๐ŸŽ‰ New: QR Code Payments are now live โ€” Try it free today โ†’
Skip to main content
Legal & Compliance

Privacy Policy

We believe privacy is a right, not a feature. This policy explains exactly what we collect, why we collect it, who we share it with, and how you can control your data.

01

Introduction

Nobevra is a cross-platform business productivity and financial management platform operated by The Noble's Technology Services, a company registered with the Corporate Affairs Commission (CAC) in Nigeria.

Our Privacy Commitment
Nobevra does not sell your personal information. We do not make money by showing you third-party advertisements. We collect only what we need to provide the service you requested.

This Privacy Policy applies whenever you visit our website, create an account, use our web or mobile applications, interact with our AI features, scan a QR code, or contact us.

Applicable law baseline: Nigeria Data Protection Act 2023 (NDPA) ยท GDPR / UK GDPR ยท California Privacy Law (CCPA/CPRA)
02

Who Controls Your Data

The Noble's Technology Services
CAC-Registered ยท Lagos, Nigeria
Controller vs. Processor
When you use Nobevra as a business and store your own customers' data (names, emails, invoices), you are the data controller for that data โ€” and Nobevra acts as your data processor. You are responsible for providing appropriate privacy notices to your customers.
03

What We Collect

We collect different categories of information depending on how you use Nobevra. Here is a transparent breakdown of every category.

Account & Identity
  • Full name & username
  • Email address & phone number
  • Country & language preference
  • Profile photograph
  • Password (hashed โ€” never stored in plain text)
Business & Workspace
  • Business name, address & tax details
  • Logo, brand colors & invoice preferences
  • Team workspace & role information
  • API keys (hashed)
  • Custom domain configuration
Technical & Device
  • IP address & approximate location
  • Device type & operating system
  • Browser & app version
  • Session tokens (encrypted on device)
  • Crash & performance data
Financial & Payment
  • Invoice amounts, line items & currencies
  • Payment status & transaction references
  • Card token (last 4 digits, brand, expiry โ€” no full card numbers)
  • Payout bank account details
  • Wallet balance & transaction history
Client CRM data (processor role): If you store your clients' personal information inside Nobevra (names, emails, invoices), you remain the controller of that data. Nobevra processes it on your instructions to provide the service.
04

AI Features

Nobevra uses AI to power the AI assistant, receipt/OCR scanning, and report insights. All AI features use Google Gemini (via the Generative Language API).

AI Assistant
Data sent: Your messages + aggregated financial context
Model: Gemini 1.5 Flash
Receipt OCR
Data sent: Receipt image (base64)
Model: Gemini 1.5 Flash Vision
Report Insights
Data sent: Aggregated financial metrics (no PII)
Model: Gemini 2.0 Flash
Zero Training Guarantee
Per Google's API Terms of Service: data submitted via the Gemini API is not used to train Google's general-purpose AI models. Google acts as a data processor with respect to content submitted through the API. AI usage is tracked only as a usage count โ€” the content of your AI sessions is never stored in our database.
AI Output Disclaimer
AI-generated invoices, financial classifications, and business recommendations may contain errors. You remain responsible for reviewing all AI outputs. Nobevra is not a substitute for a qualified accountant, lawyer, or financial adviser.
05

QR Codes & Analytics

Third-Party Scan Data โ€” Important

When someone (e.g. your customer) scans a QR code you created with Nobevra, our systems collect data about that third party's device, even though they may have no relationship with Nobevra. As the QR code owner, you are responsible for ensuring this is consistent with applicable privacy laws and providing appropriate notice to those individuals.

Data collected on each QR scan:

  • Raw IP address of the scanning device
  • User-Agent string (browser/device type and version)
  • Accept-Language header (language/locale preference)
  • Referer header
  • City and country โ€” derived from IP via Cloudflare geo-detection (Supabase infrastructure)
  • Timestamp and QR code identifier

Contract Signatures

When a contract is electronically signed through Nobevra, we capture the signer's IP address and User-Agent at the moment of signing to create a legally valid audit trail. A SHA-256 cryptographic hash is generated and retained as part of the binding legal record.

06

Cookies & Tracking

Strictly NecessaryAlways Active

Authentication sessions, security tokens, cookie preference storage. No consent required โ€” these are essential for the platform to function.

Google Analytics 4 (GA4)Consent Required

Measurement ID: G-6ME42JV7BJ. Collects anonymized page views, user interactions, device/browser type, and referral source. IP anonymization is enabled. GA4 is only loaded after you click "Accept All" on the cookie banner.

