Legal

Privacy Policy

This policy explains what personal data ReConnect handles, why, who can see it, and the rights you have. We've kept it as plain as we can. The short version: your customers' data belongs to your business, we never sell it, ReConnect never messages your customers on its own, and our team can't open your customer list unless you let us.

Last updated 26 September 2026

1.Who we are

ReConnect is operated by RECONNECT HUB (Reg No. 9890503) (“ReConnect”, “we”, “us”). We provide software that helps businesses keep their customers in one place, follow up with them on WhatsApp and track the sales that come back.

We process personal data in line with the Nigeria Data Protection Act 2023 (NDPA) and other laws that apply to us. You can reach us about privacy at our contact form.

2.Our two roles

For people who use ReConnect — business owners and their team members — we decide how and why your account data is used. For this data we are the data controller.

For the customers of those businesses — the names, phone numbers, conversations and purchase details a business adds or imports — the business decides what to collect and how to use it. The business is the data controller and ReConnect is its data processor: we only process that data to provide the service, on the business's instructions.

The terms on which we process a business's customer data for it are set out in the Data Processing Agreement that forms part of our Terms of Service, which the business owner accepts when setting up. Each business is responsible for having a lawful basis for the customer data it adds, for telling its customers how it uses their details, and for answering their requests. ReConnect gives businesses tools to help: communication preferences, privacy request tracking, customer data exports, erasure and retention settings.

If you are a customer of a business that uses ReConnect and you have questions about your data, please contact that business first. We will help them respond.

3.What we collect

About account holders and their teams

  • Account details: your name, email address, phone number and password (stored only in hashed form).
  • Business details: business name, country, industry, address, description, contact numbers, website, logo, and the bank account details a business adds for its customers to pay into.
  • Billing details: your plan, payment amounts, dates and references. Card details are collected by Paystack; we never receive or store your card number.
  • Work activity: what each team member does in ReConnect — for example messages sent, how quickly customers were answered, follow-ups completed or missed, and sales recorded. This powers the team results, scorecards and ReConnect Score described below.
  • Usage and technical data: IP address, browser and device information, and log records, used to run and secure the service.
  • Messages to us: what you send through our contact form, by email, or through Help & support in the app, and our replies.
  • How you found us: when you first visit our website before signing up, a cookie remembers the site or ad that sent you (for example “instagram”), the campaign name in the link, the first page you saw and any referral code. We read it once, when you sign up, together with your optional answer to “How did you hear about ReConnect?”, to learn which of our marketing works. If you signed up with another business's referral link, we record that link so we can give you both a free month.
  • Phone notifications: if you turn them on, the address your browser gives us for sending notifications to that device.
  • Google Business Profile: if the owner connects it, the Google account email, access permissions (stored encrypted), the profile's details (name, address, phone, website, hours, category, description), reviews (with the reviewer's public name and photo), replies, posts and the performance numbers Google reports.

Added or imported by businesses about their customers

  • Names, phone numbers, email addresses, delivery addresses, birthdays (day and month), gender only where the customer chose to share it, purchase history, spend, products of interest, tags and the team's internal notes.
  • Orders (items, prices, payments and what is still owed), receipts, deliveries (address, instructions, status, and why a delivery failed), and whether the customer was asked for a Google review.
  • WhatsApp messages sent and received through ReConnect, their delivery and read status, and when each message was answered and by whom.
  • Consent records: whether a customer opted in or out of WhatsApp messages, when and how.
  • From the WhatsApp Business app, if the owner connects it: the app's contacts (names and numbers of contacts who use WhatsApp), up to six months of past one-to-one chats — only if the owner chooses to share chat history on their phone during setup — and, from then on, messages the business sends from the app. Meta sends this to us at the owner's request. Group chats are not imported. Contacts who haven't chatted with the business are only listed for the owner to review; they don't become customers unless the business adds them.
  • From phone contacts or a contacts file: the contacts are read on your own device, and only the contacts you tick are sent to ReConnect.
  • From spreadsheets (CSV files) a business uploads.

About riders

  • The name, phone number, vehicle and notes a business enters for the people who deliver its orders, and the delivery updates they make.

4.How we use personal data

  • To provide ReConnect: storing and importing customer lists, working out segments and health, reminding teams about follow-ups, building each person's Today list, running the shared inbox, sending the WhatsApp messages the business chooses to send, and recording sales.
  • To send alerts and service emails, such as missed-customer and VIP alerts, follow-up reminders, verification, password resets, invitations, receipts and important account notices.
  • To show businesses how their team is doing (see “Team results” below).
  • To take payments and manage subscriptions.
  • To help new businesses get started, with a few emails and notifications if their setup stalls (for example, if no customers have been added yet).
  • To send phone notifications, if you turn them on.
  • To measure our own advertising on Facebook and Instagram, only if you accept advertising cookies on our website (see “Cookies”).
  • To answer questions and provide support, including through Help & support in the app.
  • To keep the service secure, prevent fraud and abuse, and fix problems.
  • To understand, in aggregate, how the product is used so we can improve it.
  • To meet legal obligations.

