Legal

Privacy Policy

AVENIQUE PRIVACY POLICY

Last Updated: July 20, 2026

Welcome to Avenique. BafaTech Studio ("BafaTech", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, process, share, and protect your information when you use the Avenique mobile application, website, and related services (collectively, the "Service").

We have designed this policy to be comprehensive, ensuring compliance with global data protection laws including the General Data Protection Regulation (GDPR) in the European Union, the California Consumer Privacy Act (CCPA) as amended by the CPRA, the Nigeria Data Protection Act 2023 (NDPA), and other applicable privacy frameworks.

This Privacy Policy works together with our Biometric Information Policy, our Cookie & Tracking Technologies Policy, our Subprocessor List, our Child Safety & CSAM Enforcement Policy, and our Community Guidelines, each incorporated by reference.

1. WHO WE ARE

For the purposes of applicable data protection legislation, the data controller of your personal information is:

BafaTech Studio 5885 Cumming Hwy NE Ste 108 Sugar Hill, GA 30518 USA

Data Protection Officer (DPO) and General Privacy Inquiries: Use the contact form at the bottom of this page (choose Data Protection Officer or Privacy inquiry).

2. INFORMATION WE COLLECT

We collect information about you in three primary ways: information you provide directly to us, information collected automatically through your use of the Service, and information we obtain from third parties.

2.0 Website Waitlist (before you create an account)

The waitlist is open only to individuals 18 years of age or older, and the waitlist form requires you to confirm this. If we learn that a waitlist entry belongs to a person under 18, we delete it. If you join the public waitlist on avenique.app, we collect:

  • Email address
  • Phone number (required for Nigeria; optional elsewhere)
  • Country (Nigeria, United States, or Other)
  • City / metro (for example Lagos, Houston, or DMV)
  • Gender (for recruitment balance measurement)
  • Relationship intent (for example Marriage, Long-term, or Serious dating)
  • When you are looking to be matched (for example actively searching now, within 6 months, or just curious)
  • How you heard about us (optional), and a referral code when you arrive via a partner link (?ref=)
  • Marketing consent (timestamp and consent version) confirming you want launch updates

We use this information only to manage the waitlist, send confirmation and launch invitations, measure interest by city and demographics, attribute partner referrals, and operate the Service. We store waitlist records in our database hosted by Supabase and send confirmation email through Resend, as listed in our Subprocessor List. You can unsubscribe from marketing email using the link in any message, or use the contact form at the bottom of this page (choose Data rights or deletion request) to request deletion of your waitlist entry.

2.1 Information You Provide Directly

When you create an account and use Avenique, you provide us with specific information, including:

Account Registration Data: Your phone number, verification codes (OTP), and login credentials. If you register using Apple or Google, we receive basic profile information from them (like your name and email) as authorized by your provider settings.

Profile Information: Your name, date of birth (to verify age), gender, sexual orientation, relationship goals, occupation, education, religious beliefs, and other demographic information.

Photographs and Biometric Data: You may upload profile pictures. To protect the community, we require a live selfie and derive facial geometry data to verify that you match your photos and, in the case of permanently banned accounts, to prevent banned individuals from returning (see our Biometric Information Policy). Biometric data is processed only with your explicit, separate consent, is never sold or used for advertising or matching, and is destroyed on the schedule set out in our Biometric Information Policy (raw selfies within 72 hours of a verification decision; facial geometry templates within 30 days of successful verification; any face-derived ban signal no later than three years after a permanent ban is imposed). The Biometric Information Policy governs in the event of any conflict with this section.

Questionnaire Responses: Your answers to our onboarding questionnaires and compatibility assessments which feed into our Compatibility Engine.

Communications: The content of your chats, messages, and interactions with other users on the platform. As described in Section 7.4 of our Terms of Use, we process these using automated systems and human review to facilitate the Service and to detect fraud, scams, financial solicitation, harassment, child-safety violations, and other Trust & Safety violations under our Child Safety & CSAM Enforcement Policy.

Customer Support: Information you provide when contacting our support team, including email addresses, screenshots, and problem descriptions.

2.2 Information Collected Automatically

When you access the Service, we automatically collect certain technical and behavioral data:

Device Information: We collect hardware model, operating system version, device memory, and unique application/device identifiers used solely for fraud prevention, device-ban enforcement, and attribution of app installs. We do not use these identifiers for cross-context behavioral advertising, and we do not track you across other companies' apps or websites; for this reason the app does not request iOS App Tracking Transparency permission, and Android ad-personalization settings do not affect Avenique because we do not use the advertising ID for advertising. See our Cookie & Tracking Technologies Policy for the full list of technologies in use.

