Who is responsible for your data?
Inkora Beauty Supplies is responsible for the Inkora storefront processing described in this policy, except where a service provider acts as an independent controller for its own processing.
This notice explains how Inkora Beauty Supplies collects, uses, shares, protects, retains, and manages personal data across the storefront and customer account.
Inkora Beauty Supplies is responsible for the Inkora storefront processing described in this policy, except where a service provider acts as an independent controller for its own processing.
Send a clear request identifying the relevant account, order, or processing activity. Inkora may verify identity before disclosing, correcting, exporting, restricting, or deleting information.
Submit a Privacy RequestThe exact information depends on the features used and the transaction or enquiry involved.
Examples: Name, email address, telephone number, account UUID, customer number, and other contact details supplied through registration, checkout, or support.
Used for: Account creation, identity and ownership checks, communication, order fulfilment, customer support, and transaction records.
Examples: Billing and shipping addresses, recipient details, delivery instructions, city, state, country, postcode, courier, tracking, shipment, and delivery records.
Used for: Shipping eligibility, rate calculation, fulfilment, courier handover, tracking, delivery confirmation, failed-delivery handling, and returns.
Examples: Cart contents, products, variants, quantities, prices, discounts, coupons, taxes, shipping method, order status, notes, invoice, and fulfilment information.
Used for: Checkout, stock reservation, transaction fulfilment, customer history, accounting, support, returns, and reporting.
Examples: Payment method, provider, amount, currency, payment status, transaction reference, gateway reference, payment attempt, receipt, refund, and reconciliation information.
Used for: Payment initiation, verification, fraud and error checks, receipts, refunds, reconciliation, accounting, disputes, and financial records.
Examples: Return reason, affected items and quantities, requested resolution, written details, evidence files, courier information, inspection findings, approved amount, refund, replacement, or exchange records.
Used for: Eligibility review, authorisation, logistics, inspection, resolution, fraud prevention, quality control, and customer redress.
Examples: Contact enquiries, email logs, notification records, customer notes, complaint details, support references, and related correspondence.
Used for: Responding to enquiries, customer service, complaint resolution, delivery communication, service records, and quality improvement.
Examples: Notification categories, delivery channels, minimum priority, quiet hours, digest frequency, marketing preference, and read or archived status.
Used for: Delivering requested alerts, respecting communication choices, reducing unnecessary messages, and maintaining notification history.
Examples: IP address, user agent, device or browser information, session identifiers, login attempts, audit logs, timestamps, request metadata, security events, and error records.
Used for: Authentication, session management, service operation, abuse prevention, troubleshooting, security monitoring, audit, and incident investigation.
A processing activity may rely on more than one lawful basis where the circumstances support it.
Create and maintain customer accounts, manage carts and addresses, place and fulfil orders, process supported payments, provide delivery, issue documents, and handle returns and refunds.
Maintain required transaction, tax, accounting, payment, complaint, security, and compliance records and respond to lawful requests.
Prevent fraud and misuse, secure accounts, reconcile payments, protect stock and systems, investigate incidents, maintain logs, improve reliability, and establish or defend legal claims.
Send promotional messages, offers, newsletters, or personalised marketing where enabled. Customers may opt out through available preferences or the message instructions.
Record, investigate, communicate about, and resolve product, account, payment, delivery, return, refund, privacy, or other support matters.
Inkora shares personal data only where reasonably required for the relevant service, legal duty, protected interest, or user choice.
Paystack and other enabled payment or banking providers may receive transaction data required to initialise, verify, reconcile, refund, or investigate a payment.
Recipient, address, telephone, parcel, tracking, order, delivery, collection, and return information may be shared to perform shipping and logistics services.
Email, SMS, WhatsApp, push, or related service providers may process destination and message-delivery information where those channels are configured.
Hosting, storage, backup, security, maintenance, support, monitoring, and software providers may process data only as required to provide their services.
Authorised employees, contractors, accountants, auditors, insurers, legal advisers, and consultants may access information where necessary and subject to confidentiality and access controls.
Information may be disclosed where required by law, court order, regulatory request, law-enforcement process, tax requirement, or to protect rights, safety, property, and the integrity of the service.
Rights are applied according to the request, lawful basis, applicable exceptions, and identity-verification needs.
Receive clear information about the collection and use of personal data.
Request confirmation and access to personal data that Inkora processes about you.
