Terms & conditions
Terms for using FieldCRM.
These Terms govern authorised access to the FieldCRM credit-operations platform operated for Mainstreet Microfinance Bank Limited. They form part of Mainstreet’s internal technology, information-security, employment and operational control framework.
- Effective
- 2 September 2026
- Governing law
- Federal Republic of Nigeria
- Audience
- Authorised staff and approved service personnel
1. Definitions and acceptance
“FieldCRM” means the web application, Android application, APIs, records, configurations and related services used for Mainstreet credit operations. “Mainstreet” means Mainstreet Microfinance Bank Limited. “User” means an individual expressly authorised to access FieldCRM. “Customer Data” includes information relating to applicants, customers, guarantors, referees, collateral owners and other identifiable persons.
By signing in, using a linked device, or performing an action in FieldCRM, you confirm that you have read and will comply with these Terms, applicable Mainstreet policies, your assigned authority, and Nigerian law. If these Terms conflict with a mandatory law, CBN direction or approved Mainstreet policy, the mandatory requirement or formally approved policy prevails.
2. Eligibility, employment and authority
Access is limited to current personnel and approved service providers who have been provisioned by an authorised administrator. Access does not expand your employment duties, delegated authority, approval limit, branch scope or legal capacity. You must act only for the organisation, branch, portfolio, customer and workflow action assigned to you.
You must promptly notify Mainstreet if your role, branch, employment, engagement or need for access changes. Mainstreet may change permissions or require additional authentication at any time.
3. Credentials, sessions and devices
Your account is personal. Do not share passwords, reset links, session tokens, verification codes or devices authenticated to FieldCRM. Use a strong unique password, lock unattended devices, install required security updates, and avoid public or untrusted devices and networks where possible. You are responsible for actions taken through your account except to the extent caused by Mainstreet’s breach of applicable law.
Report suspected compromise, loss, unauthorised access, phishing, malware or mistaken disclosure immediately. Mainstreet may revoke sessions, reset credentials, block devices or suspend access to protect users, customers and systems.
4. Permitted use
Use FieldCRM only for authorised credit intake, identity and document verification, field visits, underwriting, workflow review, approval, legal or collateral review, disbursement support, repayment and portfolio monitoring, collections records, customer service, configuration, administration, audit, compliance and related Mainstreet duties.
Information entered must be accurate, relevant, obtained lawfully and supported by appropriate evidence. Required reasons, recommendations, confirmations and attestations must reflect your own authorised work.
5. Prohibited conduct
You must not:
- access or attempt to access another organisation, branch, user, customer or record without authority;
- circumvent permissions, maker-checker separation, approval limits, workflow controls, rate limits, security headers or audit mechanisms;
- impersonate another person, share accounts, approve your own prohibited action, or submit a customer’s signature or consent on their behalf;
- alter, fabricate, suppress or destroy evidence, audit history, customer information or decisions;
- upload malware, unlawful material, unrelated files or content that infringes another person’s rights;
- probe, scan, reverse engineer, scrape, overload or interfere with FieldCRM except under written authorised security testing;
- copy Customer Data to personal email, messaging, storage, removable media, AI tools or any unapproved service;
- use FieldCRM or its data for personal benefit, discrimination, harassment, fraud or any unlawful purpose.
6. Personal data, confidentiality and banking secrecy
Customer Data, staff information, account and transaction details, documents, credentials, configuration and internal decisions are confidential. Process only the minimum information needed for your assigned duty and disclose it only through approved channels to authorised recipients.
Personal data must be handled in accordance with the Nigeria Data Protection Act 2023, applicable CBN requirements, Mainstreet’s privacy and retention policies, and the FieldCRM Privacy Notice. Users must respect data-subject rights, lawful-purpose restrictions, security safeguards and any approved cross-border transfer controls.
7. Electronic records, acknowledgements and signatures
FieldCRM may retain timestamps, authenticated user identity, workflow events, documents, approvals, reasons and other electronic records. To the extent permitted by applicable law, these records may be relied upon as evidence of actions performed through your account.