Google Privacy Policy
FormSubmit.co
Contact form

Your name, email, and message are sent to FormSubmit.co for delivery to our inbox when you use the contact form.

ip-api.com
Mobile geo-detection

Mobile app sends your IP to ip-api.com (HTTPS) to auto-detect your country for currency selection.

ipapi.co
Web geo-detection

Web app proxies your IP to ipapi.co to auto-detect your country for currency selection.

07

Sharing & Providers

We do not sell your data
Nobevra does not sell personal information as a business model. We do not share data with third-party advertisers.

We share information only with service providers that are necessary to operate Nobevra. Every provider is contractually required to protect your data and use it only for the stated purpose.

Cloud Infrastructure
Supabase (database, auth, storage) ยท Vercel (web hosting)
Authentication
Supabase Auth ยท Google OAuth (Google Sign-In)
Payments
Flutterwave (subscription billing, card tokenization, payouts)
AI Processing
Google Gemini API (AI assistant, OCR, insights)
Email
Self-hosted SMTP (mail.noblesworld.com.ng)
Push Notifications
Firebase Cloud Messaging (FCM) โ€” device tokens stored in database
Social Media
LinkedIn API ยท Twitter/X API (only if you connect your accounts)
International transfers: Your data may be processed in countries outside Nigeria (primarily the United States) via Supabase, Vercel, Google, and Flutterwave. We implement appropriate safeguards including contractual protections.
08

Subprocessors

This table reflects the verified, production state of the Nobevra platform. We update it when providers change.

ProviderRegionPurpose
SupabaseUSDatabase, Auth, Storage, Edge Functions
VercelUSWeb hosting & edge delivery
Google Gemini APIUSAI assistant, receipt OCR, report insights
Google Analytics 4USWeb analytics (consent-gated only)
Google OAuth / FCMUSSign in with Google, push notifications
FlutterwaveNigeriaPayment processing, card tokenization, payouts
LinkedIn APIUSSocial media posting (if connected)
Twitter / X APIUSSocial media posting (if connected)
Self-hosted SMTPNigeriaTransactional email delivery
ip-api.comEUIP geolocation (mobile โ€” currency detection)
ipapi.coUSIP geolocation (web โ€” currency detection)
FormSubmit.coUSContact form handling
09

Your Rights

Depending on your jurisdiction, you have the following rights. We honour these rights regardless of where you live.

Right to Know
Know what personal data we hold about you
Right to Access
Request a copy of your personal data
Right to Correct
Fix inaccurate or incomplete data
Right to Delete
Request deletion of your account and data
Right to Portability
Export your data in a usable format
Right to Object
Object to certain types of processing
Right to Restrict
Limit how we use your data
Right to Complain
Lodge a complaint with a supervisory authority
Nigerian Users โ€” NDPA 2023

The Nigeria Data Protection Commission (NDPC) is the relevant supervisory authority. Nobevra processes personal data in accordance with the Nigeria Data Protection Act 2023 and applicable NDPC regulations.

EEA / UK Users โ€” GDPR / UK GDPR

You may lodge a complaint with your local data protection authority. For UK users, this is the ICO. For EEA users, contact your national supervisory authority.

California Users โ€” CCPA / CPRA

California residents have rights to access, delete, correct, and opt-out of the sale/sharing of personal information. Nobevra does not sell personal information.

10

Security & Contact

Encryption in transit
TLS on all connections between clients and servers
Row-level security
Supabase RLS policies enforce data isolation per user
Tokenized payments
No full card numbers โ€” Flutterwave tokenization only
Device-level encryption
JWT tokens stored in flutter_secure_storage (iOS Keychain / Android EncryptedSharedPreferences)
Access controls
Role-based permissions and workspace isolation
Account deletion
Full data deletion pipeline via cleanup-user-data Edge Function
Contact the Data Protection Officer
For privacy questions, data-subject requests, or complaints:

Effective Date: August 8, 2026. We may update this policy periodically. Material changes will be notified via in-app notification or email. This policy is interpreted in accordance with applicable Nigerian, European, and international data-protection law. Governing law: Lagos, Nigeria.

NOBEVRA PRIVACY POLICY

Effective Date: August 8, 2026
Last Updated: August 8, 2026

1. INTRODUCTION

Welcome to Nobevra. Nobevra is a cross-platform business productivity and financial management platform operated by The Noble's Technology Services, a company duly registered with the Corporate Affairs Commission (CAC) in Nigeria. Nobevra provides tools and services including invoicing, quotations and estimates, client relationship management, expenses and receipt management, products and services management, inventory management, payment functionality, digital business cards, QR-code generation, digital identity tools, productivity tools, analytics, team collaboration, AI-assisted functionality and related business-management services.

