Crifs Privacy Policy
Last updated: August 2026
You're trusting us with the two most sensitive things a founder or investor has: your identity and your money. This policy explains, in plain English, what we collect, why, who sees it, and what you can do about it. No tricks, no forty-page fog.
1. Who we are
Crifs is built by Crifs Investments Ltd, registered in Lagos and London. The app helps founders raise and manage capital, and helps investors track what they've backed. Legally speaking, we're the “data controller”, the company responsible for your data.
Questions, complaints, anything: hello@crifs.io. A real person replies. Our office address is at No 2 Ilara Road, Ode Remo, Beside Health Center Roundabout, Ode Remo, Ogun State, Nigeria.
2. What this covers
This policy covers the Crifs app (iOS and Android), crifs.io, and our support channels, including WhatsApp support. It doesn't cover any third-party services you use alongside Crifs; those have their own policies.
3. What we collect
Things you give us
- Your account:name, email, phone number, password or passkey, whether you're a founder or an investor, and your company details.
- Your identity (KYC):government ID, a selfie for verification, date of birth, nationality, home address, and (for companies) director and ownership information. We're legally required to check who you are before money moves, and we screen against sanctions and PEP lists. Our verification partners handle some of this for us.
- Your money: committed and released capital, bank details, payment records, your cap table and share register, currencies, and any activity on the early-exit marketplace.
- Your documents: prospectuses, financials, board resolutions, votes and e-signatures, plus the audit trail that proves who signed what, and when.
- Your messages: support conversations (including WhatsApp) and the investor updates you write.
Things we pick up automatically
- Your device: phone model, operating system, app version, device identifiers, language and time zone.
- How you use Crifs: screens viewed, features used, crash reports, and your IP address (which gives us a rough idea of where you are).
- Biometrics (read this one): Face ID and fingerprint unlock happen entirely on your phone, handled by Apple or Google. Your face and fingerprint never leave your device, and we never see them. Ever.
Things others tell us
Identity-verification and sanctions-screening providers send us results, and we sometimes check public company registries. If you upload a share register or cap table yourself (for example as a CSV), the data in that file comes across too.
4. Why we collect it
Every piece of data above earns its place. We use it to:
- run the product: accounts, capital tracking, tranche releases, voting, the data room, investor updates (we need this to deliver what you signed up for);
- meet our legal duties:KYC, anti-money-laundering checks, sanctions screening, fraud prevention (the law doesn't give us, or you, a choice here);
- generate your compliance score and AI performance grade.These come from the financials, KPIs and milestones you put in. They inform humans; they don't replace them (more in Section 10);
- keep the platform secure: encryption, device-bound keys, monitoring, audit trails;
- support you and improve the product;
- send marketing,only if you've said yes, and you can say no at any time.
Where GDPR-style laws apply, our legal bases are: performing our contract with you, complying with legal obligations, our legitimate interests, and your consent (which you can withdraw whenever you like).
5. Who sees your data
We don't sell your data. Not to advertisers, not to data brokers, not to anyone. Here's who does see it:
- The people in your deals.That's the point of Crifs. Investors in your round see the data room, votes and milestone reports they're entitled to. Founders see their investors' names, commitments and votes. Nobody sees deals they're not part of.
- Companies that help us run Crifs:cloud hosting, identity verification, e-signatures, payments and banking, FX, analytics, support tools. They work under contract, on our instructions, and can't use your data for their own ends. Want the current list? Email hello@crifs.io.
- Our advisers and auditors, under confidentiality.
- Regulators and courts, when the law genuinely requires it, not just when someone asks nicely.
- A future owner of Crifs,if we're ever acquired. This policy would still bind them.
6. Where your data travels
Crifs runs in Nigeria, Kenya, South Africa, the UK and the US, so your data may be processed in any of them. When it crosses borders out of a country with transfer rules, we use the approved mechanisms (Standard Contractual Clauses, the UK transfer addendum, or adequacy decisions) and it stays encrypted the whole way.
7. How long we keep it
As long as your account is active, plus only what the law demands after that. KYC and anti-money-laundering records must be kept for 5 to 7 years after you leave (that's the law, not our preference). Signed resolutions and share transfers are corporate records with their own legal retention periods. Support chats: 10 years. Diagnostic logs: 8 months. After that, we delete it or strip it of anything that identifies you.
8. How we protect it
This is where we spend a lot of our time. Crifs is SOC 2 Type II audited. Everything is encrypted: AES-256 while stored, TLS 1.3 while moving. The app unlocks with your biometrics, and keys are bound to your device, so a stolen phone is just a brick. Every dilution event and signature is cryptographically sealed so nobody can quietly rewrite history. Access to production data is restricted, logged and reviewed.
We won't pretend any system is unbreakable. If a breach ever affects you, we'll tell you and the regulator quickly, within 72 hours where the law sets that clock.
9. Your rights
Wherever you are (Nigeria, Kenya, South Africa, the UK, the EU or California) you can:
- ask for a copy of everything we hold on you;
- correct anything that's wrong;
- delete your data (we'll do it, except the records the law forces us to keep, and we'll tell you exactly which);
- object to or restrict certain processing, including marketing. One tap, no guilt trip;
- take your data with you in a usable format;
- withdraw consent at any time;
- insist a human, not an algorithm, makes any decision that seriously affects you (see Section 10);
- complain to your regulator: the NDPC (Nigeria), ODPC (Kenya), Information Regulator (South Africa), ICO (UK), your EU authority, or the California AG. Though we'd love the chance to fix it first.
To use any of these: Account → Privacy in the app (deletion lives at Account → Deletion), or email hello@crifs.io. We answer within 30 days (45 in California).
California folks: we don't “sell” or “share” your data as the CPRA defines it, and crifs.io honours Global Privacy Control.
10. About our scores and AI
Crifs shows a compliance score and an AI performance grade, built from your filings, KYC status, financials, KPIs and milestone delivery. Here's our promise: these numbers inform decisions, they never make them. When a tranche gets released, it's because investors who are actual humans voted in the app. If a score looks wrong to you, ask us to explain it, challenge it, and a person will review it: hello@crifs.io.
12. Under 18?
Crifs is a financial platform for founders and investors, so it's adults only. We don't knowingly collect data from anyone under 18. If you think a minor has slipped through, tell us at hello@crifs.ioand we'll delete their data.
13. When this policy changes
We'll post updates here and change the date at the top. If a change actually matters, we'll tell you in the app or by email before it takes effect, not bury it and hope you don't notice.
14. Talk to us
Crifs Investments Ltd · Lagos & London · Registered address: No 2 Ilara Road, Ode Remo, Beside Health Center Roundabout, Ode Remo, Ogun State, Nigeria · hello@crifs.io· Company Secretary: Muhammed Awwal Omopupa, omopupaawwalt@gmail.com. Median support response is under 11 minutes during market hours, and privacy questions get the same treatment.