Privacy policy

This Policy explains how Gathr Technologies Limited collects, uses, discloses, and protects personal data in connection with the Gathr website, mobile applications, API integrations, and online fundraising platform. If you have questions, reach us at privacy@gathrhq.com.

Effective date: July 13, 2026. Last updated: July 13, 2026.

Contents

1. Introduction

This Privacy Policy explains how Gathr Technologies Limited ("Gathr", "we", "us", "our") collects, uses, discloses, and protects personal data in connection with the Gathr website, mobile applications, API integrations, and online fundraising platform (collectively, the "Services").

This Policy is issued in accordance with the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Commission's General Application and Implementation Directive (GAID), Section 37 of the Constitution of the Federal Republic of Nigeria, and, to the extent applicable, other statutes referenced in our Terms of Service, including the Money Laundering (Prevention and Prohibition) Act, 2022, the Cybercrimes (Prohibition, Prevention, etc.) Act, and CBN AML/CFT/CPF guidelines.

By using the services, you acknowledge that your personal data will be processed in accordance with this Policy. Where consent is our legal basis for processing, we will ask for it separately and specifically before proceeding.

2. Who we are

Gathr is a technology platform that enables organisers to create and manage fundraising campaigns and enables donors to contribute to those campaigns. For most personal data collected in connection with using the services generally (account registration, campaign content, browsing behaviour, communications), Gathr acts as the data controller.

For identity verification data described in Section 4, Gathr acts in a more limited capacity as described there.

3. Scope and application

This Policy applies to:

  • Organisers who create and manage campaigns
  • Donors who contribute to campaigns
  • Beneficiaries named in campaigns
  • Visitors who browse the platform without registering
  • Any other individual whose personal data we process in connection with the services

This Policy applies regardless of the device or channel used to access the services and applies to data subjects located in Nigeria, and, in accordance with the extraterritorial scope of the NDPA, to any data subject whose personal data we process in connection with operating in Nigeria.

4. Categories of personal data we collect

4.1 Data you provide directly

  • Identity data: full name, date of birth, gender, phone number, email address, residential or business address
  • Account data: username, password (stored in hashed form), account preferences, profile photograph
  • Campaign data: campaign title, story, images, videos, goal amount, category, updates, and any personal or medical information you choose to include in a campaign description
  • Communication data: messages sent to our support team, comments, feedback, dispute correspondence
  • Corporate and organisational data: for NGOs, charities, or corporate organisers, the names, roles, and contact details of authorised representatives, as well as organisational registration information

4.2 Identity verification data processed through third parties

  • Gathr does not itself capture, store, or process raw National Identification Number (NIN), International Passport, or bank account credential data on its own servers
  • Where our Terms of Service require Tier 1, Tier 2, or Tier 3 Customer Due Diligence, verification is performed by licensed third-party identity verification providers and by Paystack Payments Limited, directly against the relevant federal databases
  • Gathr receives only a verification outcome from these providers: a confirmation status (verified or not verified), a masked or tokenised reference, and the minimum identity attributes reasonably necessary to match the verification to your account
  • Gathr does not receive or retain your full NIN or unmasked account number
  • The identity verification providers and Paystack act as independent data controllers for the underlying raw identification and banking data, governed by their own privacy policies

4.3 Politically exposed persons (PEP) data

Where our Enhanced Due Diligence obligations under Section 4(6) of the Money Laundering (Prevention and Prohibition) Act, 2022 apply, we or our verification partners may collect additional information concerning your source of wealth, source of funds, political exposure status, and, where relevant, information regarding immediate family members or close associates, strictly to the extent required by law. This constitutes sensitive personal data processing under Section 30 of the NDPA and is carried out on the lawful basis of compliance with a legal obligation.

4.4 Payment and transaction data

  • Donation amounts, dates, and currency (USD, NGN, GHS, KES)
  • Payout requests and settlement records
  • Chargeback and dispute records
  • Card metadata such as card type and last four digits, as received from Paystack or Bachs (not full card numbers)

4.5 Data collected automatically

  • Device data: IP address, device identifiers, browser type, operating system
  • Usage data: pages visited, campaign views, referral source, session duration, click patterns
  • Cookies and similar tracking technologies: see Section 11 for details
  • Location data derived from your IP address, where used for fraud prevention or sanctions screening

4.6 AI-assisted content generation data

When you use Gathr's embedded AI features to draft or edit campaign content, the prompts and draft text you submit are processed to generate suggested content. We retain such prompts and generated drafts as part of your campaign record for accountability and dispute-resolution purposes.