Our website is: Nobevra

This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal information when you:

  • visit our website;
  • create a Nobevra account;
  • use our web application;
  • use our Android or iOS applications;
  • use our business, invoicing or productivity features;
  • communicate with us;
  • contact customer support;
  • subscribe to paid services;
  • interact with our public QR codes, digital business cards or public-facing pages; or
  • otherwise interact with Nobevra.

By using Nobevra, you acknowledge that you have read and understood this Privacy Policy.

2. WHO IS RESPONSIBLE FOR YOUR INFORMATION?

For purposes of applicable data-protection laws, the relevant Nobevra entity is: The Noble's Technology Services A company registered with the Corporate Affairs Commission (CAC), Nigeria. Nobevra is the product/platform operated by The Noble's Technology Services.

Contact
General privacy contact: invoice@noblesworld.com.ng
Data Protection Officer / Privacy Contact: privacy@noblesworld.com.ng
Website: nobevra.noblesworld.com.ng

3. OUR ROLE: DATA CONTROLLER AND DATA PROCESSOR

Depending on the circumstances, Nobevra may act as either a data controller or a data processor/service provider.

3.1 When Nobevra acts as a controller

We may act as a controller when we determine why and how personal information is processed for purposes such as:

  • creating and administering user accounts;
  • authentication;
  • account security;
  • subscription management;
  • billing;
  • customer support;
  • fraud prevention;
  • platform security;
  • product analytics;
  • service improvement;
  • communications;
  • legal compliance;
  • abuse prevention;
  • marketing where permitted;
  • maintaining business records.

3.2 When Nobevra acts as a processor/service provider

If you use Nobevra as a business customer to store or manage information relating to your own customers, employees, contractors, suppliers or other individuals, you may determine the purposes for which that information is processed. In those circumstances, you may be the controller/business responsible for that information, while Nobevra may process the information on your instructions to provide the service. For example, if an agency stores its clients' names, email addresses and invoice information inside Nobevra, the agency may remain responsible for determining why that client information is processed. Where legally required or commercially appropriate, Nobevra may enter into a Data Processing Addendum (DPA) with business customers.

4. INFORMATION WE COLLECT

We collect information necessary to provide, secure, improve and administer Nobevra. The exact information collected depends on how you use the platform.

4.1 Account information

This may include:

  • full name;
  • username;
  • email address;
  • telephone number;
  • country;
  • preferred language;
  • password credentials or authentication identifiers;
  • profile photograph;
  • account identifiers;
  • authentication information;
  • security settings. We do not intentionally store your plain-text password.

5. BUSINESS AND ORGANIZATION INFORMATION

When you create or configure a business workspace, we may collect:

  • business name;
  • trading name;
  • registered business name;
  • business address;
  • business email;
  • business telephone number;
  • website;
  • business category;
  • industry;
  • tax identification information;
  • registration information;
  • business logo;
  • brand colors;
  • invoice preferences;
  • currency;
  • tax settings;
  • payment information;
  • business descriptions;
  • digital identity information.

6. INVOICE AND FINANCIAL INFORMATION

Nobevra may process information contained in business records created by you, including:

  • invoice numbers;
  • invoice dates;
  • due dates;
  • invoice amounts;
  • currencies;
  • products;
  • services;
  • quantities;
  • prices;
  • discounts;
  • taxes;
  • payment status;
  • payment references;
  • customer information;
  • billing addresses;
  • shipping information;
  • notes;
  • quotations;
  • estimates;
  • recurring invoice information;
  • receipts;
  • transaction records;
  • expense records;
  • financial reports;
  • account balances;
  • wallet information;
  • payment-link information.

Nobevra is not a bank merely because the platform provides wallet or payment-related functionality. Payment transactions may be processed by third-party payment providers.

7. CLIENT AND CRM INFORMATION

When you use our Client CRM, you may submit information about your customers, prospects or business contacts. This may include:

  • name;
  • email address;
  • telephone number;
  • company;
  • job title;
  • address;
  • communication history;
  • transaction history;
  • invoice history;
  • payment history;
  • customer status;
  • notes;
  • tags;
  • customer tier;
  • relationship information.

You are responsible for ensuring that you have an appropriate legal basis and authorization to submit third-party personal information to Nobevra.

8. PRODUCTS, SERVICES AND INVENTORY INFORMATION

We may process information relating to:

  • products;
  • services;
  • product names;
  • descriptions;
  • SKU numbers;
  • prices;
  • quantities;
  • inventory levels;
  • categories;
  • product images;
  • product metadata;
  • product passports;
  • Digital Product Passport information;
  • suppliers;
  • inventory transactions.