Request correction of inaccurate data or completion of incomplete data.
Request deletion where the applicable requirements are met and retention is not otherwise required.
Request restriction of processing in circumstances recognised by applicable law.
Object to certain processing, including eligible direct-marketing or legitimate-interest processing.
Request eligible data in a structured, commonly used, machine-readable form or transmission where applicable.
Withdraw consent for future processing where consent is the lawful basis, without affecting earlier lawful processing.
Request appropriate human intervention where a significant decision is made solely by automated means and the right applies.
Raise a privacy concern with Inkora and lodge a complaint with the Nigeria Data Protection Commission where appropriate.
This privacy policy applies to personal data processed through the Inkora Beauty Supplies website, storefront, customer account, checkout, payment, order, delivery, notification, contact, return, refund, and related support workflows.
Inkora Beauty Supplies determines why and how the personal data described in this notice is processed for the Inkora storefront and is the relevant data controller except where another organisation acts as an independent controller for its own service.
A third-party website, payment page, courier portal, social platform, or other external service may have its own privacy notice. Review that notice before submitting information to the third party.
We collect information directly when you register, sign in, update a profile, save an address, add products to a cart, place an order, initialise or verify payment, contact support, change notification preferences, request a return, upload evidence, submit tracking details, or otherwise interact with the storefront.
We may receive information from payment providers, couriers, delivery personnel, communication providers, fraud or security services, business advisers, suppliers, administrators, and other persons involved in an order or support request.
Technical information may be created automatically when the service records sessions, authentication, requests, security events, timestamps, device or browser details, errors, audit events, and service activity.
Do not provide personal data about another person unless you have authority to do so and the information is necessary for the relevant delivery, collection, support, or transaction.
Inkora uses hosted or provider-controlled payment flows such as Paystack for supported online payments. Payment providers process the information entered on their payment interface under their own responsibilities and privacy terms.
Inkora records payment and reconciliation information such as amount, currency, method, status, transaction reference, gateway reference, payment channel, receipt, refund, and verification metadata.
Inkora does not intentionally request or store your complete card number, card PIN, CVV, bank password, Paystack secret key, or one-time password in the storefront application.
Never send payment credentials through the contact form, customer notes, return evidence, email, chat, or social media.
The lawful basis depends on the activity and may include performance of a contract, steps requested before a contract, compliance with legal obligations, legitimate interests balanced against individual rights, consent, or another basis recognised by applicable law.
Where consent is used, it should be specific enough for the relevant purpose and may be withdrawn for future processing. Withdrawing consent does not invalidate processing that was lawful before withdrawal.
Where legitimate interests are used, Inkora considers necessity, proportionality, reasonable expectations, potential effects on individuals, and available safeguards.
Some information is required to create an account, place or fulfil an order, verify payment, deliver products, process a return, issue a refund, meet a legal obligation, or protect the service. Refusing required information may prevent the related service from being provided.
We do not disclose personal data merely because it may be commercially useful to another person. Disclosure must relate to the service, a lawful instruction, a legal requirement, a protected business purpose, or the individual’s choice.
Service providers should receive only the information reasonably required for their role and should be subject to appropriate contractual, confidentiality, security, or legal obligations.
Where a business reorganisation, financing, sale, merger, acquisition, insolvency, or transfer affects the storefront, relevant data may be reviewed or transferred subject to lawful safeguards and notice where required.
Aggregated or de-identified information that does not reasonably identify an individual may be used for reporting, planning, analysis, and service improvement.
Some payment, hosting, email, messaging, security, analytics, backup, or technical providers may operate infrastructure or personnel outside Nigeria.
Where personal data is transferred internationally, Inkora will seek to use a lawful transfer mechanism and safeguards appropriate to the destination, recipient, purpose, sensitivity, and applicable data-protection requirements.
International processing may be subject to lawful access rules in the destination country. Inkora evaluates providers and limits disclosures to what is reasonably required for the service.
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide and document the transaction, maintain security and audit records, resolve disputes, enforce agreements, meet accounting or legal obligations, and preserve legitimate business records. Different categories may therefore have different retention periods.
Account deletion does not necessarily erase transaction, payment, tax, invoice, refund, audit, security, complaint, or dispute records that Inkora is required or reasonably entitled to retain.
When data is no longer required, it may be deleted, anonymised, securely destroyed, or isolated from ordinary use. Backup copies may remain for a limited period until overwritten or securely removed under the backup cycle.
