Privacy Policy

Version 1.3 · Updated 6 September 2026

This Privacy Policy explains how CHECKLL SARL collects, uses, shares and protects your personal data when you use the CHECKLL platform (the mobile app and checkll.com). Please read it together with our Terms & Conditions.

1. Who we are (Data Controller)

The controller responsible for your personal data is CHECKLL SARL, a company registered in Cameroon (RCCM No. CM-NSI-01-2026-B13-00691), registered office at Camp-David-Oyomabang, Yaoundé, Cameroon. You can contact us about privacy at [email protected].

2. The data we collect

We do not access your device's contact list, and we do not collect your precise (GPS) location.

3. How we use your data

Legal bases (where applicable): your consent; performance of our contract with you (the Terms); our legitimate interests in operating a trustworthy platform and preventing fraud; and compliance with law.

Automated decisions and your trust score. Your trust score is calculated from the references your referees provide and from verified signals on your profile (for example, whether your identity and references are verified). It is not used to make solely-automated decisions that produce legal or similarly significant effects about you. CHECKLL does not decide, by automated means alone, whether you are hired, lent to, or insured — those decisions are made by the employer, lender or insurer who views your report, with their own human judgement.

Where automated processing is involved, you have the right to obtain human review, to express your point of view, and to contest the outcome by contacting [email protected]. On request we will give you meaningful information about the main factors behind your score, without disclosing the exact internal weightings, which we keep confidential to protect the integrity of the trust system.

4. How we share your data

We do not sell your personal data, and we do not use it for third-party advertising.

If you are named as a referee. When someone asks you to vouch for them, we process your name, contact details, your relationship, the reference you give, and the live selfie you provide to confirm you are a real, distinct person. We use this only to verify and record the reference; your individual ratings are combined into a score and are never shown to the person you vouched for. You can ask us to access, withdraw, or delete your details at [email protected].

5. Biometric (facial-recognition) data

What we process and why. When you upload a selfie, we derive facial-recognition data from it. This special-category biometric data is used solely to (a) check that your selfie matches your identity document and (b) detect duplicate, fraudulent or banned accounts. We rely on your explicit consent and our legitimate interest in preventing fraud. It is not used for advertising, is not sold, and is retained only as long as needed for these purposes and our legal/accountability obligations. You may withdraw consent by asking us to delete your account, subject to the retention rules in Section 8.

Biometric retention and destruction. We keep your facial-recognition data only for as long as it is needed for the purposes above (identity verification and fraud/duplicate-account detection). We permanently destroy it when that purpose is satisfied — for example when you close your account — or within three (3) years of your last interaction with CHECKLL, whichever occurs first, unless a longer period is required by law or to establish, exercise or defend legal claims. Because the clock runs from your last interaction, an active user's biometric data remains available for the anti-fraud checks and is not deleted while you keep using the service. This retention-and-destruction schedule forms part of our public policy. We do not sell, lease, trade, or otherwise profit from your biometric data, and we obtain your written consent before collecting it.

6. International transfers

Our primary database and file storage (Supabase) are hosted in the European Union — Frankfurt, Germany (region eu-central-1) — so your personal data, including your profile, documents and biometric data, is stored within the European Economic Area (EEA). Some ancillary service providers may process a limited part of your data (for example your email address for email delivery) outside the EEA or the UK; where they do, we rely on an appropriate legal safeguard — in particular the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved — so that your data keeps a level of protection consistent with EU and UK law. You can ask us for more information about these safeguards at [email protected].

7. Security

Your data is transmitted over encrypted connections (HTTPS/TLS) and stored on secure servers with access controls and encryption at rest. Access by CHECKLL staff is role-restricted and recorded. No system is perfectly secure, but we work to protect your information and to limit who can see it.

8. How long we keep it, and your rights

Order and Work-Agreement records. When an order is closed (completed, refunded or cancelled), we retain the order and its Work Agreement — the agreed terms, amount, payment references, electronic-signature timestamps and the CHECKLL account identifiers of the buyer and seller — for ten (10) years, to meet our commercial and tax record-keeping obligations (including under the OHADA Uniform Act on commercial records) and to resolve any complaint raised after the order ends. Where a dispute, complaint or safety report concerns an order, the related records are kept until the matter is resolved; if it is still open at the end of the ten-year period, retention continues until it is closed. Full names and contact numbers are held in the parties' verified accounts (never printed on the shareable agreement, which shows first name and last initial only) and are disclosed only to CHECKLL for dispute handling. After the applicable period — or on a valid deletion request where no legal hold applies — order records are deleted or irreversibly anonymised; aggregate, de-identified statistics may be retained.

We keep your data for as long as necessary to provide the service and to meet our accountability and legal obligations. To protect the integrity of the trust system, certain records — for example a profile that has completed a trade or received a rating — are retained and cannot simply be erased to avoid accountability (see Terms, Section 3).

Subject to that and to applicable law, you have the right to access, correct, object to, and request deletion of your personal data, and to withdraw consent. To exercise any of these, email [email protected]. Depending on where you live, you may also have the right to complain to your national data-protection authority (for example under the GDPR, South Africa's POPIA, or Nigeria's NDPA).

If you are in California (USA). Biometric information and government-identity documents are treated as "sensitive personal information" under California law. In addition to the rights above, you have the right to know, delete and correct your personal information; the right to limit the use and disclosure of your sensitive personal information to what is necessary to provide the service; and the right not to be discriminated against for exercising these rights. We do not sell, or "share" for cross-context behavioural advertising, your personal information, so there is nothing to opt out of. To exercise any California right, email [email protected]; we will verify your request and respond within the time the law allows.

Other US states. Illinois, Texas and Washington have specific biometric-privacy laws. Our handling of biometric data (Section 5) — written consent before collection, a published retention-and-destruction schedule, and no sale or profit — is designed to meet these requirements.

9. Cookies & local storage

CHECKLL does not use advertising or cross-site tracking cookies. The app uses your browser's local storage for strictly necessary purposes only — keeping you signed in, remembering your language and settings, and showing your wallet/escrow display. Our providers (Supabase, Cloudflare) may set strictly-necessary storage to deliver the service. You can clear this at any time in your browser settings.

10. Children

CHECKLL is not intended for children. You must be at least 18 years old (or the age of majority where you live) to use it.

11. Changes to this policy

We may update this policy as the service and the law evolve. We will post the updated version here with a new effective date and, where changes are significant, notify you in the app.

12. Contact

Questions or requests about your privacy: CHECKLL SARL, Camp-David-Oyomabang, Yaoundé, Cameroon — [email protected].