6membership6membershipA 6clement Joshua service™Legal & Trust Center
ID/Photo · Legal document

Application, Identity and Photograph Policy

Detailed terms governing applications, membership relationships, payment review, benefits, conduct, verification and status.

Version 0.9-draftUpdated 6 August 202618 sections110 detailed clauses
Statusdraft
Effective dateNot yet effective
Change typeinitial publication
ReacceptanceNot required yet
Before you continue

Understanding this document

This Application, Identity and Photograph Policy explains the identity information, applicant photographs, supporting documents and verification evidence that 6membership may request.

It also explains how identity materials may be collected, reviewed, matched, protected, corrected, retained, deleted and used to prevent impersonation, duplicate applications, card misuse and payment fraud.

6membership is a membership service operated by 6clement Joshua under the laws of the Federal Republic of Nigeria, with mandatory local privacy, consumer and statutory rights preserved where they apply.

Identity processing must remain consistent with the Nigeria Data Protection Act 2023, the Nigeria Data Protection Act General Application and Implementation Directive 2025 where applicable, and other binding privacy requirements governing the relevant person and processing activity.

Submitting an applicant photograph or identity document does not grant 6membership unrestricted ownership of the image or permission to use it for unrelated advertising, publicity, facial recognition or artificial-intelligence training.

This Policy must be read with the Membership Terms and Conditions, Privacy and Data Protection Notice, Membership Card, Certificate and Public Verification Policy and the other policies referenced throughout this document.

The submitted photograph must show the real applicant

The applicant photograph must be recent, recognisable and genuinely connected to the person applying. A stock image, celebrity image, artificial face, screenshot of another person, heavily altered image or photograph submitted without authority may cause the application to be paused, denied or investigated.

Scope

Who these Terms apply to

01

Individuals applying for Starter, Silver, Black, Platinum, Elite or another individual membership.

02

Primary representatives applying for a Family membership.

03

Primary representatives applying for a business, organisation, investor or strategic relationship.

04

Parents and guardians acting for a permitted younger applicant.

05

Associated persons whose details appear in an approved household or entity application.

06

Applicants asked to provide identity, age, address, authority or source-of-funds evidence.

07

Approved members requesting a photograph, name or card correction.

08

Persons reporting a lost, stolen, copied, altered or impersonated membership card.

09

Administrators and authorised reviewers handling application evidence.

10

Service providers supporting private storage, security, document delivery or verification.

Jump toDocument sections
1

Purpose and governing principles

Why identity verification exists and the standards that govern it.

1.1

Protecting membership integrity

Identity verification helps 6membership determine whether an application appears to concern the person, household, business or organisation represented.

It also helps prevent impersonation, duplicate applications, altered cards, unauthorised representation, stolen payment use and misuse of higher-tier relationships.

Verification is a risk-control process. It does not guarantee that every false document, impersonation attempt or identity error will always be detected.

1.2

Proportionate verification

The information requested should be proportionate to the selected tier, applicant category, age, payment value, geographic coverage, requested relationship and identified risk.

An ordinary Starter application should not automatically require the same evidence as a high-value Elite application, business relationship or private 6clement Joshua consideration request.

6membership may request stronger evidence where information is inconsistent, payment ownership differs, predecessor membership cannot be confirmed or fraud indicators are identified.

1.3

Data minimisation

Only information reasonably relevant to the verification purpose should be requested.

Applicants should not upload unrelated financial records, medical information, passwords, complete banking credentials or other unnecessary private information.

Where a document contains information that may lawfully be obscured without undermining verification, the upload instructions may permit appropriate redaction.

1.4

Fair and explainable review

A verification decision should consider the available evidence rather than relying only on a single visual impression, technical flag or formatting error.

Where reasonably possible, an applicant should receive an opportunity to correct a genuine quality problem or explain a material inconsistency before a final adverse decision.

This opportunity may be limited where there is credible fraud, impersonation, security risk, repeated evasion or a legal restriction.

1.5

Relationship with other policies

This Policy governs the collection and use of identity materials.

The Privacy and Data Protection Notice governs the broader processing of personal information.

The Membership Card, Certificate and Public Verification Policy governs approved cards, public status checks and card misuse.

Related documents
Membership Terms and ConditionsPrivacy and Data Protection NoticeMembership Card, Certificate and Public Verification Policy
2

Identity information that may be requested

The categories of information used to establish identity, age and authority.