9. RECEIPTS, DOCUMENTS AND OCR

If you use receipt scanning or OCR functionality, you may upload:

  • receipts;
  • invoices;
  • expense documents;
  • photographs;
  • PDFs;
  • other business documents.

These documents may contain personal, financial or other information. Nobevra processes such information to provide the functionality requested by you. Where third-party OCR or AI services are used, applicable information may be processed by those providers as necessary to deliver the requested feature. Our current production integrations should be accurately listed in our Subprocessor List.

10. QR CODES AND DIGITAL BUSINESS CARDS

Nobevra provides QR-code and digital identity functionality. Depending on the QR-code type and configuration, a QR code may contain or redirect to information such as:

  • website URLs;
  • contact information;
  • Wi-Fi configuration;
  • telephone information;
  • SMS information;
  • email information;
  • digital business cards;
  • documents;
  • payment information;
  • public business profiles.

QR Scan Analytics โ€” Important Disclosure
When a third party (for example, your customer or a member of the public) scans a QR code you have created using Nobevra, our systems may automatically collect and store the following information about that scan event:

  • IP address of the scanning device (raw, at point of collection);
  • User-Agent string (browser/device type and version);
  • Accept-Language header (language/locale preference);
  • Referer header (the source from which the QR code was accessed);
  • City and country, derived from the IP address using infrastructure-level geo-detection (via Cloudflare headers processed by Supabase's infrastructure);
  • Timestamp;
  • QR code identifier.

This information is collected to provide you with QR code scan analytics as part of the Nobevra platform. The individuals scanning your QR codes may not be Nobevra users, and they may have no direct relationship with Nobevra. If you create publicly accessible QR codes using Nobevra, you are responsible for ensuring that your use of QR scan analytics is consistent with applicable privacy laws and that you provide appropriate notice to the individuals whose QR scan data you collect and view through the platform.

You should not place highly sensitive personal information into a publicly accessible QR code unless you understand the risks.

11. DIGITAL BUSINESS CARDS

If you create a digital business card, you may provide:

  • name;
  • photograph;
  • business name;
  • job title;
  • telephone number;
  • email;
  • website;
  • social media links;
  • business address;
  • professional information;
  • QR code;
  • NFC-related information.

You understand that information intentionally published as a public digital identity may be accessible to anyone who receives or discovers the relevant link or QR code.

12. AI FEATURES

Nobevra may provide AI-assisted functionality including:

  • AI voice-assisted invoice creation;
  • business insights;
  • productivity analysis;
  • client intelligence;
  • categorization;
  • document/OCR processing (AI-powered receipt scanning);
  • recommendations;
  • business automation;
  • other AI-assisted features introduced in the future.

AI functionality may process information you provide to generate the requested output.

Current AI Providers
Nobevra currently uses Google Gemini (via Google's Generative Language API) for AI-assisted features including the AI assistant, receipt/OCR scanning, and report insights. When you use an AI-assisted feature, relevant information (such as your message, financial metrics, or a receipt image) is transmitted to Google's Gemini API for processing.

Per Google's API usage terms and Google Cloud's data processing addendum, data submitted to the Gemini API is not used to train Google's general-purpose AI models. Google acts as a data processor with respect to the content you submit through the API. For details, refer to Google's Gemini API Terms of Service and Privacy Policy.

Important
Nobevra does not represent that AI-generated content is always accurate, complete or suitable for your particular business, accounting, tax, legal or financial circumstances. You remain responsible for reviewing AI-generated:

  • invoices;
  • financial classifications;
  • business recommendations;
  • tax information;
  • summaries;
  • reports;
  • other outputs.

Nobevra should not be treated as a substitute for a qualified accountant, lawyer, tax adviser, financial adviser or other professional.

13. PRODUCTIVITY AND BEHAVIORAL INFORMATION

If you use Nobevra productivity features, we may process:

  • tasks;
  • projects;
  • time blocks;
  • focus sessions;
  • productivity categories;
  • habits;
  • completion rates;
  • task velocity;
  • usage patterns;
  • productivity metrics;
  • workspace activity.

We may use this information to provide:

  • productivity dashboards;
  • focus analytics;
  • reports;
  • recommendations;
  • personalized experiences.

We will not represent productivity or wellness analytics as medical diagnoses.

14. TEAM AND WORKSPACE INFORMATION

If you participate in a team workspace, we may process:

  • team membership;
  • invitation information;
  • roles;
  • permissions;
  • workspace activity;
  • membership status;
  • administrative actions;
  • audit records.

Workspace administrators may be able to access or manage information associated with the workspace depending on their permissions. If you use Nobevra through an employer, agency or other organization, that organization may control certain aspects of your account.

