Privacy Policy

Last updated: 21 July 2026

This Privacy Policy explains what personal data Passy collects, why we collect it, and how we handle it when you use passy.ng and its subdomains (the "Service"). Passy is designed around a simple principle: we collect the minimum needed to let an estate manage visitor access.

1. Data we collect

Estate administrators: name, phone number, estate name and location, and password (stored as a secure hash). Residents: name, phone number, unit label, number of occupants, and password (hashed). Visitors: the name (and optionally phone number) a resident enters when creating a code, plus check-in and check-out times recorded at the gate. Technical data: standard server logs (IP address, timestamps) used for security and troubleshooting.

2. How we use it

We use this data solely to operate the Service: authenticating users, generating and verifying visitor codes, keeping visit records for the estate, and showing estates their own visit statistics. We do not sell personal data, and we do not use it for advertising.

3. Who can see what

Data is scoped to your estate. Estate administrators can see their estate's residents, units, and visit records. Residents see their own codes and their own unit's visitor history. Gate users see the details of the code they are verifying. No estate can see another estate's data.

4. Storage and security

Data is stored on servers we operate. Passwords and gate PINs are stored as bcrypt hashes, never in plain text. All traffic between your browser and the Service is encrypted with TLS. Access to production systems is restricted and logged.

5. Retention

Visit records are retained for the estate's use for as long as the estate account is active. If an estate closes its account, its data is deleted within 90 days. Residents removed or rejected by an estate have their account marked inactive; estates may request deletion of resident records via support.

6. Your rights

Under the Nigeria Data Protection Act (NDPA), you may request access to, correction of, or deletion of your personal data. Residents should direct requests to their estate administrator or to us at support@passy.ng; we will respond within 30 days.

7. Cookies and local storage

The Service uses browser local storage to keep you signed in. We do not use advertising or cross-site tracking cookies.

8. Changes

We may update this Policy from time to time. Material changes will be announced to estate administrators. The "Last updated" date above reflects the current version.

9. Contact

Privacy questions or requests: support@passy.ng.