Last updated: August 28, 2026
This Privacy Policy explains how Ureh ("Ureh," "we," "us," or "our") collects, uses, discloses and protects information when you use our API platform, the Developer Console, our documentation site, or any related service (together, the "Service"). It applies to registered developers and businesses ("you," a "Client") that integrate with the Service, and, indirectly, to the end users on whose behalf a Client submits transactions.
This is a policy for a live, transaction-processing API; it is written to reflect how the Service actually works technically, not generic template language. If any section below conflicts with a specific written agreement between you and Ureh, that agreement controls.
Looking for how we expect the Service to be used, rather than how we handle data? See the Terms of Acceptable Use.
Information We Collect
We collect information you provide directly, information generated automatically as the Service is used, and information about the end users of the transactions you submit.
Account and business information
Name, email address, phone number, business name and registration details, settlement/bank information, and any KYC documentation submitted through the Developer Console when you register, verify your account, or update your profile.
API and transaction data
Every request your integration sends and every response we return: the product
requested (airtime, data, cable TV, electricity or education), amounts,
recipient/beneficiary identifiers (such as a phone number, smart card or meter
number), idempotency_key values, transaction references, and the
resulting status. We also log which API key and IP address a request came from,
since that's how authentication, rate limiting and fraud detection work.
Technical and device data
Standard request metadata (IP address, user agent, timestamps), and, on the Developer Console and documentation site, basic usage analytics (pages viewed, session duration) used to keep the Service reliable and easy to use.
End-user information
When your integration submits a purchase on behalf of one of your own customers, we process whatever identifier that product requires to complete it (for example a phone number for airtime and data, a smart card number for cable TV, a meter number for electricity, or a registration/exam number for education payments). We process this solely to route the transaction to the correct provider and confirm its outcome; we are a processor of that data on your behalf, not the party with the direct relationship to that end user. You are responsible for your own end users' privacy notices and consent.
Cookies and Similar Technologies
The marketing and documentation site (the pages this policy is linked from) uses a single first-party preference cookie/local-storage value to remember your light/dark theme choice; nothing else is set here, and no third-party advertising or tracking script runs on these pages.
The Developer Console uses strictly necessary cookies to maintain your signed-in session and to protect against cross-site request forgery. These cannot be disabled without disabling sign-in itself. We do not use cookies for cross-site advertising, and we do not sell or share cookie data with data brokers.
How We Use Information
- To operate the Service. Authenticating requests, resolving pricing, debiting and crediting wallets, routing purchases to the correct provider, and delivering webhook notifications.
- To secure the Service. Detecting fraud, abuse, credential compromise and rate-limit circumvention, and enforcing the Terms of Acceptable Use.
- To provide support. Investigating and resolving a transaction you or your end user has raised with us.
- To maintain accounts. Verifying identity (KYC/KYB), settlement and billing.
- To improve the Service. Understanding aggregate usage patterns across products, endpoints and error rates.
- To meet legal obligations. Record-keeping, tax, anti-money laundering and other requirements applicable to a regulated payment intermediary.
We do not sell personal information, and we do not use transaction data to serve advertising, to you or to your end users.
How We Share Information
We share information only where it is necessary to deliver the Service, and never as a means of monetizing it separately:
| Recipient | What's shared | Why |
|---|---|---|
| Billers and network operators | The recipient identifier and amount for that specific transaction | To fulfil the airtime, data, cable TV, electricity or education purchase |
| Payment and settlement partners | Wallet funding and payout details | To move funds into and out of your wallet |
| Cloud and infrastructure providers | Whatever is stored or processed in the ordinary course of running the Service | Hosting, databases, queues and backups, under contracts that restrict their own use of it |
| Regulators and law enforcement | Records legally compelled by a valid request | Compliance with applicable law |
| A successor entity | The same information you already provided us | Only in connection with a merger, acquisition or asset sale, and only under obligations at least as protective as this Policy |
Data Retention
We keep information for as long as your account is active, and afterward for as long as needed to satisfy the purpose it was collected for:
- Transaction and financial records. Retained for a minimum of five years after the transaction date, consistent with standard financial record-keeping and anti-money-laundering obligations for a payment intermediary.
- API request logs. Retained for 12 months for security, debugging and abuse investigation, then aggregated or deleted.
- Account and KYC information. Retained for the life of the account and for a further period afterward as required by applicable regulation.
- Support correspondence. Retained for as long as reasonably needed to resolve the matter and defend against any related claim.
When retention is no longer required, data is deleted or irreversibly anonymized.
Data Security
Every Secret Key request is authenticated as a bearer token and authorized server-side against exactly what that key is allowed to do; a Public Key can never touch a monetary endpoint, regardless of what the request claims. Passwords and credentials are stored hashed, never in plain text. Data in transit is encrypted (HTTPS/TLS); wallet-affecting operations are applied as atomic transactions with row-level locking, so a debit or credit can never be partially applied. Access to production data internally is limited to what a given role requires.
No system is perfectly secure. If we become aware of a breach affecting your account or data, we will notify you without undue delay through the contact details on file, along with what happened and what we're doing about it.
Your Rights and Choices
Depending on where you're located, you may have the right to request access to, correction of, or deletion of your personal information; to object to or restrict certain processing; and to receive a portable copy of the information you provided. To exercise any of these, contact us using the details below; we will respond within the time required by applicable law, and may need to verify your identity first.
Some information cannot be deleted on request while your account remains active or while a retention obligation above still applies: for example, we cannot delete the transaction record behind a completed purchase, since that record is what the retention obligations above exist to preserve.
International Data Transfers
Ureh operates from Nigeria, and the infrastructure providers we rely on may process data in other countries. Where information is transferred internationally, we require contractual safeguards appropriate to that transfer, consistent with the Nigeria Data Protection Act 2023 and, where applicable to a given Client or end user, other data protection laws such as the GDPR.
Children's Privacy
The Service is intended for businesses and developers, not children. We do not knowingly collect personal information directly from anyone under 18. An end user's own age is a matter between you and that end user; we process only the transaction identifier your integration submits.
Changes to This Policy
We may update this Policy as the Service evolves or as legal requirements change. A material change will be reflected by updating the "Last updated" date above, and, for a change that meaningfully reduces your rights, by additional notice through the Developer Console or by email before it takes effect. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
Contact Us
Questions about this Policy, or a request to exercise any of the rights above, can be sent to [email protected], through our Support page, or — if you already have an account — through the Developer Console's Support page.
Related: Terms of Acceptable Use · Developer Earnings