HomePrivacy Policy

Privacy Policy

 

Effective Date: 01 February 2024  |   Last Updated: 10 July 2026

This Privacy Policy explains how JAM-Forte Logistics Co. Ltd (“we”, “us”, “our”, or the “Company”) collects, uses, discloses, and protects personal data when you visit our website at https://jamfortelogistics.com, create an account, use our products, or access our Application Programming Interface (API) and related developer services (collectively, the “Services”).

We are committed to protecting your privacy in accordance with the Nigeria Data Protection Act, 2023 (“NDPA”), the NDPA General Application and Implementation Directive (“GAID”) 2025, and other applicable data protection laws. By using our Services, you agree to the collection and use of information as described in this Policy.

1. Definitions
  • “Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”).
  • “Sensitive Personal Data” means personal data relating to health, sex life, sexual orientation, race, ethnicity, religious or political beliefs, trade union membership, genetic or biometric data, criminal record, or other data classified as sensitive under the NDPA.
  • “Data Controller” means the entity that determines the purpose and means of processing personal data.
  • “Data Processor” means an entity that processes personal data on behalf of, and under the instructions of, a Data Controller.
  • “API Customer” means a business or individual who registers for and uses our API products to integrate our Services into their own applications.
  • “End User” means an individual whose personal data is submitted to our API by an API Customer.
  • “Processing” means any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion.

2. Scope of This Policy

This Policy applies to personal data we process through:

  • Our public website, https://jamfortelogistics.com, and any related marketing pages;
  • Registration for and use of user accounts on our platform;
  • Our API services and developer products, including SDKs, documentation portals, and sandbox/testing environments;
  • Customer support, billing, and account management interactions;
  • Any other product, feature, or service that links to this Policy.

Where we process personal data on behalf of an API Customer as a Data Processor (see Section 9), the API Customer’s own privacy policy, not this one, governs how they collect and use End User data, and this Policy applies to our processing activities as their processor.

3. Information We Collect

3.1 Account and Registration Information

When you create an account or otherwise register to use our Services, we collect information such as:

  • Full name, email address, and phone number;
  • Company or organisation name and job title;
  • Username and password (stored in encrypted/hashed form);
  • Billing name, billing address, and other account administration details.
3.2 Usage Data and API Request Logs

When you or your integrations interact with our website, dashboard, or API, we automatically collect:

  • API keys, request and response metadata, endpoint(s) called, timestamps, and status/error codes;
  • Request volume, rate-limit usage, and consumption metrics used for billing and abuse prevention;
  • IP address, device and browser type, operating system, and referring URLs;
  • Log files, diagnostic data, crash reports, and performance metrics.

We log API request and response metadata (e.g., endpoint, timestamp, status code, request size) for security, billing, debugging, and abuse-prevention purposes. Unless expressly stated in a separate agreement, we do not use the substantive content of API payloads submitted by API Customers for our own independent purposes beyond providing, securing, and improving the Services.

3.3 Payment Information

If you purchase a paid plan or API usage tier, payment details (such as card number and billing information) are collected and processed directly by our third-party payment processor(s). We do not store full payment card numbers on our own servers; we retain only limited billing metadata (e.g., transaction ID, amount, plan tier, last four digits of a card) necessary for invoicing, reconciliation, and support.

3.4 Information You Provide Directly
  • Content of support tickets, emails, or messages you send us;
  • Feedback, survey responses, and information shared during sales or onboarding calls;
  • Any other information you choose to submit through forms on our website.
3.5 Cookies and Similar Technologies

Our website uses strictly necessary cookies and similar technologies (such as session identifiers and authentication tokens) required for the Services to function, for example, to keep you signed in and to remember basic preferences. We do not currently use these technologies for third-party advertising. If this changes, we will update this Policy and, where required by law, request your consent.

4. Legal Basis for Processing

Under the NDPA, we process personal data only where we have a lawful basis to do so, including:

  • Performance of a contract — to create and administer your account, provide the Services, and process payments;
  • Consent — where you have given clear consent, such as for optional marketing communications;
  • Legitimate interests — to secure our Services, prevent fraud and abuse, and improve our products, provided this does not override your fundamental rights and freedoms;
  • Legal obligation — to comply with applicable laws, regulations, or lawful requests from public authorities.

