Privacy Policy

Effective Date: March 12, 2026
Last Updated: September 4, 2026

1. Introduction

Daya Labs Limited (“Daya”, “we”, “us”, or “our”) provides financial technology products including Daya Pro, Daya Borders, Daya Coins, Daya Stocks, Daya Business, and the Daya APIs. We are committed to protecting the privacy and security of your personal information.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:

  • visit or interact with our website at daya.co and its subdomains;
  • create or use an account on any Daya product, including the Daya Pro mobile application, Daya Borders, Daya Coins, Daya Stocks, and Daya Business;
  • use the Daya APIs; or
  • otherwise communicate with us.

We refer to all of these collectively as the “Service”.

Please read this policy carefully. By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. Where we rely on your consent for a particular activity, we will ask for it separately and you may decline or withdraw it.

2. Information We Collect

2.1 Website Visitors

When you visit daya.co, we and our partners may collect:

  • Device and browser information: browser type and version, operating system, screen size, and language settings.
  • Network information: IP address (which indicates your approximate location) and user agent string.
  • Usage information: pages viewed, time spent on pages, links clicked, referring website or advertisement, and the search terms that brought you to us.
  • Identifiers set by cookies and similar technologies: see Section 3.

You do not need an account for us to collect this information, and some of it is collected automatically. Section 3 explains which of it is optional and how to decline.

2.2 Account Information

When you create an account or use our Service, we may collect:

  • Account Information: email address, first name, last name, and username.
  • Authentication Credentials: passkey data (WebAuthn credentials), PIN (stored securely on-device), and one-time passwords (OTPs) for verification.

2.3 Identity and Security Information

To enhance user protection and account security, and to help prevent fraud and bot activity, we collect identity and security information, including:

  • Selfie Photographs and Identity Information: selfie photographs and identity-related information used to enhance protection and security for our users, confirm account ownership, and help prevent the Service from being spammed or abused by fraudulent users or bots.
  • Identity Documents: government-issued identification documents (passport, driver’s licence, or national identification card), selfie photographs submitted with those documents, and the country of issuance where needed to confirm account ownership and protect the Service from abuse.

2.4 Financial Information

In the course of providing the Service, we collect financial information, including:

  • Bank Account Details: bank name, account number, and account name for fiat (NGN) deposits and withdrawals.
  • Blockchain Wallet Addresses: deposit and withdrawal addresses across supported blockchain networks (Ethereum, Base, Polygon, Arbitrum, Optimism, Solana, TRON, BNB Smart Chain, Aptos, and others).
  • Transaction History: records of deposits, withdrawals, trades, orders (including order type, side, quantity, price, fees, and status), and wallet balances.

2.5 Device and Technical Information

We automatically collect certain device and technical information when you use the Service:

  • Device Identifiers: device type, device name, and operating system name and version.
  • Network Information: IP address and user agent string.
  • Application Information: app version and build number.

2.6 Usage and Telemetry Data

We collect limited usage data to improve the reliability and performance of the Service:

  • Event Data: interactions with key features such as passkey setup, login flows, and recovery processes.
  • Telemetry Logs: timestamped client events buffered in memory for diagnostic purposes. Telemetry collection may be enabled or disabled based on environment configuration.

2.7 Notification Preferences

We collect your preferences for receiving notifications, including:

  • Communication Channels: push notification and email preferences.
  • Notification Categories: preferences for order updates, deposit confirmations, withdrawal updates, and price alerts.
  • Push Notification Tokens: device tokens required to deliver push notifications through the Expo Push Notification service.

2.8 Face Data-Specific Disclosures

To make our face-data practices clear:

  • Device Biometrics Are Not Collected by Daya: we do not collect, receive, or store biometric templates or scans created by Apple Face ID, Touch ID, or similar device-level biometric systems. Those biometric templates remain on your device and are not shared with Daya.
  • Passkey Recovery Selfies Are Not Retained by Daya: if you use the passkey recovery flow, we may ask you to capture a selfie to re-confirm your identity against information already linked to your account. Daya uses that selfie for a one-time identity check and does not retain it after the request is completed.
  • Selfie Images We Do Retain: we retain selfies and other face images submitted during account security and identity confirmation checks. We store this face data to enhance the protection and security of our users, confirm account ownership, help ensure the Service is not spammed or abused by fraudulent users or bots, and support short-term review of suspected abuse or account-security issues.
  • We Do Not Retain Face Data Indefinitely: retained selfie images are stored for up to 30 days after submission and are then deleted. We use this specific retention period because it gives us a limited window to review security alerts, investigate suspected fraudulent or bot activity, and resolve related support issues without keeping face data longer than necessary.
  • Third Parties We Share Face Data With: we do not share face data with third parties.
  • Third-Party Storage of Face Data: because we do not share face data with third parties, no third party stores face data on our behalf.

