Skip to content

Version 2026-09-04

Global Privacy Notice

Effective and last updated: 4 September 2026

This notice explains how MyStocks collects and uses personal information across its websites, applications, APIs, investment services, support channels, and partner platform.

1. Who is responsible for your information

The MyStocks entity that offers the relevant service is responsible for deciding why and how your information is used. The group includes Mystocks Inc., 300 Creek View Road, Suite 209, Newark, Delaware 19711, United States; MyStocks Technologies (Pty) Ltd, Cape Town, South Africa; and Hemms Stocks Ltd, Westlands, Nairobi, Kenya. MyStocks Technologies (Pty) Ltd provides South African services as a juristic representative of TanFox (Pty) Ltd, FSP 52040, where applicable.

Your account, product terms, onboarding screen, or transaction confirmation identifies the contracting entity for a particular service. Where more than one entity jointly determines processing, they coordinate requests through the privacy contact below. Service providers that act only on documented instructions are processors or operators, not controllers for those instructed activities.

Privacy questions and rights requests: privacy@mystocks.africa or our Privacy Request form. Security incidents: security@mystocks.africa.

2. Who and what this notice covers

This notice covers visitors, prospects and waitlist members, individual investors, institutional contacts, partner personnel, partner-managed customers, competition participants, and people who contact support or investor relations. It covers information collected directly, generated through use of the services, or received from identity, payment, market, security, broker, custodian, and business partners.

3. How we use personal information

PurposeInformationPrimary basisRecipientsRetention approach
Create and secure accountsName, email, phone, country, age/date of birth, account and business details, authentication eventsContract; pre-contract steps; security legitimate interestsFirebase/Google Cloud, email and security providersAccount life; security and legal evidence retained for applicable limitation periods
Identity, AML, sanctions and fraud checksIdentity documents, address, nationality, date of birth, source-of-funds/wealth information, verification evidence, face/biometric data when the active provider uses it, sanctions/PEP resultsLegal obligation; substantial public interest; contract; fraud-prevention interests; explicit consent only where a law specifically requires itCompliance personnel, Sumsub or the disclosed active provider, regulated partners and authoritiesNormally the relationship plus up to 7 years, or longer where law, investigation, or legal hold requires
Provide wallets, funding, trading, custody and settlementBank and beneficiary details, wallet addresses, deposits, withdrawals, orders, holdings, transactions, tax and settlement recordsContract; legal obligation; fraud and service-delivery interestsPayment rails, banks, brokers, custodians, settlement providers, auditors and authoritiesNormally the relationship plus up to 7 years, subject to market-specific law
Operate partner APIsPartner contacts, staff access, partner-managed customer references and records, API/webhook/audit eventsContract; legal obligation; security interestsPartner, cloud, communications, trading and settlement providersContract schedule; operational logs generally 90–365 days; regulated records may be longer
Support and communicationsContact details, support/investor messages, attachments, notification preferences and delivery eventsContract; requested steps; legitimate interests; consent for optional marketingSupport staff, Resend/email providers, relevant service partnersSupport records generally up to 3 years; suppression evidence retained to honor opt-outs
Security and service integrityIP address, user agent, approximate location, device/session information, logs and risk signalsSecurity, fraud-prevention and service-reliability legitimate interests; legal obligation where applicableGoogle Cloud/Firebase, ipapi.co for approximate location, security providers and authoritiesActive security logs generally up to 12 months unless needed for an incident or legal claim
Measure product useCookie/device identifiers, pages and features used, approximate location and event dataConsent where requiredGoogle Analytics when enabled by your choiceConfigured analytics retention; current target maximum 14 months for user-level event data
Waitlists and requested updatesEmail, source, locale, user agent and submission timestampsConsent or requested pre-contract stepsGoogle Cloud/Firebase and email providerUp to 24 months after last interaction unless you withdraw sooner

We do not use consent where processing is necessary to meet AML or financial-record obligations. If required information is not provided, we may be unable to open an account, verify identity, process a transaction, or provide the requested service. Optional analytics and marketing can be refused without losing core service access.

