Privacy At a Glance

Before you read the full policy, here is a plain-language summary of how CrediBio handles your data:

Who we are:  CrediBio — a West African business credibility and review platform

Data we collect:  Account info, business details, reviews, usage data, device info, cookies

Why we collect it:  To provide and improve the Service, verify identities, display ads, and communicate with you

Who we share it with:  Service providers, advertisers (via ad networks, not raw personal data), and regulators when required by law

Your rights:  Access, correct, delete, or restrict your data — contact us at privacy@credibio.com

Advertising:  We use Google AdSense; third-party cookies may be used to serve relevant ads

Cookies:  Yes — essential, analytics, and advertising cookies are used

Data retention:  Retained as long as your account is active or as required by law

Contact:  privacy@credibio.com

1. Introduction

CrediBio (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at www.credibio.com or use any of our services (collectively, the “Service”).

This policy applies to all users of the Service, including visitors, registered users, business owners, and reviewers. By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.

This Privacy Policy should be read alongside our Terms of Use, which govern your use of the Service.

2. Information We Collect

We collect information in several ways: information you provide directly, information collected automatically, and information obtained from third parties.

2.1 Information You Provide Directly

This includes:

• Account registration details — your name, email address, phone number, and password.

• Business profile information — business name, address, category, description, contact details, website URL, and operating hours.

• KYC and verification documents — government-issued identification, business registration certificates, or other documents submitted to verify your identity or business ownership.

• Reviews and ratings — the text, star ratings, photos, and other content you submit as reviews.

• Business responses — any replies you post in response to customer reviews.

• Media uploads — images and videos uploaded to your business gallery.

• Communications — messages you send to us via the contact form, email, WhatsApp, or customer support channels.

• Payment and billing information — where applicable, billing name, address, and payment method details are processed through our secure payment gateway providers. We do not store full card numbers on our servers.

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

• Log data — your IP address, browser type and version, pages visited, time and date of your visit, time spent on pages, and referring URLs.

• Device information — device type, operating system, screen resolution, and unique device identifiers.

• Location data — approximate geographic location derived from your IP address, and precise location only if you grant permission through your device settings.

• Usage data — how you interact with the Service, including search queries, filters applied, listings viewed, and features used.

• Cookies and tracking technologies — see Section 6 (Cookies and Tracking) for full details.

2.3 Information from Third Parties

We may receive information about you from:

• OAuth providers — if you choose to log in using a third-party account (such as Google), we receive basic profile information permitted by that provider.

• Payment processors — transaction status and confirmation data from our payment gateway partners.

• Advertising networks — aggregated and anonymised audience data from our advertising partners to help us understand the effectiveness of our advertising.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 To Provide and Operate the Service

• Create and manage your account.

• Process business verification and KYC checks.

• Display business profiles, reviews, ratings, and credibility badges.

• Enable business owners to manage listings, respond to reviews, and access analytics.

• Facilitate communication between users and businesses via contact forms.

3.2 To Improve and Personalise the Service

• Analyse usage patterns and platform performance.

• Conduct research and develop new features.

• Personalise your experience based on your location, preferences, and activity.

• Generate SEO-optimised content and sitemaps to improve discoverability.

3.3 To Communicate with You

• Send transactional emails — account confirmations, verification status updates, review notifications, and billing receipts.

• Send service announcements and platform updates.

• Respond to your enquiries and support requests.

• Send marketing communications where you have given consent (you may opt out at any time).

3.4 To Serve Advertising

• Display third-party advertisements through Google AdSense and other advertising networks.

• Allow advertising networks to use cookies and similar technologies to serve advertisements relevant to your interests.

• Measure the performance and reach of advertisements displayed on the Service.

3.5 To Ensure Safety and Compliance

• Detect and prevent fraud, fake reviews, spam, and abuse.

• Enforce our Terms of Use and other policies.

• Comply with applicable legal obligations and respond to lawful requests from authorities.

• Protect the rights, property, and safety of CrediBio, our users, and the public.

4. How We Share Your Information

CrediBio does not sell your personal information to third parties. We share your information only in the following circumstances:

4.1 Publicly Displayed Information

Information you voluntarily submit to public-facing parts of the Service — such as your review, business name, business description, ratings, and profile photos — is visible to all visitors of the platform. Please consider this before submitting content.

4.2 Service Providers

We share information with trusted third-party vendors who assist us in operating the Service, including:

• Cloud hosting and infrastructure providers.

• Email delivery services (including Resend.com for transactional email).

• Payment gateway processors.

• Analytics providers.

• Customer support tools.

These providers are contractually obligated to use your information only for the purpose of providing services to us and to maintain appropriate data protection standards.

4.3 Advertising Partners

We work with third-party advertising networks, including Google AdSense, to display advertisements on the Service. These partners may use cookies, web beacons, and similar technologies to collect information about your visits to our Service and other websites in order to provide advertisements about goods and services that may interest you.

Important clarifications:

• We do not share your name, email address, phone number, or KYC documents with advertisers.

• Advertising partners receive anonymised or aggregated data, or data collected directly through their own cookies.

• Google’s use of advertising cookies enables it to serve ads based on your prior visits to our site and other sites on the internet.

• You can opt out of Google’s use of cookies by visiting Google’s Ads Settings at https://adssettings.google.com.

• You can opt out of third-party vendor use of cookies by visiting the Network Advertising Initiative opt-out page at https://optout.networkadvertising.org.

4.4 Business and Legal Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

4.5 Legal Compliance and Protection

We may disclose your information when we believe in good faith that disclosure is necessary to:

• Comply with a legal obligation, court order, or governmental request.

• Enforce our Terms of Use or other agreements.

