Privacy Policy

Your privacy matters. This policy explains what BillioPlus collects, how we collect it, why we process it, and your rights under the Nigeria Data Protection Act 2023 (NDPA).

Effective date: August 23, 2026 · Last updated: August 24, 2026

We collect only what we need to run the wallet, deliver numbers and SMS, operate the API and support you. We store passwords in hashed form, encrypt data in transit with HTTPS/TLS, and share data only with the service providers described in Section 16.

This policy is framed around the Nigeria Data Protection Act 2023 and current Nigeria Data Protection Commission (NDPC) guidance.

1. Who Operates BillioPlus

BillioPlus (“we”, “us”, “our”) operates the platform at https://billioplus.com.ng. For data-protection purposes, BillioPlus is the data controller for the personal data described in this policy.

For formal legal-entity details for contracting or compliance review, please contact us at contact@billioplus.com.ng.

2. Scope of This Policy

This policy applies to personal data we process when you:

  • visit the public website, blog, docs, manual or marketing pages;
  • create an account, verify your email, log in, or manage your profile and settings;
  • fund your wallet, make purchases, rent numbers, order voice numbers, or use boost services;
  • receive SMS or call transcripts in the dashboard or via webhooks;
  • use API keys or make API requests;
  • contact support, submit a ticket, or send a contact-form message; or
  • interact with cookie banners, analytics or support widgets.

It does not apply to the practices of third-party platforms that you verify using a BillioPlus number (e.g., WhatsApp, Telegram, Google, Facebook, TikTok, banks). Their privacy policies govern their own processing.

3. Categories of Personal Data We Collect

We collect only what is needed to provide the service:

CategoryExamples
Account & identityUsername, email address, name (optional), phone (optional), referral code
Authentication & securitySecurely hashed password, email-verification code and expiry, password-reset code, login history
Wallet & paymentsWallet balance, boost balance, transaction history (type, amount, status, date, reference, method), gateway confirmation and reference
Orders & numbersOrder details, operator name, country and service, assigned phone number, activation reference, price, status and expiry
Messages & callsReceived SMS text and received time, voice call recording and transcript where applicable
SupportContact messages, support tickets and replies, attachments you upload
API & developerAPI key name and usage counters, last-used date, webhook address and signing secret, per-request logs
Device & security logsIP address, browser/device information inferred from user-agent, security and audit logs
Cookies & analyticsEssential cookies (session, preferences), required analytics (PostHog, Google Analytics/Tag Manager), error monitoring (Sentry), and YouTube tutorial playback cookies

We do not intentionally collect government IDs or full card numbers. Card and bank details are entered on the payment gateway's hosted page, not on BillioPlus.

4. How Each Category Is Collected
  • Directly from you: when you register, update your profile, fund your wallet, buy or rent numbers, submit support tickets, upload attachments, configure a webhook, or use the API.
  • Automatically: device and security information when you use the site, log in or make API calls; your cookie preferences.
  • From service providers: payment confirmations from Paystack or Flutterwave; order, number and message data from virtual-number suppliers; email delivery status from our email providers; analytics events and embedded YouTube player data where applicable.
5. Why We Process Each Category
  • Account & security: to create and secure your account, authenticate you, verify your email, and enforce session controls.
  • Wallet & payments: to credit funding, debit purchases, record transactions, and handle refunds, including deposit bonuses where advertised.
  • Orders & numbers: to source numbers from suppliers, assign them, manage expiry and recycling, and display status.
  • Messages & calls: to display verification codes and transcripts in your dashboard and deliver them to your webhook where configured.
  • Support: to triage and respond to your enquiries.
  • API & developer: to authenticate requests, count usage, and provide request history.
  • Device & security logs: to prevent fraud, enforce rate limits, troubleshoot errors, and investigate abuse.
  • Cookies & analytics: to keep you logged in, remember preferences, measure usage, improve the service, and play embedded tutorial videos.
6. Lawful Bases for Processing (NDPA 2023)

Under the NDPA, we rely on one or more of these bases:

  • Consent — e.g., where you consent to optional marketing cookies or optional referrals.
  • Performance of a contract — e.g., to provide the account, wallet, number purchase, rentals, voice, boost and API services you request.
  • Legitimate interests — e.g., to secure the service, prevent fraud, measure and improve performance, and handle support, balanced against your rights.
  • Legal obligation — e.g., to keep transaction records for tax, accounting or law-enforcement requests where required.
  • Vital interests or public interest — rarely, where necessary to prevent serious harm or comply with a lawful request.

