Version 3.0 · Effective 27 August 2026
Macroblocs Limited (RC 1976836), operator of the Cash-in App. This is our notice to customers under the Nigeria Data Protection Act 2023.
Macroblocs Limited (RC 1976836) owns and operates the Cash-in App. This Privacy Policy explains what personal data we collect about you, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It applies to our website and blog at cash-in.app, our mobile application, our WhatsApp chatbot and our Telegram chatbot @cashin_app_bot.
| Purpose | Contact |
|---|---|
| Privacy questions, and to exercise any right in Section 6 | compliance@cash-in.app |
| Everything else, including help with your account | support@cash-in.app |
| Complaints, if you are not satisfied with our response | You may complain to the Nigeria Data Protection Commission. You do not need our permission and you do not need to come to us first. |
We operate remotely and do not maintain a physical office, so please use the email addresses above rather than looking for a street address.
The law that governs this policy is the Nigeria Data Protection Act 2023, together with the Nigeria Data Protection Commission's General Application and Implementation Directive 2025. Some of the service providers we use are also subject to privacy laws in their own countries. Where they are, that does not displace your rights under Nigerian law, and it does not reduce our responsibility to you.
For the purposes of the Act we are the data controller. That means we decide what data is collected and why, and we remain answerable to you for it even where a service provider holds it on our behalf.
By using the Cash-in App you accept this policy. Where we rely on your consent for a specific thing — the biometric check at sign-up, marketing messages, or the optional chat channels — we ask for that consent separately, and you can refuse or withdraw it without losing access to the service, except where refusing means we cannot verify your identity and therefore cannot lawfully let you transact.
We do not sell or rent your personal data to anyone, for marketing or for any other benefit. There is no circumstance in which we would.
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity verification | Bank Verification Number, National Identification Number, and the information held against those identifiers on the relevant government databases. | You, and the government databases we check |
| Biometric and liveness | Facial images and short liveness captures — for example a prompt to turn your head or change expression — taken when you verify your identity, and the result of comparing your selfie with the photograph held against your identity record. | Your device, and the facial recognition service at Section 5 |
| Personal details | Your name, email address, phone number, date of birth, gender, country and residential address. | You |
| Financial | Bank account number and account name, payout details, transaction history, and the cryptocurrency deposit addresses linked to your account. | You, and the platform |
| Transactional | Your crypto-to-Naira conversions: amounts, rates applied, timestamps and status. | The platform and the blockchain |
| Account and authentication | Login credentials, passkeys, session and security information, and identifiers from Apple or Google where you choose to sign in that way. | You, and the sign-in provider |
| Technical and device | IP address, device and push-notification identifiers, browser type, operating system, and usage patterns collected through cookies and similar technologies. | Your device, automatically |
| Activity and security logs | Records of key actions on your account — logins, verification attempts, bank changes, payouts — with the IP address, device information and timestamp. | The platform, automatically |
| Messaging identifiers | Your Telegram ID or WhatsApp phone number, where you choose to use those channels, linked to your Cash-in account. | You, through the platform you choose |
| Rewards and referrals | Referral codes and relationships, the verification and transaction activity used to calculate rewards, reward balances and credit and debit history, withdrawal requests and payout destinations, leaderboard metrics, and records of resets, forfeitures and adjustments. | The platform |
| Communications | Your emails, chat logs, support tickets and chatbot conversations with us. | You and us |
On passkeys: we hold only the public-key credential. The biometric you use to unlock your device — your fingerprint or your face unlock — never leaves your device and is never sent to us. It is not the same thing as the biometric verification at sign-up, which is described above and which we do process.
We do not collect data about your health, genetics, trade union membership, political opinions, religious belief, sexual orientation, race or ethnic origin. There is no field in our systems in which such data could be recorded, and the identity and facial recognition services we use are not asked to infer any of it.
