Privacy Policy

How Zylink Corp collects, uses, and protects your personal data across all our products and services.

Last updated: October 8, 2026
On this page
  1. 1. Introduction
  2. 2. Data We Collect
  3. 3. How We Use Your Data
  4. 4. Legal Basis
  5. 5. How We Share Data
  6. 6. Third-Party Services
  7. 7. Cookies & Local Storage
  8. 8. Data Retention
  9. 9. Data Security
  10. 10. Your Rights
  11. 11. Children's Privacy
  12. 12. International Transfers
  13. 13. Changes to This Policy
  14. 14. Contact Us

1 Introduction

Zylink Corp ("we", "us", "our") is a Nigerian technology company headquartered in Port Harcourt, Rivers State. We build software products that help Nigerian and African businesses operate online — including Clid Cloud (backend-as-a-service), Clid Business (storefront builder), Clid Workspace (productivity suite), Friday F.ai (AI assistant), and Plutous Pay (subscription billing).

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at zylinkcorp.com.ng and any of our products. We are committed to protecting your privacy and complying with the Nigeria Data Protection Regulation (NDPR) 2023 and the Nigeria Data Protection Act 2023.

The short version: We collect only what we need to run your account, process payments, and improve our products. We never sell your data. You can request deletion at any time by emailing .

2 Data We Collect

2.1 Information you provide directly

  • Account information: email address, display name, phone number (optional), password hash (we never store passwords in plain text)
  • Business information: business name, business type, address, logo, brand colors, slogan, contact phone/WhatsApp, social media links
  • Product catalog: product names, descriptions, prices, images, stock levels, categories — you upload these when building your storefront
  • Payment information: bank account details, Flutterwave sub-account ID, settlement preferences. We do NOT store card numbers — Flutterwave tokenizes them on their PCI-DSS compliant servers
  • Customer support communications: messages you send us via email, WhatsApp, or our feedback widgets

2.2 Information collected automatically

  • Usage data: pages visited, features used, time spent, click patterns, error logs
  • Device information: IP address (truncated for privacy), browser type, operating system, screen size
  • Approximate location: derived from IP address — city/country level only, never precise GPS
  • Local storage: session tokens, UI preferences (dark/light mode, language), cart contents (on storefronts)

2.3 Information from third parties

  • Google sign-in: email, name, profile picture, and Google ID (if you sign in with Google)
  • Flutterwave: payment status, transaction references, payout confirmation
  • Cloudflare: security telemetry, bot detection signals, performance metrics

2.4 Sensitive data we DO NOT collect

We never collect: race/ethnicity, political opinions, religious beliefs, health data, biometric data (other than what your device uses locally for passkey authentication — we never see it), sexual orientation, or trade union membership. If you accidentally submit any such data, contact us and we'll delete it immediately.

3 How We Use Your Data

We use your information for these legitimate business purposes:

  • Provide the service: create your account, host your storefront, process orders, send magic-code sign-in emails, generate AI responses through Lana and our storefront chat assistants
  • Process payments: route customer payments to your Flutterwave account, calculate platform fees, issue receipts
  • Communicate with you: order confirmations, status updates, security alerts, product announcements (you can opt out of marketing emails)
  • Improve our products: analyze usage patterns to fix bugs, prioritize features, optimize performance
  • Prevent abuse: detect fraud, spam, bot activity, and Terms of Service violations
  • Comply with the law: respond to lawful requests from Nigerian authorities or courts, where required
  • Anonymized analytics: aggregate usage statistics stripped of personal identifiers — used for product decisions and shared in our public roadmap

5 How We Share Data

We do NOT sell your personal data. We do NOT share it for advertising purposes. We only share data in these specific situations:

  • With service providers: companies that help us operate (listed in Section 6 below). They are contractually bound to use your data only on our behalf.
  • With your customers: when a customer places an order on your storefront, they see your business name, contact info, and order details — but never your bank details.
  • For legal compliance: if required by Nigerian law, court order, or to protect our rights and safety.
  • Business transfers: if Zylink Corp is acquired, merged, or restructured, your data may transfer to the successor entity — we'll notify you 30 days before.
  • With your consent: any other sharing requires your explicit opt-in.

6 Third-Party Services

We use these third-party services to operate our products. Each has its own privacy policy — we encourage you to review them:

Infrastructure & hosting

  • Cloudflare, Inc. — web hosting, DDoS protection, DNS, edge caching, Workers serverless compute. Privacy policy.
  • Google Cloud / Firebase — authentication, AI model hosting (Friday F.ai). Privacy policy.

Payments

  • Flutterwave — payment processing for Nigerian Naira transactions. Privacy policy.

Communications

  • Resend — transactional email delivery (magic codes, receipts, alerts). Privacy policy.
  • Termii — SMS delivery for verification codes and order alerts. Privacy policy.
  • WhatsApp Cloud API (Meta) — for the WhatsApp bot feature (when launched). Privacy policy.

