Legal Document
Privacy Policy
Pagora respects your privacy and is committed to protecting your personal and business data. This policy explains how we collect, use, and safeguard your information across our platform.
Effective date: March 17, 2025
1. Overview
Pagora ("Pagora", "we", "us", or "our") operates a multi-tenant workspace platform that lets businesses create, manage, and scale websites ,including online stores, service platforms, shipping operations, and personal brand sites. This Privacy Policy explains what personal data we collect across our marketing site and product dashboard, why we collect it, how it's shared, and the choices and rights available to you.
This Policy applies to visitors of usepagora.com, workspace owners and team members ("Workspace Users"), and end customers who interact with sites built on Pagora ("Site Visitors"). Where a Workspace User collects data from their own Site Visitors through a site they've built, that Workspace User acts as the data controller for that data, and Pagora acts as a processor on their behalf, their own privacy policy governs that relationship.
2. Information We Collect
We collect what's needed to run your workspace and sites: your account details, the content you publish, payment information (handled by our payment processor, never stored by us), and basic usage data so the dashboard keeps getting better.
| Category | Examples | Source |
|---|---|---|
| Account & Workspace | Name, email, password hash, role, workspace name, team members | Provided by you |
| Site & Content | Pages, product catalogues, media, domain settings, theme configuration | Provided by you |
| Payment | Billing address, plan tier, last 4 card digits, transaction history | Our payment processor |
| Usage & Device | IP address, browser type, pages viewed, feature usage, crash logs | Collected automatically |
| Communications | Support tickets, emails, call notes, survey responses | Provided by you |
We do not collect more than is necessary to provide the Service, and we never ask for sensitive categories of data (such as government IDs or health information) unless a specific feature you opt into requires it, in which case we'll tell you at the point of collection.
3. How We Use Your Information
We tell you at the point of data collection what we use it for, and we only process your data for the reasons stated below:
| Purpose | Examples | Legal Basis |
|---|---|---|
| Provide the Service | Hosting sites, rendering dashboards, syncing teams | Contract |
| Billing & Invoicing | Processing subscriptions, sending receipts | Contract |
| Security & Fraud Prevention | Detecting suspicious logins, rate-limiting abuse | Legitimate interest |
| Product Improvement | Understanding which features are used, fixing bugs | Legitimate interest |
| Support & Communication | Responding to tickets, sending service notices | Contract |
| Product updates & tips | Emails about our own similar products and services, sent to customers | Legitimate interest (soft opt-in) — opt out any time |
| Marketing to non-customers | Newsletters and campaigns where you are not a Pagora customer | Consent |
We never use the content of your sites or your customer data to train third-party advertising models, and we don't sell personal information to data brokers.
4. Data Sharing
We share personal data only with the following categories of recipients, and only as needed to operate the Service:
- Payment processors — to process subscription charges and payouts. We never store full card numbers ourselves.
- Infrastructure & hosting providers — cloud compute, storage, CDN, and email delivery vendors that keep Pagora online.
- Analytics & product tooling — privacy-conscious analytics tools used to understand aggregate product usage.
- Professional advisors — auditors, lawyers, and accountants, bound by confidentiality.
- Legal & regulatory authorities — only where required by law, court order, or to protect the rights and safety of our users.
- Business transfers — in the event of a merger, acquisition, or asset sale, with notice provided beforehand.
We do not sell or rent your personal information to third parties for their own marketing purposes.
6. Data Security
Security is built into the platform, not bolted on. Production data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to customer data is role-based and logged, and every workspace is logically isolated from every other workspace.
7. International Data Transfers
Pagora is operated from Nigeria and serves customers across Africa and beyond. Some of the infrastructure and service providers we rely on process data outside Nigeria, so your personal data may be transferred to and stored in other countries.
Where we transfer personal data outside Nigeria, we do so on a basis permitted by the Nigeria Data Protection Act 2023 (NDPA) — including transfers to a country the Nigeria Data Protection Commission recognises as providing an adequate level of protection, transfers made under contractual terms that oblige the recipient to protect the data to the standard the NDPA requires, or, where neither applies, transfers you have specifically consented to after being told of the risk. We hold our infrastructure partners to the same security standards described in Data Security above.
If you are in another African country, your own national data protection law may apply alongside the NDPA — for example the Data Protection Act in Kenya or Ghana, or POPIA in South Africa. Where it does, we handle your data to whichever standard gives you the greater protection.
8. Data Retention
We keep data only as long as we need it to provide the Service or meet our legal obligations:
| Data Type | Retention Period | Why |
|---|---|---|
| Account & workspace data | Duration of your account + 30 days | Recovery window after account deletion |
| Published site content | Until removed by you or account closure | You control your own content |
| Billing records | 7 years | Tax & accounting obligations |
| Support tickets | 3 years | Quality & dispute resolution |
| Server & security logs | 12 months | Fraud detection, incident response |
9. Your Rights
Under the Nigeria Data Protection Act 2023, and under your own national law if you are elsewhere in Africa, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data, subject to legal retention requirements.
- Export your data in a portable format.
- Object or restrict certain processing, including marketing.
- Withdraw consent at any time where processing is based on consent.
Exercise a privacy right
Get in touch and we'll respond within 30 days, or sooner where the law requires it.
If you are not satisfied with how we handle your request, you can complain to the Nigeria Data Protection Commission (NDPC), which regulates data protection in Nigeria. If you are in another country, you may complain to your own national data protection authority instead.
Submit a Request10. Children's Privacy
Pagora is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18, which is how a child is defined under Nigerian law. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Policy as our Service evolves or as laws change. Material changes will be announced via email or an in-product notice at least 14 days before they take effect. The "Last Updated" date at the top of this page always reflects the current version.
12. Contact Us
If you have questions regarding this Policy or about the privacy practices of Pagora, please contact us by email at support@usepagora.com.
Pagora LTD
Ugbowo, Benin City
Edo State, Nigeria