A valid legal hold, investigation, dispute, chargeback, fraud concern, regulatory request, or security incident may require relevant information to be preserved for longer.
Inkora uses reasonable administrative, technical, and organisational safeguards appropriate to the nature of the service and the personal data processed.
Safeguards may include access controls, customer ownership checks, password hashing, session protections, CSRF controls, server-side validation, audit logging, payment signature verification, secure provider connections, backups, monitoring, and restricted document access.
No internet transmission, device, application, or storage method can be guaranteed completely secure. Customers should use unique passwords, protect reset links and devices, sign out on shared systems, and report suspicious activity promptly.
Where a personal-data breach creates a risk that requires notification under applicable law, Inkora will take reasonable steps to investigate, contain, document, remediate, and notify the appropriate authority or affected individuals as required.
The storefront uses essential session, authentication, cart, security, and preference technologies required for the site to function. Optional analytics, marketing, or personalisation technologies should operate only where they are enabled and supported by an appropriate lawful basis or user choice.
Essential technologies may remember a cart, maintain a login session, protect forms, prevent abuse, preserve user choices, and support the requested features. Blocking them may cause parts of the storefront to stop working.
Where optional analytics or marketing technologies are introduced, the storefront should provide information and controls appropriate to the technology and applicable requirements.
Browser settings may allow cookies to be blocked or deleted. The effect depends on the browser and the type of technology used.
Operational messages concerning account security, orders, payments, deliveries, returns, refunds, support, or important service changes may be necessary to provide the service and may be treated differently from optional marketing.
Optional marketing may be controlled through available account preferences, an unsubscribe instruction, or a direct request to Inkora.
Opting out of marketing does not prevent necessary transactional, security, legal, or customer-service communications.
Notification preferences may control channel, category, priority, frequency, digest timing, quiet hours, and other available communication choices.
The storefront uses automated rules to validate stock, cart totals, coupons, shipping eligibility, taxes, payment references, customer ownership, return quantities, security controls, and other transaction requirements.
These operational checks help prevent invalid, duplicate, unsafe, unauthorised, or inconsistent transactions.
Inkora does not intend to make a decision producing legal or similarly significant effects solely through automated processing without providing applicable information, safeguards, and human review where required.
The storefront is intended for persons who can lawfully create an account and enter the relevant transaction. Where personal data relating to a child is processed, Inkora may require appropriate parental, guardian, or other lawful authorisation and may apply additional safeguards.
A parent, guardian, or authorised adult should contact Inkora where a child has provided personal data without appropriate authority or where correction, restriction, or deletion should be considered.
Inkora may retain limited information where necessary to investigate the request, comply with law, prevent repeated collection, or protect the child and the service.
Available rights depend on the circumstances, lawful basis, applicable exemptions, identity verification, and the nature of the request.
Inkora may ask for information reasonably necessary to confirm identity, authority, account ownership, scope, or the personal data involved before acting on a request.
A request may be refused, limited, or delayed where permitted by law, including where it conflicts with another person’s rights, legal retention, security, fraud prevention, privilege, litigation, or a valid regulatory requirement.
Inkora will not ordinarily charge for a reasonable rights request, but applicable law may permit a fee or refusal for requests that are manifestly unfounded, excessive, repetitive, or abusive.
Send a privacy request through the contact page or the privacy email shown below. Describe the request, identify the relevant account or transaction, and avoid sending unnecessary sensitive information.
Inkora will acknowledge and assess the request, verify identity where appropriate, search relevant systems, consider legal requirements and third-party rights, and communicate the outcome or next step.
You may lodge a complaint with the Nigeria Data Protection Commission if you believe your personal data has been processed contrary to applicable data-protection law.
A privacy concern may also involve a consumer, payment, courier, security, employment, or contractual issue that requires coordination with another responsible team or organisation.
Inkora may update this privacy policy to reflect changes in the storefront, processing activities, service providers, security practices, legal requirements, or regulatory guidance.
The effective date at the top of the page identifies the current published version. Material changes may also be communicated through the storefront, account notifications, or another appropriate channel.
Continued use of the service after an update does not replace any consent or other lawful basis that may be required for a new processing activity.
Contact Inkora with a clear description of the privacy request. Do not send passwords, PINs, OTPs, complete card numbers, CVV codes, or payment secret keys.