FlutterGive LogoFlutterGive

Privacy Policy

Effective August 3, 2026 · Version 1.0 · FLG-POL-002

Operated by GOFUNDMEAFRICA LTD · Platform: FlutterGive

1Introduction

GOFUNDMEAFRICA LTD ("we", "our", "us"), operating the FlutterGive crowdfunding platform (the "Platform"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Platform.

This Policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Commission (NDPC) regulations, and, where applicable, the EU General Data Protection Regulation (GDPR). By accessing or using FlutterGive, you acknowledge the practices described in this policy.

Data Controller: GOFUNDMEAFRICA LTD is the data controller responsible for your personal data. We are registered with the Nigeria Data Protection Commission (NDPC) as a Data Controller of Major Importance. You can contact our privacy team at [email protected].

2Information We Collect

We collect information you provide directly to us, including:

  • Full name, contact email address, and verified phone number.
  • Country, home address, and supported platform currency.
  • KYC documents: government-issued ID, proof of address, and live selfie.
  • Campaign details, payout bank account details, and transaction histories.
  • Login credentials (encrypted), login attempt records, and account activity.
  • Support tickets, correspondence, and feedback submissions.

We automatically collect technical telemetry when you interact with the Platform, including IP address, browser headers, device identifiers, and security logs for fraud prevention and regulatory compliance.

3Lawful Bases for Processing

Under the NDPA 2023, we must have a lawful basis for each processing activity. We rely on:

PurposeData UsedLawful Basis
Account creation & loginName, email, phone, passwordContract performance
KYC/AML complianceID documents, selfie, addressLegal obligation
Payment processingTransaction data, payout detailsContract + legal obligation
Fraud preventionIP, device, login attemptsLegitimate interest + legal obligation
Sanctions/PEP screeningName, ID, countryLegal obligation
Support & ticketingName, email, message contentLegitimate interest
Marketing emailsEmail addressConsent (withdrawable)
Regulatory reportingTransaction + KYC dataLegal obligation

4Data Sharing & Third Parties

We do not sell your personal information. To operate the Platform, we share data with trusted entities under written Data Processing Agreements (DPAs):

  • Payment Gateways:Flutterwave (primary, live) and Paystack (secondary adapter, in development). We share payment details, transaction metadata, and settlement banking profiles to process payments, settle funds, and monitor for fraud.
  • Hosting & Infrastructure:Vercel (frontend hosting), Amazon Web Services (backend hosting), Cloudflare (CDN, SSL, media storage via R2). These providers store and serve data on our behalf.
  • Email Services:Resend (transactional emails and notifications).
  • Support Ticketing:Zoho Desk (support ticket management and correspondence).
  • Authentication:Google (OAuth sign-in, if you choose to use it).
  • Fraud Detection & Abuse Prevention:IPQualityScore (IPQS). We share the IP address and limited request metadata associated with signup and login events for automated fraud scoring and abuse prevention. IP reputation signals are stored internally and used solely for compliance and security purposes.
  • Identity Verification:Didit (didit.me). We transmit identity documents, selfies, and proof of address to Didit's hosted verification service for automated identity verification, liveness detection, and face-match checks. Didit processes this data as our data processor under a Data Processing Agreement. See Didit's privacy policy at didit.me/privacy.
  • Legal Authorities:Data may be disclosed to financial regulators, the NDPC, financial intelligence units (e.g., NFIU), or law enforcement when mandated by law.
KYC Verification: KYC documents you upload are stored securely on our platform and also transmitted to Didit for automated verification (ID authenticity, passive liveness, 1:1 face match, and device/IP analysis). Automated checks produce a preliminary verdict and score; final approval or rejection is made manually by our trained compliance team. Sanctions and PEP screening is performed against official lists (OFAC, UN, EU, UK HMT) and OpenSanctions. We do not share raw KYC documents with marketing or advertising partners.

5International Data Transfers

Some of our service providers are located outside Nigeria (including in the United States, the European Union, and other jurisdictions). When we transfer personal data outside Nigeria, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, where GDPR applies.
  • Written Data Processing Agreements (DPAs) with every processor.
  • Contractual commitments to confidentiality and security.
  • Transfers only to jurisdictions with adequate data protection frameworks, or with supplementary safeguards where required.

You may request more information about our international transfer safeguards by contacting [email protected].

6Security, Cookies & Data Retention

Data Security: We implement TLS 1.2+ encryption in transit, AES-256 encryption at rest, restricted access controls, multi-factor authentication for administrative accounts, and continuous network monitoring. Card data is never stored on our servers — it is processed directly by PCI-DSS Level 1 certified partners.

Cookies: We use essential HTTP-only cookies for secure authentication, session management, and CSRF protection. We do not use third-party advertising cookies. See our Cookie Policy for details.

Retention Periods:

Data TypeRetention Period
Account dataLifetime of account + 30 days after deletion request
KYC documents5 years after account closure (MLA 2022)
Transaction records5 years (MLA 2022 + FATF Rec. 11)
Login attempts12 months
Audit logs5 years
Marketing consentUntil withdrawn

7Your Privacy Rights

Under the NDPA 2023 and, where applicable, the GDPR, you have the following rights:

  • ✓ Right to be informed about how your data is used
  • ✓ Right to access your personal data
  • ✓ Right to rectification of inaccurate data
  • ✓ Right to erasure ("right to be forgotten")
  • ✓ Right to restrict processing
  • ✓ Right to data portability
  • ✓ Right to object to processing
  • ✓ Right to withdraw consent at any time
  • ✓ Right not to be subject to automated decision-making
  • ✓ Right to lodge a complaint with the NDPC

To exercise any of these rights, contact [email protected]. We will respond within 30 days. Where a request affects statutory record-keeping (e.g., AML retention), some data cannot be deleted before the mandatory retention period expires.

8Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by Section 40(2) of the NDPA 2023.
  • Where the breach poses a high risk to your rights and freedoms, we will notify you directly without undue delay.
  • We will describe the nature of the breach, the categories and approximate number of affected records, the likely consequences, and the measures taken to address it.
  • We maintain an internal incident response plan and will cooperate fully with regulators.

9Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors, and minors are not permitted to create accounts, initiate campaigns, or receive donations on the Platform. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact [email protected].

10Policy Review & Changes

This Privacy Policy is reviewed at least annually and updated as required to reflect changes in law, regulation, or our data practices. Material changes will be notified to users via email or prominent notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision.

11Complaints & Escalation

If you are dissatisfied with how we have handled your personal data or a privacy request, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng. You may also contact our Trust & Safety team at [email protected].

12Contact & Full Policy

For privacy inquiries, data subject rights requests, or questions about this Policy, contact our privacy desk. A downloadable version of this policy is available below.