1. Who is responsible for your data
Alphaa Africa Limited is the data controller for personal data processed through this platform. That means we decide the purposes and means of processing described in this policy. Where we use service providers (for example payment processing or hosting) to handle data on our behalf, they act as data processors under our instructions.
Our registered office and primary contact point is Olive Plaza, SF19, Alexandria Cres, off Aminu Kano Crescent, Wuse II, Abuja 900107, Federal Capital Territory. For any privacy question, request, or complaint, contact info@alphaaafrica.com and we will route it to the responsible team. Where the NDPA requires a designated Data Protection Officer, that contact serves as the channel to reach them.
2. Scope of this policy
This policy covers personal data collected through our website, booking and enquiry flows, customer accounts, and support conversations (including WhatsApp chats, calls, and emails where you share booking details with us). It does not cover third-party websites you reach through links on our platform — including airline, hotel, embassy, payment, map, or social-media sites — each of which has its own privacy policy.
3. Personal data we collect
We collect only data that is adequate, relevant, and limited to what is necessary for the purposes below (data minimisation). Depending on what you do on the platform, this may include:
- Identity and contact details: full name, email address, phone number, and — only where a booking or account flow requires it — date of birth and gender.
- Traveller details: for each traveller on a flight booking, first and last name, date of birth, gender, email, phone, traveller type (adult, child, held infant), and passport details where the airline or route requires them.
- Hotel and car-booking details: guest name, email, phone, stay or hire dates, room and guest counts, pickup and drop-off locations, and pickup times.
- Package enquiries and visa consultations: country of interest, travel purpose (tourism, business, study, work, medical, family visit, or other), preferred dates, number of applicants, and any message or documents you choose to share so a specialist can advise you.
- Account data: login credentials (passwords are stored only as irreversible hashes — never in readable form), email-verification and password-reset codes, profile updates, and booking history.
- Transaction records: booking references, payment references, amounts, currency, payment status, and verification outcomes. Card and bank credentials are entered on Paystack's secure pages — we never collect, see, or store your card number, CVV, PIN, or bank login.
- Support correspondence: messages, call notes, and documents you send over WhatsApp, phone, email, or our contact forms, including booking references you quote so we can locate a transaction.
- Technical and usage data: device and browser type, approximate location derived from IP address, pages viewed, searches performed, and booking-funnel events. Analytics events never carry passport data, payment credentials, passwords, or authentication tokens.
4. Lawful bases we rely on (NDPA sections 25–26)
We process personal data only where at least one recognised lawful basis applies. In practice that means:
- Contract: to search fares, create pending bookings, process payments, issue confirmations, and manage enquiries and consultations you asked us to perform.
- Consent: where you freely give it — for example marketing messages, optional cookies, or sharing documents beyond what a booking strictly requires. You may withdraw consent at any time without detriment, and withdrawal does not affect processing already carried out.
- Legal obligation: to keep transaction and tax records, respond to lawful requests from competent authorities, and comply with aviation, immigration, and financial regulations.
- Legitimate interests: to operate a secure platform, prevent fraud and duplicate charges, improve our services, and pursue or defend legal claims — balanced at all times against your rights and freedoms.
- Vital interests: in rare emergencies, to protect life or safety — for example sharing a traveller's details with an airline or emergency contact where necessary.
5. How we use your data
We use personal data for specified, explicit, and legitimate purposes only, and never for incompatible purposes:
- To display flight, hotel, package, visa, and vehicle options and to complete the searches, bookings, enquiries, and consultations you request.
- To create pending bookings, redirect you to Paystack for payment, verify the payment reference, and issue booking confirmations with PNR or reservation references.
- To operate accounts: registration, login with JWT access and refresh tokens, email verification, password reset, profile management, and order history.
- To provide human assistance: answering questions on WhatsApp, phone, and email, reconciling deducted-but-unconfirmed payments, and following up on package enquiries and visa consultations.
- To keep the platform safe: fraud prevention, duplicate-submission protection, session management, access control, and troubleshooting.
- To meet legal duties and to communicate important service information such as fare changes before payment, booking status, and policy updates.
- To send marketing only where you have consented or where the law otherwise permits, with a clear way to opt out in every message.
6. Who we share your data with
We do not sell personal data. We share it only where necessary to deliver the travel services you requested or to meet legal duties, and only with parties that need it:
- Airlines and distribution partners (including Amadeus for international offers and QuickAir for domestic Nigerian search) — traveller names, dates of birth, passport details, and contact data required to price, ticket, and fulfil a flight.
- Hotels, vehicle providers, and package suppliers — guest names, contact details, dates, and service preferences needed to hold or confirm a reservation.
- Paystack (our payment processor) — transaction amount, currency, reference, and contact details needed to authorise and verify payment. Paystack processes card and bank credentials directly under its own policy.
- Communication and infrastructure providers — hosting, email delivery, Google Maps embeds, and WhatsApp/Meta messaging services used to run support conversations you initiate.
