Bid-A-Lot

Sign in to bid, sell, and track your orders.

Sign inRegister

Privacy Policy

Last updated: 2026-05-07

Welcome to Bid-A-Lot, Ghana's mobile auction platform ("we," "us," or "our"). We are committed to protecting your privacy and handling your personal data with transparency and care.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Bid-A-Lot mobile application and related services (the "Platform"). By using Bid-A-Lot, you agree to the practices described in this Privacy Policy.

This Privacy Policy is designed to comply with Ghana's Data Protection Act, 2012 (Act 843). Your rights are detailed in Section 9 below.

1. Information We Collect

1.1 Information You Provide Directly

When you register and use Bid-A-Lot, you provide us with:

  • Phone Number: Your Ghanaian mobile phone number (required for account creation and serves as your primary identifier)
  • Full Name: Your legal name as it appears on your identification documents
  • Display Name: The public name shown to other users on the Platform
  • Email Address: Optional, used for account recovery and important notifications
  • Profile Picture: Optional photo that appears on your public profile

1.2 Seller Payout Data

If you choose to receive payouts as a seller, we collect your Mobile Money account details (account number and network provider) solely for processing seller payouts through Paystack.

1.3 Transaction and Auction Data

When you participate in auctions, we collect:

  • Auction Listings: Item descriptions, photographs, category, condition, location, pricing, and duration
  • Bidding Activity: Bid amounts, timestamps, and auction participation history
  • Delivery Addresses: Shipping addresses you provide when you win an auction
  • Payment Information: Transaction records, payment amounts, and payment method types (we do NOT store your actual payment card numbers or MoMo PINs — these are handled securely by Paystack)

1.4 Communications and Dispute Data

  • Dispute Evidence: Photos, descriptions, and other evidence you submit when opening or responding to a dispute
  • Reviews and Ratings: Feedback you provide about other users after completing transactions

1.5 Automatically Collected Information

When you use the Platform, we automatically collect:

  • Device Information: Device type, operating system version, unique device identifiers
  • Usage Data: Features you use, screens you view, time spent on the Platform, and interaction patterns
  • Location Data: Your general region within Ghana (derived from your account settings and delivery addresses, not precise GPS tracking)
  • FCM Tokens: Firebase Cloud Messaging tokens to enable push notifications on your device

2. How We Use Your Information

2.1 To Provide and Improve Our Services

  • Create and manage your account
  • Facilitate auction listings, bidding, and transactions
  • Process payments through Paystack
  • Arrange platform-managed shipping and delivery
  • Manage escrow funds and ensure secure transactions
  • Improve Platform features and user experience

2.2 For Security and Compliance

  • Prevent fraud, unauthorised access, and prohibited activities
  • Detect and investigate suspicious behaviour or policy violations
  • Enforce our Terms of Service

2.3 For Communication

  • Send transactional notifications via push notifications (FCM) and SMS (Nalo Solutions)
  • Notify you about auction activity (outbid alerts, auction ending, auction won)
  • Send payment confirmations and shipping updates
  • Communicate dispute status and resolutions
  • Provide customer support and respond to your inquiries

2.4 For Business Operations

  • Process subscription payments and manage seller subscription tiers
  • Calculate and collect platform commission fees
  • Generate financial reports and analytics
  • Comply with legal obligations and regulatory requirements

3. How We Store and Protect Your Data

3.1 Data Storage Infrastructure

We use industry-leading cloud services to store your data securely:

  • Firebase Authentication: Manages your account credentials and phone number verification
  • Cloud Firestore: Stores real-time auction data, bids, user profiles, notifications, and feed information
  • Firebase Storage: Stores profile pictures and auction item photos

3.2 Security Measures

  • Encryption: All data transmitted between your device and our servers is encrypted using TLS/SSL protocols
  • Access Controls: Strict role-based access controls limit who can view sensitive data, including verification documents and dispute evidence
  • Payment Security: We never store your payment card numbers or MoMo PINs. All payment processing is handled by Paystack, which is PCI-DSS compliant
  • Monitoring: We continuously monitor for suspicious activity and unauthorised access attempts

3.3 Data Retention

  • Active Accounts: Data is retained while your account is active
  • Auction Data: Auction listings and bid history are retained for 7 years for dispute resolution and regulatory compliance
  • Financial Records: Transaction records, payment history, and escrow data are retained for 7 years as required by Ghanaian financial regulations
  • Deleted Accounts: We remove or anonymise your personal data within 90 days, except where retention is required by law

4. Third-Party Services

We work with trusted third-party service providers to deliver our Platform. These providers have access to certain personal data only to perform specific tasks on our behalf and are obligated to protect your information.