We do not sell personal data. We do not use businesses' customer data for our own marketing or advertising, we do not use it to train AI models, and ReConnect never messages a business's customers on its own: every WhatsApp message is sent by a person at the business.

5.Automatic calculations

ReConnect works out several things from the data a business holds: customer segments and health scores, who is due to buy again, lost leads, money at risk, revenue opportunities, the ReConnect Score, and each team member's reply times and results. These are simple rules applied to the business's own data (for example, “hasn't bought for longer than usual”). We do not use artificial intelligence for them.

They are estimates to help a business decide who to contact. No decision with legal or similarly significant effects is made automatically: people at the business decide what to do, and nothing is sent to customers without someone pressing send.

6.Team results

Businesses on ReConnect can see how their team looks after customers: for each team member, how quickly customers were answered, replies that were missed, follow-ups done on time or overdue, customers waiting, messages sent, sales recorded and a ReConnect Score. Owners and managers see everyone's results; staff see only their own.

This information is about work done in ReConnect only. The business decides how to use it and is responsible for telling its team members that it is recorded. Team members can ask their employer — or us, if the employer doesn't respond — for a copy of the data about them.

7.Our lawful bases

Under the NDPA we rely on:

  • Contract — to provide the service you signed up for.
  • Legitimate interests — to keep the service secure, prevent abuse, provide team results and improve the product, balanced against your rights.
  • Legal obligation — for example, keeping billing records for tax purposes.
  • Consent — where the law requires it, for example when an owner chooses to share their WhatsApp chat history or to give our support team access, for advertising cookies on our website, and for phone notifications. You can withdraw consent at any time.

Businesses using ReConnect are responsible for having their own lawful basis for the customer data they add or import, for getting customers' consent before messaging them on WhatsApp, and for informing their team about the work activity ReConnect records.

8.When the ReConnect team can see your data

Our platform administrators can see account-level information: business details, team members' names, email addresses and phone numbers, plans and billing records, totals (such as how many customers, messages and follow-ups a business has), a log of actions taken in the account (what was done and by whom, without customer details), a log of the emails we sent (recipient, subject and delivery status), and the messages you send us through the contact form or Help & support.

They cannot open your customer list, customer details or conversations unless the business owner turns on support access — in Settings → Support access, or when sending us a support message — for 24 hours, 7 days or 30 days. While it is on, our support team can view customers read-only to help with your request; they cannot change anything or send messages. Every time they open your customers is recorded and shown to the owner, who can turn access off at any time. It also switches itself off when the time is up.

Outside support access, authorised engineers may access data directly only where strictly necessary to keep the service running, investigate a security incident or abuse, or comply with the law.

9.Who we share data with

We share personal data only with service providers who help us run ReConnect, under contracts that require them to protect it and use it only for that purpose:

  • Hosting and database — cloud infrastructure that runs the application and stores data (for example Vercel and Supabase).
  • Meta Platforms — to send and receive WhatsApp messages when a business connects its WhatsApp Business account, and to import contacts and chat history from the WhatsApp Business app when the owner chooses to.
  • Google — to read and update a business's Google Business Profile, reviews and posts, when the owner connects it. We use Google's official APIs and only the access the owner grants.
  • Paystack — to process subscription payments.
  • Meta Platforms (advertising) — only if you accept advertising cookies on our website: the Meta Pixel tells Meta which of our Facebook and Instagram ads led to a visit, a sign-up or a paid plan (the amount paid, not who paid). It never receives a business's customer data.
  • Push notification services — your browser's provider (for example Google, Apple or Mozilla) delivers phone notifications you turned on. They see the notification, not your account.
  • Email delivery — to send service emails and alerts (for example Resend).
  • Error monitoring — to detect and diagnose technical problems, where enabled (for example Sentry).

Within a business, team members see customer data according to their role: owners and managers see all customers; staff see the customers assigned to them, plus the name and latest message of customers in the shared inbox who aren't assigned to anyone yet, so they can take the conversation. Three kinds of link work without a login, and only for whoever has the link: a receipt link a business sends a customer (showing the business, the customer's name, what was bought and what was paid), an invoice link a business sends a customer (showing the business, the customer's name, the items ordered, the delivery address if there is one, what's been paid, what's left and the business's bank details), and a rider link a business gives its rider (showing that rider's deliveries: customer name, phone number, address and amount to collect). They use long random codes, are hidden from search engines, and a business can reset a rider link at any time. We may also disclose data if required by law or a valid legal request, to protect rights and safety, or as part of a merger or acquisition (in which case this policy will continue to apply).

