Legal

Privacy Policy

This Privacy Policy explains what data Wealthstein collects, how we use it, and the choices available to you — whether you're a lender using our platform or a borrower whose data a lender has submitted to us on your behalf.

Who this applies to

Wealthstein works with two kinds of data. The first is lender account data: information about the people and institutions using our dashboard and API. The second is borrower data: financial and identity information a lender submits to us, under that borrower's own consent, in order to receive a credit score. Borrowers never interact with Wealthstein directly or create accounts with us.

What we collect

From lenders: full name, work email, company name, and a securely hashed password when you request a pilot or create a dashboard account. We never store passwords in plain text. Optional fields such as role and phone number may be added to our records manually during follow-up.

From borrowers, via lenders: financial and identity signals submitted by a lender under their own consent process — for example, payment history, account activity, and identity verification data. Phone numbers and other direct identifiers are hashed before storage; we do not retain raw identifiers where a hash is sufficient for our scoring purposes.

How we use it

Lender account data is used to operate your dashboard access, process billing, and follow up on pilot and support requests. Borrower data is used solely to compute and return a credit score to the lender who submitted it, and to maintain a single persistent Credit Identity per borrower that updates as new, consented data arrives. We do not use borrower data for advertising, and we do not sell borrower or lender data to third parties.

Consent and access control

A lender only ever receives a score for a borrower they have directly onboarded with that borrower's consent. If a borrower's underlying Credit Identity has been built up from data submitted by more than one lender, each additional lender still requires its own explicit, named, revocable consent record before it can see that borrower's score — an identity match alone never grants access. Every score request is logged and attributed to the requesting lender for audit purposes.

How we protect it

Passwords are hashed, never stored in plain text. Phone numbers and similar borrower identifiers are hashed before storage. Access to production lender accounts requires approval, and dashboard sessions use secure, HTTP-only cookies rather than exposing API keys to the browser directly. Administrative actions that affect billing or account status are protected separately from ordinary lender access.

Data retention

We retain lender account data for as long as the account remains active, and borrower data for as long as needed to provide the scoring service to the lender who submitted it, subject to the retention limits of applicable data-protection law in Nigeria and any other jurisdiction where we operate. You can request deletion of your lender account data at any time by contacting us.

Your rights

Depending on your jurisdiction, you may have the right to request access to, correction of, or deletion of your personal data, and to object to certain processing. Lenders can reach us directly to exercise these rights for their own account data; borrowers should contact the lender who submitted their data, since Wealthstein does not hold a direct relationship with borrowers.

International data

Our infrastructure may process and store data outside the country where you or your borrowers are located. Where this occurs, we take reasonable steps to apply protections consistent with this policy regardless of where the data is processed.

Changes to this policy

We may update this policy as our Service evolves. Material changes will be communicated to active lender accounts by email or dashboard notice before taking effect.

Contact

Questions about this policy, or requests relating to your data, can be sent to adekoya@wealthstein.com.