2.1

Basic identity details

Basic identity information may include first name, middle name, last name, date of birth, age range, gender where relevant and lawful, nationality, country of residence and applicant category.

It may also include an Application Reference, existing Membership ID and information needed to distinguish the applicant from another person with a similar name.

2.2

Contact and address information

Verification may use a registered email address, telephone number, residential address, business address, city, state, region and country.

Proof of address may be requested where geographic coverage, payment review, legal obligations or the nature of the membership relationship makes it reasonably necessary.

2.3

Applicant photograph

A clear, recent and recognisable photograph of the applicant is ordinarily required.

The photograph may be used to support application review, identity matching, card production, duplicate detection, card replacement and impersonation investigations.

2.4

Identity and supporting documents

Where required, supporting evidence may include a government-issued identity document, passport, driving licence, national identity record, birth record, proof of address or another reliable document appropriate to the applicant and jurisdiction.

The acceptable document type may differ according to country, age, applicant category and verification purpose.

A document will not be requested merely because it is available where a less intrusive method is sufficient.

2.5

Parent and guardian evidence

A permitted younger applicant may require evidence concerning age, parent or guardian identity, relationship and authority.

The evidence may include a birth record, guardianship record, consent declaration or another document legally sufficient for the relevant jurisdiction.

2.6

Business and organisation evidence

An applicant acting for a business or organisation may be asked to provide registration information, operating address, representative identity, position, authorisation, beneficial-owner details or signatory evidence.

A person must not claim to represent an entity without appropriate authority.

2.7

Payer and transaction identity

Where the payer differs from the applicant or primary representative, 6membership may request the payer’s name, relationship, payment authority and a reasonable explanation.

For payments processed through Flutterwave, 6membership may receive and compare limited payer and transaction information returned by Flutterwave with the application record for payment verification, fraud prevention, refund handling and dispute resolution.

A Flutterwave transaction response, payer name, email address or payment-method category supports the relevant payment check but does not independently prove every aspect of legal identity or authority.

The purpose is to prevent unauthorised payment use, fraud, money laundering, unexplained third-party funding and refund disputes.

Related documents
Payments, Taxes, Refunds, Chargebacks and Renewals PolicyAnti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy
3

Applicant photograph requirements

The quality, authenticity and presentation standards for submitted photographs.

3.1

The real applicant

The photograph must show the actual person whose individual identity is connected to the application.

For a household, business or organisation application, the photograph must show the approved primary representative unless the form expressly requests another person.

A person must not submit a celebrity, public figure, family member, employee, customer or unrelated individual as the applicant image.

3.2

Recent and recognisable

The photograph should be sufficiently recent to represent the applicant’s current appearance.

The face should be recognisable and should not be hidden by excessive blur, darkness, glare, masks, hands, objects or extreme camera angles.

Reasonable religious, cultural, disability and medical accommodations will be considered where identity can still be verified appropriately.

3.3

One principal person

The photograph should ordinarily contain only the applicant.

Group photographs, event photographs and images in which the applicant cannot be clearly distinguished may be rejected for card and verification purposes.

3.4

Filters and material alteration

Minor adjustments for lighting, orientation or cropping may be acceptable where they do not misrepresent identity.

Beauty filters, face replacement, artificial ageing, artificial de-ageing, face reshaping, identity-changing retouching and comparable alterations are not permitted where they materially affect verification.

6membership may request an unfiltered replacement where the submitted image cannot be reliably assessed.

3.5

Artificial or synthetic images

An entirely artificial, synthetic or computer-generated face must not be submitted as an applicant photograph.

An artificial image representing a person who does not exist cannot establish a real membership identity.

An image generated from the applicant’s appearance may still be rejected where it does not faithfully and verifiably represent the applicant.

Synthetic identity prohibition

Creating a false applicant using an artificial face, stolen identity information or fabricated supporting documents is prohibited and may lead to denial, revocation, refund restriction, investigation or lawful reporting.

3.6

Screenshots and copied images

A screenshot of a social-media profile, membership card, printed photograph or another screen may be rejected where image quality or ownership cannot be established.

6membership may ask for a new photograph taken or uploaded directly by the applicant.

3.7

File quality and format

The application interface may impose supported file types, size limits, dimensions and quality requirements.

A file may be compressed, resized or rejected where it is excessively large, corrupted, unsupported or unsafe.

Compression and card cropping must not intentionally change the applicant’s identity or physical appearance.

