Privacy Policy
Last updated: 5 September 2026
CicilyHomes Estates ("CicilyHomes", "we", "us", "our") operates a rental marketplace connecting landlords and tenants in Abuja, Nigeria, at cicilyhomes.com. This policy explains what personal data we collect through the platform, why we collect it, how we protect it, and the rights you have over it under the Nigeria Data Protection Act (NDPA) 2023 and applicable regulation.
By creating an account or otherwise using CicilyHomes, you acknowledge this policy. If you do not agree with it, please do not use the platform.
1. Information we collect
Account information. Name, email address, phone number, area of residence, and a password (see Section 3 on how passwords are stored).
Identity verification data (landlords and tenants). Your National Identification Number (NIN), submitted so our team can manually verify your identity before a listing goes live or a lease is signed.
Financial information (landlords). Bank account number and bank name, used solely to receive rent payments collected on your behalf and to auto-detect the account holder name for your confirmation.
Property and verification documents. Property photos, utility bills, and any other document you upload to support a listing or verification review.
Payment data. Rent payments are processed by a third-party payment processor (Stripe, Paystack, or Flutterwave, depending on deployment). We store the payment amount, status, and a provider reference — we do not store your full card or bank-transfer credentials ourselves.
Usage and device data. IP address, browser/user-agent, login timestamps, and security-relevant events (failed logins, password resets, 2FA changes), kept for account security and fraud prevention.
2. Why we collect it
- To create and secure your account, and to tell landlords, tenants, and administrators apart so each only sees what they're entitled to (see our Terms of Service on account roles).
- To manually verify landlord identity and property documents before a listing is published — see "How verification works" on our About page for exactly what this does and does not check today.
- To process rent payments and route them to the correct landlord bank account.
- To detect and prevent fraud, account takeover, and abuse (rate limiting, lockouts, audit logging).
- To send you account, verification, payment, and security notifications.
- To comply with legal obligations and respond to lawful requests from authorities.
We do not sell your personal data, and we do not use your NIN or bank details for any purpose beyond identity verification and rent-payment routing.
3. How we protect your data
- Passwords are never stored as plain text. We store only a one-way cryptographic hash (via PHP's
password_hash()), which cannot be reversed back into your password — not even by us. - Your NIN and bank account number are encrypted at rest (AES-256-GCM) in our database, distinct from and in addition to normal database access controls.
- Uploaded verification documents (utility bills, identity documents) are stored outside the public web server entirely and are only ever served back through an authenticated, access-logged endpoint — never by a direct public link.
- Optional two-factor authentication (TOTP) is available on every account, with encrypted-at-rest secrets and single-use, hashed recovery codes.
- Every session is protected against fixation and cross-site request forgery, and repeated failed login attempts temporarily lock an account.
4. Who we share data with
We share the minimum necessary data with:
- Payment processors (Stripe, Paystack, or Flutterwave), to process a rent payment you initiate.
- Email delivery providers, to send account, verification, and security notifications you'd expect from using the platform.
- Law enforcement or regulators, only when legally required to do so.
We never sell personal data to third parties, and we never share your NIN or bank details with other users of the platform. A landlord sees a tenant's verification status, not their NIN; a tenant never sees a landlord's bank account number.
5. Data retention
We keep account and transaction data for as long as your account is active, and for a reasonable period afterward to meet tax, accounting, and dispute-resolution obligations typical for a rental and payments platform. Security/audit logs are retained separately for fraud investigation purposes. You may request deletion of your account as described in Section 6, subject to records we're legally required to keep (e.g. completed payment records).
6. Your rights
Under the NDPA and comparable data-protection principles, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your account and associated personal data, where we are not legally required to retain it.
- Object to or restrict certain processing.
- Withdraw consent at any time where processing is based on consent, without affecting processing already carried out.
To exercise any of these rights, contact support@cicilyhomes.com. We will respond within a reasonable time and may need to verify your identity first.
7. Cookies
We use a single essential session cookie to keep you logged in (HttpOnly, SameSite, and marked Secure over HTTPS) and, optionally, a local browser preference for light/dark theme stored on your device. We do not currently use third-party advertising or tracking cookies.
8. Children's privacy
CicilyHomes is intended for adults entering into rental agreements and is not directed at children. We do not knowingly collect personal data from anyone under 18.
9. Changes to this policy
We may update this policy as the platform evolves (for example, as automated identity/utility verification integrations described on our About page go live). We'll update the "Last updated" date above when we do, and post material changes here before they take effect.
10. Contact us
Questions about this policy or how your data is handled: support@cicilyhomes.com, or by mail at 1 Zilly Aggrey drive, Epic Center 4th floor, Idu Karmo, FCT, Nigeria.