Skip to main content
Data residency

Where every byte of your data actually lives

Vague cross-border disclosures are now a known NDPC fine trigger (MultiChoice paid ₦766.2M in July 2025). Your primary personal data — accounts, payout-account hash, session recordings, payout records — is held on hardware Ranked Technologies Ltd owns and controls. That hardware is located in Türkiye, not in Nigeria, which makes it an international transfer under the NDP Act 2023; the basis relied on is section 43(1)(b). Below is the live list of the few third-party sub-processors that touch data, in which region, handling which data, under which legal basis.

Last reviewed 1 August 2026 · Material changes published here at least 30 days before they take effect · [email protected]

Primary data residency

Self-hosted · Türkiye

Hardware the company owns and controls, not a third-party cloud. Located in Türkiye, not Nigeria · nightly encrypted DB snapshots, ~14-day retention, on the same company-controlled hardware

Cross-border position

International transfer

Primary storage is outside Nigeria, under NDP Act 2023 s.43(1)(b). Transient third-party touchpoints: Cloudflare edge routing + Mailtrap email. Payments are processed in Nigeria by Flutterwave

Change-notice window

30 days

Posted here + emailed to Enterprise customers

Self-hosted — not a third-party cloud

Your primary data is held on hardware we own and control

We run our core stack on hardware owned and operated by Ranked Technologies Ltd — not AWS, not Google Cloud, not Azure, not any other hyperscaler. The systems listed below are not third-party sub-processors; they are operated by 9jatesters. Where that hardware is physically located, and the legal basis for it, are set out in the section immediately below.

  • PostgreSQL database — accounts, payout-account hash, payout records, session metadata.
  • Authentication — self-hosted Supabase / GoTrue stack running in Docker.
  • Session-recording video — stored on local disk on our own server. Served only through authenticated, ownership-checked streaming proxies; never a public URL.
  • The Next.js web application — served from our own origin server.
  • Backups — nightly encrypted database snapshots (pg_dump), roughly 14-day retention, on the same company-controlled hardware.

The payout bank-account number is HMAC-SHA256 hashed and never stored in plaintext; only the hash is persisted. TLS 1.3 with HSTS is enforced in transit. Two third-party touchpoints are transient (Cloudflare edge routing and Mailtrap email delivery). The physical location of this hardware, and the NDP Act basis for it, are set out immediately below.

International transfer — Türkiye

The hardware holding your data is located in Türkiye, not in Nigeria

Ranked Technologies Ltd (RC 9522220) is a Nigerian company registered in Lagos. The server holding primary personal data — the database, session recordings and the encrypted backups — is hardware the company owns and controls, and that hardware is physically located in Türkiye. It is not located in Nigeria. Holding personal data on it, and administering it from there, constitute an international transfer under the NDP Act 2023.

  • What is held there: accounts, payout-account hashes, payout records, session metadata, session recordings, and the nightly encrypted database snapshots.
  • Legal basis: section 43(1)(b) of the NDP Act 2023 — necessary for the performance of the contract with the data subject. That is the basis relied on for this transfer.
  • Destination law: Türkiye has a general data-protection statute, KVKK (Law No. 6698), closely modelled on the European GDPR. This is stated as context about the destination country only. It is not a claim that the NDPC has issued an adequacy decision in respect of Türkiye.
  • Who has access: the company's sole director, who is resident in Türkiye. Ordinary administration, support and engineering can involve viewing personal data, including recordings. Every rule in our privacy policy applies to that access.
  • Payments are separate: Flutterwave is a CBN-licensed Nigerian processor and payment processing takes place in Nigeria. The above does not apply to it.
  • Correction: until 1 August 2026 this page stated that primary personal data was stored in Nigeria and did not leave Nigeria for storage; that statement was incorrect and has been withdrawn.
Third-party sub-processors

6 external parties that touch data

Flutterwave

Payments
Provider privacy policy →
Region
Nigeria
City
Lagos
Jurisdiction
Nigeria (CBN-licensed, PCI-DSS compliant)

Data categories handled

Client billing details handled for payment processing: billing contact, transaction amount and reference.

