privacy

Privacy policy

AfrikCru stores the minimum data needed to operate the integrations a merchant asks for: merchant identity, encrypted API credentials (AES-256-GCM, never stored or logged in plain text), and records of the integration actions performed (for example, payment status lookups) — never the underlying transaction content beyond what's needed for reconciliation.

Credentials are encrypted at rest and are only decrypted in memory, for the duration of an outbound call to the relevant third-party API. This page will be expanded with full data retention and deletion procedures ahead of general availability.