5. How We Use Your Information

  • To create and fulfil your delivery request
  • To create, authenticate, and administer your account and API credentials;
  • To provide, operate, maintain, and improve the website and API Services;
  • To process payments, generate invoices, and manage subscriptions or usage-based billing;
  • To monitor, detect, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
  • To provide customer support and respond to inquiries;
  • To send administrative communications (e.g., service updates, security alerts, billing notices);
  • To send marketing communications where you have consented, and to allow you to opt out at any time;
  • To comply with legal, regulatory, tax, and accounting obligations;
  • To analyse aggregated, de-identified usage trends for product planning and capacity management.

6. How We Share Your Information

We do not sell your personal data. We share personal data only with trusted third-party service providers and subprocessors who perform services on our behalf, under written agreements that require them to protect your data and use it solely for the purposes we specify. These subprocessors may include:

  • eCommerce Platforms and Marketplace
  • Retail and Wholesale Businesses
  • Cloud hosting and infrastructure providers;
  • Payment processors and billing platforms;
  • Customer support and communication tools;
  • Security, fraud-prevention, and monitoring services;
  • Professional advisers (legal, audit, and accounting), where necessary.

We maintain, and will make available on request or via our website, a current list of key subprocessors. We may also disclose personal data where required to comply with a legal obligation, enforce our agreements, protect the rights and safety of our users, or in connection with a merger, acquisition, or sale of assets, subject to appropriate safeguards and, where required, notice to affected individuals.

7. Cross-Border Data Transfers

Some of our subprocessors and infrastructure providers may be located outside Nigeria. Where we transfer personal data outside Nigeria, we do so in accordance with the NDPA’s cross-border transfer requirements, which may include verifying that the receiving country has an adequate level of data protection, entering into standard contractual clauses or other appropriate safeguards, or relying on a derogation permitted under the NDPA and applicable NDPC guidance.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to provide the Services, comply with legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. API request logs and usage metadata are generally retained for a limited period for security, billing, and debugging purposes and are then deleted or anonymised, unless a longer period is required by law or a specific agreement with you. Account information is retained for the duration of your account and for a reasonable period afterward to comply with legal and accounting obligations, after which it is securely deleted or anonymised.

9. API Services — Additional Provisions

Where API Customers submit personal data belonging to their own End Users through our API, the API Customer acts as the Data Controller for that End User data, and we act as a Data Processor, processing such data solely on the API Customer’s documented instructions and for the purpose of providing the Services.

  • API Customers are responsible for ensuring they have a valid legal basis (including, where required, End User consent) before submitting End User personal data to our API.
  • We process End User data only as necessary to provide the API Services, and we do not use such data for our own independent marketing or profiling purposes.
  • We implement appropriate technical and organisational measures to protect End User data processed via the API, consistent with Section 10 below.
  • Upon request or termination of an API Customer’s account (and subject to legal retention requirements), we will delete or return End User personal data in accordance with the applicable agreement.

Enterprise and business API Customers requiring a formal Data Processing Agreement (DPA) should contact us at hello@jamfortelogistics.com to execute one.

10. Data Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption of data in transit, access controls and authentication for our systems and API keys, network security monitoring, and regular security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and API keys confidential.

11. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of Data Subjects, we will notify the Nigeria Data Protection Commission (NDPC) and affected individuals without undue delay, in accordance with the timelines and requirements set out in the NDPA and GAID.

12. Your Rights as a Data Subject

Subject to applicable law, you have the right to:

  • Be informed about how your personal data is processed;
  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete personal data;
  • Request erasure of your personal data, subject to legal retention requirements;
  • Object to or restrict certain processing, including direct marketing;
  • Request data portability, where technically feasible;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been violated.

To exercise any of these rights, please contact us using the details in Section 16. We will respond within the timeframes required under the NDPA.

13. Children’s Privacy

Our Services are not directed to children, and we do not knowingly collect personal data from individuals under the age of 18 without appropriate parental or guardian consent, where required by law. If you believe a child has provided us with personal data without appropriate consent, please contact us so we can take appropriate action, which may include deletion of that data.

14. Third-Party Links

Our website and API documentation may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing any personal data.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy on this page with a revised “Last Updated” date and, for material changes, will provide additional notice (such as by email or an in-product notification) where appropriate.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, or wish to exercise your rights as a Data Subject, please contact:

  • Data Protection Officer: John Miracle
  • Email: Hello@jamfortelogistics.com
  • Postal Address: 1473 Inner Block Street, Central Business District, Abuja
  • Website: www.jamfortetech.com

You also have the right to lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng.