Privacy Policy

Effective 5 July 2026. Applies to the Galucy Identity Platform ("GID"), operated by Galucy Niels Enterprises ("we", "us", "our") at https://gid-swart.vercel.app.

1. What this covers

GID lets a host create events, invite guests, and check guests in by QR code, and lets anyone verify a code or QR issued through the platform. This policy explains what personal data we collect through GID, why, how long we keep it, and how to exercise your rights over it under the Nigeria Data Protection Act 2023 (NDPA) and its General Application and Implementation Directive (GAID).

2. Data we collect

Host accounts. Name, email address, and a securely hashed password (we never store your password in plain text). We also keep a hashed, time-limited token if you request a password reset.

Events. Whatever a host chooses to enter to describe an event: a name, venue, start time, an optional note, and an optional image.

Guests. A host (or, where a host enables public self-registration, the guest directly) provides a guest's name and, optionally, an email address and phone number, so an invite code can be issued and contacted. We also record RSVP responses, check-in status and time, and any private note the host adds about that guest.

Verification scans. When a code is looked up on a public verify page, we log the code checked, the result returned, and, where available, the requesting IP address and browser user agent, so suspicious or abusive verification activity can be identified.

Audit trail. Sensitive actions (a code being revoked or suspended, an account being deleted, an event being deleted) are logged with the acting admin or user and a timestamp, so there is a record of who did what.

Cookies. A signed session cookie so you stay logged in. If Google Analytics is configured for this deployment, it may set its own analytics cookies; if it is not configured, no analytics cookies are set.

3. Why we process it (purpose limitation)

Strictly to run the features you use: creating and managing an account, creating events and guest lists, sending invites, recording RSVPs, checking guests in, verifying codes, keeping the platform secure (rate-limiting, fraud/abuse detection), and maintaining the audit trail described above. We do not sell personal data, and we do not use guest data for advertising.

4. How long we keep it (storage limitation)

Today, event and guest data is retained for as long as the host's account and event exist. A host can delete an individual event, or delete their own account, at any time from within the app, which permanently removes that event's guest list and check-in history. We do not yet have an automated policy that deletes or anonymizes data from old, past events on its own; this is a known gap we are actively working through, consistent with the NDPA's storage-limitation requirement, and this policy will be updated with a specific retention period once one is set.

5. Your rights, and how to reach us

Under the NDPA you can ask to access, correct, or delete your personal data, and object to certain processing. In practice today:

  • A host can view, correct, or delete their own account and its events/guests directly in the app at any time, with no need to contact us.
  • A guest can request removal of their own data, independent of the host who added them, directly from their own ticket link (the "Request my data be removed" link on the invitation page). This notifies the host, who owns and is responsible for acting on the request; it does not delete the record automatically. A guest can also always email hellogalucyniels@gmail.com instead.
  • Anyone can email hellogalucyniels@gmail.com with any other privacy request or question.

6. Security measures

All traffic is served over HTTPS. Passwords are hashed with scrypt, never stored or logged in plain text. Sessions are signed and tamper-evident. Write endpoints are rate-limited. The app sends the standard security headers (strict Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Strict-Transport-Security, and a restrictive Permissions-Policy) and keeps an audit log of sensitive account and data actions.

7. Where your data is processed (cross-border transfer)

GID's database and application hosting run on Neon (Postgres) and Vercel, both of which may process or store data on infrastructure located outside Nigeria. The NDPA places specific conditions on cross-border data transfer, and we take this seriously given real enforcement precedent in this space. By using GID you acknowledge your data may be processed outside Nigeria on infrastructure operated by these providers under their own security and compliance commitments.

8. Breach notification

If a data breach occurs that poses a real risk to you, we will notify the Nigeria Data Protection Commission (NDPC) within 72 hours as required by the NDPA, and notify affected individuals directly where the risk is high.

9. Children

GID is not directed at children and is not knowingly used to collect personal data from children.

10. Changes to this policy

We may update this policy as the product changes, particularly as the retention-policy and guest-initiated deletion gaps noted above are closed. We will update the effective date above when we do.

11. Contact

Galucy Niels Enterprises, reachable at hellogalucyniels@gmail.com.