15. PAYMENT INFORMATION

Nobevra may integrate with third-party payment providers (e.g. Flutterwave). Depending on the payment method, payment providers may process:

  • card information;
  • bank information;
  • payment identifiers;
  • transaction references;
  • payment status;
  • billing information;
  • fraud-prevention information.

Where payment information is handled directly by a payment provider, Nobevra does not intentionally store full payment-card credentials unless explicitly stated otherwise. The applicable payment provider's privacy policy also applies to information it processes.

If you configure payout methods for receiving funds, your payout bank account details are stored securely in our database. While our infrastructure provider (Supabase) encrypts all data at rest at the storage level, we strongly recommend you do not store highly sensitive banking information beyond what is strictly required for payouts.

16. DEVICE AND TECHNICAL INFORMATION

When you use Nobevra, we may automatically collect technical information including:

  • IP address;
  • device type;
  • operating system;
  • browser;
  • application version;
  • device identifiers;
  • language;
  • time zone;
  • approximate location;
  • network information;
  • crash information;
  • performance information;
  • referring URLs;
  • interaction information.

16A. MOBILE APPLICATION LOCAL STORAGE

If you use the Nobevra mobile application, certain data is stored locally on your device to enable offline functionality and improve performance. Client records, invoice data, and related information may be stored in an offline cache (such as Isar database) on your device. This locally cached data is protected by your device's native security (such as your lock screen or biometrics), but it is not inherently encrypted at rest by the Nobevra application itself. You are responsible for securing your mobile device.

17. LOGS, SECURITY AND AUDIT TRAILS

For security, accountability and troubleshooting, we may maintain logs containing:

  • authentication events;
  • login attempts;
  • account changes;
  • permission changes;
  • workspace actions;
  • API activity;
  • security events;
  • administrative events;
  • payment events;
  • system errors;
  • IP addresses;
  • timestamps.

These records may be retained for longer than ordinary account information where reasonably necessary for security, fraud prevention, legal compliance or dispute resolution.

18. COOKIES AND TRACKING TECHNOLOGIES

Strictly Necessary
We use strictly necessary cookies and browser storage for:

  • maintaining your authenticated session;
  • security and CSRF protection;
  • remembering your cookie preferences;
  • platform functionality that cannot operate without these technologies.

These are used on the basis of our legitimate interest in providing a functional, secure service. They do not require consent.

Analytics โ€” Google Analytics 4 (GA4)
Our web application uses Google Analytics 4 (GA4, measurement ID: G-6ME42JV7BJ), a service operated by Google LLC. GA4 uses cookies and similar technologies to collect information about how visitors interact with our website, including:

  • pages visited and time spent;
  • user interactions and navigation paths;
  • approximate geographic region;
  • device and browser type;
  • anonymized IP address (IP anonymization is enabled);
  • referral source.

GA4 analytics cookies are non-essential and are only loaded after you have explicitly accepted optional cookies through our cookie consent banner. If you decline optional cookies, Google Analytics will not be activated during your session. You may change your preference at any time by clearing site data in your browser settings and revisiting the site.

For more information about how Google processes this data, see: https://policies.google.com/privacy.

Contact Form
Our public contact form is processed by FormSubmit.co, a third-party form-handling service. When you submit our contact form, the information you provide (such as your name, email address, and message) is transmitted to FormSubmit.co's servers for delivery to our inbox. FormSubmit.co's own privacy policy governs their processing of this data.

Mobile App โ€” IP Geolocation
Our mobile app uses the ip-api.com API (https://ip-api.com) to automatically detect your country based on your device's IP address. This allows Nobevra to pre-select an appropriate currency for your region. Only your IP address is sent to this service; it is not linked to your account or stored by us from this request.

Web App โ€” IP Geolocation
Our web application uses the ipapi.co API (https://ipapi.co) for the same currency auto-detection purpose. As above, only your IP address is involved, and we do not store the result in association with your identity.

We will not treat all cookies as requiring the same legal basis. A separate Cookie Policy accompanies this Privacy Policy and provides further detail.

19. HOW WE USE PERSONAL INFORMATION

We may use information to:

Provide the service

  • create accounts;
  • authenticate users;
  • create invoices;
  • manage clients;
  • manage expenses;
  • process documents;
  • generate QR codes;
  • create business cards;
  • manage teams;
  • provide analytics;
  • provide AI features;
  • provide payment functionality.

Maintain security

  • detect fraud;
  • prevent abuse;
  • detect unauthorized access;
  • investigate security incidents;
  • protect users;
  • enforce platform rules.

Improve Nobevra

  • analyze product usage;
  • identify bugs;
  • improve performance;
  • develop new functionality;
  • personalize experiences;
  • conduct product research.