4. Automated checks and human review

Identity, sanctions, fraud, eligibility, and transaction-monitoring systems may generate risk indicators or recommendations. A failed or uncertain automated check can delay or restrict access. Where applicable law provides a right not to be subject to a solely automated decision with significant effect, you may request human review, express your view, and challenge the outcome through the Privacy Request form or support channel.

5. Providers and disclosures

Depending on country and enabled service, providers may include Google Cloud/Firebase, Google Analytics (only after the required choice), Resend, Sumsub, ipapi.co, Gravv/Kredete, Qadi, Paylor, Globpay, Flutterwave, Yellow Card, Blockradar, ElementPay, and regulated brokers, custodians, banks, exchanges, and settlement partners. Not every provider is active in every country. We also disclose information where required by law, to protect users and the service, in a corporate transaction subject to safeguards, or at your direction.

We do not sell personal information for money. If a technology is treated as “sale,” “sharing,” or targeted advertising under an applicable U.S. law, you may opt out through Privacy Choices, including through a recognized browser signal where required.

6. International transfers

MyStocks operates across Africa and the United States, and service providers may process information in other countries. Transfers are made only under the mechanism applicable to the sending jurisdiction, such as an adequacy decision, approved contractual clauses, a binding agreement providing comparable protection, necessity permitted by law, or specific informed consent for an exceptional transfer. Routine transfers do not rely on acceptance of general platform terms as consent. Contact us for the safeguard relevant to your data.

7. Retention, deletion and legal holds

We keep information only for the purpose and period described above or while a legal obligation, dispute, investigation, security need, or legal hold applies. When retention ends, information is deleted or irreversibly anonymized through production and backup lifecycles. Closing an account does not require deletion of records that financial, AML, tax, securities, or fraud-prevention law requires us to retain. We restrict those records from unrelated use.

8. Your rights and choices

Depending on your location, you may have rights to:

  • be informed and obtain access or a portable copy;
  • correct inaccurate or incomplete information;
  • request deletion, restriction, or anonymization;
  • object to processing based on legitimate interests or direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • opt out of sale, sharing, or targeted advertising where applicable;
  • limit certain uses of sensitive information;
  • request human review of qualifying automated decisions;
  • appeal a refused U.S. state privacy request; and
  • complain to the privacy regulator in your country.

Submit a request at Privacy Request. We verify identity proportionately and will not discriminate against you for exercising a right. Some rights are subject to legal exceptions. An authorized agent may apply where local law permits and authority can be verified.

9. Jurisdiction information

  • EU/EEA: You may complain to the supervisory authority where you live, work, or believe an infringement occurred. GDPR rights and transfer safeguards apply when the GDPR covers the processing.
  • Kenya: Requests and complaints may be made under the Data Protection Act to MyStocks and the Office of the Data Protection Commissioner.
  • South Africa: POPIA rights may be exercised through our privacy channel and complaints may be submitted to the Information Regulator. PAIA access requests may also apply.
  • Nigeria: Rights under the Nigeria Data Protection Act may be exercised through our privacy channel or the Nigeria Data Protection Commission.
  • Ghana: Rights under the Data Protection Act may be exercised through our privacy channel or the Ghana Data Protection Commission.
  • United States: Applicable state rights depend on statutory scope and thresholds. Covered users may submit access, correction, deletion, portability, opt-out, limitation, and appeal requests as applicable. Financial information may also be protected by sector-specific law.

10. Security

We use administrative, technical, and organizational controls appropriate to the sensitivity of the information, including access restrictions, authentication, encryption in transit, logging, and provider oversight. No system is risk-free. Please report suspected compromise promptly to security@mystocks.africa.

11. Children

MyStocks investment accounts are intended for adults aged 18 or older. We do not knowingly open investment accounts for children. If you believe a child supplied personal information outside an expressly authorized educational or guardian-managed program, contact us so we can investigate and take appropriate action.

12. Changes

We publish the effective date and version above. Material changes will be highlighted through the service or an appropriate communication. We request fresh consent only where a change introduces processing that legally requires it; continued use is not treated as blanket consent.