Legal
Privacy policy
What we collect, why we collect it, who sees it, and what you can ask us to do.
Draft for legal review. This document has not been reviewed by a qualified lawyer and must not be treated as final. Last updated 21 September 2026.
Who is responsible for your data
[legal entity name: to be added], of [registered address: to be added], decides how and why your personal data is used. You can reach us about your data at [privacy contact email: to be added].
The data protection laws that apply to you depend on where you live. We are building our practices around the laws of the countries we serve, which include Nigeria, South Africa, Kenya and Ghana.
What we collect, and why
| Data | Why we need it |
|---|---|
| Email, country of residence, optional phone number | To create your account, check which challenges you may buy, and contact you about your account. |
| Password (stored only in scrambled, one-way form) | To let you sign in. We cannot read your password. |
| Orders and receipts: which challenge, amount, currency, status, provider reference | To sell you a challenge, confirm payment, give you a receipt, and keep financial records. |
| Identity documents and a selfie, if you submit them, and the result of the check | To verify who you are before any reward could be paid, and to prevent fraud. |
| Trading records for your challenge accounts | To calculate results under the rules and to explain them to you. |
| A record of actions on the Service: what happened, when, by which account, and a reference number | To keep the Service secure, investigate problems, and show how decisions were made. |
We do not collect your card number: card payments are taken by our payment provider on its own page. We do not use advertising or analytics trackers on this site today. If that changes, we will update this page and the cookie policy first.
Identity documents
These are the most sensitive data we hold, so we handle them more strictly than everything else. They are encrypted when stored. Only our verification team can open them, they cannot open their own, and every time one is opened it is recorded with who opened it and when. We use documents only for verification and do not use them for marketing.
Who we share data with
- Our payment provider, so it can take and confirm your payment.
- Companies that host and run our systems, who process data for us under our instructions.
- Authorities, where the law requires it or to protect against fraud.
We do not sell your personal data.
Where data is kept
Our systems are hosted in [hosting region: to be added]. If your data is moved or accessed from a different country, we will take steps to protect it as the law requires.
How long we keep it
We keep data only as long as we need it for the reasons above or the law requires. The specific periods for each kind of data are being set and will be listed here. You can ask us today what we hold about you and how long we plan to keep it.
One kind of record is different. Our log of actions on the Service is append-only by design, so that it can be trusted. It holds reference numbers and descriptions of actions rather than your name, contact details or documents, and entries in it cannot be edited or deleted.
Your rights
Depending on where you live, you may have the right to:
- ask what personal data we hold about you and get a copy;
- have wrong data corrected;
- ask us to delete data, where the law allows;
- object to, or ask us to limit, some uses of your data;
- receive your data in a portable form;
- complain to a data protection authority: [regulators: to be added].
To use any of these, write to [privacy contact email: to be added]. We may need to check it is you before we act.
How we protect it
Passwords are stored in one-way form. Identity documents are encrypted. Access to sensitive functions is limited by role, and important actions are logged. No system is perfectly secure, and if a breach affects you we will tell you and the authorities as the law requires. To report a security problem, write to [security contact email: to be added].
Children
The Service is for people aged 18 and over. We do not knowingly collect data from anyone younger.
Changes
If we change this policy in a way that matters, we will tell you before the change takes effect.