Nigerian law requires us to have a lawful basis for each purpose. Where the basis is consent you can withdraw it. Where the basis is a legal obligation we cannot stop, even at your request.
| Purpose | What we do | Legal basis |
|---|---|---|
| Verifying your identity | Checking your BVN and NIN, and comparing your selfie against the photograph held against your identity record, so that we can lawfully let you transact. | Legal obligation under anti-money laundering law, with your separate consent to the biometric check |
| Processing your transactions | Detecting your crypto deposit, pricing the conversion, and paying Naira to the bank account you nominate through our payment partners. | Performance of our contract with you |
| Regulatory compliance and reporting | Meeting our obligations under the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022 and SCUML requirements, including reporting suspicious transactions to the authorities. | Legal obligation |
| Preventing fraud and protecting the platform | Detecting and preventing fraud, money laundering, terrorism financing and abuse of our reward programmes. To do this we may match information across accounts — email addresses, phone numbers, identification numbers, bank details, device information, name and date of birth — to identify duplicate, linked or fraudulent accounts. | Our legitimate interest, and legal obligation where a report follows |
| Service messages | Telling you about your transactions, your security, and your verification codes. | Performance of our contract with you |
| Marketing messages | Telling you about features and offers. | Consent, given separately and withdrawable at any time with no effect on your service |
| Chatbots and automated assistance | Running our Telegram and WhatsApp chatbots, including the automated interpretation of your messages described at Section 4. | Performance of our contract with you, and your consent to the channel |
| Rewards, referrals and promotions | Calculating, capping, crediting, paying out, withholding, forfeiting and resetting reward balances, including periodic and year-end resets; enforcing “while stocks last” limits; and detecting abuse. | Performance of our contract with you, and our legitimate interest in preventing abuse |
| Cooperating with law enforcement | Responding to lawful requests, court orders and investigations. | Legal obligation |
| Customer support | Answering your questions and resolving disputes. | Performance of our contract with you |
| Improving the service | Understanding how the app is used so we can make it better. | Our legitimate interest |
We collect only what these purposes need. Where a purpose stops applying, we stop collecting for it — and Section 8 says how long we keep what we already have.
When you message our Telegram or WhatsApp chatbot, the text you send may be processed by a third-party artificial intelligence service — currently Google's Gemini models — so that we can work out what you are asking and answer you. The text is sent to that provider for that purpose and may be processed on its infrastructure outside Nigeria.
This is used to route and answer your request. It is not used to make any decision about your credit, your eligibility, or anything else with a significant effect on you.
Please avoid typing sensitive personal information into a free-text chat message where it is not needed. We never ask for your BVN, NIN, password, passcode or full bank details in a chat message, and you should treat any request that appears to do so as fraudulent.
If you would rather not use automated chat assistance, contact our support team directly at support@cash-in.app. You lose nothing by doing so.
We also use automated checks to verify your identity, including the facial and liveness matching at Section 2, and to detect fraud and abuse. No automated check on its own results in you being refused. Where a check does not pass, your case goes to a person to look at, and you are told the outcome and may submit a fresh capture. You can ask for a human review of any automated outcome by writing to compliance@cash-in.app.
We share your data only where a purpose in Section 3 requires it. Each recipient below receives only what its function needs, under terms that limit it to that function.
| Recipient | What reaches them | Where |
|---|---|---|
| Identity verification providers | Your identification numbers and related details, to confirm your identity against government and regulatory databases. Currently Dojah. | Nigeria |
| Facial recognition and liveness service | Your selfie and liveness images and the reference photograph, to confirm you are a live person and that the images match. Currently Amazon Web Services. Your images are sent for comparison; they are not enrolled in any searchable face database. | Outside Nigeria |
| Payment partners and payment fulfillers | Your bank account number, account name, the amount and a reference, so that your account can be verified and your payout executed. They never receive your biometric images or your identity documents. | Nigeria |
| Infrastructure, hosting and security providers | Our hosting and managed database provider holds the platform data. Our edge and transport provider carries your traffic, including your IP address, and protects the service against attack. | Europe and the United States |
| Blockchain infrastructure providers | Your deposit and withdrawal addresses and transaction identifiers, so that we can detect and confirm your deposit. No name, contact detail or identity data is sent with them. | Outside Nigeria |
| Authentication and app-integrity providers | Limited account identifiers, where you sign in with Apple or Google, or for app-integrity checks through Google Firebase. | Outside Nigeria |
| Notification and messaging providers | Push notifications through Google Firebase Cloud Messaging; email through Zoho ZeptoMail and our email infrastructure; messages through Telegram and Meta/WhatsApp where you use those channels. What you exchange on Telegram or WhatsApp is also subject to those platforms' own privacy policies. | Outside Nigeria |
| Artificial intelligence provider | Chatbot message content, as described at Section 4. Currently Google. | Outside Nigeria |
| Other service providers | Approximate location from your IP address, so we can tell you where a new sign-in came from; and review and feedback collection. | Outside Nigeria |
| Regulators and law enforcement | Whatever the law requires, including to SCUML, the Central Bank of Nigeria, the Nigerian Financial Intelligence Unit, other regulators, law enforcement agencies and courts, where required by law or court order or where we have reasonable grounds to suspect a financial crime. | Nigeria and, where lawfully required, abroad |
| Government databases | We check your identifiers against the relevant government databases as part of verification. | Nigeria |
Our servers are located in Europe and the United States of America, and several of the providers in Section 5 are outside Nigeria. Your data therefore leaves Nigeria.
