Privacy Policy & Mobile App Data Disclosure
Effective Date: January 1, 2026 | Last Updated: September 24, 2026
com.triple.mobileapp) on Google Play and Apple App Store.1. Introduction & Commitment to Your Privacy
Triple A Microfinance Bank Limited (“Triple A MFB”, “the Bank”, “we”, “us”, or “our”) recognizes the absolute importance of protecting your personal and financial information. We are strictly governed by the Nigeria Data Protection Act (NDPA) 2023, the Nigeria Data Protection Regulation (NDPR), the Central Bank of Nigeria (CBN) Consumer Protection Framework, and international standards for digital banking privacy.
This Policy transparently details how we collect, store, process, share, and protect your data when you visit our website, register for accounts, apply for credit facilities, use our web dossiers, or install and operate the Triple A Mobile App.
2. Information We Collect Through Our Mobile App & Website
To provide secure microfinance banking, comply with statutory Know Your Customer (KYC) guidelines, and prevent financial fraud, we collect and process the following specific categories of user data:
A. Personal Identification Data
- Full legal name (First, Middle, Surname)
- Date of Birth and Gender
- Residential street address and closest landmark
- Verified email address and active mobile telephone number
- Bank Verification Number (BVN) and National Identity Number (NIN) for NIBSS/NIMC regulatory identity verification
- Government-issued identity cards (NIN slip, Voter's Card, Driver's License, International Passport)
- Corporate documents (CAC registration, Form Status Report) for business accounts
B. Biometric & Facial KYC Captures
- Frontal and lateral live passport snapshots captured during account opening and KYC verification
- Liveness detection telemetry (blink and nod checks) to prevent spoofing, deepfakes, and identity theft
- Biometric sensor data (fingerprint or device facial recognition) used strictly on your local device hardware for fast login; biometric templates are never transmitted to or stored on our external servers
C. Financial & Transactional Data
- Triple A MFB account numbers and wallet balances
- Complete transaction records: deposits, withdrawals, interbank transfers, bill payments, and airtime purchases
- Beneficiary account numbers and bank codes saved for your convenience
- Loan application files, credit scores, debt obligations, and repayment records
- Debit card identifiers and masked PANs for card management
D. Technical & Device Identifiers
- Smartphone manufacturer, hardware model, and operating system build
- Unique hardware identifiers (Android ID, Advertising ID, or IDFV) for device binding security
- Internet Protocol (IP) address, network provider, and browser user agent
- Crash reports, latency statistics, and app performance telemetry
3. Specific Mobile Device Permissions & Hardware Usage
The Triple A Mobile Banking App requests specific runtime permissions on your mobile operating system. We request only the minimal permissions strictly necessary to operate a secure digital banking service:
Used exclusively to capture your live facial KYC photograph during remote account opening, take images of your physical identity documents, and scan QR codes for merchant payments. The camera is never accessed in the background without your explicit action.
Enables you to select and upload identity documents (such as utility bills, CAC certificates, or government ID cards) from your device gallery, and save generated PDF transaction receipts and account statements to your device storage.
Utilized during sensitive transactions to combat unauthorized remote account takeover, verify authorized regional access, comply with Central Bank of Nigeria Anti-Money Laundering (AML) location verification standards, and pinpoint nearby Triple A MFB branches and agent banking cash points.
Used solely for cryptographically binding your bank account to your authorized mobile handset to prevent SIM-swap fraud and automatically auto-filling one-time verification passcodes (OTP). We never read, store, or transmit your private SMS text conversations.
Requested only if you actively choose to use the instant airtime or mobile data recharge feature to select a recipient from your phonebook. Your contact entries are never uploaded, stored on our servers, or shared with third parties.
4. Why We Process Your Data (Purpose & Legal Grounds)
We process your data strictly under recognized legal bases defined under the Nigeria Data Protection Act (NDPA):
- Performance of Banking Contract: To open your bank account, execute interbank transfers, process loan disbursements, issue account statements, and manage fixed deposits.
- Statutory & Regulatory Compliance: To comply with mandatory directives of the Central Bank of Nigeria (CBN), Nigeria Financial Intelligence Unit (NFIU), Economic and Financial Crimes Commission (EFCC), and tax authorities (FIRS/LIRS).
- Fraud Prevention & Cyber Defense: To detect suspicious transfers, prevent phishing, authenticate user sessions, and block fraudulent transactions.
- Customer Support & Service Delivery: Managed through our designated Customer Care desk (
[email protected]) to resolve account disputes, process service requests, and send critical transaction notices.
