Privacy Policy.
Important
Nobevra does not represent that AI-generated content is always accurate, complete or suitable for your particular business, accounting, tax, legal or financial circumstances. You remain responsible for reviewing AI-generated:
- invoices;
- financial classifications;
- business recommendations;
- tax information;
- summaries;
- reports;
- other outputs.
Nobevra should not be treated as a substitute for a qualified accountant, lawyer, tax adviser, financial adviser or other professional.
13. PRODUCTIVITY AND BEHAVIORAL INFORMATION
If you use Nobevra productivity features, we may process:
- tasks;
- projects;
- time blocks;
- focus sessions;
- productivity categories;
- habits;
- completion rates;
- task velocity;
- usage patterns;
- productivity metrics;
- workspace activity.
We may use this information to provide:
- productivity dashboards;
- focus analytics;
- reports;
- recommendations;
- personalized experiences.
We will not represent productivity or wellness analytics as medical diagnoses.
14. TEAM AND WORKSPACE INFORMATION
If you participate in a team workspace, we may process:
- team membership;
- invitation information;
- roles;
- permissions;
- workspace activity;
- membership status;
- administrative actions;
- audit records.
Workspace administrators may be able to access or manage information associated with the workspace depending on their permissions. If you use Nobevra through an employer, agency or other organization, that organization may control certain aspects of your account.
15. PAYMENT INFORMATION
Nobevra may integrate with third-party payment providers (e.g. Flutterwave). Depending on the payment method, payment providers may process:
- card information;
- bank information;
- payment identifiers;
- transaction references;
- payment status;
- billing information;
- fraud-prevention information.
Where payment information is handled directly by a payment provider, Nobevra does not intentionally store full payment-card credentials unless explicitly stated otherwise. The applicable payment provider's privacy policy also applies to information it processes.
If you configure payout methods for receiving funds, your payout bank account details are stored securely in our database. While our infrastructure provider (Supabase) encrypts all data at rest at the storage level, we strongly recommend you do not store highly sensitive banking information beyond what is strictly required for payouts.
16. DEVICE AND TECHNICAL INFORMATION
When you use Nobevra, we may automatically collect technical information including:
- IP address;
- device type;
- operating system;
- browser;
- application version;
- device identifiers;
- language;
- time zone;
- approximate location;
- network information;
- crash information;
- performance information;
- referring URLs;
- interaction information.
16A. MOBILE APPLICATION LOCAL STORAGE
If you use the Nobevra mobile application, certain data is stored locally on your device to enable offline functionality and improve performance. Client records, invoice data, and related information may be stored in an offline cache (such as Isar database) on your device. This locally cached data is protected by your device's native security (such as your lock screen or biometrics), but it is not inherently encrypted at rest by the Nobevra application itself. You are responsible for securing your mobile device.
17. LOGS, SECURITY AND AUDIT TRAILS
For security, accountability and troubleshooting, we may maintain logs containing:
- authentication events;
- login attempts;
- account changes;
- permission changes;
- workspace actions;
- API activity;
- security events;
- administrative events;
- payment events;
- system errors;
- IP addresses;
- timestamps.
These records may be retained for longer than ordinary account information where reasonably necessary for security, fraud prevention, legal compliance or dispute resolution.
18. COOKIES AND TRACKING TECHNOLOGIES
Strictly Necessary
We use strictly necessary cookies and browser storage for:
- maintaining your authenticated session;
- security and CSRF protection;
- remembering your cookie preferences;
- platform functionality that cannot operate without these technologies.
These are used on the basis of our legitimate interest in providing a functional, secure service. They do not require consent.
Analytics โ Google Analytics 4 (GA4)
Our web application uses Google Analytics 4 (GA4, measurement ID: G-6ME42JV7BJ), a service operated by Google LLC. GA4 uses cookies and similar technologies to collect information about how visitors interact with our website, including:
- pages visited and time spent;
- user interactions and navigation paths;
- approximate geographic region;
- device and browser type;
- anonymized IP address (IP anonymization is enabled);
- referral source.
