joygiver is a wishlist and group-gifting app for nigeria. this policy covers the joygiver app (with its app clip, widgets and extensions) and our website, joygiver.app, including the pages your friends use to give without the app.
who we are
joygiver ("we", "us") runs the joygiver app and joygiver.app, and decides how the personal data described here is used. you can reach us in the app (settings → help & support → start a chat) or by email at hello@joygiver.app.
what we collect, and why
your phone number and sign-in
your phone number is your account. to sign you in we text you a one-time code (or read it out in a voice call, if you pick that). we keep the code only as a keyed hash, never the code itself. each sign-in attempt (the number, the ip address it came from and the code's hash) is deleted after 7 days. if you change your number, we keep a record of the old and new number, and payouts pause for 24 hours to protect your money.
your name, handle, city, birthday and photo
your profile. you choose what to add, and you can change it in the app. your name and photo show to the people who see your lists and the gifts you send, and your handle is your profile link (joygiver.app/@yourhandle). friends on joygiver see the month of your birthday, so they know it's coming. profile photos and list covers are kept in a public media store: anyone with the link to the image can open it.
unless you turn off let people find me by my number (settings → privacy), people who already have your number can find you on joygiver, and once you've added your name, people who have your number in their contacts may be told you've joined.
your contacts (only if you allow it)
to show which of your people are already on joygiver. nothing is read until you say yes.
- the app sends only the phone numbers in your contacts, never names or anything else, over an encrypted connection.
- our server turns each number into a peppered hash (a keyed sha-256 with a secret only our server holds) and keeps just that hash. the numbers themselves are never stored.
- we compare those hashes with the hashes of joygiver members' own numbers to find matches. people who turned off being found by their number, and anyone you've blocked or who has blocked you, never match.
- we never message the people in your contacts.
- you can turn it off any time: settings → privacy → use my contacts. we delete every hash we hold for you straight away. a fresh sync also drops the hashes of numbers you've since removed.
lists and wishes
this is the service itself: the lists you make, their title, date, cover and who can see them, the wishes on them (names, prices, photos and links), and the co-hosts you add. who sees a list is up to you: anyone with the link, your people, or only the people you pick.
gifts, notes and thank-yous
for each gift we record the list and wish, the amount, the name you want shown, your phone number, your note, and whether the gift is secret. if you give on joygiver.app without an account, you give us your name and phone number so we can text you a receipt. photos, videos and voice notes on a note or a thank-you are kept in a private store, opened only through links that expire after 5 minutes.
payments
gifts are paid through paystack, by card, bank transfer or ussd. card details are typed on paystack's own checkout, never in joygiver: we never see or store a full card number. we keep each payment's reference, amount, method and status, and the payer's name, bank and email as paystack reports them. paystack's raw message about a payment (which can include a card's first 6 and last 4 digits) is cut down to the amount, references, status, fees, channel and dates 90 days after we process it.
your bank account, for withdrawals
to send the money on your lists to you. we check the account with your bank through paystack, and keep the bank, the account name your bank returns, the last 4 digits, and the full account number encrypted. your withdrawal pin is kept only as a one-way hash.
identity checks
this version of joygiver doesn't ask for or collect a bvn, nin or any other id. before money leaves joygiver, we match the name on your bank account against your name on joygiver, and a person on our team checks every withdrawal before it's sent. if id checks come back later, we'll update this page before they start.
- if you run a cause, the organiser check asks for a selfie and the documents it needs. they're kept in a private store and deleted 365 days after the check, or straight away if you close your account.
- if a check needs a closer look, the documents you upload for that review are kept with the review.
messages between friends, and help chats
when you chat with a friend on joygiver, the text and photos you send are stored on our servers so they reach your friend and stay in the chat. our team doesn't read chats. if someone reports a chat, the most recent messages are attached to the report so our safety team can look into it. you can delete a message you sent: its text is cleared and its photo deleted for both of you.
when you message us in the help chat, we keep the conversation and any files so we can help you. if you report a list or a person, we keep the report and the reason so our safety team can act on it.
your device and push token
to keep your account secure and to send you notifications. for each phone you sign in on we keep an id the app makes for that install, the device name, platform (ios or android), app version, and the ip address you signed in from (with the rough city it points to). you can see your devices and sign them out in settings → security. to send notifications we keep push tokens: expo's, and for live activities and widgets the tokens apple and google give the app. signing a device out switches its tokens off.
usage analytics and error reports
to see which parts of joygiver work and fix the ones that don't, we record basic events such as "list created" or "share sent" in our own database, with your account id, a random id for the install or browser, the device id, and fixed details such as a list's link name or which app you shared to. events never carry names, phone numbers, notes or other free text, ip addresses or browser details. they're deleted after 13 months; daily totals with no personal data are kept.
when something breaks on our servers, an error report goes to sentry. phone numbers, id numbers, account numbers, codes, pins and secrets are removed first, and request bodies are never sent. reports are kept for 90 days.
there is no advertising or third-party analytics code in the app or on joygiver.app, and we don't track you across other companies' apps or websites.
shop orders
if you order from the joygiver shop, we keep the delivery address and the receiver's name and phone number (encrypted) so the order reaches them.
on joygiver.app
- giving on a list page works like giving in the app (see gifts and payments).
