Legal Document — Privacy Policy

Privacy Policy

Your privacy matters to us. This policy explains clearly and honestly what data we collect, why we collect it, how we protect it, and what rights you have over it.

Effective: June 18, 2026 Last Updated: June 18, 2026 GDPR & NDPR Compliant Google Ads Policy Compliant
Plain-Language Summary: We operate Primeventory at store.mpsev.com, a subdomain of mpsev.com, both owned by Michael Prime Services. We collect only the data we need to operate our service, we never sell it, and we protect it with enterprise-grade security. By using our platform, you agree to this policy. Please read it carefully.
01

Overview & Data Controller

This Privacy Policy describes how Michael Prime Services ("we," "us," "our," or "the Company") — the owner and operator of https://mpsev.com and its subdomain https://store.mpsev.com — collects, uses, stores, shares, and protects your personal data when you visit our websites, access the Primeventory platform, or interact with any of our services.

Data Controller Information

Company NameMichael Prime Services
Parent Domainhttps://mpsev.com
Platform URLhttps://store.mpsev.com
Phone / WhatsApp+234 9072490013
Effective DateJune 18, 2026
Applicable LawsNDPR 2019, GDPR (EU), CCPA (California)

The platform we offer, Primeventory, is a Software-as-a-Service (SaaS) business management system that includes inventory management, sales tracking, staff management, payroll processing, customer management, multi-branch/warehouse control, and AI-powered analytics. This policy applies to all users of Primeventory, including business owners, administrators, staff members granted access accounts, and visitors to our marketing website.

By accessing or using store.mpsev.com, subscribing to any Primeventory plan, or registering for a 61-day free evaluation trial, you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree, please discontinue use immediately.


02

Data We Collect

We collect the following categories of personal and non-personal data:

Account & Identity Data

  • Full name and business name
  • Email address (used as your login credential)
  • Phone number (for account verification and support)
  • Country and region of operation
  • Chosen username and encrypted password
  • Subscription plan selected (61-Days Free Trial, Standard, or Premium)

Billing & Payment Data

  • Billing address and postal code
  • Payment method type (card, bank transfer, USSD)
  • Transaction IDs and payment confirmation records
  • Subscription start and renewal dates
  • Note: Full card numbers, CVVs, and raw banking credentials are never handled by us. Payment processing is managed securely by our PCI-DSS-compliant payment gateway partners (Flutterwave).

Business Operational Data

  • Inventory records, product names, SKUs, and stock levels that you enter into Primeventory
  • Customer profiles and purchase histories you create within the platform
  • Staff accounts, role assignments, attendance logs, and payroll records you manage
  • Sales transactions, returns, and revenue data you record
  • Warehouse and branch location information you configure
  • This data belongs entirely to you. We act as a data processor for this category on your behalf.

Usage & Technical Data

  • IP address and approximate geolocation (country/city level)
  • Browser type, version, and operating system
  • Device type (desktop, mobile, tablet)
  • Pages visited, features accessed, and time spent on each page
  • Session duration, login timestamps, and logout events
  • Referring URLs (the site or link that brought you to us)
  • Error logs and crash reports for debugging purposes

Cookie & Tracking Data

  • First-party cookies for session management and authentication
  • Analytics cookies (Google Analytics 4) measuring page traffic and user behaviour
  • Advertising cookies (Google Ads / DoubleClick) for measuring ad performance
  • Preference cookies storing your display and notification settings
  • See Section 5 for full cookie details and opt-out options.

Communications Data

  • Emails or messages you send to our support team
  • Demo scheduling form submissions (name, email, business details)
  • Feedback, bug reports, or feature requests you submit
  • Marketing email engagement data (opens, clicks, unsubscribe actions)
We do not collect: Government-issued ID numbers, biometric data, racial or ethnic origin data, religious beliefs, health data, or any other special category data under GDPR Article 9, unless explicitly provided by you in a support communication.

