Privacy policy
Last updated: June 2026
This Privacy Policy explains how Ntaska collects, uses, stores, and protects your personal data when you use our platform. We are committed to compliance with the Nigeria Data Protection Regulation (NDPR) and applicable international data protection standards.
1. What we collect
We collect the following categories of personal data:
- Account information: name, email address, password (hashed, never stored in plain text), and role
- Worker profile data: full name, region, skill tags, bio, and target platform preferences
- Training and assessment data: module progress, mock assessment responses, instructor feedback, and qualification status
- Payment records: payment amount, Paystack reference, and transaction status. We do not store your card details — card processing is handled entirely by Paystack
- Earnings records (self-reported): amounts in USD cents, platform, period, and optional notes — entered voluntarily by workers
- Payout account references: USDT wallet address, network, and label. We never request or store private keys or seed phrases
- Usage data: pages visited, actions taken, timestamps, and IP address (collected by Supabase for security purposes)
2. How we use your data
We use personal data to:
- Provide and operate the Ntaska training and qualification platform
- Send transactional emails (registration confirmation, payment receipts, assessment results) via Resend
- Process payments via Paystack and verify webhook events
- Display qualified workers in the public directory (only with explicit worker opt-in via the "Visible in directory" toggle)
- Respond to contact and support requests
- Detect and prevent fraud, abuse, and violations of our Terms
- Send platform and community newsletters (only with your consent)
We do not use your data for automated decision-making that produces legal effects without human review, and we do not sell or rent your personal data to any third party.
3. Data storage and security
Your data is stored in Supabase's managed Postgres infrastructure, hosted in a region with adequate data protection standards. All data in transit is encrypted via TLS/HTTPS. Passwords are hashed using bcrypt.
Row-level security (RLS) policies ensure that workers can only access their own records — not other users' data. Admin users have elevated access for operational support purposes only.
In the event of a data breach that affects your personal data, we will notify you and the relevant authority (the National Information Technology Development Agency, NITDA) within 72 hours of becoming aware of the breach, where required by the NDPR.
4. Third-party services
We share data with the following third parties only to the extent necessary to operate the Platform:
- Supabase — database, authentication, and storage. Supabase processes data as a data processor on our behalf.
- Paystack — payment processing. Paystack is a PCI DSS-compliant payment processor. We receive only payment references and status, not card details.
- Resend — transactional email delivery. We share your email address and relevant template data (e.g. your name, enrollment details) to send you emails you have requested.
- Vercel — platform hosting and edge infrastructure. Request metadata may be processed by Vercel as part of serving the application.
We do not integrate with advertising networks, data brokers, or analytics platforms that track you across other websites.
5. Cookies and local storage
We use the following cookies:
- Authentication session cookies — set by Supabase Auth to maintain your logged-in session. These are strictly necessary and cannot be disabled without logging you out.
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. If we add analytics in the future, we will update this policy and obtain consent where required.
6. Your rights
Under the NDPR and applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate or incomplete data
- Deletion: request deletion of your personal data, subject to legal retention obligations
- Portability: request your data in a structured, machine-readable format
- Objection: object to certain processing of your data, including direct marketing
- Withdraw consent: withdraw consent for processing that relies on consent (e.g. newsletter) at any time
To exercise these rights, contact us at privacy@ntaska.fun. We will respond within 30 days.
7. Data retention
We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 90 days, except where retention is required by law (e.g. payment records, which are retained for 6 years for tax and audit purposes).
Earnings records and qualification data that do not contain personally identifiable information may be retained in aggregated, anonymised form for platform analytics.
8. Children's privacy
Ntaska is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us immediately at privacy@ntaska.fun and we will delete it promptly.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email at least 14 days before they take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
10. Contact
For privacy-related enquiries, contact our data protection contact at privacy@ntaska.fun. For general enquiries, use the contact page.