GA4 analytics cookies are non-essential and are only loaded after you have explicitly accepted optional cookies through our cookie consent banner. If you decline optional cookies, Google Analytics will not be activated during your session. You may change your preference at any time by clearing site data in your browser settings and revisiting the site.
For more information about how Google processes this data, see: https://policies.google.com/privacy.
Contact Form
Our public contact form is processed by FormSubmit.co, a third-party form-handling service. When you submit our contact form, the information you provide (such as your name, email address, and message) is transmitted to FormSubmit.co's servers for delivery to our inbox. FormSubmit.co's own privacy policy governs their processing of this data.
Mobile App โ IP Geolocation
Our mobile app uses the ip-api.com API (https://ip-api.com) to automatically detect your country based on your device's IP address. This allows Nobevra to pre-select an appropriate currency for your region. Only your IP address is sent to this service; it is not linked to your account or stored by us from this request.
Web App โ IP Geolocation
Our web application uses the ipapi.co API (https://ipapi.co) for the same currency auto-detection purpose. As above, only your IP address is involved, and we do not store the result in association with your identity.
We will not treat all cookies as requiring the same legal basis. A separate Cookie Policy accompanies this Privacy Policy and provides further detail.
19. HOW WE USE PERSONAL INFORMATION
We may use information to:
Provide the service
- create accounts;
- authenticate users;
- create invoices;
- manage clients;
- manage expenses;
- process documents;
- generate QR codes;
- create business cards;
- manage teams;
- provide analytics;
- provide AI features;
- provide payment functionality.
Maintain security
- detect fraud;
- prevent abuse;
- detect unauthorized access;
- investigate security incidents;
- protect users;
- enforce platform rules.
Improve Nobevra
- analyze product usage;
- identify bugs;
- improve performance;
- develop new functionality;
- personalize experiences;
- conduct product research.
Communicate with you
- account notifications;
- security alerts;
- billing communications;
- service announcements;
- customer support;
- product updates;
- marketing communications where permitted.
Comply with law We may process information when necessary to comply with:
- applicable law;
- court orders;
- regulatory requirements;
- tax obligations;
- lawful governmental requests;
- fraud investigations.
20. LEGAL BASES FOR PROCESSING
Where GDPR, UK GDPR or another law requiring a lawful basis applies, we may rely on one or more of the following:
- Contract: Where processing is necessary to provide Nobevra services you requested.
- Legal obligation: Where processing is necessary to comply with legal obligations.
- Legitimate interests: Where processing is reasonably necessary for purposes such as security, fraud prevention, service improvement, business administration, customer support, network security, and enforcing agreements. We will consider applicable balancing requirements when relying on legitimate interests.
- Consent: Where consent is legally required, we will request it. You may withdraw consent where applicable. Withdrawal of consent does not invalidate processing that occurred before withdrawal.
21. DATA SHARING
We do not sell personal information as a business model. We may disclose information to carefully selected service providers necessary to operate Nobevra. These may include:
- cloud infrastructure providers;
- database providers;
- storage providers;
- authentication providers;
- payment providers;
- email providers;
- analytics providers;
- AI providers;
- OCR providers;
- security providers;
- customer-support providers;
- monitoring providers;
- professional advisers.
22. INFRASTRUCTURE AND THIRD-PARTY PROVIDERS
Nobevra uses the following third-party providers. Each provider acts as a data processor with respect to information we share with them for the stated purpose.
Cloud Infrastructure
- Supabase (Supabase Inc., US): Backend infrastructure including PostgreSQL database, authentication, object storage, real-time services, and Edge Functions. User data โ including account details, invoices, client records, and financial data โ is stored in Supabase's managed infrastructure.
- Vercel (Vercel Inc., US): Web application hosting, edge delivery, and infrastructure for the Nobevra web platform. Vercel publishes its own DPA addressing processor obligations, security, subprocessors, data-subject requests, deletion and international transfer provisions.