03

How We Use Your Data

We use the data we collect for the following specific purposes. We do not use your data for any purpose not listed here without first notifying you and, where required, obtaining your consent.

Service Delivery

To create and manage your Primeventory account, authenticate logins, deliver the features you subscribe to, and ensure the platform functions correctly for your business.

Billing & Subscriptions

To process subscription activations, manage plan updates, issue transactional logs, and send automated billing cycle warnings.

Customer Support

To respond to your support queries, diagnose technical issues, provide platform walkthroughs, and resolve disputes related to your account.

Analytics & Improvement

To understand how users navigate Primeventory, identify features that are underused or confusing, fix bugs, and develop new features that make the platform more useful.

Transactional Notifications

To send you account-related emails including trial transitions, plan expiration logs, critical security alerts, and system maintenance notices.

Marketing Communications

To send promotional emails about new Primeventory features, plan upgrades, or relevant business tips — only if you have opted in to marketing. You can unsubscribe at any time.

Advertising (Google Ads)

To display advertisements relevant to your interests via Google Ads and the Google Display Network. We use anonymised signals (not your personal name or email) for ad targeting purposes. See Section 6 for full details.

Security & Fraud Prevention

To detect unauthorised access attempts, protect accounts from hijacking, investigate suspicious activity, enforce our Terms of Service, and comply with applicable laws.

Legal Compliance

To fulfil our obligations under applicable laws including the Nigeria Data Protection Regulation (NDPR), GDPR, tax regulations, financial reporting requirements, and lawful requests from government or regulatory authorities.



05

Cookies & Tracking Technologies

We use cookies — small text files stored in your browser — and similar tracking technologies such as web beacons, pixel tags, and local storage. These help us operate the platform, understand how it is used, and deliver relevant advertising.

Cookie Type Purpose Duration Can You Opt Out?
Strictly Necessary Session management, login authentication, CSRF security tokens, shopping cart state. The platform cannot function without these. Session / up to 30 days No — required for service
Functional Remembering your display preferences, notification settings, language, and last-visited dashboard section. Up to 1 year Yes — via browser settings
Analytics (GA4) Google Analytics 4 measures page views, user flows, feature engagement, and session duration to help us improve the platform. Data is anonymised and aggregated. Up to 2 years Yes — see below
Advertising (Google) Google Ads conversion tracking and DoubleClick/GCLID cookies measure ad performance and enable retargeting to users who have previously visited our site. Up to 90 days Yes — see Section 6

How to Manage or Disable Cookies

  • Browser settings: All modern browsers allow you to block or delete cookies. Refer to your browser's help section (Chrome, Firefox, Safari, Edge) for step-by-step instructions.
  • Google Analytics opt-out: Install the Google Analytics Opt-Out Browser Add-on at tools.google.com/dlpage/gaoptout.
  • Ad opt-out: Visit youronlinechoices.com (EU) or optout.aboutads.info (US) to opt out of interest-based advertising.
  • Note: Blocking strictly necessary cookies will impair or prevent access to the Primeventory platform. Blocking optional cookies has no effect on core platform functionality.


07

Data Sharing & Third Parties

We do not sell, rent, or trade your personal data to any third party under any circumstances. Data is shared only as described below.

We share data with third parties only in the following limited, necessary, and lawful circumstances:

Cloud Infrastructure Providers

Our platform is hosted on third-party cloud servers. These providers store the data necessary to run Primeventory on our behalf and are contractually prohibited from using your data for any other purpose. They are subject to data processing agreements (DPAs) meeting GDPR standards.

Payment Processors

When you subscribe to a Primeventory plan, your payment information is processed by our PCI-DSS-compliant payment gateway partner(s). We pass only the data required to complete the transaction. We do not receive or store your raw card details.

Google LLC (Analytics & Ads)

We share anonymised usage data with Google Analytics 4 and Google Ads for platform improvement and advertising measurement as described in Sections 5 and 6. Google processes this data under their own Privacy Policy (policies.google.com/privacy) as a data controller for advertising purposes.