- Analytics providers (Google Tag Manager / Google Analytics, only where enabled) — aggregated, pseudonymised usage statistics with sensitive fields stripped before any event is recorded.
- Professional advisers, auditors, and competent authorities — where required by law, court order, or to establish, exercise, or defend legal claims.
Every processor we engage is required to handle data only on our instructions, keep it confidential, and apply appropriate technical and organisational safeguards.
7. Cross-border transfers
Travel is inherently international: confirming a flight, hotel, or visa service routinely means sending booking details to airlines, hotels, embassies, or technology providers located outside Nigeria. Where such a transfer occurs, we rely on an adequacy decision where one exists, or on appropriate safeguards such as contractual data-protection clauses, and we ensure your NDPA rights travel with the data. You may ask us at any time which categories of recipients outside Nigeria received your data for a given booking.
8. Cookies and analytics
We use a small number of cookies and similar storage to keep the site working and to understand aggregate usage. Strictly necessary storage (session security, search state, consent choice) is always on because the platform cannot function without it. Optional analytics cookies (for example Google Analytics via Tag Manager) are used only to measure funnel performance — searches started and completed, bookings confirmed, enquiries submitted — and never capture passport data, payment credentials, passwords, or tokens.
You can manage or delete cookies in your browser settings at any time; blocking optional analytics will not break booking. Where analytics is disabled by configuration, our measurement code no-ops entirely.
9. How long we keep your data
We retain personal data no longer than necessary for the purposes collected (storage limitation), then delete or anonymise it:
- Booking and transaction records: retained for as long as needed to service the booking, handle changes, refunds, or disputes, and to satisfy tax, accounting, and aviation record-keeping duties.
- Account data: retained while your account is active; on closure we delete or anonymise profile data except where law requires retention.
- Enquiries and support messages: retained for a reasonable follow-up and quality-assurance window, then deleted or anonymised.
- Technical logs and analytics: retained in aggregated or short-lived form for security and performance monitoring.
10. How we protect your data
We apply appropriate technical and organisational measures to safeguard security, integrity, and confidentiality: encrypted transport (TLS/SSL), access controls limited to authorised personnel, centralised authentication with automatic token refresh and logout, server-side validation, and a rule that passwords, tokens, passport data, and payment credentials are never logged or placed in URLs. No method of transmission over the internet is completely secure, so where we become aware of a personal-data breach that poses a risk to your rights, we will notify the Nigeria Data Protection Commission within 72 hours and inform affected individuals as required by the NDPA.
11. Your rights and how to exercise them (NDPA sections 34–38)
As a data subject you have the right to be informed; to access your data and obtain a copy; to rectify inaccurate or incomplete data; to erase data where it is no longer necessary or consent is withdrawn (subject to legal retention duties); to restrict processing while a dispute is resolved; to receive your data in a structured, commonly used, machine-readable format and to port it; to object to processing including direct marketing and to withdraw consent at any time; not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects; and to lodge a complaint with the Nigeria Data Protection Commission or seek redress in court.
To exercise any of these rights, email info@alphaaafrica.com with the subject “Data Rights Request”, telling us your name, the email or phone number used on the platform, and the right you wish to exercise. We will verify your identity proportionately, respond without undue delay and in any event within the statutory timeframe, and we will never charge you or penalise you for exercising your rights.
12. Children's data
Our platform is intended for adults who can enter binding contracts. Children's and infants' traveller details may only be submitted by a parent, legal guardian, or person authorised to act for them, strictly for the purpose of completing a booking that includes them. We do not knowingly collect data directly from children for marketing or accounts.
13. Marketing communications
We send promotions, new-package alerts, or travel inspiration only with your consent or where the law otherwise permits, and every message includes a simple way to opt out. Withdrawing marketing consent does not affect service messages we must send about a booking, payment, or consultation you requested.
14. Changes to this policy
If we change this policy materially, we will publish the updated version on this page with a new effective date and, where appropriate, notify account holders or active customers by email. The version in force at the time you use the platform governs that use. Continued use after the effective date constitutes acknowledgement of the updated policy.
15. Contact and complaints
For privacy questions, data-rights requests, or complaints, contact Alphaa Africa Limited at info@alphaaafrica.com, on WhatsApp at +234 706 685 1051, or at Olive Plaza, SF19, Alexandria Cres, off Aminu Kano Crescent, Wuse II, Abuja 900107, Federal Capital Territory (Monday to Saturday, 8:00 AM to 6:00 PM WAT). If you remain dissatisfied after contacting us, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) or seek redress before a court of competent jurisdiction in Nigeria.
Questions about this document?
Our travel specialists answer privacy and booking-term questions on WhatsApp, by email at info@alphaaafrica.com, or at our Abuja office. Quote the section heading so we can respond precisely.
Booking, payment, refund, and liability terms.