Encrypted in transit
Every connection to and from Tajami uses modern TLS — between the platforms, our servers, the payment partner and your phone. Nothing travels in the clear.
Tajami › Security
Security & complianceYour customers trust you with their messages, their addresses and their money. So Tajami connects only to your business account, never sees a card number, and encrypts everything it holds. Here is exactly what that means — what is built, what comes before launch, and what we will not claim.
To answer your customers, Tajami has to read what they send your business. That is the whole of it — and some things are out of reach by design, not by promise.
Every connection to and from Tajami uses modern TLS — between the platforms, our servers, the payment partner and your phone. Nothing travels in the clear.
Messages, catalogues, orders and backups are encrypted where they are stored, with keys kept in a managed key service — never in code.
The token that links your business account is encrypted separately, and you can revoke it in one tap, from Tajami or from the platform itself.
Every record is tied to your business and checked in the database itself. One seller’s data never informs another’s answers or reports.
Nobody at Tajami browses your chats. Support sees a conversation only with your consent, for a set time, and every access is logged.
The AI providers we use are contracted not to train on your data, and only the context one answer needs is ever sent to them.
Your business account is your livelihood, so the locks are yours to hold.
The same periods the privacy policy sets out, enforced by scheduled deletion rather than by someone remembering.
| What | How long |
|---|---|
| Customer messages and order history | As long as you keep them; deleted when you delete them or close your account |
| Your account, after you close it | Up to 90 days, so you can come back or export, then deleted |
| Payment and billing records | As long as tax and financial law requires — usually six years |
| Security logs | Up to 12 months |
No system is perfectly secure, and pretending otherwise is how trust is lost. This is what happens if something affects your data.
The cause is stopped and the evidence kept, by a named lead who is on call at every hour.
What happened, what data, what we have done, and what you should do — including what you need to tell your own customers, if anything.
Within the time the Nigeria Data Protection Act requires, and the same for each market we operate in.
A review within two weeks, and for anything that affected sellers, a plain summary of what we changed so it cannot happen the same way again.
Tajami is being built now. This page says only what is true today, and it is updated as each piece ships.
Encryption in transit and at rest, sealed connection tokens, each seller walled off, no card data, no standing staff access, and no customer details written to logs.
An independent penetration test, with every critical finding fixed first. Two-step required for owners, the activity log, export, a public status page, a data protection impact assessment and a named data protection officer.
Tajami claims no security certification yet. When an independent audit is under way, this page will say so, and name the auditor.
Write to security@tajami.com with what you found, how to reproduce it, and how to reach you.
/.well-known/security.txtContact: mailto:security@tajami.com
Policy: https://tajami.com/security#report
Preferred-Languages: en
Canonical: https://tajami.com/.well-known/security.txt
No, and any service that answers your messages for you cannot honestly say it is. WhatsApp chats are end-to-end encrypted between people; when a customer messages a business that uses software to answer, the platform delivers the message to that software so it can reply. From there, Tajami keeps it encrypted in transit and at rest, readable only by the systems that answer it and by you.
Not by default. Nobody has standing access. Support can open a conversation only when you grant it, for a set time, and every access is logged. The only exceptions are a legal requirement or an active security incident, and those are logged too.
With cloud providers, some of which store or process data outside Nigeria. Where that happens, the safeguards the law recognises apply, as the privacy policy explains.
Sign in from another device and sign out everywhere in one tap. Two-step sign-in stops a stolen phone alone from getting in, and changing payout details asks you to confirm again and holds the first payout.
Yes. You can delete a customer’s conversations and details from your account, and it is removed from Tajami too. Records the law requires us to keep, like payments, are kept only for as long as it requires.
Disconnecting stops all access at once. If you close your account, your data is kept for up to 90 days so you can come back or export it, and then deleted.