Face data is not used for advertising, is not shared with advertising partners, and is never used to build a marketing profile.

3. Cookies and Similar Technologies

A cookie is a small text file placed on your device when you visit a website. We also use technologies that work in a similar way, including pixels (small pieces of code that record that a page was viewed), local storage, and software development kits inside our mobile applications. In this policy we refer to all of them as “cookies”.

3.1 The Categories We Use

Cookie categories used on daya.co and whether each requires consent
CategoryWhat it doesConsent required
Strictly necessaryKeeps you signed in, secures your session, protects against fraud and abuse, remembers your cookie choices, and keeps the site working. The Service cannot function without these.No
AnalyticsTells us which pages are visited, how people move through the site, and where things break, so we can improve the Service.Yes
AdvertisingMeasures whether an advertisement led to a visit or a sign-up, and allows our advertising partners to show you Daya advertisements on their platforms.Yes

Strictly necessary cookies are set automatically because the Service cannot be delivered without them. Everything else is set only if you accept it. Nothing in the other two categories runs before you make a choice, and you can accept some categories and decline others.

3.2 Your Choices

When you first visit daya.co you will see a consent notice offering a clear option to accept or decline each optional category. Declining costs you nothing — the Service works the same way, and we will not treat you differently for it.

You can change your choice at any time using the “Cookie settings” link in the site footer. Withdrawing consent is as easy as giving it, and takes effect immediately for future collection.

You can also control cookies through your browser settings, and reset or limit the advertising identifier on your mobile device through your device settings. Blocking strictly necessary cookies through your browser may stop parts of the Service from working.

4. Analytics and Advertising Partners

We use third-party tools to understand how our website is used and to measure whether our advertising works. This section names them and says what each receives.

Advertising pixels load only where you have accepted advertising cookies, and may not be active at all times.

4.1 Who They Are

Analytics and advertising partners, what each is used for, and how to opt out
PartnerCategoryWhat it is used forHow to opt out
Google LLC (Google Analytics 4)AnalyticsAggregated reporting on site traffic, traffic sources and page performance.Decline analytics in our banner; or the Google Analytics opt-out browser add-on
Vercel Inc. (Web Analytics and Speed Insights)AnalyticsCounts page views per page and measures how quickly pages load on daya.co. Uses no cookies; recognises a repeat visit within the same day by a hash of your connection details, which is discarded after 24 hours.Decline analytics in our banner
Meta Platforms, Inc. (Facebook, Instagram)AdvertisingWhere you accept advertising cookies, the Meta Pixel may be used to measure actions taken on daya.co after someone sees or clicks a Daya advertisement, and to show advertisements to people who have visited the site.Decline advertising in our banner; adjust Meta's Ad Preferences and Off-Facebook Activity settings in your Meta account
X Corp. (X, formerly Twitter)AdvertisingWhere you accept advertising cookies, the X Pixel may be used to measure actions taken on daya.co after someone sees or clicks a Daya advertisement, and to show advertisements to people who have visited the site.Decline advertising in our banner; adjust the personalisation and data settings in your X account

All four are established outside Nigeria. Section 7 explains the basis on which we transfer data to them.

4.2 What These Partners Receive

When the relevant category is active, these partners may receive your IP address, information about your browser and device, the pages you viewed on daya.co, and the actions you took, together with an identifier they use to recognise your browser. If you are signed in to an advertising partner’s own service on the same device, they may be able to connect this activity to your account with them.

They do not receive: your Daya account credentials, your identity documents, your face data, your bank account details, your wallet addresses, your balances, or your transaction history. We do not send any of that to any analytics or advertising partner, and we do not sell your personal information to anyone.