Usage Data: We track how you interact with the Service, including the time you log in, features you use, profiles you view in Discover (our verified-member directory), structured interests you send and receive, curated daily introductions served to you and your responses to them, and the duration of your sessions.

Geolocation Data: With your consent, we collect your device's geolocation to show you matches in your area. We do not track your location continuously in the background, nor do we store highly precise GPS coordinates on our permanent databases. We store your location at a city/regional level (e.g., a radius of more than 5km) to protect your privacy.

Log Data: IP addresses, network connection type (Wi-Fi, 5G), crash reports, and server logs.

2.3 Information From Third Parties and Other Users

Safety Partners: We may receive information about users from third-party safety and anti-fraud partners to protect our platform from bad actors.

Other Users: We may receive information about you from other users, for example when another user submits a report about you, or when your information appears in another user's messages, photos, or support tickets. We process this information for Trust & Safety, moderation, and enforcement purposes.

What Others Do With What You Share: Information you share with other users (including your profile, photos, and messages) can be copied, screenshotted, or shared by them outside the Service. We cannot control what other users do with information you choose to share with them, so exercise care in what you share.

2.4 Summary of Categories, Purposes, and Retention (CCPA/CPRA Notice at Collection)

  • Identifiers (phone number, name, device IDs, IP address): Account creation, security, fraud prevention. Retention: life of account; ban-enforcement hashes per Section 8.
  • Sensitive personal information (precise-consent geolocation, religious beliefs, sexual orientation, biometric data): Matching (non-biometric); verification (biometric, per Biometric Information Policy). Retention: per Section 8 and Biometric Information Policy.
  • Internet/network activity (usage data, log data): Service operation, security, product improvement. Retention: as long as necessary for the stated purposes.
  • Audio/visual information (profile photos, verification selfies): Profiles, verification. Retention: photos for life of account; selfies per Biometric Information Policy.
  • Inferences (Compatibility Engine outputs): Curated introductions and matching. Retention: life of account.
  • Commercial information (subscription and transaction records): Billing, tax, accounting. Retention: as required by tax and accounting law.

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted under CPRA regulations section 7027(m).

3. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

To Provide the Service:

  • Create and manage your account.
  • Run the Compatibility Engine to generate tailored matches and curated introductions.
  • Facilitate messaging and interactions between you and other users.
  • Process in-app purchases and subscriptions.

To Maintain Trust and Safety:

  • Verify your identity using biometric selfie scans to prevent catfishing.
  • Monitor user behavior and chat logs using automated moderation tools to detect harassment, fraud, child-safety violations, and other violations of our Community Guidelines.
  • Prevent, detect, and fight fraud or other illegal or unauthorized activities.
  • Retain data related to banned users to prevent them from creating new accounts.

Breach Notification: In the event of a personal data breach likely to result in risk to your rights, we will notify the competent supervisory authority within the period required by applicable law (72 hours for the NDPC for Nigerian users and for the relevant EEA/UK authority for European users; and within the periods prescribed by applicable US federal and state breach notification laws for US users), and we will notify affected users without undue delay where the risk is high.

To Improve and Optimize the App:

  • Conduct data analysis, testing, and research to improve our matching algorithms.
  • Analyze app crashes and debug technical issues.
  • Develop new features and services.

Legal Compliance:

  • Comply with legal requirements, respond to subpoenas, and assist law enforcement when necessary, including mandatory reporting obligations described in our Child Safety & CSAM Enforcement Policy.

De-Identified and Aggregate Data: We may create de-identified, aggregated, or anonymized data from personal information by removing information that identifies you. We may use and disclose de-identified and aggregate data for any lawful purpose, including analytics, research, service improvement, and reporting. We commit to maintaining and using de-identified data in de-identified form and will not attempt to re-identify it, except as permitted by law to test whether our de-identification processes are effective.

4. LEGAL BASES FOR PROCESSING (EEA/UK USERS)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we rely on the following legal bases under the GDPR/UK GDPR to process your data:

Performance of a Contract: Most of the data we process (profile info, messaging, location, usage data) is strictly necessary to perform our obligations under the Terms of Use (e.g., to find you matches and let you chat).

Legitimate Interests: We process device data, log data, and activity data to maintain the security of our platform, detect fraud, enforce our terms, and improve our services. We balance these interests against your privacy rights.

Consent: For specific processing activities, such as collecting precise geolocation data or processing biometric data for selfie verification, we rely on your explicit, opt-in consent. You can withdraw your consent at any time via your device settings or account settings.

Legal Obligation: We may process your data to comply with tax, accounting, or valid legal obligations.

5. HOW WE SHARE YOUR INFORMATION

We do not sell your personal data to data brokers. We share your information only in the following ways:

With Other Users: The core function of Avenique is to connect you with others. Your profile information, photos, and public questionnaire responses are visible to other users. Be mindful of what you share.