Communicate with you

  • account notifications;
  • security alerts;
  • billing communications;
  • service announcements;
  • customer support;
  • product updates;
  • marketing communications where permitted.

Comply with law We may process information when necessary to comply with:

  • applicable law;
  • court orders;
  • regulatory requirements;
  • tax obligations;
  • lawful governmental requests;
  • fraud investigations.

20. LEGAL BASES FOR PROCESSING

Where GDPR, UK GDPR or another law requiring a lawful basis applies, we may rely on one or more of the following:

  • Contract: Where processing is necessary to provide Nobevra services you requested.
  • Legal obligation: Where processing is necessary to comply with legal obligations.
  • Legitimate interests: Where processing is reasonably necessary for purposes such as security, fraud prevention, service improvement, business administration, customer support, network security, and enforcing agreements. We will consider applicable balancing requirements when relying on legitimate interests.
  • Consent: Where consent is legally required, we will request it. You may withdraw consent where applicable. Withdrawal of consent does not invalidate processing that occurred before withdrawal.

21. DATA SHARING

We do not sell personal information as a business model. We may disclose information to carefully selected service providers necessary to operate Nobevra. These may include:

  • cloud infrastructure providers;
  • database providers;
  • storage providers;
  • authentication providers;
  • payment providers;
  • email providers;
  • analytics providers;
  • AI providers;
  • OCR providers;
  • security providers;
  • customer-support providers;
  • monitoring providers;
  • professional advisers.

22. INFRASTRUCTURE AND THIRD-PARTY PROVIDERS

Nobevra uses the following third-party providers. Each provider acts as a data processor with respect to information we share with them for the stated purpose.

Cloud Infrastructure

  • Supabase (Supabase Inc., US): Backend infrastructure including PostgreSQL database, authentication, object storage, real-time services, and Edge Functions. User data โ€” including account details, invoices, client records, and financial data โ€” is stored in Supabase's managed infrastructure.
  • Vercel (Vercel Inc., US): Web application hosting, edge delivery, and infrastructure for the Nobevra web platform. Vercel publishes its own DPA addressing processor obligations, security, subprocessors, data-subject requests, deletion and international transfer provisions.

Authentication

  • Google OAuth (Google LLC, US): Used to enable "Sign in with Google" on both the web and mobile applications. When you authenticate using Google, Google processes your Google account identity information to verify your identity. Google's Privacy Policy applies to their processing.
  • Supabase Auth (see above): Manages session tokens, password hashing, and authentication flows.

Payments

  • Flutterwave (Flutterwave Inc.): Used for subscription billing, payment processing, card tokenization, and payouts. When you make a payment, relevant billing and payment information is transmitted to Flutterwave. Flutterwave is PCI-DSS compliant as a payment processor. Nobevra stores only tokenised card identifiers (card brand, last 4 digits, expiry), not full card numbers. Flutterwave's Privacy Policy applies to their processing.

AI Processing

  • Google Gemini API (Google LLC, US): Used for AI-assisted features including the AI assistant, receipt OCR/scanning, and report insights. Content submitted to AI features (such as receipt images, financial metrics, and messages) is transmitted to Google's Gemini API. Per Google API terms, data is not used for AI training.

Email

  • Self-hosted SMTP (mail.noblesworld.com.ng, operated by The Noble's Technology Services): Used to send transactional emails including invoice delivery, invoice reminders, and team invitation emails. Invoice and client details are included in outbound emails as necessary to deliver the relevant email.

Analytics

  • Google Analytics 4 (Google LLC, US): Used for web analytics on our public website and web application (analytics cookies only load after consent โ€” see Section 18).

IP Geolocation

  • ip-api.com (Intersoft Data Labs): Used by the mobile app to detect your country from your IP address for currency auto-detection. Connection is made over HTTPS.
  • ipapi.co (Kloudend Inc.): Used by the web app for the same currency auto-detection purpose.

Push Notifications

  • Firebase Cloud Messaging (FCM) (Google LLC, US): Used to deliver push notifications to Android and iOS devices. Nobevra stores your device's FCM registration token in our database to send you relevant notifications such as invoice payment confirmations and team updates. FCM tokens are device-level identifiers provided by the Firebase SDK.

Social Media Integration

  • LinkedIn API (LinkedIn Corporation, US): If you connect your LinkedIn account, LinkedIn OAuth credentials (access token and expiry) are stored in our database to enable automated social media posting on your behalf. LinkedIn's Privacy Policy governs their processing.
  • Twitter / X API (X Corp., US): If you connect your Twitter/X account, the API is used to post content on your behalf. Server-side API credentials are used; no OAuth tokens from your personal account are stored beyond what is necessary for the connection.

