Catcher legal

Privacy Policy

This Privacy Policy explains how Catcher Global Technology Limited, trading as Catcher, collects, uses, shares and protects personal data when you use the Catcher website, dashboard and mobile application. It is written to meet our obligations under the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation, and it explains the rights those laws give you.

Effective 28 August 2026Last updated 28 August 2026Version 1.0

1. The short version

We collect what we need to run a property registry: who you are, how to reach you, what you have registered, what you have reported stolen, and what you have paid. We publish a deliberately limited subset of that on public pages. We never sell your data, and we never use it for advertising.

  • Your name, contact details, national identity number and next-of-kin details are never shown on a public verification page.
  • Your name can appear in registry search results next to an item you registered. Your email address and phone number are withheld from signed-out visitors, and your NIN is never shown to any other user.
  • Item details you report stolen — including the serial number, location and description — are published in the public stolen items database, because that is the point of reporting.
  • We use trusted providers for login, payments, image storage, email and hosting. Some of them process data outside Nigeria.
  • You can access, correct, export or delete your data by writing to contact@catchersecurities.com.

The sections below give the full detail. This summary does not replace them.

2. Who is responsible for your data

Catcher Global Technology Limited (RC 8343759), of Abuja, Nigeria, is the data controller for the personal data described in this policy. That means we decide why and how your data is processed, and we are accountable for it.

For any privacy question, request or complaint, contact our data protection contact at contact@catchersecurities.com with “Privacy request” in the subject line.

3. The personal data we collect

We group the data we hold into the following categories.

CategoryWhat it includesWhere it comes from
Account and identity dataYour name, email address, account role, profile photograph, phone number, and — where you supply it — your National Identification Number (NIN).You, at sign-up and when completing your profile.
Next-of-kin dataThe name, email address and phone number of the person you nominate as your next of kin.You. You are responsible for having their permission before you supply it.
Property recordsItem name, category, serial number or identifier, description, registration date, status, cover photograph and additional photographs.You, when registering or editing a property.
Stolen report dataThe item reported, its serial number, the date and location of the theft, your description of the circumstances, evidence images, and the report status.You, when filing a report. Status changes come from our review team.
Coverage and billing dataThe plan you chose, the amount charged, currency, transaction reference, payment status, coverage start, expiry and grace dates, renewal history, and the billing receipt issued to you.You and our payment processor.
Payment event recordsTransaction references, provider event types, transaction identifiers, environment, amounts, statuses and provider payloads relating to your payments.Our payment processor, via checkout, verification and webhook events.
Communications dataNotifications we generate for you in the product, the transactional emails we send you, delivery status, and any correspondence you send our support team.Our systems, our email provider, and you.
Verification dataThe public verification slug, token and active status generated for each covered property, and the QR code derived from it.Generated by our systems.
Wallet and referral dataYour credit balance, wallet transaction history, credit expiry dates, transfers sent and received, your referral code, the accounts attached to it, referral qualification status and milestone awards.Generated by our systems from your activity and that of people you refer.
Referral integrity signalsEmail address, phone number and device installation identifier, compared between a referring and a referred account to detect self-referral and duplicate accounts.Collected automatically when a referral code is attached to a new account.
Administrative recordsAudit log entries recording actions taken on records, and internal notes our administrators write when reviewing an account, property or report.Our administrators and our systems.
Technical and security dataIP address or a derived identifier, request timing and counts used for rate limiting and abuse prevention, device and browser information, and server logs.Automatically, when you use the Service.

Please do not upload data you do not need to

Photographs and evidence files can contain more than you intend — faces of bystanders, documents in the background, or location metadata. Only upload what is necessary to identify the item, and redact anything sensitive before you upload it.

4. National identity numbers and sensitive data

Where you supply a National Identification Number (NIN), we treat it as high-risk identity data. It is stored under access control, is never displayed on any public page, and is not included in the public stolen items database or in any public verification page.

A NIN may be visible to a signed-in user performing an authenticated registry lookup on a property record, and to our administrators when handling a support case, a dispute or a lawful request. Misusing identity data obtained this way is a serious breach of our Acceptable Use Policy and may be a criminal offence.

We do not deliberately collect special-category data such as health, biometric, religious or political data. Please do not submit it.

5. Why we use your data, and our lawful basis

Under the Nigeria Data Protection Act 2023 we must have a lawful basis for every use of your data. Ours are set out below.