Authentication
- Google OAuth (Google LLC, US): Used to enable "Sign in with Google" on both the web and mobile applications. When you authenticate using Google, Google processes your Google account identity information to verify your identity. Google's Privacy Policy applies to their processing.
- Supabase Auth (see above): Manages session tokens, password hashing, and authentication flows.
Payments
- Flutterwave (Flutterwave Inc.): Used for subscription billing, payment processing, card tokenization, and payouts. When you make a payment, relevant billing and payment information is transmitted to Flutterwave. Flutterwave is PCI-DSS compliant as a payment processor. Nobevra stores only tokenised card identifiers (card brand, last 4 digits, expiry), not full card numbers. Flutterwave's Privacy Policy applies to their processing.
AI Processing
- Google Gemini API (Google LLC, US): Used for AI-assisted features including the AI assistant, receipt OCR/scanning, and report insights. Content submitted to AI features (such as receipt images, financial metrics, and messages) is transmitted to Google's Gemini API. Per Google API terms, data is not used for AI training.
- Self-hosted SMTP (mail.noblesworld.com.ng, operated by The Noble's Technology Services): Used to send transactional emails including invoice delivery, invoice reminders, and team invitation emails. Invoice and client details are included in outbound emails as necessary to deliver the relevant email.
Analytics
- Google Analytics 4 (Google LLC, US): Used for web analytics on our public website and web application (analytics cookies only load after consent โ see Section 18).
IP Geolocation
- ip-api.com (Intersoft Data Labs): Used by the mobile app to detect your country from your IP address for currency auto-detection. Connection is made over HTTPS.
- ipapi.co (Kloudend Inc.): Used by the web app for the same currency auto-detection purpose.
Push Notifications
- Firebase Cloud Messaging (FCM) (Google LLC, US): Used to deliver push notifications to Android and iOS devices. Nobevra stores your device's FCM registration token in our database to send you relevant notifications such as invoice payment confirmations and team updates. FCM tokens are device-level identifiers provided by the Firebase SDK.
Social Media Integration
- LinkedIn API (LinkedIn Corporation, US): If you connect your LinkedIn account, LinkedIn OAuth credentials (access token and expiry) are stored in our database to enable automated social media posting on your behalf. LinkedIn's Privacy Policy governs their processing.
- Twitter / X API (X Corp., US): If you connect your Twitter/X account, the API is used to post content on your behalf. Server-side API credentials are used; no OAuth tokens from your personal account are stored beyond what is necessary for the connection.
Contact Form
- FormSubmit.co: Used to process our public contact form. Name, email, and message are transmitted to FormSubmit.co. See Section 18 for more detail.
The exact provider list, data categories, and processing purposes are maintained in our Subprocessor List, which is updated periodically.
23. INTERNATIONAL DATA TRANSFERS
Nobevra serves users in Nigeria, Africa and other jurisdictions. Your information may therefore be processed in countries other than the country in which you reside. Where applicable law requires safeguards for international transfers, we will seek to implement appropriate mechanisms, which may include:
- adequacy decisions;
- Standard Contractual Clauses;
- contractual safeguards;
- other legally recognized transfer mechanisms. Users should understand that cloud infrastructure may involve international processing even when a business operates primarily in Nigeria.
24. DATA RETENTION
We retain personal information only for as long as reasonably necessary for:
- providing the service;
- maintaining your account;
- fulfilling contractual obligations;
- legal obligations;
- accounting;
- tax;
- fraud prevention;
- security;
- dispute resolution;
- enforcement of agreements.
Retention periods may vary depending on the category of information. For example, financial transaction records may need to be retained longer than ordinary marketing information.
25. ACCOUNT DELETION
You may request deletion of your Nobevra account through the available account-management functionality or by contacting us. Deletion may not result in immediate destruction of every record where retention is required or permitted by law. We may retain limited information where reasonably necessary for:
- legal obligations;
- tax/accounting;
- fraud prevention;
- security;
- dispute resolution;
- enforcing agreements.
