Version 2026-09-04
Global Privacy Notice
Effective and last updated: 4 September 2026
This notice explains how MyStocks collects and uses personal information across its websites, applications, APIs, investment services, support channels, and partner platform.
1. Who is responsible for your information
The MyStocks entity that offers the relevant service is responsible for deciding why and how your information is used. The group includes Mystocks Inc., 300 Creek View Road, Suite 209, Newark, Delaware 19711, United States; MyStocks Technologies (Pty) Ltd, Cape Town, South Africa; and Hemms Stocks Ltd, Westlands, Nairobi, Kenya. MyStocks Technologies (Pty) Ltd provides South African services as a juristic representative of TanFox (Pty) Ltd, FSP 52040, where applicable.
Your account, product terms, onboarding screen, or transaction confirmation identifies the contracting entity for a particular service. Where more than one entity jointly determines processing, they coordinate requests through the privacy contact below. Service providers that act only on documented instructions are processors or operators, not controllers for those instructed activities.
Privacy questions and rights requests: privacy@mystocks.africa or our Privacy Request form. Security incidents: security@mystocks.africa.
2. Who and what this notice covers
This notice covers visitors, prospects and waitlist members, individual investors, institutional contacts, partner personnel, partner-managed customers, competition participants, and people who contact support or investor relations. It covers information collected directly, generated through use of the services, or received from identity, payment, market, security, broker, custodian, and business partners.
3. How we use personal information
| Purpose | Information | Primary basis | Recipients | Retention approach |
|---|---|---|---|---|
| Create and secure accounts | Name, email, phone, country, age/date of birth, account and business details, authentication events | Contract; pre-contract steps; security legitimate interests | Firebase/Google Cloud, email and security providers | Account life; security and legal evidence retained for applicable limitation periods |
| Identity, AML, sanctions and fraud checks | Identity documents, address, nationality, date of birth, source-of-funds/wealth information, verification evidence, face/biometric data when the active provider uses it, sanctions/PEP results | Legal obligation; substantial public interest; contract; fraud-prevention interests; explicit consent only where a law specifically requires it | Compliance personnel, Sumsub or the disclosed active provider, regulated partners and authorities | Normally the relationship plus up to 7 years, or longer where law, investigation, or legal hold requires |
| Provide wallets, funding, trading, custody and settlement | Bank and beneficiary details, wallet addresses, deposits, withdrawals, orders, holdings, transactions, tax and settlement records | Contract; legal obligation; fraud and service-delivery interests | Payment rails, banks, brokers, custodians, settlement providers, auditors and authorities | Normally the relationship plus up to 7 years, subject to market-specific law |
| Operate partner APIs | Partner contacts, staff access, partner-managed customer references and records, API/webhook/audit events | Contract; legal obligation; security interests | Partner, cloud, communications, trading and settlement providers | Contract schedule; operational logs generally 90–365 days; regulated records may be longer |
| Support and communications | Contact details, support/investor messages, attachments, notification preferences and delivery events | Contract; requested steps; legitimate interests; consent for optional marketing | Support staff, Resend/email providers, relevant service partners | Support records generally up to 3 years; suppression evidence retained to honor opt-outs |
| Security and service integrity | IP address, user agent, approximate location, device/session information, logs and risk signals | Security, fraud-prevention and service-reliability legitimate interests; legal obligation where applicable | Google Cloud/Firebase, ipapi.co for approximate location, security providers and authorities | Active security logs generally up to 12 months unless needed for an incident or legal claim |
| Measure product use | Cookie/device identifiers, pages and features used, approximate location and event data | Consent where required | Google Analytics when enabled by your choice | Configured analytics retention; current target maximum 14 months for user-level event data |
| Waitlists and requested updates | Email, source, locale, user agent and submission timestamps | Consent or requested pre-contract steps | Google Cloud/Firebase and email provider | Up to 24 months after last interaction unless you withdraw sooner |
We do not use consent where processing is necessary to meet AML or financial-record obligations. If required information is not provided, we may be unable to open an account, verify identity, process a transaction, or provide the requested service. Optional analytics and marketing can be refused without losing core service access.