• Protect the rights, property, or safety of CrediBio, our users, or the public.

• Detect, prevent, or address fraud, security issues, or technical problems.

5. Legal Basis for Processing

Where applicable under data protection law, we process your personal information on the following legal grounds:

• Contract — to perform our obligations to you under the Terms of Use, such as creating and managing your account.

• Legitimate interests — to operate and improve the Service, prevent fraud, and serve advertising, where these interests are not overridden by your rights.

• Consent — for marketing communications and, where required, for certain cookies. You may withdraw consent at any time.

• Legal obligation — to comply with applicable laws and respond to lawful authority requests.

6. Cookies and Tracking Technologies

6.1 What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences, keep you logged in, and understand how you use the site. We also use similar technologies such as web beacons, pixel tags, and local storage.

6.2 Types of Cookies We Use

• Essential cookies — necessary for the Service to function correctly. These include session management and security cookies. These cannot be disabled without affecting core functionality.

• Analytics cookies — used to understand how visitors interact with the Service, which pages are most popular, and where users encounter errors. We use this data to improve the platform.

• Advertising cookies — used by Google AdSense and other advertising partners to serve relevant advertisements and measure their effectiveness. These may track your activity across multiple websites.

• Preference cookies — used to remember your settings and preferences, such as language selection and location filters.

6.3 Third-Party Cookies

Google AdSense and other advertising networks may place their own cookies on your device when you visit our Service. These third-party cookies are governed by the privacy policies of those networks, not by this Privacy Policy. We encourage you to review Google’s Privacy Policy at https://policies.google.com/privacy.

6.4 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to:

• View what cookies are stored and delete them individually.

• Block third-party cookies.

• Block all cookies from specific websites.

• Block all cookies entirely.

Please note that disabling certain cookies may affect the functionality of the Service. For instructions on managing cookies in your specific browser, visit your browser’s help documentation.

7. Data Retention

We retain your personal information for as long as your account remains active or as necessary to provide the Service. We also retain information as required to comply with legal obligations, resolve disputes, and enforce our agreements.

Specific retention periods:

• Account and profile data — retained for the duration of your account, plus up to 2 years after account deletion for audit and legal compliance purposes.

• Review and public content — may remain visible on the platform after account deletion unless specifically requested for removal, subject to our content policies.

• KYC and verification documents — retained for the period required under applicable anti-fraud and financial regulations.

• Transaction records — retained for a minimum of 7 years as required by Nigerian financial regulations.

• Log and usage data — typically retained for 12 months.

You may request deletion of your personal data at any time. See Section 9 for your rights and how to exercise them.

8. Data Security

CrediBio implements industry-standard technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, and destruction. These measures include:

• Encryption of data in transit using SSL/TLS protocols.

• Secure storage of passwords using one-way hashing.

• Access controls limiting data access to authorised personnel only.

• Regular security assessments and monitoring.

However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. In the event of a data breach that is likely to result in risk to your rights, we will notify you and relevant authorities as required by applicable law.

9. Your Rights and Choices

Depending on your location and applicable law, you may have the following rights regarding your personal information:

• Right of access — you may request a copy of the personal information we hold about you.

• Right to rectification — you may request that we correct inaccurate or incomplete information.

• Right to erasure — you may request that we delete your personal information, subject to certain legal exceptions.

• Right to restriction — you may request that we limit how we process your information in certain circumstances.

• Right to data portability — you may request that we provide your data in a structured, machine-readable format.

• Right to object — you may object to our processing of your data for direct marketing or where we rely on legitimate interests.

• Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@credibio.com. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.

Please note that some of these rights are subject to limitations under applicable law, and we may need to retain certain information for legal, security, or operational reasons.

10. Children’s Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe that a child under 18 has provided us with personal information without parental consent, please contact us at privacy@credibio.com and we will take steps to delete such information promptly.

11. International Data Transfers

CrediBio is based in Nigeria and primarily serves users in West Africa. Your information may be processed and stored on servers located in other countries, including countries outside West Africa, where our cloud infrastructure and service providers operate.

When we transfer personal information internationally, we ensure appropriate safeguards are in place, including contractual protections with our service providers that require them to maintain data protection standards consistent with this Privacy Policy.

12. Links to Third-Party Websites

Our Service may contain links to third-party websites, including business websites listed on our platform. This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices or content of third-party websites.

13. Google AdSense and Advertising Disclosure

CrediBio participates in the Google AdSense programme. Google AdSense is an advertising service provided by Google LLC. This section is provided specifically to meet Google AdSense programme requirements.

The following disclosures apply to our use of Google AdSense:

• Google uses cookies to serve ads on our site based on your prior visits to our website or other websites.

• Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and/or other sites on the internet.

• We use DoubleClick cookies, which enable Google and its partners to serve ads to our users based on their visits to our Service and/or other sites on the internet.

• Users may opt out of personalised advertising by visiting https://adssettings.google.com.

• Alternatively, users can opt out of third-party vendor use of cookies for personalised advertising by visiting https://optout.aboutads.info.

We do not use AdSense to target children or to display ads on pages with content directed at children. All advertisements displayed on our platform are subject to Google’s advertising policies. We do not have control over the specific ads displayed, but we do not knowingly permit ads that are deceptive, illegal, or harmful.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the Effective Date at the top of this document and notify you by email or through a prominent notice on the Service.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes.

15. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise any of your rights, please contact our Privacy Team:

CrediBio Privacy Team

Email:  info@credibio.com

Website:  www.credibio.com

Subject line:  Privacy Request / Data Enquiry

We aim to respond to all privacy-related enquiries within 30 days of receipt.