Who this policy covers
This Privacy Policy applies to the Orbit microfinance and cooperative management platform, its public website, member and staff portals, installable web app, and Android app. Orbit is operated by NewKipp Software Solution Ltd (“NewKipp”, “we”, “us”, or “our”).
Orbit is a multi-company platform. A subscribing microfinance institution, cooperative, association, merchant, or other company decides which records to create, which financial products to offer, which optional providers to enable, and which staff may access its data. For that company-managed information, the company is normally responsible for its collection and instructions, while NewKipp processes and protects it to provide Orbit. NewKipp separately controls information used for platform accounts, subscriptions, security, support, public website operation, and service improvement.
Information Orbit may collect and process
The information handled depends on the user, the company’s configuration, and the features used. Orbit’s current implementation may process:
- Account and registration information: name, email address, phone number, password, payment PIN, role, company, branch, account or registration number, profile photograph, account status, login history, and authentication or password-reset records.
- Member and customer records: first, middle and last name; gender; date of birth; occupation; residential and business address; city, state and local government area; account type; group, branch and account officer; next-of-kin or guarantor details; and company-defined custom fields.
- Identity and KYC information: BVN, NIN, identification type and number, identity document images, selfie or profile image, proof of address, document dates, verification status and dates, verification references, masked identity-number endings, provider responses, KYC notes, and consent or verification records.
- Financial and product information: wallet balances and ledger entries; deposits, withdrawals and transfers; savings and rotational savings; loans, guarantors, collateral, mandates and repayments; investments; commodity credit; virtual accounts; bank-account details; charges and fees; bills, insurance, cashback, commissions, merchant transactions, accounting entries, approvals, and transaction references and statuses.
- Credit and risk information: credit scores, risk grades, credit limits, outstanding obligations, credit-bureau check results, report references, summaries, negative-record indicators, consent, and provider responses when a company enables these features.
- Documents and communications: files, photographs and images submitted for profile, KYC, address, loan, guarantor, collateral, payment, support or other company workflows; support messages; notifications; email, SMS, WhatsApp and in-app message delivery records; and notes entered by authorized users.
- Company, staff, merchant and agent information: company registration and contact details, branding, domains, branches, staff profiles and permissions, merchant onboarding and verification details, bank or settlement details, subscription and billing records, and activity performed through authorized accounts.
- Technical and usage information: IP address, user agent, browser, operating system or platform, device type, visited page and URL, query string, referrer, campaign tags, session identifier, login and activity events, current page, online status, error and security logs, and timestamps.
We collect information directly from users and authorized company staff, automatically from use of the service, from connected payment, banking, identity, credit and communication providers, and from company-authorized imports or integrations.
How information is used
NewKipp and subscribing companies use information, as appropriate to their roles, to:
- create and administer company, staff, member, merchant and agent accounts;
- authenticate users, apply permissions, secure transactions, prevent fraud, investigate incidents, and maintain audit trails;
- provide wallets, virtual accounts, payments, transfers, savings, loans, investments, commodity, billing, insurance, merchant and reporting features;
- verify identity, eligibility, bank details and credit information where a user or company requests the relevant service;
- process scheduled contributions, repayments, approved wallet deductions and authorized bank debits;
- deliver service notices, transaction alerts, reminders, support responses and company-authorized communications;
- operate subscriptions, calculate fees, reconcile provider activity, produce company reports, and resolve disputes;
- monitor availability, diagnose errors, protect the platform, improve workflows and understand use of public pages; and
- comply with lawful requests and applicable financial, accounting, fraud-prevention and record-keeping obligations.
We do not sell personal or sensitive user data. We do not use BVN, NIN, financial information or uploaded identity documents for advertising.
Financial, payment and bank information
Orbit records financial activity needed to run the products configured by a company. This includes amounts, balances, schedules, interest, fees, repayment and contribution status, transaction references, payment-provider responses, virtual account details, beneficiary or settlement information, and reconciliation and ledger records.
Where online checkout or direct debit is enabled, payment details are submitted to the configured provider. Orbit may store the provider’s customer or authorization reference, mandate status, bank name, account name, masked account details, or an account number needed for bank-account services. Orbit’s payment workflow is not designed to store a card’s full number, expiry date or CVV; card entry and authorization take place on the provider’s service.
