1Who we are and what this covers
Proxxera operates a product authentication and anti-counterfeit platform. In this policy, "Proxxera", "we", "us" and "our" refer to the operator of this platform, and "you" refers to the person whose information we handle.
This policy applies to:
- Buyers and visitors — anyone who uses the public verification and report pages, texts a code over SMS or WhatsApp, or browses this website. You are never required to create an account to verify a product.
- Brand users — administrators, operators and viewers who sign in to a brand dashboard to manage products, batches, codes, billing and reports.
- Reporters — anyone who submits a suspected-counterfeit report through the platform.
Controllers. Proxxera is the controller of the information described in this policy. When you report a product, the brand that owns the verification code receives your report and becomes an independent controller of the information in it under its own privacy obligations.
2Information we collect
Verification checks
When you verify a product on the web, by SMS, or on WhatsApp, we record: the code you entered (stored as an irreversible SHA-256 hash, never in plain text), the result of the check (genuine, previously verified, flagged, invalid, and so on), the channel used, your IP address, an approximate region derived from that IP, your browser or device type, and the date and time. For invalid attempts we retain only the first few characters of what was typed — just enough to recognise attack patterns. We do not ask buyers for a name, email, or account.
Product reports
If you submit a counterfeit report we collect: your phone number (required, so the brand can follow up), your name if you choose to give it, the state and LGA or city, where and from whom you bought the product, any photo or receipt you upload, and your description of what seemed wrong.
Brand accounts
When a brand signs up or is onboarded we collect the brand name, its public verification URL slug, your name, your work email, and a password (stored only as a salted bcrypt hash). Brand dashboards also hold the products, batches, label artwork, messaging configuration and team invitations (name, email, role) the brand chooses to enter.
Billing
Credit purchases are completed on Paystack, Flutterwave or Monnify — we never see or store full card numbers, bank credentials or PINs. We receive the payment reference, amount, currency, status, and the gateway's confirmation so your wallet is credited exactly once, plus the accounting records we are legally required to keep.
Messaging
If a brand enables SMS or WhatsApp verification, we receive the sender's phone number and message text (for example, VERIFY XXXX-XXXX-XXXX) from the provider, verify the code, and log the check. Outgoing replies are delivered through the brand's own configured gateway.
Contact and support
Messages you send through the contact page, and any correspondence with our support team, are kept so we can respond and keep a record of what was agreed.
Technical data
Signed-in users receive a session cookie (pd_session) holding a JWT that expires after 12 hours. Theme preferences are stored locally in your browser. Our servers keep standard request logs (IP, time, pages requested) for security and debugging.
3How and why we use your information
We use personal information for the following purposes and legal bases:
- To deliver the service (performance of a contract): returning verification results, generating and activating codes, maintaining brand dashboards, crediting wallets, and supporting your account.
- To detect and fight fraud (legitimate interest): logging every check and running the brand's fraud rules against it so duplicate checks, cross-region spread and blocked codes surface as flags instead of silently passing.
- To investigate counterfeit reports (legitimate interest, performed for the reporting brand): routing reports with your contact details to the brand that owns the code.
- To bill and account correctly (contract and legal obligation): payment confirmation, credit ledgers, invoices and tax records.
- To secure the platform (legitimate interest): rate-limiting, abuse detection, debugging and incident investigation from server logs.
- To communicate with you (contract or legitimate interest): answering contact-page messages, support requests, and notices about material changes to the service.
- To comply with law (legal obligation): responding to lawful requests from courts or regulators, and retaining records we are required to keep.
We do not sell personal data. We do not run advertising, and we do not build marketing profiles from verification activity. Verification logs exist to protect brands, not to market to buyers.
4Fraud detection and verification records
Every verification attempt — genuine or not — is written to an immutable log entry: the code (hashed), the result, the channel, IP address, approximate region, device type and timestamp. These records are the evidentiary core of the platform: they show where a code was checked, how often, and from how many locations, which is how counterfeiting patterns are recognised.
Brand fraud rules run against these logs after each check. Depending on the brand's configured thresholds and actions, a code or account can be monitored, flagged as suspicious, or blocked outright. Rules are set by the brand, not by us, and are visible to the brand in its dashboard.