26. YOUR PRIVACY RIGHTS
Depending on your jurisdiction, you may have rights including:
- right to know/information;
- right of access;
- right to correction;
- right to deletion/erasure;
- right to restriction;
- right to object;
- right to data portability;
- right to withdraw consent;
- right to complain to a supervisory authority;
- rights relating to automated decision-making where applicable.
27. NIGERIAN DATA PROTECTION RIGHTS
For individuals protected by Nigerian data-protection law, Nobevra intends to process personal data consistently with applicable provisions of the Nigeria Data Protection Act 2023 and applicable NDPC regulations, guidance and directives. The NDPA establishes data-subject rights and imposes obligations on controllers and processors. Where applicable, Nobevra will provide mechanisms for users to exercise their rights.
28. EUROPEAN ECONOMIC AREA USERS
If GDPR applies to your processing, you may have rights including access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. We will provide the information required by applicable transparency obligations.
29. UNITED KINGDOM USERS
Where UK data-protection law applies, Nobevra will process applicable personal data in accordance with applicable UK privacy requirements.
30. CALIFORNIA USERS
Where applicable California privacy laws apply, California residents may have rights concerning personal information, including applicable rights relating to access, deletion, correction, portability, opting out of certain forms of sale/sharing, and limiting certain uses of sensitive personal information where applicable. Nobevra does not intend to sell personal information as a revenue model.
31. CHILDREN'S PRIVACY
Nobevra is intended primarily for adults and businesses. You must not use Nobevra if you are legally prohibited from doing so based on your age or applicable law. We do not knowingly solicit personal information from children where prohibited by applicable law.
32. SECURITY
We use reasonable technical and organizational measures designed to protect personal information. These may include encryption in transit, access controls, authentication controls, role-based permissions, database security policies, logging, monitoring, secure infrastructure, environment-variable management, vulnerability management, backup mechanisms, and security reviews. However, no Internet service can guarantee absolute security.
33. DATA BREACHES
If we become aware of a personal-data breach, we will assess the incident and take actions required by applicable law. Depending on the circumstances, this may include containment, investigation, remediation, documentation, notification of regulators, notification of affected individuals, and notification of customers.
34. BUSINESS CUSTOMERS AND THEIR DATA
If you use Nobevra to process information about your customers, employees or other individuals, you remain responsible for determining appropriate purposes, ensuring lawful collection, providing appropriate privacy notices, obtaining consent where required, respecting data-subject rights, configuring your workspace appropriately, and not uploading information you are not authorized to process.
35. DATA PROCESSING AGREEMENTS
Business customers that require processor terms may request or enter into a Data Processing Addendum where available.
36. SUBPROCESSORS
Nobevra uses the following verified subprocessors and third-party service providers. This list reflects the current production state of the platform.
| Provider | Country | Purpose | Personal Data Involved |
|---|---|---|---|
| Supabase | US (AWS us-east-1) | Database, authentication, storage, Edge Functions | Account data, invoices, client records, financial data, auth tokens |
| Vercel | US (with edge nodes globally) | Web hosting, edge delivery | Request logs, IP addresses (Vercel access logs) |
| Google Gemini API | US | AI assistant, receipt OCR, report insights | Receipt images, financial metrics, user messages |
| Google Analytics 4 | US | Web analytics (consent-gated) | Anonymized usage data, IP (anonymized) |
| Google OAuth / Firebase | US | Authentication (Google Sign-In), push notifications (FCM) | Google account identity, FCM device tokens |
| Flutterwave | Nigeria / US | Payment processing, card tokenization, payouts | Billing details, card tokens, transaction records |
| LinkedIn API | US | Social media posting (if connected) | LinkedIn OAuth access token, post content |
| Twitter / X API | US | Social media posting (if connected) | Post content |
| Self-hosted SMTP | Nigeria | Transactional email delivery | Client name, email, invoice details |
| ip-api.com | EU | IP geolocation (mobile, currency detection) | IP address |
| ipapi.co | US | IP geolocation (web, currency detection) | IP address |
| FormSubmit.co | US | Contact form handling | Name, email, message |
We review our subprocessors periodically and update this list when providers change. This list does not include infrastructure subprocessors used by the above providers (e.g., Supabase's use of AWS). For those, refer to the respective provider's subprocessor list.
