Privacy Notice

Your Privacy Matters

This notice explains how BadMarket.ng collects, uses, shares and protects personal data, and what rights you have over it. It is written to meet the UK GDPR transparency requirements (Articles 13/14) as well as Nigeria's Data Protection Act, since BadMarket.ng is used by people in both countries.

Last updated: 22 August 2026 · Version 2.0

Who is the data controller

BadMarket.ng is operated by [CONTROLLER FULL NAME], an individual based in Nigeria, trading as BadMarket.ng (“we”, “us”). BadMarket.ng is not yet incorporated as a registered company — as an unincorporated business, the individual named above is the data controller responsible for your personal data under both the UK GDPR and Nigeria's Data Protection Act.

Postal address for data protection purposes: [REGISTERED/BUSINESS ADDRESS].

BadMarket.ng and RRSource (rrsource.com) are separate brands with separate, independent controllers. This notice covers BadMarket.ng only — see rrsource.com/privacy for RRSource's privacy notice.

Because BadMarket.ng is reachable by, and used by, people in the United Kingdom, we have UK GDPR obligations toward those users even though our controller is based in Nigeria. Under UK GDPR Article 27, a controller established outside the UK that offers services to UK residents must appoint a UK representative. [UK REPRESENTATIVE NAME/FIRM — TO BE APPOINTED]. Until this is in place, UK data-subject requests should still be sent to the contact below and will be honoured directly by the controller.

Data protection contact

For any question about this notice or to exercise your rights, contact: privacy@badmarket.ng.

Our data protection support is provided by DPO Assist. If you are not satisfied with our response, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or Nigeria's Data Protection Commission (NDPC) at ndpc.gov.ng.

Regulatory status: we are required to register as a data controller with the ICO. That registration has not yet been completed; this notice will be updated with the registration reference once it has.

What we collect, why, and our lawful basis

We only collect what a feature you use actually needs. In outline:

  • Account data (email, username, password, phone) — to create and secure your account. Lawful basis: performance of a contract with you (Art. 6(1)(b)).
  • Report content you submit (names, businesses, descriptions, money amounts, evidence files, and — where you choose to add them — the reported party's bank details, phone or email) — to operate the accountability platform. Lawful basis: legitimate interests in enabling consumer protection and fraud reporting (Art. 6(1)(f)), balanced against the reported individual's rights; see “People you report about” below.
  • Identity documents, where you submit them for regulator/verification tooling — Lawful basis: legitimate interests in preventing fraudulent reports, or consent where indicated at collection.
  • Payment and wallet data (via Paystack) — to process withdrawals and sponsorships. Lawful basis: contract performance and legal obligations (e.g. financial record-keeping).
  • Technical/activity data (IP address, user agent, pages viewed, API calls — see “Activity logging” below) — to secure the platform and diagnose abuse. Lawful basis: legitimate interests in platform security.

People you report about

When you submit a report, you provide personal data about someone else (the reported individual or business). We process this under legitimate interests (Art. 6(1)(f)) — enabling consumer protection and public-interest accountability reporting — balanced against that person's own data protection rights. Some fields (full bank account number, the reported party's NIN) are restricted from public view and only shown in masked or redacted form; see our evidence and report-field handling for detail. The reported person can dispute a report or request a review through the platform.

Automated processing, ranking and moderation

We use automated signals (e.g. duplicate-report detection, fraud/fabrication scoring, search ranking, “searchable tier”) to help surface and moderate content. These signals inform, but do not replace, human review — reports are only published after admin approval, and any account restriction or content removal can be appealed through our support channels. No automated system makes a final decision about you that produces legal or similarly significant effects without a human able to review it, so the enhanced safeguards in UK GDPR Article 22 are addressed by that human-review step.

How long we keep data

  • Approved reports and evidence: retained for up to 4 years from the report's last substantive activity (new evidence, comments, a resolution update), or for as long as the report continues to see genuine community engagement (witnesses, disputes, active threads), whichever is longer. Reports with no activity for 4 years are reviewed for deletion or anonymisation.
  • Rejected or withdrawn reports: deleted or anonymised within 90 days of rejection/withdrawal, other than data we must keep to defend against a legal claim.
  • Identity-verification documents: retained only as long as needed to support the verification decision and any related dispute, then deleted; see our biometric/identity notice below for verification-specific detail.
  • Activity and IP logs: retained for up to 12 months for security and abuse investigation, then deleted or aggregated.
  • Closed/deleted accounts: identifying profile data is erased on account deletion (see “Deleting your account”); reports you submitted may be retained per the periods above, delinked from your identity.

Who we share data with

We use the following processors to run BadMarket.ng. None of them are permitted to use your data for their own purposes.

  • Supabase (database, authentication, file storage) — may process data outside Nigeria/UK; transfers are covered by Supabase's standard contractual clauses.
  • Vercel (hosting) — as above.
  • Persona (identity verification) — processes identity documents and selfies for verification purposes only.
  • AWS SES / Resend (transactional email).
  • Bunny.net (video hosting/streaming for video reports).
  • Paystack (payment processing for wallet/withdrawals).
  • Termii (SMS delivery).

Where any of these processors store or process data outside Nigeria or the UK, we rely on their standard contractual clauses or equivalent safeguards for that transfer. We do not sell personal data.

Cookies & tracking

We use strictly necessary cookies (keeping you signed in, remembering your session) which don't require consent. We do not currently run optional analytics or marketing cookies; if that changes, we will ask for your consent first via a cookie banner, in line with Nigeria's NDPA and (for UK visitors) PECR.

Age requirement

BadMarket.ng is intended for people aged 18 and over. We ask for your date of birth at registration and do not knowingly allow accounts for under-18s. If we learn an account belongs to someone under 18, we will close it and delete the associated personal data.

Your rights

Subject to some exceptions, you can ask us to:

  • tell you what personal data we hold about you and why (access);
  • correct inaccurate data (rectification);
  • delete your data (erasure) — see Delete My Data;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, where processing is based on consent.

We respond to rights requests within one month, as required by UK GDPR Article 12(3).

Deleting your account

Requesting deletion via Delete My Data submits a tracked request that we review and action within one month. Deletion erases your identifying profile information and disables sign-in permanently. Reports and evidence you submitted may be retained per the retention periods above, delinked from your identity, for the accountability and legal-claims purposes described in this notice.

Contact us

For privacy concerns, contact us at: privacy@badmarket.ng