Privacy
Privacy, in plain terms.
This notice follows the Nigeria Data Protection Act 2023.
Who we are
WantMyTime is run by Kredit Technologies Limited (RC 9834452), House No. 348, Jamaina Road, Pompomari Bypass, Maiduguri, Borno State, Nigeria. We decide how your personal data is used, which makes us the data controller. Our data protection officer can be reached at privacy@wantmytime.com.
What we collect
- Your account: your email address and name, and the sign-in sessions you open.
- If you take bookings: your link, photo, profile link, prices, available hours, cancellation policy and bank account for payouts. We store the full account number encrypted and show only its last four digits.
- Bookings and offers: who booked whom, when, for how long and for how much; meeting links; reported problems, no-shows, cancellations and reviews.
- Payments: payment references, amounts and status from our payment provider. We do not take card payments, and we never see your bank login or mobile money PIN.
- Google Calendar, only if you connect it: when your calendar is busy (not what your events are), plus an encrypted access grant.
- Notifications, only if you switch them on: the address your browser gives us for delivering notifications to that device, and which notifications were sent. Turning them off, or deleting your account, removes it.
- Product and security records: anonymous product events (for example “link copied”), the actions taken on your account, and request logs used to keep the service secure.
Why we use it, and on what legal basis
- To run bookings and payments you ask for (performing our contract with you): sign-in, booking pages, emails about your sessions, collecting payment and paying hosts.
- To meet legal duties: keeping payment, refund and payout records for tax and anti-money-laundering law, and answering lawful requests.
- For our legitimate interests: preventing fraud and abuse, keeping the service secure, and understanding which features are used, using only anonymous events.
- With your consent: connecting Google Calendar. You can disconnect at any time.
- With your consent: our news and offers, which can include other Kredit Technologies products such as kredit.ng. We ask when you sign up, book or make an offer, and you can untick the box. Unsubscribe any time with the link in every email or under Settings. We keep a record of when you agreed and the wording you saw. Saying no never affects your bookings, and booking emails keep coming either way.
We do not sell personal data, show advertising, or use your data to train AI models.
Who we share it with
Only the service providers we need, each under a contract that limits what they may do with it:
- Kora (payments and payouts; Nigeria, and the other African countries where sellers are paid).
- Cloudflare (hosting of profile photos and protection of the site).
- Our email provider (sign-in codes, booking emails and, if you agreed to them, news emails). If we use a separate mailing service for news, it gets only your name and email and each person’s unsubscribe link.
- Google, only if you connect Google Calendar.
- Your browser’s notification service (Google, Apple, Mozilla or Microsoft, depending on your device), only if you switch notifications on. Each notification is encrypted so that only your device can read it.
- Our error-reporting service, which receives technical error details without form contents.
- Our hosting and database provider.
Some of these providers process data outside Nigeria. When they do, we rely on the safeguards the Act allows, such as contractual protections, and we choose providers with strong security.
The person you book sees the name and email you give when booking. People who visit a host’s page see only what the host chose to publish.
Google Calendar
If you connect Google Calendar, WantMyTime reads only when your primary calendar is busy, not what your events are, so booked times don’t clash with your other plans. It adds an event for each booking, with a Google Meet link, to a calendar you own, and updates or removes that event when the booking changes. Buyers aren’t added as guests. WantMyTime stores an encrypted access grant and the busy time ranges for your booking window, and deletes both when you disconnect. Disconnecting also revokes WantMyTime’s access at Google. Events already added stay on your calendar.
WantMyTime’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is used only to provide these calendar features. It is never sold, used for advertising, or read by people except to fix a problem you ask us to fix, for security, or where the law requires it.
How long we keep it
- Sign-in codes: deleted a day after they expire.
- Sign-in sessions: deleted 30 days after they end.
- Meeting links: removed 30 days after the session.
- Names on unpaid holds: removed after 90 days. Emails on closed offers: removed after 180 days.
- Anonymous product events: 13 months.
- Payment, refund, payout and accounting records: six years, as tax and anti-money-laundering law requires. If you delete your account, your name and email are removed from them.
- Backups: deleted data can remain in encrypted backups for up to 14 days before they are replaced.
Your rights
You can ask to see, correct or delete your data, to receive it in a portable file, to restrict or object to how we use it, and to withdraw consent you gave. Most of this you can do yourself:
- Download your data or delete your account from Settings → Your data.
- Correct your name, link details and hours from your workspace.
- For anything else, email privacy@wantmytime.com. We reply within 30 days.
If you are unhappy with how we handled your data, you can complain to the Nigeria Data Protection Commission. If you live in another country, you can also complain to the data protection authority there, and you have the rights its law gives you as well as these.
Security
Connections are encrypted. Bank account numbers, calendar grants, meeting links and operator security keys are encrypted in our database with separate keys. Sign-in uses one-time email codes, and operator access needs a second factor. If a breach puts your data at risk, we will tell the Commission within 72 hours and tell you without delay.
Children
WantMyTime is for people aged 18 and over. We do not knowingly collect data from children.
Changes
If we change this notice in a way that matters, we will email account holders before the change takes effect. Last updated: 25 September 2026.