Stake history, odds accepted, self-exclusion settings, and responsible-gambling flags shared with licensing regulators where required.
01Who this covers
This policy applies to anyone who creates an AssetTf account, verifies their identity with us, or uses any AssetTf product: sports and event betting, cryptocurrency trading and custody, real estate investment pools, gold-backed holdings, or an AssetTf virtual card. It applies whether you reach us through the app, the web dashboard, or our API.
AssetTf NG is the data controller for users onboarded in Nigeria. If you're onboarded through a regional entity, that entity is the controller for your data, and this policy still describes how your information is handled.
02What we collect
We collect only what's needed to open your account, meet regulatory obligations, and keep your funds and identity safe.
- Identity data — full name, date of birth, government ID, BVN or NIN where applicable, selfie for liveness checks, and address.
- Account data — email, phone number, password hash, device identifiers, and two-factor authentication settings.
- Financial data — linked bank accounts, card details (tokenised, never stored in raw form), wallet addresses, transaction history, and source-of-funds declarations for larger deposits.
- Behavioural data — login times, in-app navigation, deposit and withdrawal patterns, and betting or trading activity, used mainly for fraud and risk monitoring.
- Support data — anything you share with us in chat, email, or a dispute, including attachments.
03Product-specific data
Because AssetTf spans five distinct asset classes, each carries its own extra layer of data collection, on top of the identity and account data above.
Wallet addresses, on-chain transaction hashes, exchange counterparties, and travel-rule data for transfers above regulatory thresholds.
Investment tier, unit or fund allocation, proof-of-funds documents, and beneficiary details for payout on maturity or sale.
Vaulted holding records, grams held, redemption and delivery preferences, and insurance-related identity checks for physical redemption.
Card issuance data, merchant category spend, authorisation logs, and the card processor's fraud-scoring signals.
04How we use it
- To open, verify, and maintain your account, including Know-Your-Customer and Anti-Money-Laundering checks.
- To process deposits, withdrawals, trades, stakes, card transactions, and asset purchases.
- To detect fraud, account takeover, and market abuse across all five products.
- To meet obligations to regulators, tax authorities, and licensing bodies in the jurisdictions where we operate.
- To send you transactional notices, security alerts, and — only with your consent — product updates and offers.
- To improve the product, using aggregated or de-identified data wherever we can.
06Virtual cards & payments
When you issue an AssetTf virtual card, we work with a licensed card processor to generate and manage it. We never store your full card number ourselves — it's tokenised at the processor and referenced by that token internally. We do see merchant name, category, amount, and timestamp for each transaction, which we use for your statements and for fraud monitoring.
If you fund a card from your crypto, gold, or real estate balances, the conversion record is kept alongside the card transaction so your statement stays reconcilable.
07How long we keep it
We keep identity and transaction records for as long as your account is active, plus the retention period required by financial regulation afterward — typically five years from your last transaction, longer where a specific product's regulator requires it (for example, betting compliance records). Support conversations are kept for three years to resolve any future disputes. When a retention period ends, data is deleted or irreversibly anonymised.
08Security
- Data in transit and at rest is encrypted; card numbers and sensitive credentials are tokenised or hashed.
- Access to production data is role-restricted and logged; support staff see only what's needed to resolve your ticket.
- We run regular penetration testing and independent security reviews across the platform.
- Two-factor authentication is available — and required above certain transaction thresholds — on every account.
09Your rights
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Correction | Ask us to fix inaccurate identity or contact details. |
| Deletion | Request account and data deletion, subject to regulatory retention rules — see our separate account deletion page. |
| Portability | Get your transaction history in a portable format. |
| Objection | Opt out of marketing communications at any time. |
| Restriction | Ask us to pause certain processing while a dispute is resolved. |
To exercise any of these, contact us using the details below. We aim to respond within 30 days.
11Age requirements
AssetTf is for adults only. You must be at least 18 — or the legal age for betting and investing in your jurisdiction, whichever is higher — to open an account. We don't knowingly collect data from anyone below that age, and we close accounts and delete associated data if we learn otherwise.
12Changes to this policy
We'll update this page when our practices change, and update the "last reviewed" date at the top. For material changes — anything that affects how your data is used — we'll also notify you directly by email or in-app before the change takes effect.
13Contact & complaints
Questions, requests, or complaints about how AssetTf handles your data can go to our privacy team at privacy@assettf.com. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.