Privacy policy
What we collect, why, who sees it, how long we keep it, and what you can ask us to do about it.
Last updated 27 September 2026
1Who this covers
This policy covers seedcut.io and the Seedcut platform. Seedcut is the controller of the personal data described here: we decide what is collected and why.
Write to privacy@seedcut.io about anything in this document, including to exercise the rights in clause 8.
2What we collect
Your account. Email address, and the password or sign-in provider you use. Role and verification status.
Your profile. Display name, handle, country, phone, biography, avatar and any links you add. You choose how much of this to give.
Verification. For investors and funds: legal or registered name, country, registration number where one applies, and the identity or registration document you upload. This is the most sensitive material we hold and it is treated accordingly.
What you create. Projects, synopses, budgets, documents, messages and the deals you record. Much of this is not personal data, but some of it identifies people - attached talent and crew, for instance.
What you do. Which protected projects you open and when, every change of a project’s status, verification decisions, and administrative actions. Operational logs - IP address, browser, timestamps - for security and diagnosis.
We do not collect payment card details, because we take no payments.
3Why we use it, and on what basis
- To run your account and the platform - because we have a contract with you.
- To verify who you are - to meet our legal obligations and because the platform cannot work without trust between counterparties.
- To record who reads protected work - our legitimate interest, and the creator’s, in protecting intellectual property.
- To send service email - submissions, review outcomes, offers - because we have a contract with you.
- To keep the platform secure and to improve it - our legitimate interest in a service that works and is not abused.
We do not sell personal data, and we do not use it to train third-party models.
4Who sees what
Other users see very little. Your display name, handle, country, biography and avatar are visible to signed-in users. Your email address is not shown to other users.
Creators see who read their work. When you open a project’s protected details, your name and the time are shown to that project’s owner. This is deliberate, it is the protection creators are here for, and it cannot be switched off - if you would rather not be recorded, do not open the material.
Counterparties see your deal. Make an offer or back a project and the creator sees your name, the figure and any message. Seedcut reviewers and admins see both sides.
Verification documents are seen by admins only. They are stored privately, reachable only through short-lived links generated for a named administrator, and are never shown to other users or to the creators you deal with.
5Who processes it for us
We keep this list short on purpose, and each of these acts on our instructions only:
- Supabase - database, authentication and file storage.
- Vercel - hosting and delivery of the site.
- Resend - sending transactional email.
- Sentry - error reporting, so faults can be diagnosed.
These providers process data outside Nigeria, including in the European Union and the United States. Transfers are made under the providers’ standard contractual clauses and equivalent safeguards. We will also disclose data where the law requires it.
6How long we keep it
- Account and profile - while your account is open, and a short period afterwards.
- Verification records - for as long as your account is verified, and then for the period anti-money-laundering and record-keeping rules require, typically five years.
- The audit trail - permanently. Records of who read protected work and how a project moved through review are append-only: they exist to be relied on, so they are never edited or deleted, including when an account closes.
- Deals and projects - while the parties may need them, and as long as the law requires.
7How it is protected
Access is enforced in the database itself, not only in the application: every table carries row-level rules, so a draft project, a private document and another user’s deal are unreachable even to a request that gets past the interface.
Documents live in private storage and are served through short-lived signed links. Traffic is encrypted in transit. Administrative actions are logged. No system is perfect; if a breach affects you, we will tell you and the regulator as the law requires.
8Your rights
Under the Nigeria Data Protection Act and, where it applies to you, the UK and EU GDPR, you may ask us to:
- give you a copy of what we hold about you;
- correct anything inaccurate;
- delete what we no longer have a reason to keep;
- restrict or object to a particular use;
- hand your data to another service in a portable form.
Two limits, stated plainly. We cannot delete the audit trail, for the reason in clause 6. We cannot delete verification records we are required to retain. Everything else we will act on within 30 days.
You may also complain to the Nigeria Data Protection Commission, or to your local supervisory authority.
10Children
Seedcut is for adults doing business. It is not for anyone under 18, and we do not knowingly collect their data. Tell us if a child has given us information and we will remove it.
11Changes
When this policy changes we will update the date at the top, and tell account holders directly if the change is significant. See also the terms of use.