Email Service Providers

To send transactional emails (subscription confirmations, password resets, low-stock alerts) and, where consented, marketing emails. These providers operate under data processing agreements and are prohibited from using your email address independently.

Legal & Regulatory Authorities

We may disclose personal data to government authorities, law enforcement agencies, or courts when required to do so by applicable law, court order, or regulatory authority — including NITDA under the NDPR. We will notify you of any such disclosure to the extent legally permitted.

Business Transfers

In the event of a merger, acquisition, or sale of assets of Michael Prime Services, your data may be transferred to the successor entity. You will be notified prior to any such transfer, and the acquiring entity will be bound by this Privacy Policy or an equivalent standard.


08

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law. The following retention schedules apply:

Data Category Retention Period Reason
Active account data Duration of subscription + 30 days Service delivery; 30-day grace period for reactivation
Billing & payment records 7 years from transaction date Financial regulation compliance (Nigeria Finance Act, FIRS requirements)
Business operational data (inventory, staff, sales) Duration of subscription; deleted within 90 days of account termination unless export requested Customer data ownership; NDPR data minimisation principle
Support communications 3 years from last interaction Dispute resolution and continuous service improvement
Security & access logs 12 months Fraud detection and security incident investigation
Analytics data (GA4) 14 months (Google's default) Trend analysis and platform improvement
Advertising cookies Up to 90 days Ad performance measurement per Google Ads policy
Unsubscribed marketing email records Indefinitely (email address only) To honour your unsubscribe request and not re-add you without fresh consent

Upon account deletion or subscription termination, you may request a complete export of your business data (inventory, customer records, sales history) within 90 days. After this period, data is permanently and irrecoverably deleted from our servers unless legally required to be retained.


09

Security Measures

We implement enterprise-grade technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction, or alteration. Our security architecture includes:

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). HTTP connections are automatically redirected to HTTPS.

Encryption at Rest

Sensitive data stored in our databases (including passwords, which are bcrypt-hashed and never stored in plaintext) is encrypted at rest using AES-256.

Role-Based Access Control

Even internally, our engineers access only the minimum data required for their function. Production data access is logged, audited, and restricted.

DDoS & Intrusion Protection

We employ web application firewall (WAF) protection, rate limiting, IP reputation filtering, and DDoS mitigation at the infrastructure level.

Regular Security Backups

Your business data is backed up daily to geographically redundant storage. Backups are encrypted and tested for integrity on a regular schedule.

Security Audits

We conduct periodic internal security reviews and vulnerability assessments. Critical vulnerabilities are patched within 24 hours of detection.

Important Notice: Despite our robust security measures, no system connected to the internet can be guaranteed 100% secure. In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant regulatory authority (NITDA / applicable data protection authority) within 72 hours of becoming aware, in accordance with NDPR and GDPR breach notification requirements.

10

Your Privacy Rights

You have substantial rights over your personal data. Under the NDPR, GDPR, and other applicable data protection laws, you are entitled to the following:

Right to Access

You may request a copy of all personal data we hold about you, free of charge, within 30 days of your request.

Right to Rectification

If any data we hold about you is inaccurate or incomplete, you may request that it be corrected promptly.

Right to Erasure ("Right to be Forgotten")

You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, or where you withdraw consent. Legal retention obligations may prevent complete erasure in some cases.

Right to Restrict Processing

You may request that we restrict processing of your data (but not delete it) while a complaint or query is being investigated.

Right to Data Portability

You may request your data in a structured, machine-readable format (JSON or CSV) to transfer to another service provider.

Right to Object

You may object to processing of your data for direct marketing at any time. You may also object to processing based on legitimate interests where your specific situation warrants it.

Right Not to Be Subject to Automated Decisions

We do not make legally significant automated decisions about you using profiling. Our AI analytics produce business insights for you — not decisions about your access or legal rights.

