Privacy Policy
No boilerplate. This describes exactly what our system does with data — written from the actual database tables, the actual code, and the actual companies we send data to.
On this page
- Who we are
- Two different relationships
- What we collect
- What we deliberately don't do
- Why we process it
- Who we share it with
- How AI providers handle your data
- International transfers
- How long we keep it
- How we protect it
- Your rights
- Cookies and local storage
- Children
- If something goes wrong
- Changes to this policy
- Contact and complaints
1. Who we are
SabiBot is an AI assistant platform for Nigerian businesses, operated by Pioneers ICT (RC 1033498), of Suite 1, No. 42, Gidan Saude, Beside First Bank, Zoo Road, Kano, Kano State, Nigeria. In this policy, "SabiBot", "we", "us" and "our" mean that entity.
We are the data controller for information about our own customers — the businesses who sign up for SabiBot accounts. Section 2 explains the important difference between that and the customer conversations flowing through your bot.
Our data protection contact is hello@sabibot.ng.
2. Two different relationships — this matters
Privacy law treats these two situations differently, and conflating them is the most common mistake platforms make. So we separate them clearly:
| Situation | Whose data | Our role | Governed by |
|---|---|---|---|
| You sign up for SabiBot | Your name, email, phone, business details, billing records | Controller — we decide how it is used | This Privacy Policy |
| Your customers chat with your bot | Their messages, names, phone numbers, orders, bookings | Processor — we only act on your instructions | Our Data Processing Agreement |
In plain terms: the data your customers give your bot belongs to your business, not to us. We hold it on your behalf, we do not use it for our own purposes, and you can export or delete it at any time. If your customer asks you to delete their data, we help you do it — see the DPA.
3. What we collect
3.1 Account information (you, the business owner)
- Name, email address, phone number
- Business name, industry, and business description
- Password — stored only as a PBKDF2-SHA512 hash with a unique per-user salt and 10,000 iterations. We never store, log or transmit your password in readable form, and we cannot recover it for you — only reset it.
- Your plan, trial status, and subscription history
3.2 Bot configuration (content you give us)
Whatever you enter or upload to train your bot: business hours, FAQs, product names and prices, stock levels, services, booking slots, policies, and any documents you upload for the bot to learn from.
3.3 Conversations
Messages exchanged between your customers and your bot, together with a session identifier, the channel used (website widget or WhatsApp), the detected language, and timestamps. Where a customer volunteers their name, phone number or email, those are stored as part of the conversation and as a lead record.
3.4 Commerce records
Orders and order line items, products and stock levels, leads, and generated documents (invoices, quotes and receipts). These typically include a customer name, phone number, and what they ordered.
3.5 Bookings
Customer name, phone number, email where given, the service booked, and the appointment slot.
3.6 Payment records
Transaction reference, amount, currency, gateway used, and payment status.
We never see or store card details. Card entry happens entirely on your payment gateway's own hosted checkout page (currently Flutterwave, which is licensed by the Central Bank of Nigeria and PCI-DSS certified). Card numbers, CVVs and PINs never touch a SabiBot server. We only ever receive a reference and a "paid / not paid" result.
3.7 Voice notes
If a customer sends a voice note, the audio is transmitted to our speech-to-text provider, converted to text, and the text is what we store as the message. We do not retain the audio file after transcription.
3.8 Website analytics
We run our own analytics rather than embedding a third-party tracker. For each event we record the event name, a timestamp, the browser's user-agent string, and a visitor hash. The hash is produced from the IP address combined with a secret salt that rotates every day.
Two consequences of that design, both deliberate: we never store a raw IP address, and the same visitor produces a different hash tomorrow — so we cannot build a long-term profile of anyone even if we wanted to.
4. What we deliberately don't do
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone, under any circumstances.
- We do not use advertising or tracking cookies. There is no Google Analytics, no Meta Pixel, no third-party tag manager on our site.
