Privacy Policy

What personal data Bridge collects, why we collect it, and how long we keep it.

Version 1.0Effective 7 September 2026

1. Scope

This policy explains how Bridge Ecosystem ("Bridge", "we", "us") handles personal data, and is written with reference to the Nigeria Data Protection Act 2023 (NDPA). Where you are located elsewhere, we apply equivalent standards.

2. What we collect

Account data: name, email, avatar and profile identifiers supplied by the sign-in provider you choose (Google, X, LinkedIn, Discord, Facebook).

Profile and portfolio data: the biography, links, resume and work samples you choose to publish.

Submission data: the links, descriptions and files you submit to bounties.

Identity verification data: where you complete KYC, the identity document images and any liveness video you upload. This is sensitive personal data and is handled under the Identity Verification Consent.

Wallet data: your on-chain addresses and transaction history. Your private key is stored encrypted; see the Wallet & Self-Custody Terms.

Technical data: IP address, user agent, and timestamps, including those recorded alongside each consent you give.

3. Why we process it

To operate your account, display your profile, and run bounties and payouts (performance of our contract with you).

To verify identity, prevent fraud, plagiarism and multi-accounting, and to keep the platform secure (legitimate interest and legal obligation).

To meet anti-money-laundering and record-keeping obligations (legal obligation).

To prove that you agreed to our terms at a given time (establishment and defence of legal claims).

To send service messages. Marketing messages are sent only where you have opted in.

4. Who we share it with

Sponsors see the profile and submission data of creators who apply to their bounties. They do not receive your identity documents.

We use processors to run the service — hosting and database (Supabase, Vercel), email delivery (Resend), and Telegram for internal administrative alerts. They act on our instructions.

We disclose data to law enforcement or regulators only where legally required, and we do not sell personal data.

5. Retention

Account, submission and payout records are retained while your account is open and for up to seven years afterwards, to meet financial record-keeping obligations and to defend claims.

Identity verification documents are retained for the period stated in the Identity Verification Consent and deleted thereafter.

Consent records are retained for as long as the underlying agreement could be disputed, because their entire purpose is evidential.

6. Your rights

Subject to the NDPA, you may request access to your data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing based on legitimate interest. You may also lodge a complaint with the Nigeria Data Protection Commission.

Some data cannot be deleted on request where we must keep it by law, or where it evidences a transaction or agreement.

To exercise a right, contact us through the in-app support page.

7. Security and transfers

We use encryption in transit and at rest, encrypted storage for wallet keys, role-based access controls and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

Our infrastructure providers may process data outside Nigeria. Where that happens we rely on the transfer mechanisms permitted by the NDPA.