Contact Form

  • FormSubmit.co: Used to process our public contact form. Name, email, and message are transmitted to FormSubmit.co. See Section 18 for more detail.

The exact provider list, data categories, and processing purposes are maintained in our Subprocessor List, which is updated periodically.

23. INTERNATIONAL DATA TRANSFERS

Nobevra serves users in Nigeria, Africa and other jurisdictions. Your information may therefore be processed in countries other than the country in which you reside. Where applicable law requires safeguards for international transfers, we will seek to implement appropriate mechanisms, which may include:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • contractual safeguards;
  • other legally recognized transfer mechanisms. Users should understand that cloud infrastructure may involve international processing even when a business operates primarily in Nigeria.

24. DATA RETENTION

We retain personal information only for as long as reasonably necessary for:

  • providing the service;
  • maintaining your account;
  • fulfilling contractual obligations;
  • legal obligations;
  • accounting;
  • tax;
  • fraud prevention;
  • security;
  • dispute resolution;
  • enforcement of agreements.

Retention periods may vary depending on the category of information. For example, financial transaction records may need to be retained longer than ordinary marketing information.

25. ACCOUNT DELETION

You may request deletion of your Nobevra account through the available account-management functionality or by contacting us. Deletion may not result in immediate destruction of every record where retention is required or permitted by law. We may retain limited information where reasonably necessary for:

  • legal obligations;
  • tax/accounting;
  • fraud prevention;
  • security;
  • dispute resolution;
  • enforcing agreements.

26. YOUR PRIVACY RIGHTS

Depending on your jurisdiction, you may have rights including:

  • right to know/information;
  • right of access;
  • right to correction;
  • right to deletion/erasure;
  • right to restriction;
  • right to object;
  • right to data portability;
  • right to withdraw consent;
  • right to complain to a supervisory authority;
  • rights relating to automated decision-making where applicable.

27. NIGERIAN DATA PROTECTION RIGHTS

For individuals protected by Nigerian data-protection law, Nobevra intends to process personal data consistently with applicable provisions of the Nigeria Data Protection Act 2023 and applicable NDPC regulations, guidance and directives. The NDPA establishes data-subject rights and imposes obligations on controllers and processors. Where applicable, Nobevra will provide mechanisms for users to exercise their rights.

28. EUROPEAN ECONOMIC AREA USERS

If GDPR applies to your processing, you may have rights including access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. We will provide the information required by applicable transparency obligations.

29. UNITED KINGDOM USERS

Where UK data-protection law applies, Nobevra will process applicable personal data in accordance with applicable UK privacy requirements.

30. CALIFORNIA USERS

Where applicable California privacy laws apply, California residents may have rights concerning personal information, including applicable rights relating to access, deletion, correction, portability, opting out of certain forms of sale/sharing, and limiting certain uses of sensitive personal information where applicable. Nobevra does not intend to sell personal information as a revenue model.

31. CHILDREN'S PRIVACY

Nobevra is intended primarily for adults and businesses. You must not use Nobevra if you are legally prohibited from doing so based on your age or applicable law. We do not knowingly solicit personal information from children where prohibited by applicable law.

32. SECURITY

We use reasonable technical and organizational measures designed to protect personal information. These may include encryption in transit, access controls, authentication controls, role-based permissions, database security policies, logging, monitoring, secure infrastructure, environment-variable management, vulnerability management, backup mechanisms, and security reviews. However, no Internet service can guarantee absolute security.

33. DATA BREACHES

If we become aware of a personal-data breach, we will assess the incident and take actions required by applicable law. Depending on the circumstances, this may include containment, investigation, remediation, documentation, notification of regulators, notification of affected individuals, and notification of customers.

34. BUSINESS CUSTOMERS AND THEIR DATA

If you use Nobevra to process information about your customers, employees or other individuals, you remain responsible for determining appropriate purposes, ensuring lawful collection, providing appropriate privacy notices, obtaining consent where required, respecting data-subject rights, configuring your workspace appropriately, and not uploading information you are not authorized to process.

35. DATA PROCESSING AGREEMENTS

Business customers that require processor terms may request or enter into a Data Processing Addendum where available.

36. SUBPROCESSORS

Nobevra uses the following verified subprocessors and third-party service providers. This list reflects the current production state of the platform.