5. Third-Party Disclosures & Sub-Processors
We do not sell, rent, monetize, or trade your personal information to third-party advertisers. We share data only with licensed financial infrastructure providers and regulatory authorities:
- Financial Regulators: Central Bank of Nigeria (CBN) and Nigeria Deposit Insurance Corporation (NDIC).
- Payment Switches & Clearing Houses: Nigeria Inter-Bank Settlement System (NIBSS) for interbank transfers, Instant Payments (NIP), and BVN validation.
- Identity Verification Registries: National Identity Management Commission (NIMC) for NIN verification.
- Licensed Credit Bureaus: CreditRegistry, CRC Credit Bureau, and FirstCentral Credit Bureau for credit assessment as required by Nigerian lending guidelines.
- Certified Payment Gateways: Licensed PCI-DSS certified payment processors for card authorization.
- Security & Cloud Infrastructure: Cloudflare (for Edge DDoS mitigation and Web Application Firewall protection) and encrypted banking core database providers.
6. Data Security & Encryption Standards
Triple A MFB implements state-of-the-art administrative, technical, and physical safeguards:
- End-to-End Encryption: All communications between your mobile device, browser, and our servers are protected using Transport Layer Security (TLS 1.3).
- Data at Rest: Core banking records, identity numbers, and biometric captures are encrypted using AES-256 standard encryption.
- Zero Password Storage: Passwords and Transaction PINs are hashed using cryptographic salt algorithms; bank employees cannot view or access your PIN.
- Cloudflare Edge Defense: Automated rate limiting, bot protection, DNSSEC, and strict Content Security Policies (CSP) to shield all web services.
7. Data Retention Policy
We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as mandated by Nigerian law. Under Central Bank of Nigeria (CBN) regulations and anti-money laundering statutes, banks are legally mandated to retain customer identity records and transaction histories for a minimum of five (5) to ten (10) years after the closure of an account. Once statutory retention requirements lapse, data is permanently erased or irreversibly anonymized.
8. User Rights: Account & Personal Data Deletion
In full compliance with Google Play Developer Policies, Apple App Store Guidelines, and the Nigeria Data Protection Act (NDPA), you have the absolute right to request the deletion of your mobile app account and associated personal data at any time.
How to Request Account & Data Deletion:
Open the Triple A Mobile App → Navigate to More / Profile → Select Security & Privacy → Tap Delete Account & Data and follow the verification prompts.
Send an email from your registered email address to our Customer Care team at [email protected] with the subject line: “Account and Data Deletion Request”, stating your full name, phone number, and account number.
- Immediately Deleted: Mobile app login credentials, device binding tokens, saved beneficiaries, contact sync caches, and marketing subscription preferences.
- Statutory Retention Exception: As a licensed financial institution regulated by the Central Bank of Nigeria, we are required by law (Money Laundering Act & CBN Guidelines) to retain transaction records and KYC identity verification records for the statutory retention period (minimum 5 years). Such retained data is placed in cold storage, restricted from any marketing or active processing.
9. Your Data Protection Rights Under NDPA / NDPR
Under Nigerian law, you possess enforceable rights regarding your data:
- Right to be Informed: Transparent disclosure of how data is collected and utilized (fulfilled by this Policy).
- Right of Access: Request a free copy of your personal records and transaction logs.
- Right to Rectification: Update or rectify incomplete or inaccurate personal information.
- Right to Erasure (“Right to be Forgotten”): Request deletion of non-statutory data.
- Right to Data Portability: Request transmission of your financial history to another institution.
- Right to Object or Withdraw Consent: Opt-out of non-essential communications or withdraw app permissions through your operating system settings.
10. Children's Privacy
Our digital banking products and the Triple A Mobile App are not directed to individuals under the age of eighteen (18) without the formal sponsorship, verification, and consent of a parent or legal guardian. We do not knowingly collect personal information directly from minors without guardian authorization.
11. Contact Our Data Protection Officer & Customer Care
If you have any questions, inquiries, complaints regarding this Privacy Policy, or wish to exercise your data subject rights, please contact our designated offices:
Customer Care Desk
Email: [email protected]
Toll-Free Phone: 080000TRIPLEA
Direct Lines: (+234) 807 3991 230 – 51
Hours: Mon – Fri: 8:00 AM – 5:00 PM (WAT)
Data Protection Officer (DPO)
DPO Email: [email protected]
Fraud Desk: [email protected]
Head Office: Plot 18, Block 114, Lekki-Epe Expressway, Lekki, Lagos State, Nigeria.