4.7 Data from third parties

  • Verification results from identity and KYC/KYB providers
  • Transaction and settlement data from Paystack and Bachs
  • Sanctions and watchlist screening results from compliance data providers
  • Publicly available information used to verify campaign claims, where relevant to fraud investigation

Gathr does not receive or retain your full NIN or unmasked account number. Verification providers and Paystack act as independent data controllers for the underlying raw identification and banking data.

5. Lawful basis for processing

In accordance with Section 25 of the NDPA, we process personal data on one or more of the following lawful bases:

  • Consent: for optional features such as marketing communications and non-essential cookies, freely given, specific, informed, and unambiguous, and withdrawable at any time under Section 35 of the NDPA
  • Contractual necessity: to create your account, operate your campaign, process donations, and deliver the services you have requested
  • Legal obligation: to comply with AML/CTF obligations under the MLPPA 2022, CBN guidelines, tax law, and disclosure obligations to the NFIU, EFCC, or SCUML
  • Vital interests: in rare cases involving imminent risk to life, such as verifying a medical emergency campaign
  • Legitimate interests: for fraud prevention, platform security, service improvement, and enforcing our Terms, balanced against your rights and freedoms

6. Purposes of processing

We process personal data to:

  • Create and administer your account
  • Enable campaign creation, publication, and promotion
  • Process donations and execute payouts through Paystack
  • Conduct Tier 1, Tier 2, and Tier 3 due diligence as required under our Terms and the MLPPA 2022
  • Monitor for structuring, rapid velocity spikes, anonymous routing, and other suspicious activity patterns
  • Detect, prevent, and investigate fraud, misrepresentation, and misuse of the platform
  • Comply with reporting obligations to the NFIU, SCUML, EFCC, CBN, SEC, or any competent authority
  • Respond to your enquiries and provide customer support
  • Improve, secure, and maintain the technical performance of the services
  • Send you service notices, campaign updates, and, where you have consented, marketing communications
  • Enforce our Terms of Service and pursue or defend legal claims
  • Generate aggregated, anonymised analytics regarding platform usage and campaign performance

7. Sensitive personal data

In accordance with Section 30 of the NDPA, certain data we may process is classified as sensitive personal data, including health information voluntarily disclosed in medical fundraising campaigns, financial account information, and PEP-related data described in Section 4.3. We process sensitive personal data only where:

  • You have given explicit consent to its inclusion in a public campaign description
  • Processing is necessary to comply with a legal obligation such as AML/CTF due diligence
  • Processing is necessary to establish, exercise, or defend a legal claim

If you include health or medical information in your campaign story, you are voluntarily publishing that information to the public, and you should consider carefully what level of detail you wish to disclose. Gathr does not independently verify the accuracy of medical claims made in campaign content.

8. Children and persons lacking legal capacity

Consistent with our Terms, the services are not available to persons under eighteen (18) years of age, in line with the NDPA's definition of a child by reference to the Child Rights Act. We do not knowingly collect personal data from children.

Where a campaign is created on behalf of a minor beneficiary, the personal data relating to that minor is submitted and controlled by the adult organiser, who is solely responsible for obtaining any necessary parental or guardian consent for the inclusion of the minor's information, in accordance with Section 31 of the NDPA. If we become aware that a child has created an account in violation of these Terms, we will take steps to close the account and delete associated data.

9. How we disclose personal data

We disclose personal data in the following circumstances:

  • Payment and verification partners: Paystack Payments Limited, Bachs (https://bachs.io/), and licensed identity verification providers, strictly to process donations, execute payouts, and complete CDD/KYC/KYB verification
  • Regulatory and law enforcement disclosure: the NFIU, SCUML, EFCC, CBN, SEC, or any competent authority, where required under the MLPPA 2022, the TPPA 2022, or a valid legal order
  • Service providers: cloud hosting providers, customer support tools, analytics providers, and other processors, each bound by a data processing agreement
  • Corporate transactions: a successor, acquirer, or affiliate in connection with a merger, acquisition, financing, or sale of assets
  • Legal compliance and protection of rights: where disclosure is necessary to comply with a legal obligation, enforce our Terms, or protect the rights, property, or safety of Gathr, our users, or the public
  • With your consent: for any other disclosure not covered above, we will seek your specific consent

Consistent with our Terms, where disclosure is made pursuant to a suspicious transaction report, we may be legally prohibited from notifying you of the fact of disclosure under applicable anti-tipping-off provisions. We do not sell personal data to third parties for their own independent marketing purposes.