With Service Providers: We use third-party infrastructure providers (such as Supabase for database hosting and edge functions, and Firebase for push notifications) to operate the Service. These sub-processors are bound by strict Data Processing Agreements (DPAs). A current list of our sub-processors is maintained in our Subprocessor List and updated before any new sub-processor processes personal data.

For Corporate Transactions: If we are involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction, subject to the commitments in this Privacy Policy and applicable law.

With Law Enforcement: We may disclose your information if reasonably necessary to (i) comply with a legal process, such as a court order, subpoena or search warrant; (ii) assist in the prevention or detection of crime (subject to applicable law), including mandatory child-safety reporting to NCMEC and equivalent bodies; or (iii) protect the safety, rights, and property of any person.

6. CROSS-BORDER DATA TRANSFERS

BafaTech Studio is based in the United States. Your information will be transferred to, stored, and processed in the U.S. and potentially other countries where our sub-processors operate.

For users in the EEA, UK, or Switzerland, we utilize appropriate safeguards for these international transfers, primarily relying on the Standard Contractual Clauses (SCCs) approved by the European Commission, and where applicable, participating in the EU-U.S. Data Privacy Framework (DPF).

For users in Nigeria, personal data is transferred to and processed in the United States and other countries where our sub-processors operate. We effect these transfers in accordance with Part IX of the NDPA 2023, relying on NDPC-recognized adequacy determinations where available and, otherwise, on contractual safeguards with our sub-processors that provide a comparable level of protection, or on your informed consent where the NDPA permits.

7. YOUR PRIVACY RIGHTS

7.1 General Rights (Including GDPR/UK GDPR)

  • Access/Portability: You have the right to request a copy of the personal information we hold about you.
  • Correction/Rectification: You can edit and update most of your profile information directly in the App. You can also request that we fix inaccurate data.
  • Deletion/Erasure: You have the "right to be forgotten" and can request the deletion of your account and personal data (subject to certain exceptions, like keeping data for banned users to prevent circumvention, and legal-hold exceptions described in our Child Safety & CSAM Enforcement Policy).
  • Restriction/Objection: You may object to or ask us to restrict the processing of your data under certain circumstances.

7.2 California Privacy Rights (CCPA/CPRA)

Under the CCPA, California residents have the right to:

  • Know what categories of personal information we collect and how it is used (see Section 2.4).
  • Request deletion or correction of personal information.
  • Opt-Out of Sales/Sharing: We do not sell your personal information for monetary value, nor do we "share" it for cross-context behavioral advertising. Our treatment of Global Privacy Control signals is described in our Cookie & Tracking Technologies Policy.
  • Limit Use of Sensitive Personal Information: We use sensitive personal information only for the purposes permitted under CPRA regulations, so no separate limitation right is required; if that changes, we will provide the required link.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

7.3 Nigeria: Your Rights Under the NDPA 2023

If you are in Nigeria, the Nigeria Data Protection Act 2023 (NDPA) applies to our processing of your personal data, and the Nigeria Data Protection Commission (NDPC) is your supervisory authority. Our lawful bases under the NDPA mirror those in Section 4: performance of contract, legitimate interests, consent (including explicit consent for biometric data and other sensitive personal data such as religious beliefs), and legal obligation. Because Avenique processes sensitive personal data, including religious beliefs, sexual orientation, and biometric verification data, we maintain a Data Protection Impact Assessment and comply with applicable NDPC registration and audit obligations.

You have the right to access, correct, delete, and port your personal data, to object to or restrict processing, to withdraw consent, and to lodge a complaint with the NDPC (ndpc.gov.ng). To exercise these rights, use the contact form at the bottom of this page (choose Data rights or deletion request). For DPO matters, choose Data Protection Officer.

7.4 Intellectual Property and Trade Secret Limitations

When you exercise your rights of access, portability, or transparency under any applicable privacy framework (including the GDPR, CCPA, and NDPA), BafaTech will provide your personal data in an accessible format. To the extent permitted by applicable law, we will not disclose information that constitutes a trade secret, is protected by intellectual property laws, contains proprietary business intelligence, or would compromise our fraud detection and platform safety mechanisms. If a requested disclosure would inevitably reveal trade secrets, we will, to the extent permitted by applicable law, redact or withhold those specific elements while fulfilling the remainder of your request, and we will tell you that a redaction was made and the general basis for it. Nothing in this Section limits any right you have under mandatory applicable law.

7.5 How We Handle Rights Requests

To exercise any rights in this Section 7, use the contact form at the bottom of this page (choose Data rights or deletion request). We may require you to verify your identity (e.g., by logging into the App) before processing your request. You will receive an automated acknowledgment with a reference number when you submit a request.