AI providers

  • Groq, Inc. — fast AI inference for Friday F.ai chat. Privacy policy.
  • Google Gemini — multimodal AI for image understanding. Privacy policy.
  • OpenRouter — AI model routing (used for Lana AI fallback). Privacy policy.
  • Pollinations.ai — free AI fallback (anonymous requests). Privacy policy.

Domain registration

7 Cookies & Local Storage

We use minimal cookies and browser storage to keep you signed in and remember your preferences:

  • Essential cookies: clid_session (session token, 30 days), clid_customer_session (customer storefront session, 30 days). Required for sign-in — without these, you can't use our products.
  • Local storage: UI preferences (theme, language), cart contents on storefronts, AI chat history (per-session). Cleared when you sign out.
  • Analytics: we use Cloudflare Web Analytics — privacy-first, no cookies, no cross-site tracking.

We do NOT use Google Analytics, Facebook Pixel, or any third-party advertising cookies. We do NOT track you across other websites.

Your cookie choice: When you first visit any Clid site, you see a "Cookie Consent" banner. Choose "Only necessary" to disable non-essential storage. Your choice is remembered for 1 year.

8 Data Retention

We keep your data only as long as needed for the purposes described above:

  • Active accounts: retained while your account is active. You can delete your account at any time from Settings → Account → Delete Account.
  • Inactive accounts: 24 months after last login, we'll email you a warning. If no response in 60 days, the account and its data are permanently deleted.
  • Order data: retained for 7 years (per Nigerian financial record-keeping regulations for tax purposes).
  • Email/SMS logs: retained for 90 days for debugging, then deleted.
  • AI chat history: retained for 90 days, then automatically deleted.
  • Security logs (IP, user agent): retained for 12 months for fraud detection, then aggregated/anonymized.
  • Deleted accounts: hard-deleted from production within 30 days; backups are purged within 90 days.

9 Data Security

We take security seriously. Our practices include:

  • Encryption in transit: all traffic uses HTTPS with TLS 1.3 — no plaintext allowed.
  • Encryption at rest: database and object storage encrypted with AES-256.
  • Password hashing: bcrypt with cost factor 12 — we never store plain-text passwords.
  • WebAuthn passkeys: support for Face ID / Touch ID / hardware security keys — phishing-resistant authentication.
  • Tokenization: we never see or store your payment card numbers — Flutterwave handles all card data on their PCI-DSS Level 1 certified infrastructure.
  • Access control: strict least-privilege access for our internal team. Production database access is logged and audited monthly.
  • Incident response: if we detect a breach, we'll notify affected users within 72 hours per NDPR requirements.

No system is 100% secure. If you believe you've found a security vulnerability, please report it to and we'll respond within 48 hours. We offer bug bounties for confirmed critical issues.

10 Your Rights

Under the NDPR 2023 and GDPR (for EU users), you have these rights regarding your personal data:

  • Right of access: request a copy of all personal data we hold about you. We'll deliver it within 30 days as a downloadable JSON file.
  • Right to rectification: correct inaccurate or incomplete information. You can do this directly in Settings → Account.
  • Right to erasure ("right to be forgotten"): request permanent deletion of your account and all associated data. Email — we'll process within 30 days.
  • Right to restrict processing: ask us to stop processing your data (except for storage) — e.g., if you dispute accuracy.
  • Right to data portability: receive your data in a structured, machine-readable format (JSON) so you can move it to another provider.
  • Right to object: opt out of marketing communications at any time (unsubscribe link in every email, or Settings → Notifications).
  • Right to withdraw consent: for any processing based on consent, you can withdraw it without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: with the Nigeria Data Protection Commission (ndpc.gov.ng) if you believe we've mishandled your data.

To exercise any of these rights, email with the subject line "Data Rights Request — [your email]". Include your account email so we can locate your data.

11 Children's Privacy

Our services are designed for businesses and are not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal data, contact us at and we'll delete it immediately.

Schools using our School Portal template must obtain parental consent before enrolling students under 16, in line with NDPR requirements for processing children's data.

12 International Data Transfers

Your data is primarily processed in:

  • Nigeria: our primary operational base — your account dashboard, business data, and customer orders are processed here.
  • European Union (Ireland / Frankfurt): Cloudflare's edge network — serves your storefront to global visitors.
  • United States: Google Cloud (for Friday F.ai), Resend (transactional email), OpenRouter (AI fallback).

For transfers outside Nigeria, we rely on:

  • Standard Contractual Clauses (SCCs) where applicable
  • NDPR Section 4(2)(b) "adequate level of protection" determination
  • Binding commitments with each service provider listed in Section 6

13 Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • Minor changes: (clarifications, formatting, contact info) — effective immediately, posted on this page with an updated date.
  • Material changes: (new data types, new purposes, new sharing partners) — we'll email all active users 30 days before the change takes effect.
  • Version archive: the previous version remains available at /privacy/v1 after each material update.

The "Last updated" date at the top of this page reflects the most recent change. Continued use of our services after a change constitutes acceptance of the updated policy.

14 Contact Us

If you have questions about this Privacy Policy or how we handle your data, we're here to help:

We aim to respond to all privacy inquiries within 48 hours (2 business days).

Data Protection Officer: For matters requiring escalation, our DPO can be reached at .