3.8

Accessibility and reasonable accommodation

An applicant who cannot satisfy an ordinary photograph instruction because of disability, injury, medical condition, religious practice or another protected circumstance may request a reasonable alternative.

The alternative must still provide a sufficiently reliable method of confirming identity.

Related documents
Accessibility and Official Communications Policy
4

Identity-document requirements

Authenticity, validity, completeness and safe submission of supporting documents.

4.1

Authentic documents

A submitted document must be authentic and connected to the person or entity represented.

A document must not be forged, purchased, stolen, unlawfully obtained, digitally fabricated or altered to change a material fact.

A certified or translated copy may be requested where reasonably necessary.

4.2

Validity and expiry

Where the verification purpose requires a current document, an expired document may be rejected.

An expired document may still be considered for a limited historical fact where legally appropriate and supported by additional evidence.

4.3

Legibility and completeness

Required names, dates, document type, issuer, photograph and validity information must be sufficiently visible for the requested check.

A document may be rejected where glare, cropping, obstruction, low resolution or missing pages prevents reliable review.

4.4

Permitted redaction

Upload instructions may allow an applicant to obscure an identifier or field that is not necessary for the particular check.

Redaction must not hide the applicant’s identity, document authenticity, authority, validity or another fact relevant to the review.

6membership may request an unredacted or differently redacted version where the submitted copy cannot support the verification purpose.

4.5

Document numbers

A complete national identity, passport, licence or registration number should not be displayed publicly on a membership card or public verification page.

Where a number is stored for verification, access should be restricted and a masked or partial version should be used where the full number is unnecessary.

4.6

Credentials that must never be submitted

Applicants must not submit email passwords, banking passwords, card security codes, complete card numbers, account PINs, email OTPs or authentication secrets as identity evidence.

An authorised reviewer must not request those credentials.

Protect authentication credentials

An email OTP may be entered only into the official verification interface for the action it authorises. It must not be forwarded to a reviewer, social account or third party.

4.7

Translations

Where a document is not written in a language supported by the review process, 6membership may request a reliable translation.

The original document may also be required so that the translation can be connected to its source.

For higher-risk decisions, a certified translation may be requested.

5

Representatives, households and younger applicants

Additional verification where one person acts for another.

5.1

Authority to act

A person providing identity information about another person must have an appropriate legal or authorised basis to do so.

6membership may request evidence that a guardian, household representative, business representative, authorised agent or legal representative is permitted to act.

5.2

Family and household applications

A Family application ordinarily identifies one primary adult representative.

The representative may provide limited information concerning approved household members where appropriately authorised.

Household information must not be used to add unrelated persons or create unauthorised individual memberships.

5.3

Applicants under 13

A child under 13 must not independently submit identity information or a membership application.

Where an authorised process permits limited information concerning a child, the information must be supplied and managed by an appropriately verified parent or guardian.

5.4

Applicants aged 13 to 17

Where participation is permitted, an applicant aged 13 to 17 may require verified parent or guardian involvement.

6membership may verify both the younger applicant and the parent or guardian.

The verification process should be proportionate to the selected tier, the younger applicant’s age and the applicable legal requirements.

5.5

Whose photograph is required

The younger applicant’s photograph may be required where the membership card will identify that applicant.

The parent or guardian may also be required to provide their own identity evidence to establish authority.

The guardian’s photograph must not be substituted for the younger applicant’s photograph on a card intended to identify the younger applicant.

5.6

Protection of younger applicants

Information concerning a younger applicant should be limited to the verification, consent, safety, administration and legal purposes that justify its collection.

A younger applicant’s photograph must not be used for unrelated promotion or public advertising merely because a guardian approved the membership application.

Related documents
Eligibility, Age and Guardian Consent PolicyPrivacy and Data Protection Notice
6

Collection and secure submission

The authorised channels through which identity evidence may be provided.

6.1

Official application interface

Identity photographs and documents should ordinarily be submitted through the official 6membership application or document-upload interface.

The interface should use secure transport and private storage appropriate to the sensitivity of the material.

6.2

Email submission

Identity evidence should not be sent by ordinary email unless 6membership specifically requests it through a verified official address and no safer approved route is reasonably available.

The request should identify the Application Reference and the exact evidence required.

Applicants should verify unexpected document requests before responding.

6.3

Social-media and messaging restrictions

Applicants should not send passports, identity cards, payment evidence or private photographs to an unverified social-media account, personal messaging account or unofficial representative.

