Legal
Privacy Policy
Effective date: April 14, 2026 · Applies to: All Crednce users
We believe privacy is a right, not a feature. This document is written in plain language wherever possible. Where legal language is unavoidable, we explain what it means. If anything is unclear, email us at privacy@crednce.io.
Overview
Crednce Sphere Ltd. ("Crednce", "we", "our", or "us") operates a delivery guarantee and escrow platform designed to protect payments between clients and service providers across Africa and beyond. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you access or use our website, mobile applications, APIs, and related services (collectively, the "Platform").
By registering for or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, you must discontinue use of the Platform immediately.
This Policy should be read alongside our Terms of Service, which govern your use of the Platform. We are committed to handling your personal data with integrity, transparency, and in compliance with applicable data protection laws including — but not limited to — the Ghana Data Protection Act 2012 (Act 843), Nigeria's Data Protection Act 2023, South Africa's Protection of Personal Information Act (POPIA), the Kenya Data Protection Act 2019, and the EU General Data Protection Regulation (GDPR) where applicable.
Information We Collect
Account & Identity Information
- Full legal name, email address, phone number, and date of birth
- Username, password (stored as a cryptographic hash), and profile photo
- Business name, registration number, and tax identification number (for business accounts)
- Government-issued identification documents (national ID, passport, driver`s licence) collected as part of our Know Your Customer (KYC) process
- Selfie or biometric likeness used for identity verification purposes
Financial Information
- Bank account details, routing numbers, and account holder information
- Mobile Money account numbers (MTN Mobile Money, Vodafone Cash, AirtelTigo Money, and equivalents)
- Card details — handled exclusively by PCI-DSS compliant payment processors; Crednce never stores raw card numbers
- Wallet balances, transaction history, and payout preferences
Transaction & Deal Data
- Deal agreements, scope documents, milestone definitions, and delivery timelines
- Files, deliverables, and communications submitted as part of a deal
- Milestone status records, approval timestamps, and audit trails
- Dispute submissions, evidence files, and resolution outcomes
- AI audit logs generated during milestone verification
- Contract metadata including parties, amounts, currencies, and deal lifecycle events
Communications
- Messages exchanged between deal parties on the Platform
- Support tickets, live chat transcripts, and email correspondence with Crednce
- Ratings, reviews, and feedback submitted on completed deals
- Notifications and responses to system-generated alerts
Technical & Usage Data
- IP address, device identifiers, browser type and version, and operating system
- Pages visited, features used, click events, session duration, and navigation paths
- Geolocation data (city or region level) derived from your IP address
- Cookies, local storage tokens, and similar tracking technologies as described in Section 8
- API request logs including timestamps, endpoints, and response codes
Information from Third Parties
- Identity verification results from accredited KYC/AML service providers
- Credit or risk signals from financial intelligence partners (aggregated, not raw bureau data)
- Social login profile data if you choose to sign in via Google or similar OAuth providers
- Referral source information when you join through a partner or affiliate programme
How We Use Your Information
Platform Operations
- To create, authenticate, and manage your account
- To facilitate the creation, management, and closure of deals and escrow arrangements
- To process deposits, milestone releases, refunds, and withdrawals
- To generate legally binding deal contracts and store timestamped records
- To send transactional notifications — payment confirmations, milestone updates, dispute alerts
Identity & Compliance
- To verify your identity and comply with KYC, AML, and counter-terrorism financing regulations
- To assess risk profiles and prevent fraudulent or prohibited transactions
- To comply with regulatory reporting obligations, tax authority requests, and court orders
- To maintain records as required by applicable financial services legislation
Trust & Safety
- To detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service
- To run AI-powered milestone audits that verify deliverables against agreed scope
- To facilitate dispute resolution — including review by human specialists
- To enforce sanctions screening and politically exposed person (PEP) checks
Product & Experience
- To personalise your dashboard, surface relevant deals or providers, and tailor notifications
- To analyse usage patterns and improve Platform features, reliability, and performance
- To conduct internal research, A/B tests, and product experiments using aggregated or de-identified data
- To generate public marketplace statistics (always aggregated — never identifying individual users)
Marketing & Communications
- To send product updates, feature announcements, and relevant promotions — only if you have opted in
- To respond to enquiries, feedback, and support requests
- To inform you of material changes to this Policy or our Terms of Service
- You may unsubscribe from marketing communications at any time via your account settings or the unsubscribe link in any email
How We Share Your Information
Crednce does not sell, rent, or trade your personal information to any third party. We share information only in the circumstances described below.
With Your Deal Counterparty
- When you enter a deal, your display name, profile, and deal-related communications are visible to the other party. We do not share your banking details or identification documents with counterparties.
