Privacy Policy
Effective August 3, 2026 · Version 1.0 · FLG-POL-002
Operated by GOFUNDMEAFRICA LTD · Platform: FlutterGive
1Introduction
GOFUNDMEAFRICA LTD ("we", "our", "us"), operating the FlutterGive crowdfunding platform (the "Platform"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Platform.
This Policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Commission (NDPC) regulations, and, where applicable, the EU General Data Protection Regulation (GDPR). By accessing or using FlutterGive, you acknowledge the practices described in this policy.
2Information We Collect
We collect information you provide directly to us, including:
- Full name, contact email address, and verified phone number.
- Country, home address, and supported platform currency.
- KYC documents: government-issued ID, proof of address, and live selfie.
- Campaign details, payout bank account details, and transaction histories.
- Login credentials (encrypted), login attempt records, and account activity.
- Support tickets, correspondence, and feedback submissions.
We automatically collect technical telemetry when you interact with the Platform, including IP address, browser headers, device identifiers, and security logs for fraud prevention and regulatory compliance.
3Lawful Bases for Processing
Under the NDPA 2023, we must have a lawful basis for each processing activity. We rely on:
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Account creation & login | Name, email, phone, password | Contract performance |
| KYC/AML compliance | ID documents, selfie, address | Legal obligation |
| Payment processing | Transaction data, payout details | Contract + legal obligation |
| Fraud prevention | IP, device, login attempts | Legitimate interest + legal obligation |
| Sanctions/PEP screening | Name, ID, country | Legal obligation |
| Support & ticketing | Name, email, message content | Legitimate interest |
| Marketing emails | Email address | Consent (withdrawable) |
| Regulatory reporting | Transaction + KYC data | Legal obligation |
4Data Sharing & Third Parties
We do not sell your personal information. To operate the Platform, we share data with trusted entities under written Data Processing Agreements (DPAs):
- Payment Gateways:Flutterwave (primary, live) and Paystack (secondary adapter, in development). We share payment details, transaction metadata, and settlement banking profiles to process payments, settle funds, and monitor for fraud.
- Hosting & Infrastructure:Vercel (frontend hosting), Amazon Web Services (backend hosting), Cloudflare (CDN, SSL, media storage via R2). These providers store and serve data on our behalf.
- Email Services:Resend (transactional emails and notifications).
- Support Ticketing:Zoho Desk (support ticket management and correspondence).
- Authentication:Google (OAuth sign-in, if you choose to use it).
- Fraud Detection & Abuse Prevention:IPQualityScore (IPQS). We share the IP address and limited request metadata associated with signup and login events for automated fraud scoring and abuse prevention. IP reputation signals are stored internally and used solely for compliance and security purposes.
- Identity Verification:Didit (didit.me). We transmit identity documents, selfies, and proof of address to Didit's hosted verification service for automated identity verification, liveness detection, and face-match checks. Didit processes this data as our data processor under a Data Processing Agreement. See Didit's privacy policy at didit.me/privacy.
- Legal Authorities:Data may be disclosed to financial regulators, the NDPC, financial intelligence units (e.g., NFIU), or law enforcement when mandated by law.
5International Data Transfers
Some of our service providers are located outside Nigeria (including in the United States, the European Union, and other jurisdictions). When we transfer personal data outside Nigeria, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where GDPR applies.
- Written Data Processing Agreements (DPAs) with every processor.
- Contractual commitments to confidentiality and security.
- Transfers only to jurisdictions with adequate data protection frameworks, or with supplementary safeguards where required.
You may request more information about our international transfer safeguards by contacting [email protected].
6Security, Cookies & Data Retention
Data Security: We implement TLS 1.2+ encryption in transit, AES-256 encryption at rest, restricted access controls, multi-factor authentication for administrative accounts, and continuous network monitoring. Card data is never stored on our servers — it is processed directly by PCI-DSS Level 1 certified partners.
Cookies: We use essential HTTP-only cookies for secure authentication, session management, and CSRF protection. We do not use third-party advertising cookies. See our Cookie Policy for details.
Retention Periods:
| Data Type | Retention Period |
|---|---|
| Account data | Lifetime of account + 30 days after deletion request |
| KYC documents | 5 years after account closure (MLA 2022) |
| Transaction records | 5 years (MLA 2022 + FATF Rec. 11) |
| Login attempts | 12 months |
| Audit logs | 5 years |
| Marketing consent | Until withdrawn |
7Your Privacy Rights
Under the NDPA 2023 and, where applicable, the GDPR, you have the following rights:
- ✓ Right to be informed about how your data is used
- ✓ Right to access your personal data
- ✓ Right to rectification of inaccurate data
- ✓ Right to erasure ("right to be forgotten")
- ✓ Right to restrict processing
- ✓ Right to data portability
- ✓ Right to object to processing
- ✓ Right to withdraw consent at any time
- ✓ Right not to be subject to automated decision-making
- ✓ Right to lodge a complaint with the NDPC
To exercise any of these rights, contact [email protected]. We will respond within 30 days. Where a request affects statutory record-keeping (e.g., AML retention), some data cannot be deleted before the mandatory retention period expires.
8Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:
- We will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by Section 40(2) of the NDPA 2023.
- Where the breach poses a high risk to your rights and freedoms, we will notify you directly without undue delay.
- We will describe the nature of the breach, the categories and approximate number of affected records, the likely consequences, and the measures taken to address it.
- We maintain an internal incident response plan and will cooperate fully with regulators.
9Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors, and minors are not permitted to create accounts, initiate campaigns, or receive donations on the Platform. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact [email protected].
10Policy Review & Changes
This Privacy Policy is reviewed at least annually and updated as required to reflect changes in law, regulation, or our data practices. Material changes will be notified to users via email or prominent notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision.
11Complaints & Escalation
If you are dissatisfied with how we have handled your personal data or a privacy request, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng. You may also contact our Trust & Safety team at [email protected].
12Contact & Full Policy
For privacy inquiries, data subject rights requests, or questions about this Policy, contact our privacy desk. A downloadable version of this policy is available below.
