Privacy Policy

Last updated: 24 August 2026
Who are we?

AfriTerminal ("we", "us", "our") is a financial data platform providing aggregated market data, company filings, and economic indicators for African capital markets.

For the purposes of data protection law, we are the data controller of any personal information we hold about you.

Contact for all privacy matters: info@afriterminal.com

What does this policy cover?

This policy explains what information we collect, why we collect it, how we use it, and your rights in relation to it. It applies to afriterminal.com and any associated services.

What data do we collect without an account?

We do not collect any personal information. The platform is served as a static website. Any preferences you set - such as watchlists or alerts - are stored locally on your own device using your browser's localStorage and are never transmitted to us.

GitHub Pages, which hosts this service, may collect standard server access logs (including IP addresses) as part of their infrastructure. This is governed by GitHub's Privacy Statement.

What data do we collect when you create an account?

When you create an account, we collect:

  • Your email address - to identify your account and send service communications
  • A hashed password - we never store your password in readable form (Google sign-in is also available, in which case no password is stored with us)
  • Your subscription tier (Free, Pro, Team, or Enterprise)
  • Your name and firm, if you provide them during onboarding
  • Your coverage universe (the NGX stocks you choose to follow, up to 20) and any personal notes you attach to them
  • Your sector focus and notification preferences, including any alert thresholds you set
  • Your in-app notification and alert history (used to display your notification inbox and to avoid sending you the same alert twice)
  • The date your account was created

If you use the features below, we also collect:

  • Portfolio tracking - the tickers, share counts, and buy prices of positions you choose to add. This is personal financial record-keeping data you control; we never see or connect to any real brokerage account, and no trade is ever placed on your behalf (see "Is portfolio tracking connected to my brokerage?" on our FAQ).
  • Direct Messages - if you use the analyst-to-analyst messaging feature, we store the connection requests you send/receive and the content of messages you send, so the recipient can read them. A message is visible to you and the other participant in that conversation only; we do not read messages except as needed for security, abuse investigation, or a legal request.
  • Blocking records - if you block another user, we store that record so it can be enforced. It is never shown to the person you blocked.
  • API keys - if you generate an API key for programmatic/Excel access, we store a one-way cryptographic hash of the key (never the key itself, which is shown to you once and never again) plus metadata about its use: which endpoints it called, when, and how many requests it made against your daily quota.

Legal basis (UK GDPR / NDPA 2023): Contract - this data is necessary to provide the personalised service you signed up for. Your coverage universe, portfolio, messages, and preferences exist solely to operate the feature you used them for; they are never shared with other users beyond what that feature itself requires (for example, the other participant in a DM conversation, or another analyst you have an accepted connection with in the directory).

What happens when you make a payment?

AfriTerminal is currently free and takes no payments. When paid plans launch, payments will be processed by Flutterwave. We never see, store, or have access to your card number, CVV, or full card details. Flutterwave is PCI DSS certified and handles all payment card data under their own security standards.

We retain a record of: the amount charged, the date of charge, and your subscription tier, for accounting and billing dispute purposes.

Legal basis: Legal obligation (financial record-keeping requirements).

Do we track usage data?

For signed-in users we record basic account activity, such as when you last signed in or loaded the dashboard. We use this to operate the service and understand whether it is being used, not for advertising or profiling.

We also keep an internal audit log of changes made to your profile, coverage universe, connections, and notification records (what changed, when, and the IP address and browser identifier where available). This exists for security and accountability: it lets us detect and investigate unauthorised changes to your account data. It is append-only and never used for any other purpose.

If you generate an API key, each request made with it (successful or not) is logged - endpoint called, timestamp, and outcome - purely to enforce your quota and detect anomalous use of a compromised key. This log is never used to profile you and is not shared outside AfriTerminal.

If we ever introduce broader analytics, we update this policy and notify existing users by email first.

How do we use your data?

We use your data only for the purposes stated at collection:

  • To operate your account and deliver the service you subscribed to
  • To send transactional emails (payment receipts, password resets)
  • To enforce our Terms of Use
  • To meet our legal and financial record-keeping obligations

We do not use your data for advertising. We do not sell your data to third parties. We do not use your data to train machine learning models without your explicit consent.

Who do we share data with?

We share data only with the service providers necessary to operate the platform:

ProviderPurposeData shared
SupabaseDatabase and authenticationEmail, hashed password, profile (name, firm), coverage universe and notes, notification preferences and history, subscription tier
CloudflareContent delivery network and security in front of our hostingConnection metadata (IP, request logs)
GitHub PagesPlatform hostingConnection metadata (IP, request logs)
Resend / Zoho SMTPTransactional email delivery (alerts, reports, DM/connection notifications)Email address, message content
FlutterwavePayment processing (when paid plans launch)Email address, payment amount

AI intelligence is generated by Anthropic's Claude models, but only market data (prices, filings, macro indicators) is sent to the model. Your personal data is never included in AI processing.

Other AfriTerminal users. Your name and firm (as you provided them at onboarding) are visible to other analysts you search for or connect with in the analyst directory, and to anyone who sends or accepts a connection request with you. If you use Direct Messages, the content of a message is visible to the other participant in that conversation. None of this is shared outside the platform, and a search only ever returns a small set of matching results - not a full member list.

We do not share your data with advertisers, data brokers, or analytics platforms.

How long do we keep your data?
  • Account data: retained while your account is active, plus 12 months after closure
  • Payment records: retained for 7 years (financial record-keeping legal requirement)
  • localStorage data: stored on your own device only - we have no access to it
What are your rights?

Under UK GDPR and the Nigeria Data Protection Act 2023, you have the right to:

  • Access - request a copy of all personal data we hold about you
  • Correction - request correction of inaccurate data
  • Deletion - request deletion of your account and associated data
  • Portability - request your data in a machine-readable format (JSON or CSV)
  • Objection - object to processing based on legitimate interests
  • Restriction - request that we limit how we process your data

To exercise any of these rights, email info@afriterminal.com. We will respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with:

Do we use cookies?

The dashboard currently does not use cookies. If we introduce cookies in future (for example, to maintain a login session), we will update this policy and present a cookie notice before any non-essential cookies are set.

How do we secure your data?

We use industry-standard security measures including bcrypt password hashing, HTTPS-only connections, and Supabase row-level security policies. Please do not share your password with anyone. Contact us immediately if you believe your account has been compromised.

What is our policy on children?

AfriTerminal is a professional financial data platform intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, contact info@afriterminal.com and we will delete it promptly.

Do we transfer data internationally?

If you are located in Nigeria, your data may be stored on Supabase servers in the United States or European Union. Where data is transferred outside Nigeria, we ensure appropriate safeguards consistent with the Nigeria Data Protection Act 2023.

If you are located in the European Union or United Kingdom, your data is processed in accordance with UK GDPR and EU GDPR respectively.

How will we notify you of changes?

We announce changes to this policy on the website: the "Last updated" date at the top of this page always reflects the current version, and material changes are noted here when they take effect. We recommend checking this page periodically. Continued use of AfriTerminal after a change takes effect constitutes acceptance of the updated policy.

If a future change materially expands how we use your personal data (for example, introducing analytics or new data sharing), we notify registered users by email before it takes effect.

Which laws govern this policy?

This Privacy Policy is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

How can you contact us?

For privacy questions, data requests, or complaints:
info@afriterminal.com
Platform: afriterminal.com