10.International transfers

Some of our service providers, including Meta, store or process data outside Nigeria. When that happens we take the steps the NDPA requires to make sure the data stays protected, such as relying on countries with adequate protection or on contractual safeguards.

11.How long we keep data

We keep account and business data, including customers, messages, imported chats and activity records, for as long as the account is open, unless the business chooses shorter periods. Businesses can archive or permanently delete customers at any time; deleting a customer also deletes their messages, notes and history from our live systems. Where a customer has sales or orders the business needs to keep for its accounts, the customer is erased instead: their name, phone number, messages, notes and delivery details are removed and the sales totals stay, with no one attached.

In Settings → Privacy & data, business owners can choose how long ReConnect keeps WhatsApp messages, archived customers, delivery addresses and the activity log. Anything older is deleted automatically each day.

Some records are deleted automatically:

  • read notifications after 90 days;
  • records of processed WhatsApp and payment notifications after 90 days;
  • technical error logs after 90 days, and background job logs after 60 days;
  • the record of emails we sent after 12 months;
  • expired sign-in sessions, email-verification, password-reset and invitation links within 30 days of expiring.
  • Google Business Profile data when the owner disconnects Google (nothing changes on Google itself);
  • phone notification addresses when you turn notifications off or the browser stops accepting them.

Owners can close their business account in Settings → Close account. Billing stops straight away, and 30 days later we permanently delete the business and everything in it — customers, messages, imported chats, follow-ups, sales, team and settings. During those 30 days the owner can download the data or reopen the account. We can delete it sooner on request. We keep payment records (amounts, dates, references, the business name and billing email) for as long as tax and accounting law requires.

Anyone can delete their own login in Settings → Your account. That deletes their name, email address, phone number and password and removes them from every team; records of what they did are kept without their name. Messages you send us for support are kept while needed to help you and for our records, then deleted.

12.Security

We use technical and organisational measures to protect personal data, including separating each business's data, role-based access checked on the server, encryption of WhatsApp and Google access tokens, hashed passwords, two-step login (required for our own staff, and available to every user), a log of important actions, and HTTPS throughout. Read more on our Security page. No system is perfectly secure; if we become aware of a breach that affects your data, we will notify you and the Nigeria Data Protection Commission as required by law.

13.Activity and security records

To keep accounts safe and to show who did what, ReConnect records sign-ins and sign-outs, changes to customers and settings, exports, deletions, privacy requests, and when someone on a team opens a customer, order or billing page (once per day per record). Business owners can see their business's activity in Settings → Privacy & data. These records hold who acted, what they did and when — not the content of messages.

We also watch for signs of misuse, such as many failed sign-ins, unusually large exports or deletions, or repeated attempts to open pages someone isn't allowed to see. These raise alerts for our team to check; they don't make decisions about you on their own.

14.Your rights

Subject to the NDPA, you have the right to:

  • be informed about how your data is used, and to access a copy of it;
  • have inaccurate data corrected;
  • have your data deleted — owners can close their account, and anyone can delete their login, from Settings;
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • receive your data in a portable format — businesses can export their customers, sales, messages and team results to CSV at any time;
  • withdraw consent where processing is based on consent, for example by turning off support access; and
  • complain to the Nigeria Data Protection Commission (NDPC).

To use these rights, send a request on our privacy requests page or contact us at our contact form. We may need to confirm your identity before we share or change anything. If your data was added to ReConnect by a business you bought from or work for, that business decides how it's used: we will pass your request to them and help them respond.

Customers of a business can also ask it to stop sending promotions or WhatsApp messages. Businesses record those choices in ReConnect, and ReConnect then leaves those customers out of promotions and follow-ups. When a business has connected its WhatsApp number to ReConnect, replying STOP to that business does the same.

15.Cookies

Needed to run ReConnect: to keep you signed in, remember which business you're working in, remember a completed two-step login for our staff, protect against misuse, and remember your cookie choice.

How you found us (our own, first-party): on your first visit before signing up, rc_src remembers the site or ad link that sent you and the page you landed on (for 90 days), and rc_ref remembers a referral code (for 60 days). They are read only when you sign up, and never shared.

Advertising (only if you accept): the Meta Pixel sets cookies (such as _fbp) so Meta can tell us which Facebook and Instagram ads led to visits and sign-ups, and show our ads to people likely to be interested. It's off until you choose “Accept” in the cookie notice, and you can change your mind any time with Cookie settings at the bottom of every page. Inside the app it does one thing only: when you pay for a plan, it reports the payment amount so we can see which ads bring paying businesses. It is never used with customer data.

16.Children

ReConnect is a business tool for adults. It is not intended for anyone under 18, and we do not knowingly collect their data as account holders.

17.Changes to this policy

We may update this policy as the product or the law changes. We'll change the date at the top, and for important changes we'll let account owners know by email or in the app before they take effect.

18.Contact

Questions or requests about privacy: our contact form, or our privacy requests page, which also lists our privacy contact.