Where consent is the basis, you may withdraw it at any time (for example, via the cookie banner, dashboard settings, or by contacting us), without affecting the lawfulness of prior processing.

7. Account & Authentication Information

We require a username and email address at registration. Email addresses are normalized and must be unique. Passwords must be at least 8 characters and are stored in hashed form — we never store them in plain text.

Sessions are managed with secure, HttpOnly cookies with appropriate lifetimes. Email verification uses a short-lived code valid for 10 minutes.

Password reset also uses a short-lived, rate-limited code and requires you to meet the password strength requirements.

8. Payment & Wallet Information

BillioPlus is prepaid. You fund your wallet via Paystack or Flutterwave and are redirected to their hosted checkout. We do not handle your raw card or bank data.

We store the amount funded, transaction history (type, status, date, reference and method), and gateway references needed to verify payment. Wallet balances and boost credits are stored per user.

BillioPlus controls the wallet ledger; the payment gateway processes the actual money movement and retains its own records under its privacy policy.

9. Virtual-Number Order Information

For each order we store the service name, country, operator name, order type, price, status, creation and expiry times, activation reference, and the assigned phone number linked to your account.

Numbers are sourced from upstream suppliers via secure server-to-server calls. Supplier availability, coverage and pricing are determined by those providers.

10. Received SMS Content & Verification Codes

Inbound SMS text, often including one-time verification codes, is stored and displayed in your dashboard. Where you have set a webhook address, we deliver each message once with a signature header so you can verify it.

SMS content may contain personal or sensitive information. Treat verification codes as confidential. We store and display what the upstream supplier delivers and do not use message content for profiling.

Retention: Messages are not automatically deleted after 24 hours.

Messages remain linked to your order until you delete the order, close your account, or we delete them following a retention or legal request. Virtual numbers may expire, be recycled, and may have had previous use.

11. API Usage & API Logs

If you use the API, we store your API keys and a per-request log that includes endpoint, method, status code, IP address and user-agent. Authentication uses the Authorization: Bearer <key> header; a legacy query parameter is still supported for backward compatibility but is deprecated.

Logs are used to show you usage history, enforce limits, and detect abuse.

12. Support & Communication Data

Contact-form submissions, support tickets and threaded replies are stored so we can respond and keep a history. Where you contact support, we may send an email notification to our support mailbox including relevant account details and message content.

Files you upload via support are stored securely and linked to the related conversation.

13. Device, Browser, IP-Address & Security Information

We process technical data where needed for security and service quality:

  • IP address and user-agent from requests, including login and API calls;
  • Login history and audit logs for rate limiting, fraud detection and troubleshooting;
  • Secure session verification for authenticated requests.

You are not completely anonymous when using BillioPlus — we necessarily process identifiers such as email, IP and order history to provide and secure the service.

14. Cookies & Analytics

We use cookies and similar storage on your device. Our banner stores your choices and respects them on future visits.

  • Strictly necessary / essential: session and preference cookies — always active and required for login and checkout.
  • Analytics: PostHog and Google Analytics / Tag Manager are required for usage measurement and product improvement. When you are logged in, events may be associated with your account.
  • YouTube tutorial playback: embedded YouTube videos are required for dashboard tutorials and may set YouTube/Google cookies when the player loads.
  • Error monitoring: Sentry where configured to help us fix issues.

You can control optional marketing cookies via the banner and your browser settings. Disabling browser cookies may affect login, purchases, analytics, and embedded tutorial playback. See the Cookie Policy for more detail.

15. Fraud Prevention & Legal Compliance

We process data to prevent fraud, enforce acceptable use, verify payments, handle chargebacks, and comply with Nigerian law and lawful requests. This includes rate limiting for login and verification flows and review of high-risk activity. Where required, we may preserve data beyond standard retention to meet legal obligations.

16. Third-Party Processors & Upstream Providers

We share data with service providers only to the extent needed to provide the features you use:

Payments

Paystack and Flutterwave for wallet funding. We send amount, currency, payment reference and contact email; they return payment status.

Email

Email delivery providers for verification, welcome and support notifications.

SMS & number suppliers

Upstream virtual-number suppliers and voice-call providers — we send service, country and activation details; they return numbers and message status.

Storage & hosting

Database hosting, Vercel/hosting infrastructure and blob storage, and Cloudinary for support attachments you upload.

