Last Updated: 3 July 2026

Privacy Policy

We believe privacy is a right, not a checkbox. This document explains exactly what data we collect, why we collect it, and how you stay in control.

Welcome to FoundrGeeks. By using our platform, you trust us with your personal information. We take that seriously. This Privacy Policy applies to all services operated under the FoundrGeeks brand and governs how we collect, use, disclose, and safeguard your information. Please read it carefully. If you disagree with any part, you should discontinue use of our platform.

1Information We Collect

Account & Identity Information

  • Full name, email address, and chosen username
  • Password (stored as a one-way cryptographic hash — we never see it in plain text)
  • Profile photo (optional)
  • Title, bio, location, and social media URLs (optional)

Professional & Collaboration Profile

  • Skills, expertise, interests, and professional background
  • Collaboration preferences (availability, commitment level, remote preference)
  • Past projects and portfolio items you choose to share

Content You Post

  • Projects you publish on the platform
  • Discussion threads and replies
  • Messages sent to other users
  • Feedback and upvotes on projects

Usage & Technical Data

  • Device type, browser version, and operating system
  • IP address and approximate geographic location
  • Pages visited, features used, and time spent on the platform
  • Referral source (how you arrived at FoundrGeeks)
  • Authentication tokens and session identifiers (stored as HTTP-only cookies)

Information We Do Not Collect

We do not collect payment card numbers (we do not currently charge for the platform). We do not access your device microphone, camera, or contacts. We do not track your activity across other websites.

2How We Use Your Information

  • To provide the platform: Create and manage your account, enable core features such as project creation, discovery, messaging, and co-founder matching.
  • AI-powered matching: Generate anonymous vector embeddings of your profile text to power our matching algorithm. These embeddings are mathematical representations — not stored alongside your identity in a queryable form.
  • Communications: Send transactional emails such as email verification, password reset, and reply/mention notifications. We do not send marketing emails without your explicit opt-in.
  • Safety & integrity: Detect fraud, abuse, spam, and security threats. Enforce our Terms of Service and protect the community.
  • Platform improvement: Understand aggregate usage patterns to improve performance, fix bugs, and develop new features. We use anonymised and aggregated data wherever possible.
  • Legal compliance: Meet our obligations under applicable laws including the Nigerian Data Protection Act (NDPA) and, where applicable, the GDPR.

3How We Share Your Information

Publicly Visible by Default

The following is visible to other logged-in FoundrGeeks users unless you change your privacy settings:

  • Your profile (name, bio, skills, title, location if enabled)
  • Projects you publish
  • Discussion threads and replies you post

Service Providers

We share data with carefully selected third-party vendors who help us operate the platform, including cloud hosting, file storage, email delivery, and error monitoring. All vendors are bound by Data Processing Agreements (DPAs) and may only process your data for the specific purpose we have contracted them for.

Legal Disclosure

We may disclose personal data when we have a good-faith belief it is required by law, court order, or government authority, or when necessary to prevent imminent harm to a person or to protect FoundrGeeks from fraud or illegal activity.

We Do Not Sell Your Data

FoundrGeeks does not sell, rent, or trade your personal information to third parties for marketing or advertising purposes — ever.

4Data Security

We implement a defence-in-depth approach to data security:

  • All data in transit is protected by TLS 1.2 or higher
  • Passwords are hashed using bcrypt with a work factor chosen to resist brute-force attacks
  • Authentication uses short-lived JWT access tokens (15 minutes) and rotating refresh tokens (21 days), both stored as HTTP-only, SameSite cookies inaccessible to JavaScript
  • Rate limiting is applied to all sensitive endpoints (login, registration, API calls) to prevent credential stuffing and abuse
  • Access to production infrastructure and databases is restricted to authorised personnel only
  • We conduct regular dependency audits and apply security patches on a timely basis

Important: No security system is impenetrable. We encourage you to use a strong, unique password and to notify us immediately at contact@foundrgeeks.com if you suspect any unauthorised access to your account.