We do not claim that any of those countries has been found to give adequate protection under the Nigeria Data Protection Act 2023. Instead we rely on the grounds the Act actually gives us: for hosting, transport, notification and transaction processing, that the transfer is necessary to perform our contract with you — we cannot run the service without a hosted environment or deliver your passcode without an email provider; and for the biometric check and the optional chat channels, your specific consent, asked for separately.
Each transfer is recorded in our internal Register of Cross-Border Data Transfers, with the data it carries, the ground relied on and the protections that apply. That register is available to the Nigeria Data Protection Commission.
We remain responsible to you for your data after it leaves Nigeria. A contract with a provider reduces our risk; it does not move our obligation to you.
| Right | What it means |
|---|---|
| Access | You can ask for a copy of the personal data we hold about you. We provide it in CSV format. |
| Rectification | You can ask us to correct data that is wrong or incomplete. |
| Erasure | You can ask us to delete your data, subject to the retention we are legally required to apply and to the account conditions at Section 8.1. |
| Portability | You can ask for your data in a structured, commonly used, machine-readable format. |
| Objection | You can object to processing that rests on our legitimate interest. |
| Withdrawal of consent | Where we rely on your consent, you can withdraw it at any time. |
| Human review | You can ask a person to review any automated outcome that affects you. |
| Complaint | You can complain to the Nigeria Data Protection Commission at any time. |
To exercise any of these rights, email compliance@cash-in.app. We will acknowledge your request and tell you what we have done with it. We aim to complete a request within 30 days and will tell you if we need longer and why.
We will ask you to verify your identity before we act on a request about an account, because acting on an unverified request would itself be a risk to you.
A request for erasure is not refused in full because part of the data must be kept. We separate what we must keep from what we need not, delete the second, and tell you in plain terms what has been kept and under which obligation.
We describe here what is actually in place, rather than what would sound reassuring.
| Measure | What it means in practice |
|---|---|
| Encryption in transit | All traffic between your device and us is encrypted, and our service is reachable only over an encrypted connection. |
| Encryption at rest | The platform on which our database runs encrypts the storage it sits on. |
| Restricted access | Access to personal data is limited to a small number of authorised officers by clearance level, on a need-to-know basis, under written access control rules. Every officer is bound by confidentiality obligations, and access is reviewed and removed when a role ends. |
| Strong authentication for you | We support phishing-resistant passkeys. Passcodes are issued for one purpose only and cannot be reused for another. We can revoke every session on your account at once. We rate-limit and lock out repeated failed attempts. |
| Strong authentication for us | Multi-factor authentication is required on administrative and infrastructure access, with short session timeouts. |
| Separation of duties | A person who can release a payout cannot also clear the compliance check on it. Our systems refuse the combination; no role can override it. |
| Monitoring and logging | Every transaction and every significant action on your account is recorded with who did it and when. |
| Incident response | We maintain a written breach management procedure with defined severities, named responsibilities and the notification timetable at Section 11. |
We assess our own controls against our written policies, record where a control is not yet in place, and assign an owner and a date to close it. Our current assessment, and the improvements scheduled from it, are available to our regulators.
We have not been audited or penetration-tested by an independent third party. We say so rather than let you infer otherwise, and commissioning an independent test is one of the scheduled improvements referred to above.