Analytics & error monitoring

PostHog, Google Tag Manager / Analytics, and Sentry — for required usage measurement, service improvement, and fixing errors.

Embedded video

YouTube / Google for inline dashboard tutorial video playback.

Other

IP geolocation for login notifications where available and internal tools for expiry and rate updates. We do not share data beyond these categories without your consent or a legal basis.

17. International Data Transfers

BillioPlus operates from Nigeria but uses providers that may be located outside Nigeria (for example, infrastructure for email, analytics, SMS suppliers and voice). Where data is transferred outside Nigeria, we rely on contractual protections with the provider and, where NDPA guidance applies, adequate safeguards.

18. Data Retention

We keep data only as long as needed for the purposes described or as required by law. In practice:

  • SMS messages and transcripts: retained linked to your order until the order is deleted, your account is deleted, or we act on a retention or legal request. Messages are not automatically deleted after a fixed period.
  • Orders and rentals: retained while active and afterwards for history, support and fraud review; expired voice orders remain as “expired” and the underlying number is returned to the pool.
  • Transactions and wallet history: retained for support and legal or accounting purposes as required under Nigerian law.
  • Account, support tickets and messages: retained while your account is active and for a reasonable period after closure to handle disputes or legal holds.
  • Security logs: retained for troubleshooting and fraud prevention.
  • Backups: database backups may retain copies for a limited recovery window beyond primary deletion.

If you request deletion or a retention period is imposed by law, we will delete or anonymise data where we are not otherwise required to retain it.

19. Security Measures

We protect your data with appropriate technical and organisational measures:

  • Transport encryption: all pages and APIs are served over HTTPS/TLS — described as encrypted in transit, not end-to-end encryption.
  • Passwords: securely hashed; raw passwords are never stored or logged.
  • Sessions: secure, HttpOnly cookies with appropriate lifetimes and protection against cross-site misuse.
  • Email verification: time-limited codes enforced server-side, with rate limiting.
  • Rate limiting: limits on login, verification and password-reset flows.
  • Input validation: validation and sanitisation for user-supplied data.
  • Access control: role-based checks for administrative features; users can only access their own orders and tickets.
  • API keys: secure generation, per-key request logging, and the ability to deactivate keys.
  • Webhook signing: signature header where you configure a secret.
20. Your Privacy Rights

Under the NDPA, you have rights subject to lawful limits, including:

  • Information & access — to know what data we hold about you and receive a copy;
  • Rectification — to correct inaccurate or incomplete data (e.g., via dashboard profile);
  • Erasure — to request deletion where we are not legally required to retain the data;
  • Restriction & objection — to ask us to limit or stop certain processing where the NDPA allows;
  • Data portability — to receive your data in a structured, commonly used format where feasible;
  • Withdraw consent — where processing is based on consent, you may withdraw at any time;
  • Not to be subject to solely automated decisions with significant effects, where the NDPA applies.

If you are located in other jurisdictions, additional laws may give you similar rights where they genuinely apply. Contact us if you need to exercise rights under those laws and we will assess applicability.

21. Account Deletion & Data Access Requests

You may request account deletion or a copy of your data at any time via dashboard settings or by emailing contact@billioplus.com.ng. Self-serve deletion is available in settings with a confirmation step.

On deletion we remove or anonymise your account data where we are not required to retain it for fraud prevention, payment reconciliation or legal compliance. Transaction and order history and security logs may be retained as described in Section 18. We aim to respond to verified access or deletion requests within 30 days.

22. Children’s Privacy

BillioPlus is not directed to children and we do not knowingly collect data from anyone under 18. If we learn that we have collected data from a child, we will take steps to delete it. Parents or guardians who believe a child has provided data should contact us.

23. Policy Changes

We may update this policy to reflect changes in technology, regulation or our practices. We will update the “Last updated” date above and, where a change is material, provide notice via the website or email. Continued use after an update constitutes acceptance of the revised policy.

24. Contact & Complaints (NDPC)

For privacy questions, access, correction or deletion requests, or to withdraw consent, contact:

You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) where the NDPA applies, if you believe your rights have been violated. The NDPC's contact details are published on its official website. This does not affect any other legal remedies you may have.

Questions about your data?

Contact us to exercise your NDPA rights or ask about retention, processors or international transfers.

Email: contact@billioplus.com.ng

Response time: within 24 hours