ProviderCountryPurposePersonal Data Involved
SupabaseUS (AWS us-east-1)Database, authentication, storage, Edge FunctionsAccount data, invoices, client records, financial data, auth tokens
VercelUS (with edge nodes globally)Web hosting, edge deliveryRequest logs, IP addresses (Vercel access logs)
Google Gemini APIUSAI assistant, receipt OCR, report insightsReceipt images, financial metrics, user messages
Google Analytics 4USWeb analytics (consent-gated)Anonymized usage data, IP (anonymized)
Google OAuth / FirebaseUSAuthentication (Google Sign-In), push notifications (FCM)Google account identity, FCM device tokens
FlutterwaveNigeria / USPayment processing, card tokenization, payoutsBilling details, card tokens, transaction records
LinkedIn APIUSSocial media posting (if connected)LinkedIn OAuth access token, post content
Twitter / X APIUSSocial media posting (if connected)Post content
Self-hosted SMTPNigeriaTransactional email deliveryClient name, email, invoice details
ip-api.comEUIP geolocation (mobile, currency detection)IP address
ipapi.coUSIP geolocation (web, currency detection)IP address
FormSubmit.coUSContact form handlingName, email, message

We review our subprocessors periodically and update this list when providers change. This list does not include infrastructure subprocessors used by the above providers (e.g., Supabase's use of AWS). For those, refer to the respective provider's subprocessor list.

36A. SOCIAL MEDIA INTEGRATIONS

If you choose to connect a social media account (such as LinkedIn or Twitter/X) to Nobevra:

  • You authorize Nobevra to post content on your behalf through the connected account.
  • OAuth credentials (access tokens) necessary to maintain the connection are stored securely in our database.
  • You may disconnect a social media account at any time through your Nobevra account settings, which will delete the stored OAuth credentials from our system.
  • The content you choose to publish through Nobevra is subject to the terms and privacy policies of the relevant social media platform.

36B. ELECTRONIC SIGNATURES AND CONTRACT DATA

If you use Nobevra's contract or electronic signature features:

  • Signer name and email address are collected.
  • The IP address and User-Agent string of the device used to sign are captured at the time of signing to create an audit trail for the validity of the electronic signature.
  • A cryptographic audit hash (SHA-256) is generated and stored.
  • This data is retained as part of the binding legal record associated with the signed contract.
  • Retention of this data may be governed by contract law obligations rather than ordinary data retention periods.

37. PUBLIC CONTENT

Some Nobevra features may intentionally make information publicly accessible, including public invoices, payment links, digital business cards, QR destinations, public profiles, client portals, and public product information. You are responsible for reviewing information before publishing it publicly.

38. THIRD-PARTY LINKS

Nobevra may contain links to third-party websites and services. We are not responsible for the privacy practices of third-party websites.

39. MARKETING COMMUNICATIONS

Where permitted, Nobevra may send product announcements, educational communications, promotional messages, feature updates, and business tips. You may unsubscribe from marketing communications using the unsubscribe mechanism provided.

40. AUTOMATED DECISION-MAKING

Nobevra may use automated systems for purposes such as fraud detection, security, recommendations, analytics, personalization, and categorization. We do not intend to make significant legal or similarly significant decisions about individuals solely through automated systems unless legally permitted and appropriately disclosed.

41. AI AND DATA TRAINING

Unless expressly stated otherwise in an applicable product disclosure or agreement, Nobevra does not grant third-party AI providers permission to use your private business information to train their general-purpose models merely because you use Nobevra.

42. DATA EXPORT

Where functionality is available, users may export applicable business information. Available export formats and supported data categories may vary by feature and subscription plan.

43. ACCOUNT SUSPENSION AND SECURITY

We may suspend or restrict an account where reasonably necessary to protect the platform, investigate fraud, prevent abuse, comply with law, prevent security threats, or enforce our Terms.

44. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically. When material changes are made, we may provide notice through the website, application notifications, email, account notifications, or other reasonable methods.

45. CONTACT US

For privacy questions, requests or complaints: The Noble's Technology Services Nobevra Email: invoice@noblesworld.com.ng / privacy@noblesworld.com.ng Website: https://nobevra.noblesworld.com.ng

46. SUPERVISORY AUTHORITIES

Depending on where you reside, you may have the right to lodge a complaint with the applicable data-protection authority. For Nigerian users, the relevant authority is the Nigeria Data Protection Commission (NDPC).

47. SEVERABILITY

If any provision of this Privacy Policy is determined to be invalid or unenforceable under applicable law, the remaining provisions will continue to apply to the extent permitted.

48. GOVERNING LAW

This Privacy Policy is interpreted in accordance with applicable laws. Nothing in this Privacy Policy is intended to remove or restrict mandatory privacy rights that cannot legally be waived or excluded in the jurisdiction applicable to an individual.

The Noble's Technology Services

ยฉ 2026 Nobevra. A product of The Noble's Technology Services. All rights reserved.