Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains how SprintCheck, operated by Mega Sprint Limited (“SprintCheck”, “we”, “us”), collects, uses, shares and protects personal data when you use our websites, dashboard and identity verification APIs (the “Services”).
1. Who this policy applies to
This policy covers two groups. First, our merchants — the businesses that hold a SprintCheck account. Second, the end users whose identity our merchants verify through the Services. For end-user data, the merchant is the data controller and SprintCheck acts as a data processor on their behalf.
2. Information we collect
- Account data: name, business name, email address, phone number and password when a merchant registers.
- Verification data: identifiers submitted for a check — such as BVN, NIN, voter's card numbers, a selfie image and liveness score — and the results returned by authoritative sources.
- Business data: registration numbers, directors and related records retrieved during CAC/KYB lookups.
- Usage and technical data: API request logs, IP address, device and browser information, and wallet or billing activity.
3. How we use information
- Perform identity and business verifications requested by merchants.
- Operate, secure and improve the Services, including fraud prevention.
- Bill for successful verifications and maintain wallet balances.
- Provide support and send service-related communications.
- Meet legal, regulatory and audit obligations.
4. Legal bases for processing
Where NDPR, GDPR or similar laws apply, we process personal data on the basis of the performance of a contract, our legitimate interests in operating and securing the Services, compliance with legal obligations, and — where required — consent obtained by the merchant from the end user.
5. Sharing and disclosure
We do not sell personal data. We share it only as needed to run the Services:
- Authoritative verification sources and regulators (e.g. NIBSS, NIMC, INEC, CAC) to complete a check.
- Infrastructure and payment providers acting as our sub-processors under contract.
- Authorities where disclosure is required by law or to protect against fraud.
6. Data retention
We retain personal data for as long as needed to provide the Services, meet legal and regulatory requirements, resolve disputes and enforce our agreements. Verification records are retained in line with applicable KYC record-keeping obligations, after which they are deleted or anonymised.
7. Data security
We apply enterprise-grade safeguards including encryption in transit and at rest, access controls, audit logging and signed webhooks. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard measures.
8. International transfers & data residency
We offer data residency options across Nigeria, the EU and the US. Where data is transferred across borders, we rely on appropriate safeguards consistent with NDPR and GDPR requirements.
9. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and request data portability. Because SprintCheck processes end-user data on behalf of merchants, end users should direct requests to the merchant that collected their data; we will assist that merchant in responding.
10. Cookies
Our website uses essential cookies to operate and, where enabled, analytics cookies to understand usage. You can control cookies through your browser settings.
11. Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children except where a merchant lawfully verifies a minor as part of its own regulated process.
12. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a revised “Last updated” date.
13. Contact us
For privacy questions or to exercise your rights, contact us at info@megasprintlimited.com.ng.