Our advertising partners use the information for their own purposes as well as ours, as described in their own privacy policies, and act as independent controllers of that data. We have no control over what they do with it once received. Our analytics partners act on our instructions and are not permitted to use the data for their own purposes.

4.3 If You Do Nothing

If you decline, or close the notice without accepting, no analytics or advertising cookies are set and nothing is sent to any of the partners above.

5. How We Use Your Information

We use the information we collect for the following purposes:

  • Account Management: to create, maintain, and secure your account.
  • Service Delivery: to facilitate trading, transfers, deposits, withdrawals, and wallet management on the platform.
  • Identity and Account Protection: to confirm account ownership, enhance protection and security for our users, and help prevent fraud, impersonation, and bot activity.
  • Credit Services: to assess, manage, and administer intraday credit lines, including monitoring credit episodes, applying penalties where applicable, and enforcing account restrictions.
  • Transaction Processing: to process and settle transactions, calculate and apply fees, and maintain accurate ledger records.
  • Communications: to send you transaction confirmations, security alerts, account notifications, and service updates based on your notification preferences.
  • Security and Fraud Prevention: to detect, investigate, and prevent fraudulent transactions, unauthorised access, and other harmful activities.
  • Compliance: to comply with applicable laws, regulations, legal processes, tax reporting, and record-keeping obligations.
  • Service Improvement: to analyse usage patterns, diagnose technical issues, and improve the performance and reliability of the Service.
  • Marketing and Advertising: to measure the effectiveness of our advertising, and to show Daya advertisements to people who may be interested in our products. We do this only where you have accepted advertising cookies, or where you have otherwise consented.

5.1 Our Lawful Bases for Processing

Under section 25 of the Nigeria Data Protection Act 2023, we must have a lawful basis for each thing we do with your personal information. Ours are:

Lawful bases for each category of processing
What we doLawful basis
Create and operate your account; process your transactionsPerformance of a contract with you
Verify your identity; anti-money-laundering and know-your-customer checks; record-keeping and regulatory reportingCompliance with a legal obligation
Detect and prevent fraud, abuse, and unauthorised access; secure the ServiceLegitimate interests, and compliance with a legal obligation
Diagnose faults and improve the reliability of the ServiceLegitimate interests
Assess and administer credit linesPerformance of a contract, and legitimate interests
Analytics cookies, advertising cookies, and marketing communicationsConsent
Transfer of personal data outside Nigeria where no adequacy basis appliesConsent, or another basis permitted under sections 41 to 43 of the NDPA

Where we rely on your consent, you may withdraw it at any time and we will stop that activity. Withdrawing consent does not affect anything we did lawfully before you withdrew it, and does not affect processing we carry out on another basis — we cannot, for example, stop verifying your identity, because that is a legal obligation.

6. How We Share Your Information

We do not sell your personal information. We may share it in the following circumstances:

6.1 Service Providers

We share information with third-party service providers who assist us in operating the Service, including:

  • Payment Processors and Banking Partners: to facilitate NGN deposits, withdrawals, and bank account verification.
  • Blockchain Infrastructure Providers: to process on-chain deposits and withdrawals.
  • Notification Services: to deliver push notifications and email communications.
  • Cloud Infrastructure Providers: to host and operate the Service securely.
  • Identity Verification Providers: to verify users’ identities for KYC and KYB.

These providers act on our instructions and are not permitted to use your information for their own purposes.

6.2 Analytics and Advertising Partners

As described in Section 4, and only where you have accepted the relevant category of cookies.

6.3 Regulatory and Legal Obligations

We may disclose your information where required by law or in response to valid legal processes, including:

  • requests from regulatory authorities, law enforcement agencies, or courts;
  • compliance with applicable legal, tax reporting, fraud-prevention, and public-safety obligations;
  • protection of our rights, property, or safety, or the rights, property, or safety of our users or the public.

6.4 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and any choices you may have regarding your information.

6.5 With Your Consent

We may share your information for other purposes with your explicit consent.

7. International Transfers of Personal Data

Some of the providers and partners described above are located outside Nigeria. This includes our cloud infrastructure, our push notification provider, and every analytics and advertising partner named in Section 4, all of which are established in the United States.