A public social profile is not an approved identity-document storage channel.

6.4

Private document storage

Identity photographs and documents should remain in private storage rather than unrestricted public storage.

Where temporary signed access links are used, they should expire and should not be treated as permanent public addresses.

6.5

Browser and local storage

Complete identity documents and highly sensitive application evidence must not be stored in ordinary browser local storage merely for convenience.

Temporary client-side processing should be limited and cleared where reasonably possible after secure submission.

Related documents
Cookie and Tracking Technologies PolicySecurity, Account Access and Incident Response Policy
6.6

Unsafe files

Uploaded files may be checked for malware, unsupported formats, corruption or dangerous embedded content.

A file may be quarantined, rejected or removed where it creates a credible security risk.

7

Verification methods

The manual, documentary and technical methods that may support review.

7.1

Manual review

An authorised reviewer may compare the submitted photograph with identity documents, application information, prior membership records and other relevant evidence.

Manual review may consider whether the photograph appears consistent, whether names and dates align and whether the document appears complete and credible.

7.2

Email verification

A verification code or secure link may be used to confirm access to the registered email address.

Email verification confirms control of the email channel at that time. It does not independently prove every aspect of legal identity.

7.3

Existing-record matching

6membership may compare an application with prior applications, Membership IDs, payment records, guardian records, card reports and administrative history.

This supports predecessor-tier confirmation, duplicate detection and prevention of repeated evasion.

7.4

Document assessment

A document may be reviewed for visible consistency, issuer format, validity, alteration indicators and connection to the applicant.

6membership may request additional evidence where a document cannot be reliably assessed.

Acceptance of a document does not mean 6membership guarantees that the issuing authority will always regard it as valid.

7.5

Additional selfie or liveness evidence

A new selfie, short video or liveness step may be requested where impersonation risk, photograph age, document mismatch or another material concern justifies it.

The applicant will be informed of the purpose and expected use before completing the step.

A liveness or video check will not be introduced secretly through a standard photograph upload.

7.6

Independent verification providers

Where an approved third-party identity-verification provider is introduced, the applicant will be informed of the provider’s role and relevant processing information before the provider receives production identity evidence.

Only information reasonably necessary for the verification should be disclosed to the provider.

A new provider must be assessed for privacy, security, retention, international-processing and contractual requirements and added to the Third-Party Service Providers List where applicable.

A provider result or automated risk signal must not be treated as infallible proof of identity, fraud or ineligibility.

Related documents
Third-Party Service Providers List
7.7

No single method proves everything

An email OTP, photograph, identity document, payment record or public profile may support verification without independently proving every relevant fact.

6membership may consider several pieces of evidence together.

8

Biometric and automated identity processing

The boundary between ordinary photograph handling and biometric recognition.

8.1

Ordinary photographs

An ordinary applicant photograph is personal information.

A manual visual review or ordinary display of the photograph does not by itself mean that 6membership has created a biometric template.

The photograph must still receive appropriate privacy and security protection.

8.2

When biometric processing may arise

Biometric processing may arise where specific technical processing extracts facial geometry, templates, measurements or other characteristics for the purpose of uniquely identifying or authenticating a person.

Such processing may carry additional legal and security obligations.

8.3

No undisclosed facial-recognition system

This Policy does not authorise a hidden facial-recognition database or undisclosed biometric profiling system.

A standard photograph upload must not silently activate unrelated facial recognition, emotion analysis or behavioural classification.

Separate assessment required

Before introducing biometric templates or automated facial recognition, 6membership must assess necessity, proportionality, lawful basis, security, retention, individual rights and any required impact assessment or consent.

8.4

Additional notice

Where biometric identity processing is introduced, the applicant will receive an additional notice describing the technology, provider, purpose, lawful basis, retention, sharing and available rights.

The notice will distinguish required verification from optional processing.

8.5

Human review of material decisions

A final denial, suspension or revocation should not be based solely on an unexplained automated facial-match result where applicable law requires meaningful human involvement.

A mismatch may be reviewed together with image quality, document condition, accessibility needs and the applicant’s explanation.

8.6

No unrelated artificial-intelligence training

Applicant photographs and identity documents must not be used to train a general artificial-intelligence, facial-recognition or image-generation model merely because they were submitted for membership verification.

A materially different research or model-training use would require a separate legal assessment, transparency and any permission required by applicable law.