Response Timelines: We respond to rights requests within the period required by applicable law: generally within one month for GDPR/UK GDPR and NDPA requests (extendable where the law permits for complex requests, with notice to you) and within 45 days for CCPA/CPRA requests (extendable once by a further 45 days with notice to you).

Authorized Agents: Where applicable law permits you to use an authorized agent to submit a request on your behalf, we require proof of the agent's authorization (such as a signed permission or power of attorney) and may still require you to verify your own identity directly with us before acting on the request. This protects your data from fraudulent requests made in your name.

Manifestly Unfounded or Excessive Requests: Where applicable law permits, we may refuse to act on, or charge a reasonable fee for, requests that are manifestly unfounded, excessive, or repetitive, and we will tell you the basis for that decision and your right to complain to the relevant supervisory authority. We never use this provision to avoid legitimate requests.

8. DATA RETENTION AND DELETION

We keep your personal information only as long as we need it for legitimate business purposes and as permitted by applicable law.

Account Deletion: If you delete your account, your profile immediately becomes invisible to other users. We begin the process of permanently deleting or anonymizing your data from our active systems.

30-Day Purge Window: Complete deletion from our active databases, storage buckets, and backups may take up to 30 days.

Biometric Data: Governed separately by our Biometric Information Policy: raw selfies within 72 hours of a verification decision, facial geometry templates within 30 days of successful verification, any face-derived ban signal no later than three years after a permanent ban is imposed, and in all cases no later than three years after your last interaction with the Service (subject to legal holds).

Exceptions for Safety: If your account is banned for violating our Community Guidelines or Terms of Use, we will retain a cryptographic hash of your phone number and device identifier, together with a record of the violation, indefinitely, and, for permanent bans involving serious violations, a face-derived ban signal on the schedule stated in the Biometric Information Policy. Where an account is subject to a legal-hold investigation (including child-safety matters), evidence is preserved for at least one year per our Child Safety & CSAM Enforcement Policy, independent of any deletion request.

Legal Retention: We may retain financial transaction data for longer periods to comply with tax laws and accounting standards.

9. CHILDREN'S PRIVACY

Our Services are restricted to individuals who are 18 years of age or older. We do not permit individuals under the age of 18 on our platform. We do not knowingly collect personal information from anyone under the age of 18. If you suspect that a user is under 18, please use the in-app reporting mechanism, and we will take immediate action to investigate and delete the account and its associated data. See our Child Safety & CSAM Enforcement Policy for our full child-protection procedures.

10. AUTOMATED SYSTEMS AND ALGORITHMIC LIMITATIONS

We use automated algorithms and machine learning models to curate your experience, recommend profiles, and calculate match compatibility. We also utilize automated trust and safety systems to scan profile content and communications for violations of our terms (such as spam, explicit content, or child safety violations), as described in Section 7.4 of our Terms of Use.

Human Intervention for Account Decisions: If your account is suspended or terminated by an automated moderation system, you have the right to request human review of that decision by using our contact form (choose Appeals), subject to the legal-hold exception in our Child Safety & CSAM Enforcement Policy.

Protection of Proprietary Technology and Trade Secrets: To protect the security, integrity, and intellectual property of the Service, and to the extent permitted by applicable law, BafaTech is not required to disclose:

  • The underlying source code, algorithmic architecture, weights, or variables of our Compatibility Engine;
  • Any proprietary business logic or trade secrets; or
  • Information that would compromise our platform security, anti-fraud systems, or user safety protocols.

Where applicable law grants you a right to meaningful information about the logic of automated decision-making, we will provide that information at the level of generality the law requires without disclosing trade secrets.

No Rights of Co-ownership: The generation of match recommendations, compatibility profiles, and curated introductions does not grant you any ownership, licensing, or access rights to our proprietary systems or the data modeling used to produce them.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will notify you by posting the updated policy in the App, sending you an email, or displaying a prominent notice, before the changes take effect. Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes, except where applicable law requires fresh consent.

12. CONTACT US

If you have questions, comments, or complaints about this Privacy Policy or our data practices, use the contact form at the bottom of this page (choose Privacy inquiry, Data Protection Officer, or Data rights or deletion request).

Mail: BafaTech Studio, Attn: Privacy Officer, 5885 Cumming Hwy NE Ste 108, Sugar Hill, GA 30518, USA

If you reside in the EEA or UK, you also have the right to lodge a complaint with your national Data Protection Authority (DPA) or the Information Commissioner's Office (ICO). If you reside in Nigeria, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

Contact us

Choose a topic and send a message. We’ll route it to the right team.