Privacy policy

How we handle personal data

Last updated 28 September 2026

Lenders trust Slice with their clients’ details, so we keep this short and plain. Questions: info@slicebyues.com.

1. Who we are and what this covers

Slice is loan management software for Nigerian microfinance banks, MFIs and cooperatives (“lenders”). This policy explains how we handle personal data on our website (slicebyues.com) and in the Slice platform, in line with the Nigeria Data Protection Act 2023 (NDPA).

We play two roles. For our website visitors, people who request a demo, and our own contacts, we are the data controller: we decide how that data is used. For the borrowers, guarantors and other people whose details a lender records in Slice, the lender is the data controller and we are its data processor: we store and process that data only to provide Slice to the lender, on its instructions.

2. What we collect

On our website

  • Demo requests: your name, work email and, if you give them, your phone number, organisation and message.
  • Career introductions: your name, email, phone if you give it, how you describe yourself, why you’d like to join Slice, and any LinkedIn, portfolio or GitHub links.
  • Anything you send us by email.
  • With your consent only: analytics cookies that record how the website is used (pages visited, device and approximate location). See “Cookies and browser storage”.

For people who sign in to Slice (lender staff)

  • Account details: name, work email, phone, branch, role and staff details the lender records.
  • Security records: a hash of your password (never the password itself), sign-in sessions with the device and IP address used, and failed sign-in attempts.
  • An audit trail of actions taken in Slice, with the time, IP address and device, so lenders can see who did what.

For a lender’s clients and guarantors (processed on the lender’s behalf)

  • Identity and contact details: name, date of birth, gender, phone, email, address, next of kin, and BVN, NIN or other ID numbers.
  • Photos and ID documents the lender uploads.
  • Business and financial details, loans, repayments and the related accounting records.
  • Identity check results, when the lender uses identity verification (see below).

3. BVN and NIN identity checks

Lenders can choose to verify a client’s or guarantor’s BVN or NIN. A check only runs after the lender’s staff confirm that the person has agreed to it.

  • The name, date of birth and ID number are sent to our identity verification provider, which compares them with the official BVN or NIN record.
  • For BVNs, the provider only tells us whether the details match. For NINs, the provider returns the record, which we compare automatically and then discard, including any photo.
  • We keep only the result (matched or not, and which details differed), the last four digits of the ID, who ran the check and when.

4. How we use personal data, and why we may

  • To provide Slice to lenders under our contract with them, including sign-in, security, support and backups (contract).
  • To reply to demo requests and messages, and to keep in touch with interested lenders (legitimate interests, or steps before entering a contract).
  • To consider you for roles at Slice when you introduce yourself on our Careers page (consent, which you give on the form).
  • To keep Slice secure, prevent fraud and investigate misuse, for example through sign-in protection and the audit trail (legitimate interests).
  • To understand and improve our website, only if you accept analytics cookies (consent).
  • To run identity checks when the lender has the person’s agreement (consent, collected by the lender).
  • To meet legal and regulatory obligations (legal obligation).

We do not sell personal data, and we do not use borrowers’ data for our own marketing or to build credit scores.

5. Who we share it with

We use a small number of service providers, each only for its job and under contract:

  • Cloud hosting in Nigeria for the Slice platform, its database and uploaded files.
  • A content delivery network that serves our website’s pages (it does not receive lenders’ or borrowers’ data).
  • An email delivery service that sends sign-in codes and notifications, and so processes the recipient’s email address and the message.
  • Our identity verification provider, only for checks a lender runs.
  • Google Analytics, only if you accept analytics cookies.

We may also disclose data where the law requires it, for example to a regulator or court. A lender’s data is never shared with another lender: each lender’s data is kept separate at the database level.

6. Where it is stored

The Slice platform, including lenders’ and borrowers’ data, runs on servers in Nigeria. Some of our providers (website delivery, email delivery and analytics) may process limited data, such as email addresses or website usage, outside Nigeria. Where they do, we rely on the safeguards the NDPA provides for such transfers, such as the provider’s contractual commitments to protect the data.

7. How long we keep it

  • Lenders’ and borrowers’ data: for as long as the lender uses Slice, and as the lender instructs. Lenders set their own retention in line with the rules that apply to them.
  • Backups: kept for 14 days, then deleted.
  • Password reset codes expire after 10 minutes; sign-in sessions after 7 days without use.
  • Career introductions: 12 months, then deleted automatically. You can ask us to delete yours sooner.
  • Demo requests and messages: for as long as we are in conversation with you, and then only as long as needed for our records.

8. How we protect it

  • Encrypted connections (HTTPS) everywhere.
  • Passwords stored only as secure hashes, temporary account locks after repeated failed sign-ins, and sessions you can see and sign out of.
  • Each lender’s data kept separate by the database itself, and role-based permissions within each lender.
  • An audit trail of actions, and nightly backups.

If a breach affecting personal data happens, we will inform the affected lenders and, where the law requires it, the Nigeria Data Protection Commission.

9. Cookies and browser storage

  • Needed to work: when you sign in, your browser stores your sign-in session; it also remembers your organisation’s address, your cookie choice, and unsent forms (so a dropped connection doesn’t lose your work). Signing out clears the session and saved client drafts.
  • Analytics (Google Analytics): only set if you choose “Accept”. You can change your choice at any time under “Cookie settings” at the bottom of any page.

10. Your rights

Under the NDPA you can ask to access your personal data, correct it, delete it, restrict or object to how it is used, receive it in a portable form, and withdraw consent at any time (without affecting what was done before).

  • For data we control (website, demo requests, career introductions, your messages): email us at info@slicebyues.com. We will respond within the time the law allows.
  • If you are a client or guarantor of a lender that uses Slice: contact that lender, which controls your data. We will help the lender respond.
  • You can also complain to the Nigeria Data Protection Commission (NDPC).

11. Children

Our website and Slice are for businesses and are not directed at children under 18.

12. Changes and contact

We will update this policy when what we do changes, and show the date of the latest version at the top.

Questions or requests about privacy: info@slicebyues.com.