Related documents
Privacy and Data Protection NoticeCountry-Specific Privacy Rights Addendum
8.7

Impact assessment before high-risk identity technology

Before deploying facial-recognition, biometric-template, automated liveness, large-scale identity-matching or another high-risk identity technology, 6membership must assess necessity, proportionality, data minimisation, security, retention, individual rights, provider access and foreseeable harm.

A Data Privacy Impact Assessment or equivalent assessment will be completed where required by the Nigeria Data Protection Act, the General Application and Implementation Directive or another applicable law.

The assessment must consider whether the same verification purpose can reasonably be achieved with less intrusive information or a less intrusive method.

Where the processing concerns a child or another vulnerable person, the assessment must address the additional risks and safeguards relevant to that person.

9

Duplicate, impersonation and fraud checks

How identity materials may be used to protect the application system.

9.1

Duplicate applications

6membership may compare names, photographs, email addresses, Membership IDs, household relationships, payment references and device or network indicators to identify possible duplicate applications.

A duplicate indicator does not automatically establish wrongdoing.

Legitimate duplicates may arise from an abandoned application, correction attempt, household relationship or technical failure.

9.2

Restriction evasion

Creating a new identity, altering a photograph, changing minor name details or using another payer to avoid a denial, suspension, predecessor requirement or verification request is prohibited.

9.3

Impersonation investigation

Where impersonation is suspected, 6membership may preserve relevant application, photograph, document, payment, communication and technical records while the matter is investigated.

Access to the investigation record should remain restricted.

9.4

Protecting identity-theft victims

A person reporting that their photograph, name, document or payment method was used without authority may be asked to verify their own identity.

6membership may restrict the disputed application or card while protecting the reporter’s information from the suspected impersonator.

9.5

Lawful reporting

Credible identity theft, forged documents, stolen payment use or serious fraud may be reported to payment providers, affected persons, regulators or lawful authorities where permitted or required.

Any disclosure should be proportionate to the incident and applicable law.

Related documents
Anti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds PolicyLaw-Enforcement, Regulatory and Government Requests PolicySecurity, Account Access and Incident Response Policy
10

Review outcomes and additional evidence

What may happen after identity evidence is assessed.

10.1

Verification accepted

Verification may be marked as accepted where the evidence reasonably supports the required identity, age, authority or eligibility check.

Acceptance concerns the check performed and does not by itself guarantee membership approval.

10.2

More information required

The application may be paused where the photograph is unclear, information is inconsistent, a document is incomplete or additional authority evidence is reasonably necessary.

The request should identify the issue and the replacement or explanation required without disclosing confidential fraud controls.

10.3

Unable to verify

6membership may be unable to verify an applicant where reliable evidence cannot be obtained or material inconsistencies remain unresolved.

An inability to verify may result in delay, cancellation or denial according to the Membership Terms.

10.4

Suspected fraud or impersonation

Where there is credible evidence of forgery, impersonation, stolen identity or deliberate evasion, the application may be restricted without providing details that would enable circumvention.

Relevant records may be preserved and escalated for security, payment, legal or regulatory review.

10.5

No unnecessary public accusation

A verification concern will not ordinarily be published publicly merely because an application was paused or denied.

Public card status may show that a Membership ID is invalid, restricted or revoked without publishing confidential investigation details.

10.6

Correction and appeal

Where an appeal or correction process is available, the applicant may provide better evidence or explain a material error.

An appeal does not require 6membership to accept evidence that remains unreliable, unlawful or unrelated.

Related documents
Membership Terms and ConditionsComplaints, Appeals and Dispute Resolution Policy
11

Membership cards, certificates and photographs

How an approved photograph may appear in membership materials.

11.1

Approved card photograph

After approval, the verified applicant photograph may be used to generate a digital or physical membership card where the card design includes a photograph.

The image may be cropped, resized, compressed or placed against a standard card background.

These production changes must not intentionally alter the holder’s identity or physical characteristics.

11.2

Household and entity cards

A Family, business or organisation card may identify the approved primary representative, the approved entity or both according to the applicable card design.

A logo must not be substituted for a representative photograph where human identity verification is required.

11.3

Photograph in public verification

A limited approved photograph may be displayed in a public verification result only where reasonably necessary to confirm that the presented card relates to the approved holder.

The public image should use an appropriate size and quality rather than exposing the original full-resolution upload.