- if you join the waitlist, we keep the handle you reserve and your phone number (encrypted) until you claim it, and count who joined through your link.
- your browser keeps a random id for this browser (for sign-in safety and the usage events above) in its local storage. opening a friend's invite link sets one first-party cookie for 30 days, so the invite still counts when you sign up. there are no advertising cookies.
our legal reasons
under the nigeria data protection act 2023 we use your data only when we have a lawful reason:
- to give you the service you asked for: your account, lists, gifts, payments, payouts, chats and help.
- because the law requires it: checks on withdrawals, and keeping financial records for anti-money-laundering, tax and central bank rules.
- our legitimate interests: keeping joygiver safe, stopping fraud, and fixing and improving the app, in ways you'd reasonably expect.
- your consent: contacts and push notifications. you can take it back at any time (see your rights).
secret gifts
when you send a gift as a secret, the list owner and the other guests see "a secret giver" instead of your name. joygiver still keeps a private record of who gave and how they paid, because receipts, refunds and the law need it. the owner (or a co-host) gets 3 guesses: a right guess shows you to each other, and you can choose to reveal yourself. 7 days after the list closes, the secret is sealed for good. our support and safety team can see who sent a secret gift when they need to, and every time they look it is logged.
who we share it with
we share personal data only with the providers who help us run joygiver, and only for what they do for us:
- paystack
- payments by card, bank transfer and ussd, refunds, bank account checks and payouts.
- termii
- sign-in codes and text messages, by sms or voice call.
- expo, apple and google
- push notifications; apple and google also deliver live activity and widget updates.
- cloudflare
- serving joygiver.app, and storing photos and files.
- heroku (salesforce)
- hosting our servers and database.
- sentry
- server error reports, with personal data removed first.
- resend
- sending our email.
other people on joygiver see only what the app shows them, such as your name and photo on your lists and on gifts that aren't secret. we may also share data when the law makes us, for example with a regulator, the police or a court.
we don't sell your personal data, we don't show ads, and we don't track you across other apps or websites.
where your data is processed
our servers and database run in heroku's european union region, so your data is stored outside nigeria. some of the providers above, including cloudflare, expo, sentry and resend, also process it in other countries. we send data to them only for the purposes on this page, under their data processing terms, and we protect it on the way and at rest as described under security.
how long we keep it
- sign-in codes and attempts
- 7 days.
- sign-in sessions
- until you sign out, or 30 days after you last used the app on that device.
- profile, push tokens and settings
- while your account is open. closing your account deletes or anonymises them (see delete your account).
- contact hashes
- until you turn contacts off, a sync drops them, or you close your account.
- messages to friends
- until you delete them or close your account.
- device records
- kept after a device signs out or an account closes, to spot fraud.
- usage events
- 13 months.
- server error reports
- 90 days.
- paystack's raw payment messages
- 90 days, then cut down to the amount, references, status and dates.
- identity selfies and raw check data
- 365 days after the check, or straight away if you close your account.
- identity check summary (id type, last 4 digits, hash, legal name, date of birth, result)
- while your account is open, then at least 5 years after it closes, for anti-money-laundering rules.
- money records: gifts, payments, payouts, refunds and our ledger
- about 6 years, even after an account closes. the law requires us to keep financial records.
- help chats, reports and safety records
- kept as records after a chat or case is closed, including after your account closes.
- uploads you never finished
- 24 hours.
your rights
under the nigeria data protection act 2023 you can:
- get a copy of your data. settings → privacy → your data → download my data gives you a file with your profile, settings, devices, lists, gifts, payouts, bank accounts, identity check summary, help chats and messages. you can download it once a day.
- correct it. edit your profile in settings, change your number in settings → security, or ask us in the help chat.
- delete it. settings → privacy → your data → delete my account. see delete your account for how, and how long we keep it for what the law makes us keep.
- take back your consent. turn off use my contacts in settings → privacy and we delete every contact hash we hold for you. turn notifications off in settings → notifications or in your phone's settings.
- object to how we use your data, or ask us to limit it. chat with us or email hello@joygiver.app.
if you're not happy with our answer, you can complain to the nigeria data protection commission (ndpc) at ndpc.gov.ng.
children
joygiver is meant for people aged 18 and over, and its money features (giving, withdrawing, identity checks) are not for anyone under 18. we don't knowingly collect data about children. if you think a child is using joygiver, tell us and we'll close the account.
security
- every connection to joygiver is encrypted (https only).
- bank account numbers, delivery addresses, waitlist phone numbers and identity check responses are encrypted in our database. id numbers, your contacts' numbers and sign-in codes are kept only as keyed hashes, and your withdrawal pin only as a one-way hash.
- identity selfies and documents, receipts and attachments are kept in a private store and opened only through links that expire after 5 minutes.
- our team signs in with a second-factor code, money actions ask for it again, and their actions are recorded in a log that can't be edited.
no system is perfectly secure. if you find a problem, please tell us at hello@joygiver.app.
changes to this policy
when what we do with your data changes, we'll update this page and the date at the top. this version is dated 9 october 2026.
contact us
chat with us in the app (settings → help & support → start a chat), or email hello@joygiver.app. for anything else, see support.