Legal
Privacy Policy
This policy explains what personal data SanjoseMart collects when you use this store, why we collect it, who processes it on our behalf, and the choices you have. It describes what this platform actually does.
Last updated 26 September 2026
Who we are
SanjoseMart is a retail technology store operated by Sanjose Dynamics Limited, with its head office at 23 Abriba Street, by Calabar Road, Umuahia, Abia State, Nigeria. We are the controller of the personal data described below.
Data we collect
- Account data: your name, email address, a securely hashed password, and your account and email-verification status.
- Order and delivery data: recipient name, phone number, delivery address, state and local government area, the items you ordered, and the amounts charged.
- Payment records: the order number, amount, currency and the payment provider reference. Card and bank details are entered on the payment provider’s own page — we never receive or store them.
- Support and after-sales data: support tickets you open, return requests, refund records, and warranty records for purchases.
- Security data: a session cookie and a CSRF cookie, and hashed identifiers used for rate limiting and abuse prevention. Raw IP addresses and raw email addresses are hashed before they are used for this purpose.
- Catalogue interaction data: aggregated product views, searches and cart events, recorded against your account or an anonymous identifier, used to produce demand reporting.
Why we use it
- To create and secure your account and verify your email address.
- To take payment, confirm your order, and deliver it to the address you give us.
- To provide customer support, process returns and refunds, and honour warranties.
- To prevent fraud and abuse, including rate limiting and blocking credential-stuffing attempts.
- To keep records we are required to keep, and to produce internal sales and demand reporting.
Cookies
This store sets two functional cookies: sjm_session, which keeps you signed in, and sjm_csrf, which protects forms against cross-site request forgery. We do not set advertising or third-party tracking cookies, and we do not run advertising pixels.
Who processes data for us
We use established service providers to run the store. They process data only on our instructions:
- Paystack — payment collection and provider refunds.
- Vercel — application hosting.
- MongoDB Atlas — database hosting.
- Cloudinary — storage and delivery of product images.
- Resend — delivery of transactional email such as verification codes, order confirmations and refund notices.
- Upstash — request rate limiting.
We do not sell personal data.
How long we keep it
Account data is kept while your account is open. Order, payment and refund records are kept after that for accounting, warranty and legal reasons. Support and return records are kept while a claim could still be made.
Your rights
Under the Nigeria Data Protection Act you may ask to see the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. We verify your identity before acting on a request, and we may keep records we are legally required to retain.
To make a request, open a support ticket from your account or write to the head office address above.
How we protect it
- Passwords are stored using scrypt hashing; we can never read them.
- Session tokens are stored hashed, and sessions can be revoked.
- State-changing requests require a CSRF token and a same-origin check.
- Sign-in, registration, verification and payment endpoints are rate limited.
- Administrative access is permission-checked on the server for every admin page and API route, and sensitive actions are written to an audit log.
Changes
If this policy changes materially we will update the date at the top of this page. Questions about it can be raised through customer support.