Identity documents, document numbers and private application photographs must not be displayed publicly merely because a Membership ID is checked.

11.4

Outdated photographs

6membership may request a new photograph where the existing image no longer provides reliable recognition.

A materially changed appearance, long membership duration, card replacement or security concern may justify re-verification.

11.5

Invalidated cards

When a card is replaced, reported stolen, revoked or materially corrected, the previous card version may be invalidated.

A saved image of the previous card does not override the current official status.

Related documents
Membership Card, Certificate and Public Verification Policy
12

Permitted and prohibited uses of identity materials

The purposes for which photographs and documents may and may not be used.

12.1

Permitted purposes

Identity materials may be used for application review, identity matching, age or authority confirmation, duplicate detection, payment review, membership-card production, public verification, fraud prevention, security investigations, complaints and legal compliance.

Each use must remain connected to an appropriate legal basis and the relevant policy framework.

12.2

No automatic advertising permission

Submitting an applicant photograph does not authorise its use in advertisements, public endorsements, social-media campaigns, testimonials, promotional banners or unrelated announcements.

An unrelated promotional use requires separate permission or another legally sufficient basis.

12.3

No sale of identity documents

6membership does not intend to sell applicant identity documents or private verification photographs for money.

Identity materials must not be exchanged with advertisers, data brokers or unrelated third parties for commercial profiling.

12.4

No unrestricted public identity gallery

Private application photographs and documents must not be placed into an unrestricted public gallery.

A limited card or verification display is governed by the approved membership purpose and does not make the original application file public.

12.5

No casual personal-device storage

Authorised reviewers should not download or retain identity documents on personal devices, personal cloud accounts or informal messaging applications without an approved operational need and appropriate safeguards.

13

Sharing and service providers

The limited circumstances in which identity materials may be disclosed.

13.1

Authorised personnel

Identity materials may be accessed by authorised application, verification, security, compliance or administrative personnel whose role requires the information.

Access should follow the principle of least privilege.

13.2

Infrastructure and storage providers

Private storage, database, hosting and security providers may process identity materials to deliver their assigned services.

The provider should receive only the access and information reasonably necessary for its role.

13.3

Verification providers

An approved identity-verification provider may receive photographs, documents or identity fields where the provider is intentionally used for the relevant check.

The provider’s role, location, retention and independent legal responsibilities should be assessed before production use.

13.4

Payment, legal and authority disclosures

Limited identity information may be disclosed to Flutterwave, a participating financial institution, professional adviser, regulator, court or lawful authority where reasonably necessary and legally permitted.

Information shared with Flutterwave should be limited to the payment, payer, transaction, fraud, refund, chargeback or compliance purpose for which it is needed.

A disclosure should be limited to the relevant purpose rather than transmitting the complete application without need.

13.5

Identity-theft and impersonation reports

Where a person credibly reports unauthorised use of their identity, 6membership may disclose limited information necessary to investigate and protect the affected person.

Information that would expose another individual unnecessarily or prejudice an investigation may remain restricted.

Related documents
Third-Party Service Providers ListLaw-Enforcement, Regulatory and Government Requests Policy
14

Security and access controls

Safeguards intended to protect sensitive identity evidence.

14.1

Private access

Identity documents and original applicant photographs should remain private by default.

Public access must be limited to the specific card or verification fields approved for public display.

14.2

Role-based permissions

Application reviewers, verification administrators, payment reviewers and system administrators should receive only the permissions necessary for their assigned responsibilities.

A person permitted to view a document should not automatically have authority to approve membership, issue a refund, alter status or permanently delete records.

14.3

Audit records

Material access, export, replacement, approval, denial, restriction and deletion actions may be recorded in an administrative audit trail.

Audit logs should identify the authorised actor, action, record, time and relevant reason where appropriate.

14.4

Secure transmission

Identity materials should be transmitted through encrypted connections and approved interfaces.

Temporary links should expire and should not be publicly indexed.

14.5

Server-only credentials

Storage secrets, privileged database credentials, email-provider secrets, Flutterwave secret credentials, webhook-signature secrets, encryption keys and administrative credentials must remain server-side.

They must not be embedded in a photograph URL, browser bundle, public repository, local storage record, client-visible source code, application log or downloadable asset.

14.6

Identity-data incidents

A suspected exposure, unauthorised download, altered document or misuse of identity evidence may be investigated under the security incident process.