PurposeData usedLawful basis
Creating and securing your accountAccount and identity data, technical dataPerformance of our contract with you
Maintaining your property records and dashboardProperty records, coverage dataPerformance of our contract with you
Publishing public verification pagesNon-personal item details onlyPerformance of our contract with you (you request the page by registering the item)
Publishing the public stolen items databaseStolen report dataPerformance of our contract with you, and our legitimate interest in helping the public avoid buying stolen goods
Taking payment and issuing receiptsCoverage and billing data, payment event recordsPerformance of our contract with you, and compliance with tax and accounting obligations
Sending service notifications, expiry reminders and payment confirmationsAccount data, coverage data, communications dataPerformance of our contract with you
Contacting your next of kin where an account or property matter requires itNext-of-kin dataOur legitimate interest in reaching an account holder or their nominated contact
Running the wallet and referral programmeWallet and referral dataPerformance of our contract with you
Detecting self-referral and referral abuseReferral integrity signalsOur legitimate interest in protecting the integrity of a promotional programme
Preventing fraud, abuse and false reportsTechnical and security data, audit records, administrative notesOur legitimate interest in protecting users and the integrity of the registry
Rate limiting and protecting service availabilityTechnical and security dataOur legitimate interest in keeping the Service available
Handling support requests, disputes and takedown claimsAny relevant categoryPerformance of our contract with you, and our legitimate interest in resolving disputes fairly
Meeting legal obligations and responding to lawful requestsAny relevant categoryCompliance with a legal obligation
Improving the Service and diagnosing faultsAggregated and technical dataOur legitimate interest in improving the Service

Where we rely on legitimate interests, we have considered the impact on you and are satisfied that our interest does not override your rights. You can object to that processing — see “Your rights” below.

6. What Catcher makes public

Catcher only works if some information can be checked by people who do not have an account. We keep that set as small as possible.

SurfacePublishedNever published
Public verification page (/verify)Item name, category, serial number, registration date, item status, plan name, plan status, coverage expiry, description, cover photograph, verification ID and QR code.Owner name, email, phone number, NIN, profile photo, next-of-kin details, payment details, receipts.
Public stolen items database (/stolen-items)Item name, serial number, date reported, location of the incident, description and report status.Owner name, email, phone number, NIN, next-of-kin details, evidence images, payment details.
Registry search, signed out (/search-registry)Item name, category, serial number, registration date, description, photograph, whether the item is reported stolen, and the registrant name and profile photograph.Registrant email, phone number, NIN and next-of-kin details.
Registry search, signed in (/search-registry)Everything above, plus the registrant email address and phone number so you can contact them about a specific item.Registrant NIN and next-of-kin details.

Registrant name is searchable; contact details are not

The registry search is open to anyone, and a signed-out visitor can see that a named person registered a given item. Email addresses and phone numbers are withheld until a visitor signs in, so the registry cannot be used to harvest contact data anonymously. If you would rather your name did not appear in registry search results at all, contact us.

Think before you type

The location and description fields of a stolen report are public. Do not enter your home address, a place of work, an account number, a vehicle location you still use, or anything else you would not want a stranger to read. Describe the incident, not your private life.

When coverage lapses beyond its grace period and a property is archived, its verification page and its stolen listing are removed from public view.

Signed-in users can also perform authenticated registry lookups through our application interface, which return the registered owner's name, email address, phone number and, where supplied, NIN and next-of-kin contact. This exists so that a finder or a prospective buyer can reach an owner. It is logged, rate limited, and restricted to authenticated accounts.

7. Who we share your data with

We do not sell your personal data. We share it only with the service providers we need to run Catcher, each acting as our processor under a written agreement, and with the recipients listed below.

RecipientRoleData shared
ClerkAuthentication and account identityEmail address, name, profile image, authentication events and session data
PaystackPayment processingName, email address, transaction amount, reference and payment metadata
CloudinaryImage storage and deliveryProperty photographs and stolen report evidence images
ResendTransactional email deliveryRecipient email address, subject and message content
NeonManaged PostgreSQL database hostingAll stored application data
VercelApplication hosting and deliveryRequest data, IP address and server logs
FrankfurterPublic currency reference ratesNo personal data — we request an NGN/USD rate only
Professional advisersLegal, accounting and audit supportOnly what is necessary for the matter concerned
Law enforcement and regulatorsLawful requests, investigations and legal claimsOnly what we are lawfully required or permitted to disclose
A successor entityMerger, acquisition or sale of assetsAccount and record data, subject to this policy continuing to apply

Our processors may only use your data on our instructions, must keep it secure and confidential, and must delete or return it when their engagement ends.

8. International transfers

Several of our providers store or process data outside Nigeria, including in the United States and the European Union. Where we transfer personal data out of Nigeria, we do so in reliance on one or more of the safeguards permitted by the Nigeria Data Protection Act 2023, which may include an adequacy determination by the Nigeria Data Protection Commission, contractual clauses imposing equivalent protection, or the necessity of the transfer for the performance of our contract with you.

You can ask us for details of the safeguards applying to a specific transfer by writing to contact@catchersecurities.com.

9. How long we keep your data

We keep data only as long as we need it for the purpose it was collected for, plus any period we are legally required to retain it.

DataRetention
Account and profile dataFor as long as your account is open, then up to 24 months after closure to handle disputes and legal claims.
Property records and photographsFor as long as the record exists. Archived records are retained in restorable form so you can reinstate coverage; you can ask us to delete them permanently.
Stolen reports and evidenceFor as long as the report is open, and for up to 7 years after it is resolved or withdrawn, because these records may be needed as evidence.
Billing receipts, coverage and payment event recordsAt least 6 years from the end of the relevant financial year, to meet Nigerian tax and accounting requirements.
Audit logs and administrative notesUp to 7 years, to support investigations, dispute resolution and accountability.
Wallet ledger and referral recordsAt least 6 years from the end of the relevant financial year, because the wallet is a financial ledger and referral awards must remain auditable.
Notifications and email delivery logsUp to 24 months.
Rate limiting and security recordsShort-lived; typically purged within 30 days of the window closing.

When a retention period ends we delete the data or irreversibly anonymise it so it can no longer be linked to you.

10. How we protect your data

We take the security of the registry seriously, because a property registry is only useful if it can be trusted. Our measures include:

  • encrypted transport (HTTPS/TLS) for all traffic between you and the Service;
  • encryption of data at rest by our database and storage providers;
  • authentication handled by a specialist identity provider, so we never hold your password;
  • role-based access control, with administrative capability restricted to a small number of accounts;
  • an audit log recording administrative actions taken on records;
  • signature verification on payment webhooks, so we only act on genuine payment events;
  • rate limiting on public lookup surfaces to prevent bulk harvesting and abuse; and
  • upload restrictions permitting only JPEG, PNG, GIF and WebP images up to 5 MB.

No system is perfectly secure. You also play a part: use a strong unique password, keep your email account secure, and tell us straight away if you think your account has been accessed by someone else.

11. Your rights

Under the Nigeria Data Protection Act 2023, and comparable laws that may apply to you, you have the following rights.

Access
Ask for a copy of the personal data we hold about you, and information about how we use it.
Rectification
Ask us to correct data that is inaccurate or incomplete. Most profile and property details you can correct yourself in the dashboard.
Erasure
Ask us to delete your data where we no longer need it. We may refuse where we must keep it — for example a billing receipt required for tax, or a stolen report connected to a live dispute or investigation.
Restriction
Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
Objection
Object to processing we carry out on the basis of legitimate interests, including a public stolen listing you believe should not stand.
Portability
Receive the data you gave us in a structured, commonly used, machine-readable format, or ask us to send it to another controller where technically feasible.
Withdraw consent
Where we rely on your consent, withdraw it at any time. This does not affect processing already carried out.
Complain
Lodge a complaint with the Nigeria Data Protection Commission if you believe we have handled your data unlawfully. We would appreciate the chance to resolve it with you first.

12. How to exercise your rights

Send your request to contact@catchersecurities.com from the email address on your Catcher account, telling us which right you want to exercise and what data it concerns.

We will acknowledge your request promptly and respond within 30 days. If your request is complex we may extend that period, and we will tell you why. We may need to verify your identity before we act, particularly for access, erasure or portability requests.

We do not charge for handling a request. If a request is manifestly unfounded or repetitive we may charge a reasonable fee or decline it, and we will explain our reasoning.

13. Automated processing

Catcher applies some rules automatically. Scheduled jobs move coverage from active, to grace period, to archived, based on the dates on your record, and generate the reminders and notifications that go with those transitions. Rate limiting temporarily blocks a visitor who exceeds our public lookup thresholds.

These are rule-based operational processes, not profiling. We do not carry out automated decision-making that produces legal or similarly significant effects on you. If an automated action affects your record and you believe it is wrong, contact us and a person will review it.

14. Children

Catcher is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

15. Data breaches

We maintain a process for detecting, investigating and reporting personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and will inform affected users without undue delay where the risk to them is high.

16. Changes to this policy

We will update this policy when our processing changes or when the law requires it. The effective date and version at the top of this page always reflect the current version. Where a change materially affects how we use your data, we will notify you by email or in-product notice before it takes effect.

17. Contact us

Write to contact@catchersecurities.com, or to Catcher Global Technology Limited, Abuja, Nigeria. If you are not satisfied with our response you may complain to the Nigeria Data Protection Commission.

Still have a question?

If anything on this page is unclear, or you need help with a record, a report or a payment, our team would rather hear from you than have you guess.