- We do not use your business's conversations to train our own AI models. We do not train models.
- We do not read your conversations except where you ask us to for support, where required to investigate abuse or a security incident, or where the law compels us.
- We do not touch your money. When you connect your payout account, customer payments settle directly to your bank account from the gateway. Funds do not sit in a SabiBot account, even briefly.
5. Why we process it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account | Account information | Performance of a contract |
| Generating bot replies | Conversation, bot configuration | Performance of a contract |
| Taking orders, bookings and payments | Commerce, bookings, payments | Performance of a contract |
| Sending service emails (receipts, alerts, reminders) | Email address, relevant record | Performance of a contract |
| Security, abuse prevention, rate limiting | Visitor hash, user-agent, request logs | Legitimate interest |
| Improving the product | Aggregated, non-identifying analytics | Legitimate interest |
| Marketing emails to you | Your email address | Consent — withdrawable at any time |
| Accounting and tax records | Billing records | Legal obligation |
6. Who we share it with
We share data only with the service providers below, only to the extent needed to run the service, and only under contracts that require them to protect it. This is our complete list of sub-processors.
| Provider | What they do for us | What they receive | Where |
|---|---|---|---|
| OpenAI | Generates bot replies; transcribes voice notes | Conversation text, bot configuration, voice audio | United States |
| Google (Gemini API) | Backup AI provider when the primary is unavailable | Conversation text, bot configuration | United States |
| Anthropic | Backup AI provider when the primary is unavailable | Conversation text, bot configuration | United States |
| Flutterwave | Processes card and transfer payments; settles funds to you | Amount, reference, customer email/phone, your payout account | Nigeria |
| Resend / Google Workspace | Delivers transactional email | Recipient address and email content | United States |
| Meta Platforms | WhatsApp Business messaging | WhatsApp number and message content | United States / Ireland |
| Database Mart (DatabaseMart.com) | Runs the servers the platform sits on | All data, at rest on disk | United States — Kansas City, Missouri |
We will also disclose data where we are legally required to — for example under a valid court order or a lawful request from a Nigerian regulator or law enforcement agency. Where we are permitted to tell you about such a request, we will.
If SabiBot is ever sold, merged or restructured, data may transfer to the acquiring entity. It would remain subject to a policy at least as protective as this one, and we would notify you before it took effect.
7. How AI providers handle your data
To answer a customer's question, the relevant part of the conversation and your bot's configuration are sent to an AI provider. This is unavoidable — it is how the assistant works. What matters is what happens to it there.
- We send the minimum context needed to answer: recent conversation turns and your bot configuration, not your full customer database.
- We access these providers through their business API tiers, whose terms state that content submitted via the API is not used to train their models.
- Providers may retain content briefly for abuse monitoring, per their own published policies.
- We never send payment card data to an AI provider, because we never hold any.
Being straight with you: we depend on these providers' published terms here, and those terms differ between their free and paid tiers. We contract on tiers that exclude training on submitted content. If that ever changes, we will update this section and tell affected customers rather than quietly leave this page as it is.
8. International transfers
As the table in section 6 shows, our providers are based outside Nigeria — principally in the United States. This applies not only to the AI providers that generate replies, but to the servers themselves: our infrastructure is hosted by Database Mart in Kansas City, Missouri.
Being direct about what that means: your data is stored in the United States, not in Nigeria. We would rather state that plainly here than let you assume otherwise because we are a Nigerian company.
Under the Nigeria Data Protection Act 2023, such transfers require an appropriate legal basis. We rely on contractual safeguards with each provider requiring them to apply protections comparable to those required in Nigeria, and, where the transfer is necessary to deliver the service you asked us for, on the performance of our contract with you.
If you need your data to remain within Nigeria, tell us before you sign up — for some configurations we cannot currently offer that, and we would rather say so upfront than discover it later.
