Privacy Policy
Last Updated: December 23, 2025
At Plenti, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial platform and services. By using Plenti, you consent to the data practices described in this policy.
1. Information We Collect
1.1. Personal Information
We collect personal information that you provide directly to us:
- Identity Information: Name, date of birth, government-issued ID, selfie verification
- Contact Information: Email address, phone number, residential address
- Authentication Data: Username, password, two-factor authentication settings
- Financial Goals: Savings targets, ROSCA participation preferences
1.2. Financial Data via Open Banking
With your explicit consent, we collect financial data through regulated Third-Party Providers (TPPs):
- Transaction History: Income, expenses, and spending patterns
- Account Information: Bank account details, balance data
- Payment Data: Recurring payments, bill payment history
- Read-Only Access: We only access data you authorize; we cannot initiate transactions without your permission
1.3. Automatically Collected Information
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages viewed, features used, time spent on platform
- Location Data: Approximate location based on IP address (not GPS)
- Cookies and Tracking: We use cookies and similar technologies to enhance user experience
2. How We Use Your Information
2.1. Core Service Delivery
- PlentiScore Calculation: Analyzing your financial behavior to generate your community trust score
- Income Smoothing: Calculating your Safe Surplus for automated savings
- ROSCA Matching: Connecting you with compatible savings groups
- Payment Routing: Finding the best transfer rates across providers
- Investment Recommendations: Providing AI-powered investment insights
2.2. AI Model Training and Improvement
We use aggregated and de-identified data to:
- Train and improve our machine learning algorithms
- Enhance the accuracy of financial predictions
- Develop new features and services
- Identify patterns that benefit the broader Plenti community
Note: Enterprise users can opt out of data training in their settings.
2.3. Communication and Support
- Sending account notifications and updates
- Providing customer support
- Alerting you to important service changes or security issues
- Marketing communications (with your consent)
2.4. Legal and Security
- Preventing fraud and unauthorized access
- Complying with legal obligations
- Enforcing our Terms of Service
- Protecting the rights and safety of our users
3. How We Share Your Information
3.1. With Your Consent
We share information with third parties only when you explicitly authorize us to do so, such as when linking your bank account via Open Banking.
3.2. Service Providers
We work with trusted third-party providers who help us deliver our services:
- Open Banking TPPs: Regulated providers for secure financial data access
- Payment Processors: Services like Flutterwave, Paystack, Stripe
- Cloud Infrastructure: Secure hosting and data storage providers
- Identity Verification: KYC/AML compliance services
- Analytics Providers: Services that help us understand usage patterns
All service providers are contractually bound to protect your data and use it only for specified purposes.
3.3. Within ROSCA Groups
When you join a ROSCA group, limited information is shared with other members:
- Your first name and PlentiScore
- Payment status (on-time, late, or missed contributions)
- General commitment to the group cycle
We do not share your full transaction history, income details, or other sensitive financial information with group members.
3.4. Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or to protect the rights, property, or safety of Plenti, our users, or the public.
3.5. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
4. Data Security
4.1. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Strict role-based access limits within our organization
- Regular Audits: Periodic security assessments and penetration testing
- Secure Authentication: Multi-factor authentication options
- Monitoring: Real-time threat detection and incident response systems
4.2. Your Responsibility
You are responsible for maintaining the confidentiality of your account credentials. Never share your password with anyone, and notify us immediately if you suspect unauthorized access.
4.3. Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities in accordance with applicable laws.
5. Your Privacy Rights
5.1. For UK Users (UK GDPR)
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Opt out of certain data processing activities
- Right to Withdraw Consent: Revoke consent at any time
5.2. For US Users (CCPA)
- Right to Know: Request information about data collection and use
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the "sale" of personal information (Note: We do not sell your data)
- Right to Non-Discrimination: Equal service regardless of privacy choices
5.3. For Nigeria/Kenya Users (POPIA, NDPR)
- Right to access and correct your personal information
- Right to object to data processing
- Right to request deletion of your data
- Right to lodge a complaint with data protection authorities
5.4. How to Exercise Your Rights
To exercise any of these rights, contact us at:
Plenti Privacy Team
Email: privacy@plenti.com
We will respond to your request within 30 days.
6. Data Retention
6.1. Active Accounts
We retain your personal data for as long as your account is active and as necessary to provide you with our services.
6.2. Closed Accounts
After you close your account, we retain certain data for:
- Legal Compliance: 6 years for financial records (UK, US requirements)
- Fraud Prevention: Up to 7 years for security purposes
- ROSCA Records: Transaction records retained for accountability
6.3. Aggregated Data
De-identified, aggregated data may be retained indefinitely for research and service improvement.
7. International Data Transfers
7.1. Cross-Border Processing
Plenti operates globally. Your data may be transferred to and processed in countries outside your residence, including the UK, US, and EU.
7.2. Safeguards
We ensure adequate protection through:
- Standard Contractual Clauses (SCCs)
- Privacy Shield certification (where applicable)
- Adequacy decisions by relevant authorities
- Your explicit consent where required
8. Children's Privacy
Plenti is not intended for users under 18 years of age (or 13 with parental consent). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately, and we will delete such information.
9. Cookies and Tracking Technologies
9.1. Types of Cookies We Use
- Essential Cookies: Required for platform functionality
- Performance Cookies: Help us understand how users interact with the platform
- Functional Cookies: Remember your preferences
- Marketing Cookies: Deliver relevant ads (with consent)
9.2. Managing Cookies
You can control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.
10. Third-Party Links
Our platform may contain links to third-party websites or services (e.g., bank portals, payment gateways). We are not responsible for the privacy practices of these external sites. Please review their privacy policies before providing any information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify you via email or in-app notification at least 30 days before they take effect. Your continued use of Plenti after changes become effective constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
Plenti Privacy Team
Email: privacy@getplenti.com
Data Protection Officer
Email: dpo@getplenti.com
Legal Team
Email: legal@getplenti.com
13. Regulatory Authorities
You have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO) - ico.org.uk
- US (California): California Attorney General - oag.ca.gov
- Kenya: Information Regulator - inforegulator.go.ke
- Nigeria: Nigeria Data Protection Commission - ndpc.gov.ng
By using Plenti, you acknowledge that you have read and understood this Privacy Policy