36A. SOCIAL MEDIA INTEGRATIONS
If you choose to connect a social media account (such as LinkedIn or Twitter/X) to Nobevra:
- You authorize Nobevra to post content on your behalf through the connected account.
- OAuth credentials (access tokens) necessary to maintain the connection are stored securely in our database.
- You may disconnect a social media account at any time through your Nobevra account settings, which will delete the stored OAuth credentials from our system.
- The content you choose to publish through Nobevra is subject to the terms and privacy policies of the relevant social media platform.
36B. ELECTRONIC SIGNATURES AND CONTRACT DATA
If you use Nobevra's contract or electronic signature features:
- Signer name and email address are collected.
- The IP address and User-Agent string of the device used to sign are captured at the time of signing to create an audit trail for the validity of the electronic signature.
- A cryptographic audit hash (SHA-256) is generated and stored.
- This data is retained as part of the binding legal record associated with the signed contract.
- Retention of this data may be governed by contract law obligations rather than ordinary data retention periods.
37. PUBLIC CONTENT
Some Nobevra features may intentionally make information publicly accessible, including public invoices, payment links, digital business cards, QR destinations, public profiles, client portals, and public product information. You are responsible for reviewing information before publishing it publicly.
38. THIRD-PARTY LINKS
Nobevra may contain links to third-party websites and services. We are not responsible for the privacy practices of third-party websites.
39. MARKETING COMMUNICATIONS
Where permitted, Nobevra may send product announcements, educational communications, promotional messages, feature updates, and business tips. You may unsubscribe from marketing communications using the unsubscribe mechanism provided.
40. AUTOMATED DECISION-MAKING
Nobevra may use automated systems for purposes such as fraud detection, security, recommendations, analytics, personalization, and categorization. We do not intend to make significant legal or similarly significant decisions about individuals solely through automated systems unless legally permitted and appropriately disclosed.
41. AI AND DATA TRAINING
Unless expressly stated otherwise in an applicable product disclosure or agreement, Nobevra does not grant third-party AI providers permission to use your private business information to train their general-purpose models merely because you use Nobevra.
42. DATA EXPORT
Where functionality is available, users may export applicable business information. Available export formats and supported data categories may vary by feature and subscription plan.
43. ACCOUNT SUSPENSION AND SECURITY
We may suspend or restrict an account where reasonably necessary to protect the platform, investigate fraud, prevent abuse, comply with law, prevent security threats, or enforce our Terms.
44. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically. When material changes are made, we may provide notice through the website, application notifications, email, account notifications, or other reasonable methods.
45. CONTACT US
For privacy questions, requests or complaints: The Noble's Technology Services Nobevra Email: invoice@noblesworld.com.ng / privacy@noblesworld.com.ng Website: https://nobevra.noblesworld.com.ng
46. SUPERVISORY AUTHORITIES
Depending on where you reside, you may have the right to lodge a complaint with the applicable data-protection authority. For Nigerian users, the relevant authority is the Nigeria Data Protection Commission (NDPC).
47. SEVERABILITY
If any provision of this Privacy Policy is determined to be invalid or unenforceable under applicable law, the remaining provisions will continue to apply to the extent permitted.
48. GOVERNING LAW
This Privacy Policy is interpreted in accordance with applicable laws. Nothing in this Privacy Policy is intended to remove or restrict mandatory privacy rights that cannot legally be waived or excluded in the jurisdiction applicable to an individual.
ยฉ 2026 Nobevra. A product of The Noble's Technology Services. All rights reserved.