Log entries are visible to the team of the brand that owns the code, and to Proxxera personnel where needed for support, security or legal compliance. Buyers are not individually identified beyond network-level data (IP, region, device), because no buyer account exists.
6International transfers
Proxxera is built for African markets and our primary operations are in Nigeria. Our infrastructure may process information in other countries where our hosting or service providers operate. Where information leaves your jurisdiction, we rely on contractual and organisational safeguards required by applicable data protection law — including standard contractual clauses where the Nigeria Data Protection Act 2023, the UK GDPR or the EU GDPR requires them — so that your information keeps the protection it had at home.
7How long we keep your information
- Verification logs — kept for as long as the owning brand's account is active, because they are the brand's fraud-fighting evidence. When a brand is deleted, its logs are removed with it, unless we must retain specific records for a legal dispute.
- Authentication codes — only SHA-256 hashes persist; plain-text codes exist only in the one-time download the brand takes at generation, and cannot be recovered by us afterwards. Expired codes are retired by the nightly expiry job.
- Reports — kept while the brand's investigation is open and afterwards only as long as the brand needs them to pursue enforcement, unless you ask us earlier and there is no overriding legal reason to keep them.
- Billing records — retained for the period required by tax, accounting and company law, even after account closure.
- Contact and support messages — kept until the matter is resolved and a reasonable period afterwards.
- Brand account data — removed within 30 days of a verified deletion request, except billing records we are legally required to keep.
8How we protect your information
We apply the following measures, among others:
- Passwords hashed with bcrypt; verification codes stored only as SHA-256 hashes peppered with a server-side secret, never in plain text.
- Sessions in an httpOnly, SameSite, signed JWT cookie expiring after 12 hours — no credentials in URLs or local storage.
- Brand isolation enforced at the query level: every dashboard lookup is scoped to the signed-in brand, and cross-brand reads return not-found.
- Role-based access (superadmin, brand admin, operator, viewer) so staff and team members only see what their role requires.
- Transport encryption (HTTPS/TLS) across the whole site, and encrypted or access-controlled storage for backups.
- Webhook signatures verified for billing and messaging endpoints, so forged callbacks cannot credit wallets or inject messages.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities within the timeframes the applicable law requires.
10Your rights
Depending on where you live, data protection law — including the Nigeria Data Protection Act 2023 and NDPR, and the UK/EU GDPR if you are in the UK or EEA — may give you the right to:
- request access to the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- request deletion of your information, subject to what we must legally keep;
- restrict or object to how we process your information;
- receive your information in a portable, machine-readable format;
- withdraw consent at any time, where processing is based on consent; and
- opt out of any direct marketing (we do not currently send marketing emails, and this will always be available if we start).
To exercise any of these, use the contact page and state which right you are exercising. We may need to verify your identity first, and we will respond within the period the applicable law requires — normally within 30 days. If you are unhappy with our response, you may lodge a complaint with your local supervisory authority; in Nigeria that is the Nigeria Data Protection Commission (NDPC).
Verification checks are made without an account, so there is no profile of you to access or delete in that context; rights over verification logs are exercised by the brand that owns the code, and we will forward such requests to it.
11Children
Proxxera is a business platform and is not directed at children. Brand accounts may only be created by adults (18 or over). While any shopper may scan a QR code in a store, our report forms and dashboards are intended for use by adults; if you believe a child has submitted personal information to us, contact us and we will delete it.
12Third-party services and links
Verification results and brand pages may link to a brand's own website, and payments and messages run through gateways and carriers we do not control. Those parties process information under their own privacy policies, and we encourage you to read them. Proxxera is not responsible for the privacy practices of third parties we do not operate.
13Changes to this policy
We may update this policy to reflect changes in the platform, our practices, or the law. The "Last updated" date at the top of this page always shows when the current version took effect. For material changes, we will give brand administrators advance notice through the dashboard or by email before the change takes effect, and we will post the revised policy here for everyone else. Continued use of the platform after an update takes effect means you accept the revised policy.
14Contact and complaints
Questions, requests and complaints about privacy go through the contact page; privacy requests are handled first. You can also reach us about anything covered by this policy at the same address — include the right you wish to exercise and enough detail for us to locate your information.
If you believe your privacy rights have been infringed, you have the right to complain to your data protection authority — the Nigeria Data Protection Commission in Nigeria, or the equivalent authority in your country.