A typed name, checkbox, uploaded signature image or in-app acknowledgement is not automatically equivalent to every category of legally valid electronic signature or executed instrument. Users must follow approved signing procedures and must not represent system-generated or image-based signatures as notarised, witnessed, certified or otherwise legally sufficient where additional formalities apply.
8. Credit assessment and decisions
FieldCRM supports workflow and recordkeeping; it does not replace professional judgment, product rules, affordability review, fair treatment, required disclosures, approval authority, or CBN and other legal obligations. Product eligibility, scoring, readiness indicators, OCR output, CBS information and alerts must be verified where policy requires.
No User may promise approval, disbursement, pricing, waiver or restructuring outside their authority. Customer-facing product terms and disclosures, not this internal-use agreement, govern a customer’s facility.
9. Monitoring, logging and audit
To protect customers, establish accountability, maintain service security and meet legal obligations, Mainstreet may log and review authentication, access, searches, record views, changes, uploads, workflow decisions, administrative activity, device and network metadata, and suspected misuse. Monitoring must be proportionate, authorised and handled in accordance with employment, privacy and cybersecurity requirements.
Users should have no expectation that business activity performed in FieldCRM is private from authorised Mainstreet security, compliance, audit or supervisory review.
10. Third-party and integrated services
FieldCRM may connect to approved hosting, document, email, identity, credit-bureau, core-banking or other providers. Their availability and outputs may affect particular functions. Users must not independently connect unapproved services or submit credentials to third parties. Mainstreet remains responsible for selecting processors and applying appropriate contractual and legal safeguards.
11. Availability, offline use and changes
Mainstreet may maintain, update, restrict or suspend FieldCRM for security, compliance, maintenance, incident response or operational continuity. Offline or cached Android information may be incomplete or outdated; the server-confirmed record remains authoritative. Do not rely on FieldCRM as the sole repository for any record that policy requires to be retained elsewhere.
Where an error could affect a customer, decision, payment or legal deadline, stop the affected action, preserve available evidence and report the issue through the official support channel.
12. Intellectual property and brand use
FieldCRM software, interface, documentation, trademarks, logos and other materials are owned by or licensed to Mainstreet and are provided only for authorised duties. No licence is granted to reproduce, publish, sell, sublicense or create unauthorised derivative works. Mainstreet names and marks must not be used to suggest unauthorised endorsement or customer communication.
13. Suspension, investigation and termination
Mainstreet may suspend or terminate access where employment or engagement ends, access is no longer required, instructions are breached, compromise is suspected, or law, regulation or risk management reasonably requires it. Relevant records may be preserved for investigation, legal claims, regulatory reporting and retention duties. A User must return or securely delete Mainstreet information held outside the platform as directed.
14. Responsibility and limitation
Nothing in these Terms excludes liability that cannot lawfully be excluded, limits statutory or regulatory rights, excuses fraud or wilful misconduct, or reduces Mainstreet’s obligations to customers and data subjects. Subject to those limits, FieldCRM is an internal operational tool provided for authorised business use and may be unavailable or contain errors; Users must apply required verification and escalation procedures.
A User may be subject to access restriction, disciplinary action, contractual remedies, regulatory reporting or legal proceedings for misuse, in accordance with applicable law and fair process.
15. Security reports, support and complaints
Report security incidents and technical problems immediately through Mainstreet’s officially designated internal support channel. Customer complaints must be handled through Mainstreet’s approved complaints process. CBN guidance generally requires customers to complain to their financial institution first before escalating an unresolved financial complaint to the CBN Consumer Protection Department.
16. Governing law and dispute handling
These Terms are governed by the laws of the Federal Republic of Nigeria. Internal employment or service-provider disputes must first follow applicable Mainstreet grievance, disciplinary or contractual procedures. Nothing prevents a regulator, court or other competent authority from exercising jurisdiction granted by law.
17. Changes, severability and contact
Mainstreet may revise these Terms for legal, regulatory, security or operational reasons. Material changes will be communicated through an appropriate channel. Continued use after the effective date constitutes acceptance where legally permitted; fresh acknowledgement will be obtained where required. If one provision is invalid, the remaining provisions continue to the extent lawful. A delay in enforcement is not a waiver.
Questions should be directed through Mainstreet’s officially published internal support, Legal, Compliance or Data Protection Officer channel.