4.1 Nalo Solutions (SMS Provider)

  • Purpose: Send OTP codes for phone verification and transactional SMS notifications
  • Data Shared: Phone number, message content (OTP codes, auction notifications, payment confirmations)
  • Location: Ghana

4.2 Paystack (Payment Processor)

  • Purpose: Process payments, manage escrow, handle seller payouts, and process subscription billing
  • Data Shared: Name, phone number, email, payment amounts, MoMo account details (for payouts)
  • Security: Paystack is PCI-DSS Level 1 certified and handles all sensitive payment data
  • Location: Nigeria (with operations across Africa)

4.3 Firebase / Google Cloud Platform

  • Purpose: Authentication, database, file storage, and push notifications (FCM)
  • Security: ISO 27001, SOC 2, and SOC 3 certified
  • Location: Europe and United States data centres

5. Data Sharing and Disclosure

5.1 Public Information

The following information is publicly visible to other users:

  • Display name and profile picture
  • Auction listings (title, description, photos, location, pricing)
  • Reviews and ratings you receive
  • Seller statistics (total auctions, average rating)

5.2 Between Transaction Parties

When you participate in a transaction, certain information is shared between buyer and seller:

  • Display names
  • Delivery address (shared with seller after payment is confirmed)

5.3 Legal Requirements

We may disclose your personal data if required by law or in response to valid legal processes, requests from law enforcement, or to protect the rights, property, or safety of our users.

5.4 Business Transfers

If Bid-A-Lot is involved in a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity. We will notify you of any such change.

6. Push Notifications and SMS

6.1 Push Notifications (FCM)

We use Firebase Cloud Messaging to send real-time push notifications about outbid alerts, auction ending soon, auction won, payment received, item shipped/delivered, and dispute updates.

You can disable push notifications in your device settings or within the app. Note that disabling notifications may affect your ability to participate effectively in time-sensitive auctions.

6.2 SMS Communications (Nalo Solutions)

We send SMS for critical transactional events: OTP codes, auction won confirmations, payment confirmations, item dispatched notifications, and dispute outcomes.

You cannot opt out of transactional SMS messages such as OTP codes, as they are essential for Platform security.

7. Cookies and Tracking

The Bid-A-Lot mobile app does not use traditional web cookies. We use local storage to cache data and improve performance, Firebase Analytics (anonymised usage patterns) to understand how users interact with the Platform, and Firebase Authentication tokens to keep you logged in securely.

8. Children's Privacy

Bid-A-Lot is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you are under 18, you may not create an account or use the Platform.

If we become aware that we have collected personal data from a child under 18, we will take immediate steps to delete that information. Please contact us immediately if you believe a child has provided us with personal data.

9. Your Rights Under Ghana's Data Protection Act

Under Ghana's Data Protection Act, 2012 (Act 843), you have the following rights:

9.1 Right to Access

You have the right to request a copy of the personal data we hold about you. You can view most of your data directly in the app under Settings > Account Information.

9.2 Right to Rectification

You have the right to correct inaccurate or incomplete personal data. You can update your profile information, email, and delivery addresses directly in the app.

9.3 Right to Erasure

You have the right to request deletion of your personal data, subject to legal retention requirements. You can delete your account through Settings > Account > Delete Account.

9.4 Right to Object

You have the right to object to certain types of data processing, such as marketing communications.

9.5 Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format. Contact us to request a data export.

9.6 Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

9.7 How to Exercise Your Rights

Contact our Data Protection Officer using the information in Section 12 below. We will respond to your request within 30 days.

10. International Data Transfers

Your personal data may be transferred to and stored on servers located outside of Ghana, including Google Cloud Platform / Firebase (Europe and United States) and Paystack (Nigeria).

When we transfer your data internationally, we ensure appropriate safeguards are in place, including using service providers certified under internationally recognised security standards and implementing contractual protections (Data Processing Agreements).

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you via push notification or email.

Your continued use of the Platform after changes are posted constitutes your acceptance of the updated Privacy Policy.

12. Contact Us

For privacy-related inquiries, contact us:
Email: leslienarh@goharles.com
Phone: +233 26 804 9338
Address: Accra, Ghana

13. Consent

By creating an account and using Bid-A-Lot, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must not use the Platform.


© 2026 Bid-A-Lot. All rights reserved.