Skip to content

Legal

Privacy Policy

Last updated 12 September 2026.

This is a working outline, not legal advice. Have a lawyer in your jurisdiction review it before you take real money.

01 What we collect

Account details you give us: your name, email address and phone number.

Transaction records: what you bought or sold, when, for how much, and the references attached to each movement of money.

Communications: buyer-to-merchant messages and support tickets, including messages the anti-contact filter refused.

Technical data: your IP address at sign-in and at certain actions, so we can investigate account takeovers and fraud.

02 Why we collect it

To run your account, hold your wallet balance and deliver what you buy.

To attribute an incoming bank transfer to the right person. Your phone number is part of how a dedicated funding account is issued in your name.

To resolve disputes. Order records and message history are the evidence when two people disagree about what happened.

To detect fraud, account takeovers and attempts to route deals off the platform.

03 Delivery credentials

The private delivery details a merchant uploads are encrypted with AES-256-GCM before they are stored. They are decrypted only when the buyer who paid for them opens their order page.

No member of staff reads them through the admin panel; that panel does not load them at all. Losing the encryption key would make them permanently unreadable, including to us.

04 Who we share it with

Our payment provider, which needs your name, email and phone number to issue and operate your dedicated bank account.

The other party to a transaction, in the limited form the site shows: a merchant sees a buyer's first name and last initial, not their email or phone number.

Authorities, where we are lawfully required to.

We do not sell your data, and we do not share it with advertisers.

05 How long we keep it

Account and transaction records are kept for as long as the account exists and for a period afterwards, because a dispute or a lawful request can arrive after the fact.

Sign-in attempt records are short-lived and exist only to throttle brute-force attacks.

Closing your account removes your profile from the site. Financial records attached to completed orders are retained.

06 Security

Passwords are stored as bcrypt hashes and are never recoverable, by us or by anyone else.

Session cookies are HTTP-only and, in production, marked secure. Every state-changing action is protected against cross-site request forgery.

Payment notifications are verified by HMAC-SHA512 signature before a single naira moves.

07 Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to close your account. Open a support ticket and we will handle it.

Some data cannot be deleted on request where we are required to keep it — financial records in particular.

08 Cookies

We set one cookie: your session. It keeps you signed in and nothing else. Your light or dark theme preference is kept in your browser's local storage and never reaches us.

There are no advertising or tracking cookies on this site.

Questions about your data? Open a support ticket .