With Service Providers
- Payment processors and banking partners (to execute deposits, releases, and withdrawals)
- KYC/AML identity verification providers (to validate government-issued identification)
- Cloud infrastructure and hosting providers (data stored in secure, GDPR-adequate facilities)
- Email delivery, SMS, and push notification providers
- Analytics and performance monitoring tools (receiving only pseudonymous data)
- Fraud detection and risk intelligence platforms
- All service providers are bound by data processing agreements and may only use your data to provide services to Crednce.
For Legal and Regulatory Reasons
- When required by applicable law, regulation, or enforceable governmental request
- In response to valid court orders, subpoenas, or regulatory enquiries
- To protect the rights, property, or safety of Crednce, our users, or the public
- To enforce our Terms of Service or exercise or defend legal claims
In Corporate Transactions
- In the event of a merger, acquisition, asset sale, or restructuring, your information may be transferred to the successor entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
Data Retention
We retain personal information for as long as necessary to fulfil the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.
Account data is retained for the duration of your account and for a minimum of seven (7) years following account closure to comply with financial record-keeping obligations. KYC documents are retained for a minimum of five (5) years after a transaction in line with AML regulations. Deal records, contracts, and audit trails are retained for seven (7) years to enable dispute resolution and regulatory inspection.
Technical logs are retained for up to ninety (90) days, after which they are deleted or anonymised. Marketing communications preferences and opt-out records are retained indefinitely to honour your choices.
You may request deletion of personal data not subject to mandatory retention obligations by contacting us at the address in Section 12.
Data Security
Crednce implements administrative, technical, and physical safeguards designed to protect your personal information from unauthorised access, disclosure, alteration, and destruction. Our security programme includes:
- AES-256 encryption for data at rest across all production databases and file storage
- TLS 1.3 encryption for all data in transit between your device and our servers
- Strict access controls and role-based permissions — internal teams can only access data necessary for their function
- Multi-factor authentication (MFA) enforced for all employee access to production systems
- Continuous security monitoring, intrusion detection, and anomaly alerting
- Regular penetration testing and third-party security audits
- PCI-DSS compliant payment processing — we never store raw card data
- Incident response procedures with mandatory breach notification in line with applicable law
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security and encourage you to use strong, unique passwords and enable MFA on your account.
Your Rights & Choices
Depending on your jurisdiction, you may have the following rights with respect to your personal information. To exercise any of these rights, contact us at privacy@crednce.io. We will respond within 30 days.
Access
- You may request a copy of the personal information we hold about you.
Correction
- You may request that inaccurate or incomplete data be corrected. You can also update most account information directly in your profile settings.
Deletion
- You may request deletion of your personal data. We will honour such requests where data is not required by law to be retained and where deletion does not prevent us from complying with legal obligations or resolving open disputes.
Portability
- Where technically feasible, you may request your data in a structured, machine-readable format (JSON or CSV).
Objection & Restriction
- You may object to, or request restriction of, certain processing activities, particularly where processing is based on legitimate interests.
Withdrawal of Consent
- Where processing is based on consent (e.g. marketing emails), you may withdraw consent at any time without affecting the lawfulness of prior processing.
Complaints
- If you are dissatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction (e.g. the Data Protection Commission in Ghana, the NDPC in Nigeria, or the Information Regulator in South Africa).
Cookies & Tracking Technologies
We use cookies, local storage tokens, and similar technologies to operate the Platform, remember your preferences, analyse usage, and support security functions.
You can control cookies at the browser level, but disabling strictly necessary cookies will impair Platform functionality. We do not engage in cross-site tracking for advertising purposes.
Strictly Necessary
- Authentication tokens, CSRF protection, session management. These cannot be disabled without breaking core functionality.
Functional
- Preference storage (language, timezone, notification settings). Disabled by default, enabled on your choice.
Analytics
- Pseudonymous usage data to improve the Platform (e.g. page views, feature usage). You may opt out via your account settings or a global opt-out mechanism we provide.
Marketing
- Used only if you have opted in to marketing communications. Never shared with ad networks or third-party advertisers.
International Data Transfers
Crednce is headquartered in Africa and primarily processes data within Africa. Some service providers operate infrastructure in the European Union, United Kingdom, or United States. When we transfer personal data outside your country of origin, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or binding contractual commitments from recipients.
By using the Platform, you acknowledge and consent to the transfer of your information to jurisdictions that may have different data protection rules than your own.
Children's Privacy
The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a person under 18 has provided personal information, we will delete it promptly. If you believe a minor has registered on the Platform, please contact us immediately at privacy@crednce.io.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform functionality. When we make material changes, we will notify you by email (to your registered address) and/or by displaying a prominent notice on the Platform at least 14 days before the changes take effect.
Continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree, you must discontinue use and may request account closure.
Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our handling of your personal data, please contact our Privacy team:
Crednce Sphere Ltd. Privacy & Compliance Team Accra, Ghana
We aim to acknowledge all privacy requests within 5 business days and resolve them within 30 calendar days.
Also see our Terms & Conditions for the rules governing use of the Platform.
© 2026 Crednce Sphere Ltd. — All rights reserved.