4. Automated checks and human review
Identity, sanctions, fraud, eligibility, and transaction-monitoring systems may generate risk indicators or recommendations. A failed or uncertain automated check can delay or restrict access. Where applicable law provides a right not to be subject to a solely automated decision with significant effect, you may request human review, express your view, and challenge the outcome through the Privacy Request form or support channel.
5. Providers and disclosures
Depending on country and enabled service, providers may include Google Cloud/Firebase, Google Analytics (only after the required choice), Resend, Sumsub, ipapi.co, Gravv/Kredete, Qadi, Paylor, Globpay, Flutterwave, Yellow Card, Blockradar, ElementPay, and regulated brokers, custodians, banks, exchanges, and settlement partners. Not every provider is active in every country. We also disclose information where required by law, to protect users and the service, in a corporate transaction subject to safeguards, or at your direction.
We do not sell personal information for money. If a technology is treated as “sale,” “sharing,” or targeted advertising under an applicable U.S. law, you may opt out through Privacy Choices, including through a recognized browser signal where required.
6. International transfers
MyStocks operates across Africa and the United States, and service providers may process information in other countries. Transfers are made only under the mechanism applicable to the sending jurisdiction, such as an adequacy decision, approved contractual clauses, a binding agreement providing comparable protection, necessity permitted by law, or specific informed consent for an exceptional transfer. Routine transfers do not rely on acceptance of general platform terms as consent. Contact us for the safeguard relevant to your data.
7. Retention, deletion and legal holds
We keep information only for the purpose and period described above or while a legal obligation, dispute, investigation, security need, or legal hold applies. When retention ends, information is deleted or irreversibly anonymized through production and backup lifecycles. Closing an account does not require deletion of records that financial, AML, tax, securities, or fraud-prevention law requires us to retain. We restrict those records from unrelated use.
8. Your rights and choices
Depending on your location, you may have rights to:
- be informed and obtain access or a portable copy;
- correct inaccurate or incomplete information;
- request deletion, restriction, or anonymization;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent without affecting earlier lawful processing;
- opt out of sale, sharing, or targeted advertising where applicable;
- limit certain uses of sensitive information;
- request human review of qualifying automated decisions;
- appeal a refused U.S. state privacy request; and
- complain to the privacy regulator in your country.
Submit a request at Privacy Request. We verify identity proportionately and will not discriminate against you for exercising a right. Some rights are subject to legal exceptions. An authorized agent may apply where local law permits and authority can be verified.
9. Jurisdiction information
- EU/EEA: You may complain to the supervisory authority where you live, work, or believe an infringement occurred. GDPR rights and transfer safeguards apply when the GDPR covers the processing.
- Kenya: Requests and complaints may be made under the Data Protection Act to MyStocks and the Office of the Data Protection Commissioner.
- South Africa: POPIA rights may be exercised through our privacy channel and complaints may be submitted to the Information Regulator. PAIA access requests may also apply.
- Nigeria: Rights under the Nigeria Data Protection Act may be exercised through our privacy channel or the Nigeria Data Protection Commission.
- Ghana: Rights under the Data Protection Act may be exercised through our privacy channel or the Ghana Data Protection Commission.
- United States: Applicable state rights depend on statutory scope and thresholds. Covered users may submit access, correction, deletion, portability, opt-out, limitation, and appeal requests as applicable. Financial information may also be protected by sector-specific law.
10. Security
We use administrative, technical, and organizational controls appropriate to the sensitivity of the information, including access restrictions, authentication, encryption in transit, logging, and provider oversight. No system is risk-free. Please report suspected compromise promptly to security@mystocks.africa.
11. Children
MyStocks investment accounts are intended for adults aged 18 or older. We do not knowingly open investment accounts for children. If you believe a child supplied personal information outside an expressly authorized educational or guardian-managed program, contact us so we can investigate and take appropriate action.
12. Changes
We publish the effective date and version above. Material changes will be highlighted through the service or an appropriate communication. We request fresh consent only where a change introduces processing that legally requires it; continued use is not treated as blanket consent.