5Your Rights and Choices

Access & Correction

You can view and update most of your profile information directly within your account settings at any time.

Account Deletion

You may request deletion of your account and associated personal data by contacting us at contact@foundrgeeks.com. We will process the deletion within 30 days. Certain data may be retained for a longer period where we have a legitimate legal basis (e.g., to comply with financial or regulatory obligations).

Privacy Controls

  • Control whether your profile is publicly visible, visible only to connections, or private
  • Toggle visibility of your email address and location on your public profile
  • Enable or disable incoming messages from other users
  • Opt out of non-essential email notifications

Data Portability

You may request a machine-readable export of your personal data by emailing contact@foundrgeeks.com. We will respond within 30 days.

6Cookies and Tracking

We use a minimal set of cookies strictly necessary to operate the platform:

  • Authentication cookies: HTTP-only cookies that hold your access and refresh tokens. Required for you to stay logged in.
  • Session / preference cookies: Remember your in-app settings such as theme preference.

We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile you across the web. You can clear cookies via your browser settings, but doing so will log you out of the platform.

7Third-Party Services

  • Google OAuth: If you sign in with Google, we receive your name, email address, and profile photo from Google. Google's use of this data is governed by their privacy policy.
  • Cloud infrastructure: Our servers and file storage are hosted on reputable cloud providers. Your data resides on servers that may be located outside your country of residence (see Section 8).
  • Email delivery: Transactional emails are delivered via a third-party email service provider under a DPA.

Third-party services have their own privacy policies which we encourage you to review. FoundrGeeks is not responsible for the data practices of external services.

8International Data Transfers

FoundrGeeks is operated from Nigeria and serves users globally. Your data may be processed in countries other than your country of residence. Where such transfers take place, we rely on:

  • Standard contractual clauses (SCCs) approved by applicable regulators
  • Data processing agreements with all subprocessors
  • Encryption in transit and at rest

9Data Retention

We retain personal data only as long as necessary to fulfil the purposes set out in this policy or as required by applicable law. In practice:

  • Active accounts: data is retained for the lifetime of your account
  • Deleted accounts: personal data is purged within 30 days of a deletion request
  • Aggregated / anonymised analytics data may be retained indefinitely
  • Certain records (e.g., abuse logs) may be retained for up to 24 months for safety and integrity purposes

10Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Display a prominent in-app notice for at least 14 days
  • Send an email notification to registered users where required by law

Your continued use of FoundrGeeks after a change becomes effective constitutes your acceptance of the updated policy.

11Nigerian Data Protection Act (NDPA)

As a Nigerian company, FoundrGeeks complies with the Nigerian Data Protection Act 2023 (NDPA) and the regulations issued by the Nigeria Data Protection Commission (NDPC). Under NDPA, you have the right to:

  • Be informed about how your data is processed
  • Access, correct, or delete your personal data
  • Object to processing or withdraw consent at any time
  • Lodge a complaint with the NDPC

To exercise these rights, contact us at contact@foundrgeeks.com.

12GDPR – European Privacy Rights

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the GDPR / UK GDPR, including the right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to lodge a complaint with your national supervisory authority. Our legal bases for processing are: contract performance, legitimate interests, and — where required — explicit consent.

13Contact Us

If you have any questions, concerns, or requests regarding this policy or your personal data, please reach out:

Privacy enquiries: contact@foundrgeeks.com

Security issues: contact@foundrgeeks.com

General support: contact@foundrgeeks.com

Company: FoundrGeeks, Lagos, Nigeria

Website: www.foundrgeeks.com

We aim to respond to all privacy requests within 14 business days and no later than 30 days.

Our Privacy Commitment

We built FoundrGeeks on a foundation of trust. We will never sell your data, we minimise what we collect, and we give you real controls over your information. This commitment is not negotiable — it is core to who we are.

© 2026 FoundrGeeks. All rights reserved.