An authorized mandate may allow a company to request a debit for an approved repayment or scheduled contribution. Users can see the mandate status in Orbit, and provider rules may apply to cancellation, limits, refunds and disputes.
KYC, BVN, NIN and identity verification
When enabled, Orbit processes identity data to verify a member, create or validate a bank or virtual account, perform a credit check, or satisfy a company’s compliance process. Depending on the selected provider, this may include sending a name, email, phone number, date of birth, gender, address, BVN, NIN, bank account, identity image, selfie, document, or verification reference to that provider.
Orbit stores verification status and audit evidence and may store the provider response needed to support the result, billing, troubleshooting or compliance review. BVN and NIN values and selected bank-account numbers are encrypted in the Orbit database. Access is limited by company roles and permissions, but authorized company staff may view KYC status and the information required to manage a member account.
Android app, camera, files and device data
The Orbit Android app is a secure web-based client for the Orbit service. It uses internet and network-state access. It asks for camera access only when a user chooses to capture an image for an upload workflow. Users may instead select a permitted file or image from the device. A camera image may be held temporarily in the app’s private storage until it is uploaded or discarded.
The current Android app does not request precise or approximate location, contacts, microphone, SMS, call log, or advertising identifier permissions. Orbit uses cookies, local browser storage and session data to keep users signed in, preserve settings, support security controls and operate web-app features.
Data storage and security
Orbit uses role-based access, tenant separation, hashed passwords and payment PINs, encryption for selected highly sensitive fields, secure web connections, private file-storage options, session and security controls, audit logs, backups and operational monitoring. Uploaded sensitive files are served through controlled application access rather than being intentionally exposed as public files.
Data may be stored or processed in Nigeria or in other locations used by our hosting, storage and service providers. We take reasonable steps to protect information during processing and transfer. No system can guarantee absolute security, so users should protect their credentials and promptly report suspicious activity. More information is available on our Security page.
Data retention, account closure and deletion
We keep information only for as long as it is reasonably needed to provide Orbit, maintain an account, complete transactions, support a subscribing company, resolve disputes, enforce agreements, protect the service, and meet legal, financial, audit, tax or regulatory obligations. Retention periods vary by record type and company requirements. Completed or failed messaging campaign and delivery-history records are ordinarily pruned after 14 days by the platform’s current scheduled cleanup, while transaction, ledger, KYC, mandate, loan, savings, security and audit records may need to be kept longer.
A company can deactivate or archive a member account. Permanent deletion may be restricted where the account has auditable financial or compliance records; in that case, access can be disabled and data may be retained, limited or anonymized as allowed by law. Backups may retain deleted data for a limited recovery period before normal rotation.
To request deletion of an Orbit account and associated personal data, email info@newkipp.com with the subject “Orbit account deletion request”. Include the registered email or phone number and company name, but do not email your password, payment PIN, BVN or NIN. We or the relevant company may verify the requester’s identity and explain any information that must be retained. A member may also submit the request to the company that manages the member account.
User rights and choices
Subject to applicable law and the responsibilities of the company managing the account, a user may ask to access, correct, update, export, restrict, object to, or delete personal information, or withdraw a consent that is not required for an existing contract or legal obligation. Users can update certain profile and notification settings in Orbit. They may also decline optional uploads, camera access, optional communications or an optional bank mandate, although a feature that depends on that information may then be unavailable.
Members should first contact the company that created or manages their account for company-controlled records. NewKipp will assist the company where appropriate. Requests can also be sent to info@newkipp.com. We may need to verify identity before acting on a request.
Children’s privacy
Orbit is a business and financial-management service and is not directed to children. A person under 18 should not independently create or use an Orbit financial account. If a company lawfully manages an account involving a minor, it must have the authority and consent required by law and must apply suitable safeguards. If we learn that a child’s information was submitted without proper authority, we will work with the relevant company to restrict or delete it as appropriate.
Changes to this policy and contact information
We may update this policy when Orbit’s features, providers, legal requirements or data practices change. The effective date at the top will be updated, and a prominent notice may be provided where a change materially affects users.
For privacy questions, rights requests, complaints, or account and data deletion requests, contact:
- NewKipp Software Solution Ltd
- Email: info@newkipp.com
- Telephone: +234 806 466 4220
- WhatsApp: +234 806 466 4220
Ask a question or request your data.
Tell us the company and account involved so we can direct the request without asking you to send sensitive credentials by email.