Spark Tech is a restricted platform for authorised NIN enrolment/verification agents and approved organisations or users with a legitimate identity-verification need. It is not a public NIN lookup service and not a marketplace for NIN or personal information. Signup and access are granted at Spark Tech's discretion based on its requirements, and access found to be misused may be restricted, suspended, or terminated.
This Privacy Policy explains what information Spark Tech collects, why, how it is used and protected, and what is expected of every user. Submitting an application or using Spark Tech means you have read and agree to this policy and Spark Tech's applicable Acceptable Use requirements.
A. Information We May Collect
Depending on your application and your role on the platform, Spark Tech may collect:
- Full name, email address, phone number, and gender
- Residential or business address, where provided or required
- Account credentials (your password is stored as a one-way hash, never in plain text)
- Applicant type, business/organisation name and registration information, claimed professional role, and agent/enrolment certificate or number, where you apply as an agent or business
- Supporting documents you upload to establish eligibility (e.g. an agent/enrolment certificate)
- NIN-related information you submit in the course of using an authorised service (verification, IPE clearance, personalization, etc.)
- Wallet and transaction records (funding, balances, activity history)
- IP address, device/browser information, and login timestamps
- Audit and security logs of platform activity, including administrative actions taken on your account or application
- Support communications you send us
- Information necessary to investigate suspected misuse, fraud, or unauthorised activity
Spark Tech does not claim to collect a category of information above where a particular feature you use does not actually involve it.
B. Why Information Is Collected
Information may be collected and used to:
- Establish the identity of an applicant and determine eligibility for access
- Verify professional/agent status or business legitimacy where claimed
- Evaluate an applicant's stated purpose for requesting access
- Create and administer accounts and provide the authorised services requested
- Maintain security, and prevent fraud, abuse, unauthorised access, and misuse
- Maintain audit records and investigate security incidents
- Comply with applicable legal or contractual obligations
- Communicate with users about their account, application, or support requests
- Improve the security and reliability of the platform
C. Access Is Not Automatic
Submitting an application does not guarantee approval or account creation. Spark Tech may review applications, request additional information or documentation, and approve, reject, or place an application on hold before granting access.
D. Agent/Document Verification
Where an applicant claims to be a NIN enrolment/verification agent or other authorised professional, Spark Tech may request supporting documentation, such as an agent/enrolment certificate or other appropriate evidence, to help verify eligibility and prevent unauthorised access. A submitted document does not by itself guarantee that it establishes authorisation; Spark Tech reviews it as part of the overall application.
Uploaded documents are stored outside the public web server, are never reachable by a direct link, and are only viewable by an authorised administrator reviewing the application. Each time a document is viewed, that access is recorded in Spark Tech's audit log.
E. NIN and Sensitive Personal Information
NIN and related identity information is sensitive personal information and must only be processed for legitimate, authorised purposes. Users must not:
- Search for or look up people without a legitimate, authorised reason
- Sell, publish, or distribute NIN or personal information
- Share NIN or personal information with unauthorised persons
- Scrape or bulk-collect identity information
- Export or redistribute identity information without authorisation
- Use Spark Tech to investigate, stalk, harass, defraud, impersonate, or target another person
- Share their account or login credentials with anyone else
- Allow an unauthorised person to use their account
F. Data Minimisation and Retention
Spark Tech seeks to collect, process, and retain only information reasonably necessary for legitimate operational, security, verification, contractual, or legal purposes, for as long as reasonably necessary for those purposes or as required by applicable law or contractual obligation.
G. Security
Spark Tech uses security controls appropriate to the platform, which include:
- Authentication and session-based access control
- Role-based administrative permissions
- Manual account/application review where enabled
- Audit logging of sensitive administrative actions (approvals, rejections, document access, permission changes)
- Password hashing (passwords are never stored or displayed in plain text)
- Account suspension/restriction where misuse is suspected
- Access restrictions on uploaded documents and sensitive records
- Encrypted transmission (HTTPS/TLS)
No platform can guarantee absolute security, and Spark Tech does not claim its systems are impossible to compromise. Spark Tech maintains and reviews these controls on an ongoing basis.
H. Third-Party and Service-Provider Relationships
Spark Tech relies on authorised upstream identity-verification providers, payment processors, and infrastructure/service providers to deliver its authorised functionality. Information may be processed through those services where necessary to provide the specific service requested. Spark Tech operates subject to applicable laws, contractual requirements, and the terms of its authorised service/provider arrangements. Nothing on this website or in this policy should be interpreted as a representation of government endorsement or authorisation beyond the specific arrangements and authorisations applicable to Spark Tech.
Partners integrating with Spark Tech's API are shown additional service-specific terms directly on that page once logged in; this policy does not repeat them here.
I. User Responsibilities
By using Spark Tech, you agree that you will:
- Provide accurate information during application and account registration
- Provide truthful information about your identity and professional status
- Not impersonate another person or organisation
- Not share your Spark Tech account or credentials
- Use the platform only for legitimate and authorised purposes
- Not search for or access identity information without a legitimate reason and appropriate authority
- Not sell, publish, distribute, scrape, harvest, or otherwise misuse identity information
- Not attempt to bypass Spark Tech's access controls
- Not attempt to access another user's account
- Not use automated tools to abuse, scrape, overload, or circumvent the platform
- Immediately report suspected account compromise or unauthorised access
- Comply with applicable laws and contractual requirements
- Protect personal information obtained through the platform
- Not use information obtained through Spark Tech for harassment, fraud, impersonation, discrimination, stalking, or other unlawful purposes
- Cooperate with reasonable security or compliance investigations
J. Suspension and Termination
Spark Tech may suspend, restrict, or terminate access where there is suspected misuse, unauthorised access, false information, credential sharing, suspicious activity, or a violation of this Privacy Policy, Spark Tech's Acceptable Use requirements, applicable contractual requirements, or a legal or security concern.
K. Changes to This Policy
Spark Tech may update this policy from time to time. Material changes will be reflected by an updated "Last Updated" date and policy version on this page.