Privacy Policy
Effective: August 2026 - Last reviewed: 28 August 2026
This Privacy Policy explains how My Access Plug (“MAP,” “MyAccessPlug,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you use myaccessplug.com and any related application, widget, or API (together, the “Platform”), wherever in the world you access it, as a ticket buyer, event attendee, event organizer, or visitor (“you”). MAP is headquartered in Nigeria and is expanding across Africa and internationally. This Policy is designed to meet the requirements of the Nigeria Data Protection Act, 2023 (“NDPA”) as our baseline standard, while also addressing the data protection laws of other African jurisdictions in which we operate or plan to operate, the EU/UK General Data Protection Regulation (“GDPR”), and the US California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), to the extent they apply to you. Where a specific law grants you rights beyond what is described generally in this Policy, Section 12 sets out those additional, region-specific rights. By using the Platform, you acknowledge this Policy. We do not require you to accept marketing or optional cookies to use core features of the Platform.
1. Who This Policy Covers and Our Role
This Policy applies to:
- Ticket buyers and event attendees who create an account or purchase tickets on the Platform, in Nigeria or any other country;
- Event organizers, promoters, and their staff who list and manage events, sell tickets, or check attendees in through MAP, wherever their events take place;
- Visitors who browse the Platform without transacting.
For account data, payment facilitation, platform analytics, and security, MAP acts as a data controller (or, in GDPR terminology, “controller”). For attendee data collected specifically on behalf of an event organizer (for example, guest lists, RSVP details, or check-in records for that organizer's event), MAP acts as a data processor, and the organizer is the data controller responsible for that data and for its own compliance in the country where its event is held.
2. Information We Collect
2.1 Information you provide directly
- Account details: full name, email address, phone number, country of residence, password, and (for organizers) business/organization name, applicable business registration number, and settlement bank or mobile-money details.
- Ticket purchase details: billing name, email, phone number, and ticket selections.
- Event listing details: event name, description, venue/country, images, and pricing (for organizers).
- Identity/KYC documents where required for organizer verification and payout release (e.g., government-issued ID, proof of address, tax or business identification number, where mandated by our payment partners or by law in the relevant country).
- Communications you send us, including support tickets, emails, and survey responses.
2.2 Information collected automatically
- Device and usage data: IP address, browser type, device identifiers, operating system, pages viewed, referring URLs, and timestamps.
- Cookies and similar technologies (see Section 6).
- Approximate location derived from IP address, used for fraud prevention, currency selection, and localization.
2.3 Information from third parties
- Payment confirmation data from payment gateways/processors (e.g., Paystack, Flutterwave, or, as we expand, other regional or global processors). MAP does not store full card numbers, CVV, or PINs; these are handled directly by our PCI-DSS-compliant payment partners.
- Data from social login providers, if you register or log in via a third-party account.
- Fraud and risk-scoring signals from third-party verification providers.
3. How We Use Your Information
- Create and manage your account and process ticket purchases or event listings;
- Generate and deliver e-tickets, QR/barcodes, and check-in credentials;
- Process payments and payouts through licensed payment service providers, in local currency where available;
- Communicate essential service updates (purchase confirmations, event changes, cancellations, refunds);
- Send marketing communications about events or MAP features, where you have opted in or where we have a legitimate interest recognized by applicable law (with an unsubscribe option in every message);
- Detect, investigate, and prevent fraud, ticket touting/scalping abuse, and unauthorized access;
- Analyze Platform usage to improve features, performance, and security, including as we launch in new countries;
- Comply with applicable laws, regulatory requests, and lawful court orders in the countries where we operate.
We do not sell personal data to third parties for their own independent marketing purposes.
