Privacy Policy
How account, payment, and security data is handled.
This page explains what information is collected, why it is needed, how long it is kept, who it may be shared with, and how a user can exercise their privacy rights.
Effective date: 2026-04-15
Version: 2026-04-15
What is collected
- Name, email address, password hash, and M-Pesa phone number for account access and payments.
- Trading records, wallet activity, bot settings, support messages, and referral relationships needed to run the service.
- IP address, device/browser data, and security events used to detect fraud, abuse, and unauthorized access.
Why it is used
- Phone number: deposit and withdrawal processing, including M-Pesa payout routing.
- Email: login, account notices, verification, and support follow-up.
- IP and device details: fraud monitoring, duplicate-account checks, rate limits, and audit trails.
- Trading and wallet history: order execution, dispute review, tax/accounting, and platform risk management.
Data minimization and sharing
Only information required for account operation, payments, security, support, and lawful recordkeeping is collected. Data may be shared with payment providers, infrastructure vendors, market-data providers, regulators, or investigators only where needed to run the service, prevent fraud, or meet a legal obligation.
Security safeguards
- Passwords are stored as secure hashes and payment secrets are stored using encrypted application settings.
- Rate limiting, admin access controls, audit logs, and payout workflow controls are used to reduce abuse and unauthorized access.
- Production traffic should run over HTTPS, and response-security headers are applied by the application.
User rights
Users can review and correct profile data in the account settings, download an export of their account data, and request account deletion. The application aims to answer privacy-rights requests within 30 days where verification and legal retention duties allow.
Retention
Financial and audit records may be retained for compliance, dispute, fraud, and accounting needs. Separate inactive user accounts with no remaining balances or pending financial activity can be anonymized after 24 months of inactivity.