Affected persons and regulators will be notified where applicable law requires notification.

Related documents
Security, Account Access and Incident Response Policy
15

Retention, deletion and legal preservation

How long identity materials may remain and why some records cannot be removed immediately.

15.1

Purpose-based retention

Identity materials should be retained only for the period reasonably necessary for application review, membership administration, card production, fraud prevention, complaints, legal obligations and related purposes.

The original identity document may have a shorter active-access period than the core membership or verification record.

For processing governed by the Nigerian framework, where no separate time-bound legal obligation applies after the original purpose has been accomplished, continued storage must be assessed against the storage-limitation requirements of the Nigeria Data Protection Act General Application and Implementation Directive 2025.

Where continued storage beyond an ordinary purpose-completion period is justified by fraud prevention, legal claims, security, membership verification or another lawful purpose, the justification, safeguards and any required Data Privacy Impact Assessment should be documented rather than assuming indefinite retention.

15.2

Incomplete applications

An incomplete application photograph or document may be retained temporarily to allow completion and diagnose technical problems.

Unnecessary draft material may later be deleted or anonymised according to the retention schedule.

15.3

Denied or cancelled applications

A denied or cancelled application may retain limited identity evidence where necessary for refund administration, fraud prevention, appeal handling, repeated-evasion prevention or legal claims.

Full identity documents should be deleted or reduced when the original verification purpose has ended unless a documented continuing purpose, applicable retention requirement, active dispute, investigation or legal hold justifies continued storage.

Continued retention must not become permission for unrelated use.

15.4

Approved memberships

The approved card photograph and core verification result may remain throughout the active membership and for an appropriate period afterwards where necessary for card production, verification, status history, fraud prevention or disputes.

Full identity documents should be reduced or deleted earlier where the continuing membership purpose can be supported by verified fields, an audit result or a limited derivative instead of the complete source document.

This distinction allows 6membership to preserve necessary membership evidence without retaining a full identity document longer than justified.

15.5

Superseded photographs and documents

When a photograph or document is replaced, the earlier file may be removed from ordinary access.

A restricted historical copy or audit record may remain where necessary to explain a card version, correction, fraud concern or legal decision.

15.6

Legal holds and investigations

Deletion may be paused where identity evidence is relevant to a complaint, chargeback, impersonation report, security incident, regulatory request, court process or legal claim.

A legal hold should restrict ordinary use while preserving the evidence required for the matter.

15.7

Backups

Deletion from active storage may not immediately remove every encrypted backup copy.

Backup copies may expire under controlled backup cycles and should remain unavailable for ordinary application review.

Related documents
Data Retention, Deletion and Records Policy
16

Corrections, updates and replacements

How applicants and members correct inaccurate identity or photograph records.

16.1

Correction before a decision

An applicant should promptly report an incorrect name, date of birth, photograph, representative or document before the application is decided.

The correction may require re-verification and a new declaration.

16.2

Name changes

A material legal-name change may require reliable supporting evidence.

The current name may be updated while the previous name remains in a restricted historical record where necessary to connect payments, applications, predecessor memberships or legal records.

16.3

Photograph replacement

A member may request a replacement where the original photograph is incorrect, outdated, compromised or no longer sufficiently recognisable.

6membership may also request an updated photograph during renewal, card replacement, security review or significant appearance change.

16.4

Card reissuance

A corrected name or photograph may require a new card version.

The previous card may be invalidated to prevent continued use of the outdated identity record.

Replacement fees, where applicable, must be disclosed before payment.

16.5

Fraudulent correction requests

A correction process must not be used to transfer a membership to another person, replace the approved holder with an unrelated person or conceal earlier fraud.

A material identity change may require a new application rather than an ordinary correction.

16.6

Privacy correction rights

A person may also exercise applicable privacy rights concerning inaccurate identity information.

Historical records may be preserved where they accurately show what was submitted or decided at an earlier time.

Related documents
Country-Specific Privacy Rights AddendumMembership Card, Certificate and Public Verification Policy
17

Prohibited identity conduct

Conduct that undermines verification, membership records or another person’s rights.

17.1

False identity

A person must not apply using a false identity, synthetic identity, stolen identity, deceased person’s identity or another person’s information without authority.

17.2

Forgery and alteration

A person must not forge, edit, manufacture, purchase or alter a document or photograph to misrepresent name, age, appearance, nationality, address, authority, validity or eligibility.

