Airtify

Privacy Policy

What we collect, why, and what we deliberately do not keep. Airtify holds very little: no passwords, no card details, and no readable gift-card codes.

Last updated

1.Who is responsible

Cowrie Integrated Systems is the data controller for Airtify. For anything on this page, including a request about your own data, email airtify@cowriesys.com.

2.What we collect

If you buy cards:

  • Your email address — this is how we identify you, since there is no password.
  • The order itself: quantity, value, and what you paid.
  • Anything you put on the card — the photo you upload, your message and your signature. Photos have their embedded camera data, including any location, stripped before we store them.
  • A payment reference from our payment provider. Not your card details — those are entered on their page and never reach us.
  • The names and email addresses of recipients, but only if you upload them so we can send the cards for you.

If you redeem a card:

  • The phone number and network you enter, at the moment you enter them. We do not ask who you are, and you do not need an account.
  • Your IP address and browser identification, with the outcome of the attempt. This is what stops somebody guessing codes at scale, and it protects the person whose gift they would be spending.
  • A one-way hash of the code that was tried — never the code itself, so the log cannot be used to spend anything.

When you sign in:

  • The IP address the request came from, to limit how many sign-in emails can be sent to an address that did not ask for them.
  • Your browser identification, stored against the session, so you can recognise it.

3.What we deliberately never hold

  • Passwords. There are none.
  • Card or bank details. Payment happens on our provider’s own page.
  • Gift-card codes in readable form. They are encrypted at rest, and only the last four digits are shown in support views. This is also why a revealed code cannot be shown to you again — we genuinely cannot.
  • Anything about a recipient beyond what a sender chose to give us.

4.Why we hold it, and who else sees it

Under the Nigeria Data Protection Act 2023 we rely on performing our contract with you (issuing and delivering the cards you bought), our legitimate interests (preventing fraud and abuse of the redemption page), and our legal obligations (keeping financial records).

Three other organisations process some of it on our behalf:

  • Our payment provider, to take payment and issue refunds. They receive your email address and the amount.
  • Our airtime supplier, to issue the vouchers and to load one onto a number. At redemption they receive the phone number and the network, because the top-up cannot happen without them.
  • Microsoft, to deliver our email. Sending mail may involve processing outside Nigeria, under the transfer safeguards the Act requires.

Airtify’s own database, your uploaded photos and the rendered cards are held on our own server. We do not sell data, and we do not share it for advertising.

5.How long we keep it

  • Orders, payments and the audit record of actions taken on them: kept for as long as the order is live and afterwards for the period financial record-keeping requires.
  • Recipient lists you upload: you can delete them from your order page whenever you like.
  • Uploaded photos: until you remove them, or until we act on a report. Removal deletes the stored image, not merely a flag on it.
  • Redemption attempts: kept while they are useful for preventing abuse, then removed.
  • Cards themselves have no expiry, so an unredeemed card and its record stay for as long as it can still be used — which, by design, is indefinitely.

6.Cookies

One cookie, and only if you sign in: the one that keeps you signed in. It cannot be read by scripts, it is not shared with anyone, and it does nothing else.

No analytics, no advertising, no third-party trackers, and no cookie banner — because there is nothing to ask you about.

7.How it is protected

Codes are encrypted before they are stored. Sign-in links, session cookies and order links are held only as keyed hashes, so the database does not contain anything that could be replayed to get in. Card links use unguessable tokens and are excluded from search engines.

No system is perfect. If something goes wrong that affects you, we will tell you and the Nigeria Data Protection Commission as the Act requires.

8.Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, or to have it sent elsewhere. Email us and we will answer within the time the Act allows.

Some of it we may have to keep — a redeemed card’s record is part of a financial transaction — and we will say so plainly rather than quietly declining.

If you are not satisfied with how we handle a request, you can complain to the Nigeria Data Protection Commission.

9.Children

Airtify is not intended for anyone under 18 and we do not knowingly collect their data. A recipient does not need an account to redeem a card, and we do not ask a redeemer’s age or name.

10.Changes

If this policy changes, the date at the top of the page changes with it. See also our Terms of Service.

Questions about anything on this page? Email airtify@cowriesys.com.