9. How long we keep it
| Data | Retention |
|---|---|
| Account information | For as long as your account is open, then deleted within 30 days of closure — except records we must keep for tax and accounting purposes. |
| Conversations, leads, orders, bookings | For as long as your account is open, so your bot keeps its memory and you keep your records. You can delete individual records at any time from your dashboard. |
| Billing and payment records | Retained for the period required by Nigerian tax and company law, even after account closure. |
| Analytics events | Held in rotating log files that are automatically discarded once they exceed their size limit. These contain no names and no raw IP addresses. |
| Operational backups | Taken around system updates so we can restore after a failure. Deleted data may persist in a backup for a short period before the backup is cycled out. |
| Voice note audio | Not retained after transcription. |
If you close your account and want everything erased immediately rather than waiting for the 30-day window, email us and we will action it.
10. How we protect it
- Encryption in transit. The entire platform is served over HTTPS/TLS. Requests over plain HTTP are redirected.
- Password hashing. PBKDF2-SHA512, unique per-user salt, 10,000 iterations. A stolen database does not yield usable passwords.
- Access control. Accounts are separated by tenant — one business's dashboard cannot read another's data. Staff access is role-based, with Owner and scoped Administrator tiers.
- Signed webhooks. Payment notifications are cryptographically verified before they are acted on, and every payment is independently re-verified against the gateway before an order is marked paid. An unsigned or unverifiable message is rejected.
- Rate limiting on authentication, chat and API endpoints, to blunt brute-force and abuse.
- No raw IP storage in analytics, as described in section 3.8.
- Automated post-deployment testing that checks security controls are still refusing what they should refuse after every update.
No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can commit to is that these controls are real, they are tested, and we will tell you honestly if they fail.
11. Your rights
Under the Nigeria Data Protection Act 2023 you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — have your data deleted, where we have no overriding legal reason to keep it
- Restriction — ask us to pause processing while a dispute is resolved
- Objection — object to processing based on legitimate interest, and to direct marketing at any time
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent — where we relied on consent, withdraw it at any time without affecting what was lawful before
- Complain — lodge a complaint with the Nigeria Data Protection Commission
To exercise any of these, email hello@sabibot.ng. We respond within 30 days and will not charge you for a reasonable request. We may ask you to verify your identity first — that protects you, not us.
If you are a customer of a business using SabiBot and you want your data removed, contact that business directly. They control it; we act on their instruction. If you cannot reach them, tell us and we will pass the request on.
12. Cookies and local storage
SabiBot sets no cookies. Not essential ones, not analytics ones, not advertising ones. That is why you are not being interrupted by a cookie banner.
Instead, when you log in we store a session token in your browser's localStorage, along with small preferences such as your chosen theme and whether you have dismissed the setup wizard. This data stays in your browser, is never transmitted to third parties, and is cleared when you log out or clear your browser data.
Note that third-party services you reach through us — a Flutterwave checkout page, for example — set their own cookies under their own policies.
13. Children
SabiBot is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us through a bot conversation, tell us and we will delete it.
14. If something goes wrong
If we suffer a personal data breach that is likely to result in a risk to people's rights and freedoms, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and notify affected customers without undue delay where the risk is high.
Our notification will tell you what happened, what data was involved, what we have done about it, and what you should do. We would rather deliver an uncomfortable disclosure early than a reassuring one late.
15. Changes to this policy
We update this policy when our practices change. The version and effective date at the top always reflect the current text. For material changes — a new category of data, a new sub-processor, a new purpose — we notify account holders by email at least 14 days before the change takes effect, so you have time to object or leave.
16. Contact and complaints
Privacy questions, rights requests and complaints: hello@sabibot.ng, or use the contact form and choose "Privacy & data".
If we have not resolved your complaint to your satisfaction, you can escalate to the Nigeria Data Protection Commission, the supervisory authority established under the Nigeria Data Protection Act 2023. We would ask you to come to us first, but it is your right either way.
Related documents: Terms of Service · Data Processing Agreement