Right to Withdraw Consent

Where processing is based on consent (e.g. marketing emails, optional cookies), you may withdraw that consent at any time without affecting the lawfulness of prior processing.

How to Exercise Your Rights

Contact us at +234 9072490013 or through the contact form at mpsev.com. We will acknowledge your request within 72 hours and fulfil it within 30 days. Identity verification may be required before we process requests that would affect account security. Requests are free of charge unless manifestly unfounded or excessive.


11

Children's Privacy

Primeventory is a professional business management platform designed exclusively for adults operating businesses. Our services are not directed at or intended for children under the age of 18 (or the applicable age of majority in your jurisdiction).

We do not knowingly collect personal data from anyone under 18 years of age. If you are under 18, please do not use Primeventory or provide us with any personal information. If you are a parent or guardian and believe a minor has submitted personal data to us, please contact us immediately at +234 9072490013. We will delete such data promptly upon verification.


12

International Data Transfers

Michael Prime Services is headquartered in Nigeria. Primeventory serves users globally. If you access the platform from outside Nigeria — including from the European Economic Area (EA), United Kingdom, or United States — your data may be transferred to and processed in Nigeria or on servers located in other countries where our infrastructure partners operate.

When we transfer data internationally, we ensure adequate protection is in place using one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to and from the EEA
  • Data Processing Agreements (DPAs) with all infrastructure and service partners
  • Transfers only to countries or processors whose data protection standards are deemed adequate by the relevant regulatory authority

13

Nigeria Data Protection Regulation (NDPR) Compliance

As a Nigerian company, Michael Prime Services fully complies with the Nigeria Data Protection Regulation (NDPR) 2019 as issued and enforced by the National Information Technology Development Agency (NITDA), and the Nigeria Data Protection Act (NDPA) 2023 where applicable.

Lawful Basis

We process personal data only where a lawful basis exists under the NDPR — including contract performance, consent, legal obligation, or legitimate interest.

Data Minimisation

We collect only the minimum data necessary for the stated purpose. We do not collect data speculatively or "just in case."

Purpose Limitation

Personal data collected for one purpose is not repurposed for an incompatible purpose without fresh consent or legal justification.

Accountability

We maintain written records of our data processing activities and have designated an internal data protection officer responsible for NDPR compliance.

Data Subject Rights

We honour all NDPR data subject rights including access, correction, objection, and deletion — exercisable via the contact details in Section 15.

Cross-Border Transfers

International transfers of Nigerian residents' data are conducted only when the receiving country ensures adequate data protection, or appropriate safeguards are in place.

If you are a Nigerian resident and believe your data rights have been violated, you may file a complaint with NITDA at www.nitda.gov.ng in addition to contacting us directly.


14

Changes to This Policy

We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will notify you by:

  • Posting the updated policy at https://store.mpsev.com/privacy with an updated date at the top of this page
  • Sending an email notification to all registered account holders for changes that materially affect their rights
  • Displaying a prominent banner on the platform for at least 14 days following significant changes

Your continued use of Primeventory after any changes become effective constitutes your acceptance of the updated policy. If you do not agree with the updated terms, you should discontinue use and may request deletion of your account and data.

15

Contact Us

For any privacy-related questions, data subject rights requests, or concerns, please contact us through any of the following channels. We are committed to responding promptly and resolving all legitimate concerns.

Phone / WhatsApp

+234 9072490013

Company Website

mpsev.com

Platform

store.mpsev.com
Response Times: We acknowledge all privacy requests within 72 hours and aim to fully resolve them within 30 calendar days. All communication is conducted in English.

Also review our companion legal document:

Terms & Conditions →

Privacy Policy v1.1

Last Updated: June 18, 2026

Questions About Our Privacy Practices?

We're transparent about how we handle your data. Contact our team directly — we'll respond within 72 hours.