17.3

Identity substitution and transfer

A member must not replace their photograph with another person’s image, lend identity evidence or use a correction request to transfer membership.

17.4

Reviewer misconduct

An authorised reviewer must not copy, distribute, ridicule, publish, sell, threaten with or privately exploit an applicant’s photograph or document.

A reviewer must not request unauthorised payment or personal favours in exchange for approval.

17.5

Verification bypass

A person must not interfere with upload controls, submit malicious files, manipulate verification records, bribe a reviewer or use technical methods to bypass identity requirements.

17.6

Possible consequences

Prohibited conduct may result in application denial, membership restriction, card invalidation, revocation, refund review, payment dispute handling, evidence preservation or lawful reporting.

Any consequence remains subject to applicable law and the relevant policy.

Related documents
Acceptable Use, Code of Conduct and Non-Discrimination PolicyMembership Terms and ConditionsAnti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy
18

Rights, complaints and official contacts

How applicants challenge an identity record or report misuse.

18.1

Access and correction rights

Depending on applicable law, a person may request access to identity information, correction of inaccurate information, deletion, restriction, objection or another available privacy right.

The request may require identity verification before protected information is disclosed or changed.

18.2

Deletion limitations

A deletion request does not automatically require removal of evidence needed for fraud prevention, card invalidation, payment records, legal claims, regulatory duties or protection of another person.

Where complete deletion is unavailable, access or ordinary use may be restricted where appropriate.

18.3

Reporting identity theft or impersonation

A person who believes their identity, photograph, document or payment information was used without authority should report the matter promptly.

The report should identify the disputed application, Membership ID, card or communication where known.

The reporter must not publish another person’s private documents while attempting to prove the complaint.

18.4

Application identity enquiries

Application photograph, document and verification enquiries should be sent to applications@6membership.com.

The message should include the Application Reference and a concise explanation without attaching unnecessary identity documents in the first email.

18.5

Approved card corrections

Approved-member photograph, name, stolen-card and reissuance matters may be sent to admin@6membership.com.

The member should include the Membership ID and sufficient information to identify the requested correction.

18.6

Complaints and external remedies

A person may use the applicable complaint or appeal process where they believe identity evidence was mishandled or a verification decision was materially incorrect.

Where the Nigerian data-protection framework applies, the person retains the right to lodge an applicable complaint with the Nigeria Data Protection Commission.

Nothing in the internal process removes a mandatory right to contact a privacy regulator, consumer authority, court or lawful authority.

Related documents
Country-Specific Privacy Rights AddendumComplaints, Appeals and Dispute Resolution PolicyPolicy Updates, Effective Dates and Change Log
Cross-reference

Related policies

Membership Terms and Conditions

Contains the application, eligibility, verification and membership-decision framework.

Privacy and Data Protection Notice

Explains the broader processing of identity and applicant information.

Country-Specific Privacy Rights Addendum

Explains access, correction, deletion, objection and complaint rights.

Eligibility, Age and Guardian Consent Policy

Explains verification involving younger applicants and guardians.

Payments, Taxes, Refunds, Chargebacks and Renewals Policy

Explains payment ownership and refund-verification records.

Anti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy

Explains enhanced identity and payer review for relevant risks.

Membership Card, Certificate and Public Verification Policy

Explains card photographs, public verification, theft and reissuance.

Third-Party Service Providers List

Identifies infrastructure and verification providers.

Security, Account Access and Incident Response Policy

Explains access controls and identity-data incident handling.

Data Retention, Deletion and Records Policy

Explains retention periods, restricted archives and legal holds.

Acceptable Use, Code of Conduct and Non-Discrimination Policy

Prohibits impersonation, forgery, harassment and verification abuse.

Complaints, Appeals and Dispute Resolution Policy

Explains corrections, appeals and formal complaints.

Official channels

Contact points

Application identity reviewapplications@6membership.com

Applicant photographs, supporting documents, verification questions and requested corrections.

Approved membership recordsadmin@6membership.com

Approved-card photographs, legal-name changes, stolen cards and card reissuance.

Privacy rights requestsprivacy@6membership.com

Access, correction, deletion, restriction, objection and privacy questions concerning identity or photograph information.

Security and impersonation reportssecurity@6membership.com

Stolen identity evidence, exposed documents, suspicious verification requests, impersonation and unauthorised access.

6membershipA 6clement Joshua service™

© 2026 6clement Joshua. All rights reserved.