Legal

Scorift Privacy Notice

Last updated August 5, 2026

Effective August 5, 2026. This Privacy Notice explains how Scorift Africa Ltd and its affiliates handle information across our website, developer portals, dashboard, and fraud detection APIs. Read it alongside our Cookie Policy.

Section 1

Introduction

Scorift Africa Ltd and its affiliates (collectively, "Scorift," "we," "us," or "our") respect your privacy and are committed to safeguarding it responsibly. This Privacy Notice describes how we collect, use, store, share, and protect information across our website, developer portals, Application Programming Interfaces (APIs), software applications, and other tools (collectively, the "Services").

We do not take your trusting us with your information for granted. As a fraud detection API as-a-service provider, we process data to help businesses secure transactions, verify identities, and prevent fraudulent activities. This policy outlines our transparency commitments, your data privacy rights, and how we uphold security standards in compliance with applicable data protection legislations.

Section 2

Our Privacy Principles

At Scorift, our operations are guided by core data protection values:

  • Empowering the Individual: We want you to be informed about your data and able to make voluntary choices.
  • Security First: We enforce administrative, technical, and physical security measures to protect personal data from unauthorized access, loss, or misuse.
  • Transparency: We aim to be clear about what data we collect, why we collect it, how we process it, and with whom it is shared.
Section 3

Information We Collect

We collect information in distinct ways depending on how you interact with our Services: business clients (merchants/developers integrating our API) and end-users (whose data is processed through our fraud detection API on behalf of our clients).

A. Information Provided by Clients (Account & Profile Data)

When you register for a Scorift developer account, access our dashboard, or communicate with us, we collect:

  • Contact details (e.g., name, business email address, phone number, company name, and address).
  • Authentication and credential data (e.g., usernames, secure passwords, API keys).
  • Billing and financial transaction information necessary to manage subscriptions to our API services.

B. Information Collected via Our Fraud Detection APIs

As a fraud-scoring and risk-assessment API, our clients transmit transactional and user-attribute data to our endpoints to evaluate risk levels. This may include:

  • Device and technical telemetry (e.g., IP addresses, device identifiers, browser types, operating systems, and geolocation data).
  • Transaction metadata (e.g., payment amounts, timestamps, hashed email identifiers, and device fingerprints).
  • Behavioral indicators utilized exclusively for detecting, preventing, and mitigating fraudulent transactions.

C. Automatically Collected Usage and Web Data

When you visit our website or documentation portals, our servers automatically record information, including pages visited, links clicked, session durations, and log-in details. We use cookies, web beacons, and pixel tags to optimize performance and secure user sessions.

Section 4

How We Use Personal Information

We process personal information for lawful, transparent, and business-critical purposes, including:

  • Providing and Maintaining Services: To operate our API infrastructure, authenticate clients, and execute risk assessment requests.
  • Fraud Prevention and Security: To detect, prevent, investigate, and manage illegal activities, security breaches, and fraudulent transactions.
  • Legal and Regulatory Compliance: To satisfy applicable laws, regulations, anti-money laundering (AML) standards, and enforceable governmental or law enforcement requests.
  • Service Improvement: To analyze usage trends, update system architecture, debug technical issues, and enhance our fraud-scoring algorithms.
  • Client Communications: To send administrative updates, security alerts, product modifications, and technical notices.
Section 6

How We Share Personal Information

Scorift does not sell or rent your personal information. We share data only under strictly limited circumstances:

  • With Third-Party Service Providers: We share data with trusted vendors, cloud hosting providers, and infrastructure partners who process data on our behalf under strict contractual confidentiality and security obligations.
  • Corporate Transactions: If Scorift is involved in a merger, acquisition, restructuring, or asset sale, your information may be transferred, subject to advance notice and a transition to a comparable privacy policy.
  • Legal Obligations and Safety: We may disclose data if we determine in good faith that disclosure is reasonably necessary to comply with a law, regulation, legal process, court order, or subpoena, or to protect the safety, rights, or property of Scorift, our clients, or the public.
  • With Your Explicit Consent: When you authorize a third-party application or integration to access your account, data is shared based on your precise directions.
Section 7

Data Security and Retention

Security Safeguards

We implement organizational, technical, and physical safeguards — including data encryption in transit and at rest, firewalls, and strict role-based access controls — to protect personal information from unauthorized disclosure, destruction, or modification.

Data Retention

We retain personal information for as long as your account is active or as needed to provide our Services. Transaction logs and API payload histories processed for fraud detection are retained only for the duration necessary to fulfill anti-fraud obligations, resolve disputes, or comply with legal retention mandates, after which data is securely deleted, anonymized, or aggregated.

Section 8

Your Data Protection Rights

Subject to local regulatory frameworks, you have specific rights regarding your personal information:

  • Right to Access: You can request copies of the personal data we hold about you.
  • Right to Rectification: You have the right to request the correction of inaccurate, outdated, or incomplete data.
  • Right to Erasure (Deletion): You can request the deletion of your personal data where there is no compelling legal justification for its continued processing. Note: As a fraud prevention provider, certain transactional records must be retained to comply with legal and risk-management obligations.
  • Right to Object or Restrict Processing: You can object to or limit our processing of your data under specific conditions, though doing so may impact our ability to supply API services.
  • Right to Data Portability: You can request the transfer of your structured data to another service provider where technically feasible.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing conducted prior to withdrawal.
Section 9

Third-Party Links and Services

Our website and API documentation may contain links to external sites or platforms not operated by Scorift. We do not control and are not responsible for the privacy practices, content, or security measures of external websites. We encourage you to review the privacy notices of any third-party services you visit.

Section 10

Children's Privacy

Our Services are strictly directed toward enterprise clients, developers, and businesses, and are not intended for individuals under the age of 18. We do not knowingly collect or solicit personal information from minors. If we discover that we have inadvertently gathered data from a minor, we will delete it immediately.

Section 11

Changes to This Privacy Notice

We may update this Privacy Notice periodically to reflect changes in our practices, technology, or legal requirements. When we post modifications, the "Last Updated" date at the top will be revised. We encourage you to review this page regularly to stay informed about how Scorift protects your privacy.

Section 12

Contact Us

If you have any questions, complaints, or requests regarding this Privacy Notice, or if you wish to exercise your data protection rights, please contact our Privacy Team at:

Scorift risk scores and API outputs are decision-support tools, not absolute guarantees or legal determinations. Clients retain sole responsibility for compliance and final transaction decisions.

©2026 Scorift. All rights reserved.