Legal basis (NDPA)

Contract performance (NDPA s.25(c)) + CBN regulatory obligation. Processed in Nigeria by a CBN-licensed Nigerian processor.

Cloudflare, Inc.

Edge / CDN / tunnel
Provider privacy policy →
Region
Global anycast edge
City
Nearest edge POP (Lagos and other global POPs)
Jurisdiction
United States (HQ); edge: global

Data categories handled

In-flight request metadata transiting the edge — IP address, request headers, URL — used for CDN, DDoS protection, and the secure tunnel that exposes the app. Does not persistently store our users' data.

Legal basis (NDPA)

Legitimate interests (NDPA s.25(f)) for security + delivery. Terminates TLS at its global edge and proxies requests to our own origin server; Cloudflare's own processing is limited to transient edge routing, not storage.

Mailtrap (Railsware)

Transactional email
Provider privacy policy →
Region
EU / US
City
—
Jurisdiction
EU / US

Data categories handled

Transactional email delivery: recipient email address + message content (login one-time codes / OTP, receipts).

Legal basis (NDPA)

Contract performance (NDPA s.25(c)) for account access + transactional notices. A cross-border touchpoint limited to email delivery, not primary storage.

country.is

IP geolocation
Provider privacy policy →
Region
Global
City
—
Jurisdiction
External lookup service

Data categories handled

IP-to-country lookup for display only. The request IP is used transiently to compute a country code; we do not persist the raw IP.

Legal basis (NDPA)

Legitimate interests (NDPA s.25(f)) for localised display. Transient use only — no persistent storage of personal data by us.

Meta Platforms (Meta Pixel)

Ad measurement
Provider privacy policy →
Region
US / global
City
—
Jurisdiction
United States

Data categories handled

Advertising measurement on PUBLIC marketing pages only, and only for visitors who accept it: page views and key button clicks (e.g. starting signup) with browser metadata and Meta cookies, so we can measure whether our Facebook/Instagram ads work. Blocked outright on the logged-in dashboard, account pages and admin area regardless of consent; not used to profile registered testers.

Legal basis (NDPA)

Consent (NDPA s.25(1)(a)), collected on the cookie banner and withdrawable at any time via "Cookie settings" in the site footer (s.35(2)). Nothing loads unless consent is given — no answer means no pixel. Corrected 1 Aug 2026: this previously claimed legitimate interest and loaded without asking.

Sentry (Functional Software, Inc.)

Error monitoring
Provider privacy policy →
Region
US / EU
City
—
Jurisdiction
United States

Data categories handled

Error monitoring: technical crash reports (stack trace, page URL, browser info, and the request IP) when something breaks, so we can fix bugs. No session recordings or form contents.

Legal basis (NDPA)

Legitimate interests (NDPA s.25(f)) for service reliability. Error data only — not analytics or advertising.

How we handle sub-processor changes

  1. 1We publish the proposed change on this page at least 30 days before it goes live, updating the "last reviewed" date at the top.
  2. 2Enterprise customers under a signed DPA also receive an email at the technical-contact address listed on their contract.
  3. 3You can object on reasonable grounds within 14 days. We work to resolve in good faith; if unresolved after another 16 days, you may terminate the affected service with a pro-rata refund of any prepaid, unused fees.
  4. 4If the change is required by law or to address a security incident, the notice window may be shortened — we'll document the reason on this page.

Need a written data-transfer statement or a custom DPA?

Primary personal data is held on hardware we own and control, located in Türkiye, relying on section 43(1)(b) of the NDP Act 2023 — set out in full above. Enterprise customers can request a written statement of that position for their procurement file, dedicated database isolation, or a custom Data Processing Agreement aligned with their internal procurement gates. Standard turnaround is 2 business days.

Email a residency brief

See also: /trust · /privacy · /terms