User Data Protection Protocol

Privacy Policy

Last Updated: Current Operating Period • Standard Version 1.0
01. Overview

Introduction

NOVEXA ("we", "us", or "our") respects the privacy of our investors and users ("you"). This Privacy Policy details the types of personal and operational information we collect through our manual investment web application, how that information is safeguarded, and how you can exercise your privacy rights.

02. Data Scope

Information We Collect

We gather only the data required to securely maintain your account, verify manual bank deposits, execute manual cashouts, and maintain the immutable transactions ledger.

03. User Profiles

Account Information

When you register for an account, we collect your full legal name, email address, telephone contact number, and referral association. Passwords are cryptographically salted and hashed through Supabase Authentication; plaintext passwords are never stored or accessible by personnel.

04. Ledger Records

Transaction Information

Each transaction record—including manual deposit requests, investment activations, daily midnight yield accruals, referral commission distributions, and withdrawal requests—is stored as an immutable audit record with timestamps, before/after balances, and unique reference codes.

05. Telemetry

Device and Technical Information

For session security and fraud prevention, we automatically capture standard telemetry including browser type, operating system, approximate geographic IP location, and token refresh activity during login sessions.

06. Operations

How Information Is Used

Your information is utilized solely to operate platform infrastructure: managing user balances, executing idempotent midnight interest calculations, delivering account notifications, verifying manual deposit receipts, and resolving customer support tickets.

07. Authentication

Account Security

All authenticated sessions are governed by JSON Web Tokens (JWT) verified server-side through Row Level Security (RLS) policies. Users are strictly isolated so that no investor can access or modify another user's financial profile.

08. Inflow Verification

Payment and Deposit Information

When you initiate a manual bank transfer deposit, you supply the depositor name, bank transaction reference, and optional payment proof screenshot. These records are reviewed strictly by administrative personnel to confirm inflow before wallet balances are credited.

09. Outflow Protocol

Withdrawal Information

Withdrawal requests require your beneficiary bank name, 10-digit account number, and account title. This information is utilized exclusively by compliance officers to dispatch manual bank transfers. In general dashboard displays, bank account numbers are partially masked for privacy.

10. Partner Hierarchy

Referral Information

Our 3-tier partner referral structure tracks relationships at Level 1, Level 2, and Level 3. In the referral dashboard, downline members' identities are displayed using masked formats (e.g. Chukwuma A.) without exposing their emails, phone numbers, or wallet balances.

11. Storage

Cookies and Local Storage

We do not use invasive advertising tracking cookies. We utilize browser LocalStorage exclusively to maintain your authenticated session token and preserve UI preferences such as balance privacy toggles across browser tabs.

12. Messaging

Communications

We send account notifications regarding deposit approvals, cashout dispatch updates, daily yield settlements, and system maintenance directly to your dashboard alert center.

13. Lifecycle

Data Retention

Financial ledger records, deposit submissions, withdrawal receipts, and cron logs are preserved indefinitely to maintain mathematical solvency audits and satisfy financial integrity requirements.

14. Zero Commercialization

Data Sharing

We do not sell, rent, monetize, or trade your personal or financial data to third-party advertisers or commercial data brokers under any circumstances.

15. Infrastructure

Third-Party Services

Our application operates using enterprise cloud infrastructure providers including Supabase (PostgreSQL hosting, storage, and authentication) and Vercel (frontend deployment and scheduled edge triggers).

16. Control

User Rights

You possess the right to inspect your personal profile data, request corrections to your contact phone number or legal name via the profile editor, and request account deactivation through the Support Desk.

17. Technical Protections

Security Measures

All network traffic is encrypted via Transport Layer Security (TLS 1.3). Database tables are guarded by PostgreSQL Row Level Security (RLS), and balance adjustments are restricted to atomic server-side stored procedures.

18. Age Compliance

Children's Privacy

NOVEXA is strictly engineered for individuals who are at least 18 years of age. We do not knowingly enroll or process data belonging to minors.

19. Revisions

Changes to This Privacy Policy

We reserve the right to revise this policy to reflect platform upgrades. Any revisions will be published immediately on this page with an updated operational date.

20. Support

Contact and Inquiries

For questions or privacy inquiries, contact our compliance team through the Support Center on your dashboard or via our official email desk at support@novexa.com.