Legal

Security Policy

The technical and organisational controls we operate to keep customer accounts, funds and data safe.

Last updated August 1, 2026

This page is maintained by Bells Technologies Limited. It describes controls currently enabled in our platform — it is not an independent certification.

1. Scope

This policy covers the Bellspay web application, our backend services and the payment integrations used to move customer funds. It applies to all Bellspay staff, contractors and administrators with access to production systems.

2. Account protection

  • Email and password sign-in with hashed credentials — passwords are never stored in plain text.
  • A separate transaction PIN is required for every wallet debit, transfer and bill payment.
  • PIN attempts are rate-limited and the account locks after repeated failures; if lockout state cannot be verified, money-moving actions are blocked.
  • A 4-digit transaction PIN, independent of your password, required to approve sensitive actions.
  • Password reset links are single-use and expire automatically.

3. Data protection

  • All traffic between your device and Bellspay is encrypted in transit using modern TLS.
  • Data at rest is stored on managed, encrypted infrastructure.
  • Row-level access rules ensure a signed-in user can only read and write their own records.
  • Bellspay never stores full card numbers, CVVs or card PINs. Card data is captured and processed entirely by our payment processor.

4. Payments and settlement

Funding, payouts and bill payments are executed through established payment processors and value-added service aggregators. Provider callbacks are signature-verified before any balance is changed, and every ledger movement is written with an idempotent reference to prevent duplicate credits or debits.

5. Monitoring and reconciliation

  • Automated reconciliation re-queries providers for any transaction left pending and settles or refunds it.
  • Administrative actions are recorded in an immutable audit log.
  • Failed refunds are queued, retried and surfaced to the operations team until resolved.

6. Access control

Production access is restricted to a small number of named administrators, granted on a least-privilege basis and reviewed periodically. Administrative privileges are role-based and revocable, and privileged actions are logged with the acting administrator's identity.

7. Incident response

Suspected security incidents are triaged immediately. Where an incident affects customer data or funds, we contain the issue, restore correct balances, and notify affected users and the relevant authorities in line with Nigerian data protection requirements.

8. Your responsibilities

  • Never share your password, PIN or one-time codes — Bellspay staff will never ask for them.
  • Use a unique password and keep your transaction PIN private.
  • Report a lost device or suspicious transaction immediately so we can freeze the wallet.

9. Reporting a vulnerability

We welcome responsible disclosure. Email bellspaytechnologies@gmail.com with the subject "SECURITY" and include reproduction steps. Please do not access other users' data, degrade the service, or publish the issue before we have responded.

10. Contact

Security team: bellspaytechnologies@gmail.com · WhatsApp 09020270783.