10. Cross-border data transfers

Where personal data is transferred outside Nigeria, for example where Paystack or Bachs processes an international donor's card or mobile money transaction or where cloud infrastructure is hosted outside Nigeria, we ensure such transfers occur only where the recipient jurisdiction has been assessed as providing an adequate level of data protection, or where appropriate safeguards are in place, such as standard contractual clauses, binding corporate rules, or another mechanism recognised under Part VIII of the NDPA. We maintain records of the safeguards applied to each category of cross-border transfer, as required by the GAID.

11. Cookies and tracking technologies

We use cookies and similar technologies to operate the platform, remember your preferences, and understand usage patterns. In accordance with the GAID's requirements on cookie consent, we obtain your opt-in consent before deploying any non-essential cookie or tracking tool. Strictly necessary cookies required for security, login, and core platform functionality do not require consent. You may manage your cookie preferences through your browser settings or our in-platform cookie preference centre.

12. Data retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including:

  • Account and campaign data: for the duration of your account, and for a further period after account closure as necessary to resolve disputes, chargebacks, or comply with statutory record-keeping obligations
  • KYC/AML compliance records: for a minimum period consistent with CBN and MLPPA record-keeping requirements, currently a minimum of five (5) years from the date of the transaction or the termination of the business relationship, whichever is later
  • Transaction and payment records: for the periods required under applicable tax and financial regulation
  • Marketing consent records: until you withdraw consent, plus a reasonable period thereafter to evidence compliance

Where retention periods expire, we will delete or irreversibly anonymise the relevant personal data, save where continued retention is required by law or to establish, exercise, or defend a legal claim.

13. Data security

In accordance with Section 39 of the NDPA, we implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption of data in transit, access controls, and regular security review of our systems. Notwithstanding these measures, no system is entirely secure, and we cannot guarantee absolute security, particularly with respect to the systems of third-party processors such as Paystack.

14. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, in accordance with Section 40 of the NDPA. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach and the measures taken or proposed to address it.

15. Your rights as a data subject

Under Part VI of the NDPA, you have the right to:

  • Be informed of how your personal data is processed
  • Access a copy of your personal data in a commonly used electronic format
  • Rectification of inaccurate or incomplete personal data
  • Erasure of your personal data where it is no longer necessary, where you withdraw consent, or where it was unlawfully processed
  • Restrict processing in certain circumstances, such as while a dispute over accuracy is resolved
  • Object to processing carried out on the basis of legitimate interest, including direct marketing, at any time free of charge
  • Data portability, to receive your personal data in a structured, machine-readable format
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
  • Not be subject to solely automated decision-making that produces legal or similarly significant effects concerning you
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been infringed

To exercise any of these rights, contact us using the details in Section 19. We will respond within the timeframe required under the NDPA and the GAID. Certain requests, particularly those touching KYC/AML compliance records, may be limited where erasure or restriction would conflict with our statutory obligations.

16. Automated decision-making

We may use automated tools, including algorithmic transaction monitoring described in our Terms, to flag potentially suspicious campaigns or transactions for human review. Consistent with Section 37 of the NDPA, no decision to freeze funds, suspend an account, or report a transaction to a regulatory authority is made on a solely automated basis without human review of the relevant flag.

17. Data Protection Officer and accountability

Gathr has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the NDPA and this Policy, in accordance with Section 32 of the NDPA. Where Gathr is determined to be a data controller or processor of major importance under the criteria issued by the NDPC, we will register accordingly and comply with applicable audit, registration, and compliance filing obligations under the GAID.

18. Changes to this Policy

We may update this Policy from time to time to reflect changes in law, regulatory guidance, or our data processing practices. Material changes will be communicated to you via the platform or your registered email address. Your continued use of the services after such notice constitutes acceptance of the updated Policy.

19. Contact us

For any question, request, or complaint regarding this Policy or the processing of your personal data, contact our Data Protection Officer at privacy@gathrhq.com .

You may also lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) at No.12 Dr. Clement Isong Street, Asokoro, Abuja, Nigeria, or by email at info@ndpc.gov.ng.

Ready to start your own campaign?

Join the creators already raising funds on Gathr.

Start a campaign