4. Legal Basis for Processing
- Performance of a contract - to create your account, process ticket purchases, and deliver tickets;
- Consent - for marketing communications, optional cookies, and certain organizer data-sharing features, which you may withdraw at any time;
- Legal obligation - to comply with tax, anti-fraud, anti-money-laundering, and regulatory requirements in the relevant country;
- Legitimate interests - to secure the Platform, prevent fraud, improve our services, and enforce our Terms and Conditions, provided this does not override your fundamental rights;
- Vital interests - where processing is necessary to protect your vital interests or those of another person.
5. How We Share Information
We disclose personal data only as reasonably necessary, and always subject to appropriate safeguards:
- Event organizers: attendee name, contact details, ticket type, and check-in status for events they list, so they can operate their event and comply with local venue/safety requirements;
- Payment service providers and financial institutions: to process payments, payouts, refunds, and to meet Know-Your-Customer (KYC) and anti-money-laundering obligations, which may vary by country;
- Service providers/processors: hosting, cloud storage, email/SMS delivery, analytics, and customer support tools, bound by confidentiality and data processing agreements;
- Legal and regulatory authorities: where required by law, court order, or to protect the rights, property, or safety of MAP, our users, or the public, in any country where we operate;
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of your data under this Policy;
- With your consent: for other purposes where you have given explicit consent.
6. Cookies and Tracking Technologies
We use strictly necessary cookies (for login, checkout, and security), performance/analytics cookies, and, where you consent or as permitted by local law, marketing cookies. You can manage cookie preferences through your browser settings or our cookie banner. Disabling strictly necessary cookies may prevent you from completing a purchase. Users in jurisdictions requiring opt-in consent for non-essential cookies (including the EU/UK) will be presented with a consent banner before such cookies are set.
7. International and Cross-Border Data Transfers
As MAP operates across Nigeria, other African countries, and internationally, your personal data may be transferred to, stored, and processed in a country other than the one in which you are located, including countries that may have different data protection laws. Where we transfer personal data across borders, we ensure appropriate safeguards are in place, which may include:
- Verifying that the receiving country has been assessed as providing an adequate level of data protection;
- Using standard contractual clauses, binding corporate rules, or equivalent mechanisms recognized under the NDPA, GDPR, or the law of the relevant African jurisdiction;
- Ensuring our service providers are contractually bound to protect your data to a standard consistent with this Policy, regardless of where they are located.
Please contact us if you require further information on the specific safeguards used for a cross-border transfer affecting you.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including satisfying legal, accounting, tax, or reporting requirements applicable in the relevant country. As a general guide:
- Account and transaction records: retained for 6 (six) years from your last transaction or account closure, to enable resolution of disputes and to meet standard limitation periods;
- Financial and payment records: retained for up to 6 (six) years to meet tax and financial reporting obligations;
- Data relevant to ongoing regulatory investigations or active legal proceedings: retained until the matter is fully and finally resolved;
- Data held for fraud prevention and platform security: retained for up to 10 (ten) years where reasonably necessary to protect the integrity of the Platform and the safety of its users;
- Marketing data: retained until you withdraw consent or unsubscribe.
Where a specific country's law mandates a shorter or longer retention period for a category of data, we apply that country's requirement for data subject to it. At the expiry of the applicable retention period, your personal data is securely deleted or anonymized.
9. Data Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption of data in transit (TLS) and at rest, role-based access controls limiting access to authorized personnel on a need-to-know basis, routine security assessments and vulnerability testing, and staff training on data handling. Card payment data is handled by PCI-DSS-compliant processors and is never stored in full on MAP's own servers. No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and must notify us immediately if you believe your account has been compromised.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, MAP will:
- Notify the Nigeria Data Protection Commission (NDPC) within 72 (seventy-two) hours of becoming aware of the breach, where required by the NDPA;
- Notify the relevant supervisory authority in any other country where the breach requires notification under local law (for example, within 72 hours under the GDPR, where applicable);
- Notify affected users directly, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms, describing the nature of the breach, its likely consequences, and the steps we are taking to address it;
- Maintain an internal record of all data breaches, including those below the regulatory notification threshold.