No service can promise complete security, and we do not. What we undertake is to keep the measures above in place, to tell you if something goes wrong as set out at Section 11, and not to describe a protection we do not have.
| Record | How long | Why |
|---|---|---|
| Identity verification and KYC data | For as long as your account is open, and at least 5 years after it closes | Required by the Money Laundering (Prevention and Prohibition) Act 2022 and SCUML requirements. |
| BVN and NIN data | As above | Part of the customer due diligence record we are required to keep. |
| Biometric and liveness images | 90 days after your verification succeeds — or up to 12 months where it failed and your case is still under review | The images are needed to perform the check, not to keep afterwards. We keep the result of the check with your KYC record; we delete the pictures. |
| Transactional data | At least 5 years from the date of the transaction, and longer where a tax or accounting obligation requires it | Required by the Money Laundering (Prevention and Prohibition) Act 2022; kept longer where a tax or accounting obligation applies. |
| Communication records | 24 months from the closure of the matter — or 5 years where the correspondence forms part of a customer due diligence or regulatory record | Customer support and dispute resolution; the longer period applies where the correspondence is part of a due diligence or regulatory record. |
| Activity and security logs | 12 months | Security, fraud prevention and investigation of anything that goes wrong. |
| Chatbot conversation content | 90 days | Needed to handle the conversation, not to keep beyond it. |
| Rewards and referral records | As long as needed to run the programme, process withdrawals, prevent abuse and resolve disputes, then in line with our transactional retention | Your live reward balance may be reset or zeroed under the programme rules, including at year end, while the historical record is retained for audit and fraud prevention. |
| Authentication credentials | Deleted when your account closes | A closed account should not leave behind a means of signing in. Your credentials are not carried into the retained KYC record. |
| Marketing consent records | For as long as the consent lasts, then 3 years | So that we can show consent existed if you or a regulator asks. |
When data is no longer needed we dispose of it securely. Removing a row means removing it, not marking it inactive.
About backups. Our database is backed up automatically. When we delete something from the live system, a copy remains in existing backups until those backups age out on the provider's schedule. We are telling you this because the alternative — saying data is deleted while a copy persists — would not be true. Backups are not read in the ordinary course and are used only to restore the service.
We may have to keep data longer where it is subject to an ongoing legal proceeding, a regulatory investigation or a court order.
If you have a question about any period above, write to compliance@cash-in.app.
You can request deletion of your account from your profile or settings in the app, provided the account has been open for at least 30 days since you registered. Before then the option is not available.
When you submit the request a 48-hour period begins, during which your account is scheduled for permanent deactivation. You can cancel at any point inside that window.
After 48 hours the account is permanently deactivated: your access is revoked, your sessions are invalidated and you are signed out on every device.
Any transaction still in flight is completed or reversed before deactivation, and any pending reward is revoked and is not paid. We do not hold a customer balance, so there is no stored value to return.
After deactivation we still keep the data the law requires us to keep, as set out in Section 8. Everything else is disposed of under our secure deletion procedures.
We use cookies and similar technologies on our website and blog. Some are essential — they keep you signed in and keep the service secure, and the service does not work without them. Others are optional and are used for analytics and to remember your preferences.
You can manage optional cookies in your browser settings, and we will respect the choice you make. Some features may be limited if you disable them.
We do not use cookies to build an advertising profile of you, and we do not share cookie data for that purpose.
We may update this policy to reflect changes to our services, our data practices, the providers we use, or the law. Every version carries an effective date, and the current version is always the one published at cash-in.app/privacy.
We may add, change or replace the providers named in Section 5 — for identity verification, facial recognition, payments, messaging, notification, infrastructure or artificial intelligence. Internally, we do not make such a change until our transfer and provider registers have been updated to record it.
Where a change materially affects your rights, or introduces a new purpose or a new category of data, we will tell you before it takes effect, by email or in the app, and not rely on your having read the website.
For any other change, the updated policy takes effect on publication, and your continued use of the app after that constitutes acceptance. Please review the policy from time to time.
If a breach of your personal data poses a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and we will notify you.
Where the risk to you is high we will tell you immediately, rather than waiting for a full picture of what happened.
What we tell you will cover the nature of the breach, the categories of data affected, the likely consequences for you, what we are doing about it, and what if anything you should do.
The 72-hour period runs from when we become aware of the breach, not from when we finish investigating it, and it is not paused by our recovery work.
The Cash-in App is only available to people aged 18 or over. Identity verification at sign-up enforces this.
We do not knowingly collect personal data from anyone under 18. If we find that we have, we will delete it.
If you believe we hold data about a child, tell us at compliance@cash-in.app and we will act on it.
| Controller | Macroblocs Limited (RC 1976836), operator of the Cash-in App |
|---|---|
| Privacy and rights requests | compliance@cash-in.app — data provided in CSV format |
| Support | support@cash-in.app |
| Supervisory authority | Nigeria Data Protection Commission |
| Office | We operate remotely and do not maintain a physical office. Please use the email addresses above. |