Where we transfer your personal information outside Nigeria, we do so on one of the following bases:

  • the recipient is subject to laws, binding corporate rules, contractual clauses, a code of conduct, or a certification mechanism that provides a level of protection substantially similar to that required by the NDPA;
  • the transfer is necessary for the performance of a contract with you;
  • the transfer is necessary for compliance with a legal obligation; or
  • you have consented to the transfer after being informed of the possible risks.

Transfers to the partners named in Section 4 take place only where you have accepted the relevant category of cookies. Where those partners in turn pass data to their own subprocessors outside Nigeria, that onward transfer is covered by the same basis.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption: sensitive credentials and authentication tokens are stored using device-level secure storage (encrypted keychain/keystore).
  • Authentication Security: we use OAuth 2.0 with access and refresh token pairs, with automatic token rotation.
  • Access Controls: role-based access controls for internal administrative operations, with audit logging for all sensitive actions.
  • Secure Transmission: all data transmitted between the application and our servers is encrypted using industry-standard protocols (TLS/HTTPS).

While we strive to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

8.1 Personal Data Breaches

If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data, and that breach is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as required by section 40 of the Nigeria Data Protection Act 2023. Where the breach is likely to result in a high risk to you, we will notify you directly and immediately.

9. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Service. We may also retain certain information as required by law or for legitimate business purposes, including:

  • Transaction Records: retained in accordance with applicable financial record-keeping requirements.
  • Selfie Images and Related Identity Data: retained for up to 30 days after submission so we can review security alerts, investigate suspected fraudulent or bot activity, and resolve related support issues, after which they are deleted.
  • Passkey Recovery Face Images: used only for a one-time identity check and not retained by Daya after the request is completed.
  • Audit Logs: credit limit changes, suspension events, penalty applications, and administrative actions are retained in immutable audit logs.
  • Account Data: retained for a reasonable period after account closure to comply with legal obligations and resolve disputes.
  • Cookie Identifiers: retained for the lifetime of the relevant cookie.
  • Data Held by Partners: analytics and advertising partners retain data according to their own policies.

10. Your Rights

If you are in Nigeria, the Nigeria Data Protection Act 2023 gives you the following rights over your personal information. If you are elsewhere, you may have these or similar rights under your local law.

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate or incomplete personal information.
  • Deletion: request deletion of your personal information, subject to legal and regulatory retention requirements.
  • Restriction: request that we restrict the processing of your personal information in certain circumstances.
  • Data Portability: request a copy of your personal information in a structured, commonly used, and machine-readable format.
  • Withdrawal of Consent: where processing is based on consent, withdraw your consent at any time.
  • Objection: object to the processing of your personal information for certain purposes, including direct marketing.
  • Human Review: where a decision about you is made solely by automated means and significantly affects you, request that a person reviews it.

To exercise any of these rights, please contact us using the details provided in Section 14. We will respond within the period required by law. We may need to verify your identity before acting on a request, which protects you as much as us.

You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe we have handled your personal information unlawfully. We would ask that you contact us first so we can try to put it right, but you are not required to. The Commission can be reached at ndpc.gov.ng.

11. Device Permissions

The Daya mobile applications may request the following device permissions:

  • Camera: required for capturing selfie photographs to enhance user protection and security and to help prevent fraudulent users or bots from abusing the Service.
  • Photo Library: required for uploading identification documents during enhanced account security checks.
  • Biometric Authentication (Face ID / Fingerprint): used for secure account access and transaction confirmation on your device. Daya does not receive or store the biometric template created by your device operating system.

You may manage these permissions through your device settings at any time. Disabling certain permissions may limit your ability to use specific features of the Service.

12. Children’s Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete such information promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our website and within the application, or by sending you a notification. The “Last Updated” date at the top of this policy indicates when it was last revised.

Where a change requires your consent, we will ask for it rather than relying on your continued use of the Service.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Daya Labs Limited
General enquiries: support@daya.co
Website: https://daya.co

For privacy questions, data subject requests, and complaints about how we handle your personal information, please contact us at support@daya.co. If you are not satisfied with our response, Section 10 explains your right to complain to the Nigeria Data Protection Commission.

15. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023 (NDPA), the NDPA General Application and Implementation Directive, and any applicable regulations issued by the Nigeria Data Protection Commission (NDPC).