11. Your General Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your data, subject to legal retention obligations;
- Object to or restrict certain processing, including direct marketing;
- Withdraw consent at any time, without affecting processing carried out before withdrawal;
- Request data portability, where technically feasible;
- Not be subject to decisions based solely on automated processing, including profiling, that significantly affect you, except where necessary for a contract, based on your explicit consent, or authorized by law;
- Lodge a complaint with the data protection authority in your country of residence.
You may exercise these rights by contacting us using the details in Section 17. We may need to verify your identity before actioning a request.
12. Region-Specific Rights
12.1 Nigeria
If you are in Nigeria, the rights in Section 11 are given to you under the NDPA. You may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
12.2 Other African Jurisdictions
As MAP expands into other African countries, we will comply with the applicable local data protection law in each country of operation - for example, Kenya's Data Protection Act, 2019; South Africa's Protection of Personal Information Act (POPIA); Ghana's Data Protection Act, 2012; and equivalent laws elsewhere on the continent. Where a local law grants rights or protections beyond those in Section 11, or designates a specific supervisory authority (such as Kenya's Office of the Data Protection Commissioner or South Africa's Information Regulator), those additional rights apply to you and you may lodge a complaint with that authority.
12.3 European Economic Area and United Kingdom (GDPR / UK GDPR)
If you are in the EEA or UK, we process your personal data as described in this Policy in reliance on the legal bases set out in Section 4, interpreted consistently with Article 6 GDPR. You have the rights described in Section 11, and you may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office (ICO) if you are in the UK. MAP has not yet appointed an EU or UK representative; where this becomes required as we expand into those markets, their contact details will be published here.
12.4 California, United States (CCPA/CPRA)
If you are a California resident, you additionally have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share, and to request a copy of that information;
- Delete personal information we hold about you, subject to certain exceptions;
- Correct inaccurate personal information;
- Opt out of the “sale” or “sharing” of your personal information. MAP does not sell personal information for money and does not share it for cross-context behavioral advertising;
- Limit the use of sensitive personal information;
- Not receive discriminatory treatment for exercising any of these rights.
12.5 Other Jurisdictions
If you are located in a country not specifically addressed above, MAP applies the general rights and protections described in Section 11 as a minimum standard, and will comply with any additional mandatory requirements of your local law that cannot be excluded by this Policy.
13. Children's Privacy
The Platform is not directed at children under the age of 18 (or the age of majority in your country, if higher). We do not knowingly collect personal data directly from children without appropriate parental/guardian consent. Where an event is age-restricted, the ticket buyer is responsible for compliance with the organizer's age policy. If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly. Parents or guardians who believe their child has provided personal data without consent may contact us using the details in Section 17.
14. Marketing Communications
Where you have opted in, or where local law permits it on a legitimate-interest basis, we may send you updates about events, promotions, or new MAP features by email, SMS, or push notification. You can opt out at any time via the unsubscribe link, in-app settings, or by contacting us, and this will not affect essential transactional messages (e.g., purchase receipts, event-change notices).
15. Third-Party Websites
The Platform may contain links to event organizer websites, social media pages, or third-party payment pages. We are not responsible for the privacy practices of third-party sites, and encourage you to review their privacy policies separately.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our expansion into new countries, or legal requirements. We will post the revised version with an updated “Last Reviewed” date and, where changes are material, provide reasonable prior notice (e.g., by email or a Platform notice) before they take effect.
17. Contact Us / Data Protection Officer
For privacy questions, requests, or complaints, contact:
- Data Protection Officer: Olamilekan Bamidele ([email protected])
- Support email: [email protected]
- Company: My Access Plug (“MAP”), RC: 9770113
- Address: Plot 13, Oluwole Omole Street, Ikeja, Lagos
If you are not satisfied with our response, you may lodge a complaint with the data protection authority in your country of residence, or with the NDPC at ndpc.gov.ng if you are in Nigeria.