Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how Waves ("we", "us", "our") collects, uses, shares, and protects your personal information when you use the Waves website, apps, the Wave Connect Telegram experience, and related services (the "Service"). We are committed to handling your data responsibly and in line with the Nigeria Data Protection Act ("NDPA") and other applicable laws.
By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
1. Information we collect
You give us:
- Account details — name, email and/or phone number, password (stored hashed), and authentication identifiers (e.g. Google or phone sign-in).
- Profile information — gender, date-of-birth / age confirmation, location (country, state, city), bio, interests, and preferences.
- Photos and video — profile photos and any intro or content media you upload.
- Verification media — the live selfie and short liveness video you submit to get verified.
- Communications — messages you send through the Service and to our support team, and reports you file.
Collected automatically:
- Usage data — features used, interactions, and activity timestamps.
- Device & technical data — device type, browser, IP address, and app/version, used for security and to operate the Service.
- Approximate location — derived from the city/state/country you select (we do not track precise GPS in the background).
From third parties:
- Sign-in providers (e.g. Google/Firebase) — basic profile data you authorise.
- Payment processors (e.g. Paystack) — confirmation of payment status. We do not collect or store your full card details; those are handled by the processor.
2. How we use your information
- To create and manage your account and profile.
- To verify that members are real people and to display verified badges.
- To provide core features — discovery, matching, messaging, events, creator content, and subscriptions.
- To process payments and prevent fraud.
- To keep the community safe — detecting fake profiles, spam, abuse, and policy violations, and reviewing reports.
- To communicate with you about the Service, security, and (where permitted) updates.
- To comply with legal obligations and enforce our Terms of Use.
3. Legal bases
We process your data on the bases of: performance of our contract with you (to provide the Service); your consent (e.g. verification media, optional communications); our legitimate interests (safety, fraud prevention, improving the Service); and compliance with legal obligations.
4. How we share information
We do not sell your personal data. We share it only:
- With other members — your profile, photos, and the information you choose to make visible. Verification media (your selfie/video) is not shown to other members; it is used for review only.
- With service providers who process data on our behalf under contract — for example media hosting (Cloudinary), payments (Paystack), authentication (Firebase), and infrastructure/hosting providers.
- For safety and legal reasons — to comply with the law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and property of members, the public, or Waves.
- In a business transfer — if Waves is involved in a merger, acquisition, or asset sale, subject to this Policy.
5. Verification data
Your verification selfie and liveness video are used to confirm authenticity. They are accessible only to authorised reviewers and systems, are not published to your profile, and are retained only as long as needed for verification, safety, and dispute purposes, after which they are deleted or anonymised.
6. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records (e.g. for legal, safety, or financial compliance).
7. Your rights
Subject to applicable law, you may:
- Access, correct, or update your information (much of it directly in the app).
- Delete your account and associated personal data.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Request a copy of your data (portability).
To exercise these rights, use in-app settings or contact privacy@meetbywave.com. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local data protection authority.
8. Security
We use technical and organisational measures — encryption in transit, access controls, and hashed passwords — to protect your data. No system is perfectly secure, so we cannot guarantee absolute security. Please use a strong password and keep your login confidential.
9. Cookies and similar technologies
We use essential cookies and local storage to keep you signed in, remember preferences, and operate the Service. We may use limited analytics to understand usage. You can control cookies through your browser, though some features may not work without them.
10. Children
The Service is for adults 18 and older only. We do not knowingly collect data from anyone under 18. If you believe a minor is using the Service, contact safety@meetbywave.com and we will act promptly. See our Age Policy.
11. International transfers
Your data may be processed in countries other than your own, including where our service providers operate. Where we transfer data internationally, we take steps to ensure it is protected consistent with this Policy and applicable law.
12. Changes to this Policy
We may update this Policy from time to time. If changes are material, we will notify you in-app or by email. The "Last updated" date reflects the latest version.
13. Contact
Questions or requests about privacy? Contact privacy@meetbywave.com.