Last updated: March 2026
Privacy Policy
How we collect, use, share, and safeguard your information on oilflow.us.
We collect
Account info, trade profile, verification docs, technical & usage data
We use it for
KYC verification, deal matching, market intel, payments, compliance
We never
Sell your data, use tracking cookies, or let AI train on your information
1. Information We Collect
- Account information — Name, email, company name, country, role
- Trade profile — Product preferences, volume ranges, payment terms, corridors
- Verification documents — Registration certificates, director ID, trade references
- Technical data — IP address, browser type, device information
- Usage data — Login frequency, feature usage, listing activity
2. How We Use Your Information
- Verify identity and conduct KYC/AML due diligence
- Match verified buyers with verified sellers
- Deliver market intelligence and price benchmarks
- Process membership and transaction fee payments
- Communicate deal notifications and platform updates
- Improve matching algorithms and platform functionality
- Comply with legal and regulatory obligations
2A. Lawful Basis for Processing (GDPR)
3. Information Sharing
We do not sell your personal data. We share only when necessary:
- Matched counterparties — Limited info shared after both parties verified and confirm interest
- Sanctions screening — Names checked against OFAC, UN, EU, UK lists
- Stripe — Billing information for payment processing
- Supabase — Database hosting (encrypted at rest)
- Anthropic — AI services — data not retained for training
- Law enforcement — When required by law or to prevent fraud
4. Data Retention
- Verification records — 5 years after end of business relationship (AML requirement)
- Transaction records — 6 years (tax and compliance)
- Account data — Deleted on request, subject to legal retention above
- Usage and technical data — Up to 2 years
5. Data Security
- TLS encryption on all data in transit
- Row-level security and role-based access controls
- Regular security reviews of infrastructure and code
- Verification documents stored with restricted access
For technical security details, see our Security page.
6. Your Rights
EU/UK residents: You may lodge a complaint with your local supervisory authority. See edpb.europa.eu.
6A. California Privacy Rights (CCPA)
CCPA requests: privacy@oilflow.us. Response within 45 days.
6B. Kenya Data Protection Act
Your data is processed per the Kenya Data Protection Act 2019. Complaints may be directed to the Office of the Data Protection Commissioner (ODPC).
7. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database & auth | United States |
| Stripe | Payments | United States |
| Anthropic | AI matching & intel | United States |
| Resend | Email delivery | United States |
| OpenSanctions | Sanctions screening | European Union |
8. International Data Transfers
Your data may be processed in the United States. For EEA/UK transfers, we rely on Standard Contractual Clauses (Decision 2021/914) and the UK IDTA. Copies available at privacy@oilflow.us.
9. Cookies
We use only session and security cookies — no advertising, no cross-site tracking.
10. EU Representative
EU representative details will be published here once appointed. Inquiries: privacy@oilflow.us.
11. Changes to This Policy
Material changes notified by email at least 30 days before taking effect.
12. Contact
OilFlow Network
We respond to all privacy requests within 30 days.