Back to Home
Data Protection

Privacy Policy

At BuySell, we are committed to protecting the privacy and security of the businesses that trade on our platform. This policy outlines how we collect, use, and safeguard your data.

Last Updated: July 2026

1. Information Collection

As a B2B platform, we collect business-critical information necessary for account verification and transactions. This includes your company name, registration numbers, tax IDs, business address, and primary contact details (name, work email, phone number). For payments and payouts, we securely collect and transmit financial data to our authorized payment processors (e.g., Paystack). We also automatically collect metadata such as IP addresses, browser types, and interaction logs for security auditing.

2. How Information is Used

The data we collect is strictly used to facilitate and secure your B2B transactions. Specifically, we use it to: (a) Verify the legitimacy of businesses joining the platform; (b) Process orders, payments, and freight logistics; (c) Enforce Role-Based Access Control (RBAC) across your organization's accounts; (d) Communicate critical updates, compliance notices, and order statuses; and (e) Improve our platform's user experience and algorithmic matching.

3. Data Sharing & Disclosure

We do not sell your data. We only share information with trusted third parties necessary to execute your business operations. This includes: payment gateways (for processing transactions), logistics and freight partners (for fulfillment), and identity verification services. In the context of a transaction, necessary contact and shipping information is shared between the specific Manufacturer and Wholesaler involved. We may also disclose data if required by law or to protect against fraud.

4. Security Measures

Security is our highest priority. We enforce Multi-Factor Authentication (MFA) via TOTP or Email OTP for all accounts. All data in transit and at rest is encrypted using industry-standard protocols. We maintain immutable audit logs of all sensitive actions (e.g., role changes, password resets). Our infrastructure employs strict session management, HTTP-only cookies, and protections against SQL Injection, XSS, and CSRF attacks.

5. Cookies & Tracking

We use essential cookies to maintain secure sessions, remember your login state, and enforce security policies (like CSRF tokens). We also use performance and analytics cookies to understand how our platform is used, allowing us to optimize load times and interface layouts. You can control cookie preferences through your browser, though disabling essential cookies will prevent you from accessing the authenticated dashboard.

6. User & Business Rights

Depending on your jurisdiction, you have the right to access, correct, export, or delete your personal and business data. Organization Owners can manage most data directly through the Dashboard Settings. For complete account deletion or specific data inquiries, please contact our compliance team. Note that we may be legally required to retain certain transaction records and immutable audit logs even after account deletion.

Questions about your privacy?

Our compliance and security team is here to help clarify any concerns regarding your business data.

Contact Privacy Team