Legal & Trust

Privacy Policy

How we collect, use, and protect your personal information

Last Updated: July 2026

Ignite Your Faith (IYF) is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under applicable data protection laws including the Nigeria Data Protection Act (NDPA) 2023, the Nigeria Data Protection Regulation (NDPR) 2019, the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and other applicable privacy frameworks globally.

1. Who We Are

Ignite Your Faith (IYF) is a Catholic youth community platform operated by AugstMario, a digital technology brand registered in Nigeria.

Data Controller: Johnpaul Izu-Unamma (AugstMario)

Platform: Ignite Your Faith — igniteyourfaith.ng

Contact Email: admin@igniteyourfaith.ng

Operational Base: Nigeria / Ireland

For all privacy-related requests and data rights inquiries, contact us at admin@igniteyourfaith.ng

2. What Personal Data We Collect

2.1 Data You Provide Directly

  • Full name (provided at registration)
  • Email address (provided at registration)
  • Password (stored in encrypted, hashed form — we never see your plain-text password)
  • Blog posts and written content (if you are a designated IYF Writer)
  • Profile information you choose to provide

2.2 Data Generated by Your Use of the Platform

  • Quiz scores, completion times, and pillar progress
  • Leaderboard rankings
  • Login timestamps and session data
  • Push notification subscription tokens (if you enable notifications)

2.3 Data Collected Automatically

  • Basic analytics data via Google Analytics 4 (pages visited, time on site, approximate geographic region)
  • Browser type and device type (via analytics)
  • IP address (collected by our hosting provider, Netlify, and our backend infrastructure, Supabase)

3. Why We Collect Your Data

We collect and process personal data only for specific, lawful purposes. The table below sets out each purpose, the data involved, and the legal basis under NDPA, GDPR, and equivalent frameworks.

Purpose Data Used Legal Basis
Creating and managing your member account Name, email, password Contract (service provision)
Authenticating your identity at login Email, session token Contract / Legitimate Interest
Tracking your Catechism formation progress Quiz scores, pillar progress Contract / Legitimate Interest
Displaying the community leaderboard Display name, scores Legitimate Interest
Sending push notifications Notification subscription token Consent (explicit opt-in)
Sending password reset and verification emails Email address Contract
Improving the platform through analytics Anonymous usage data Legitimate Interest
Publishing blog posts you write Name, written content Consent (you submit for publication)
Complying with legal obligations Various Legal Obligation

4. How Long We Keep Your Data

  • Account data: Retained while your account is active. Deleted within 30 days of an account deletion request.
  • Quiz results and progress: Retained for the duration of your membership to maintain your formation record.
  • Push notification tokens: Retained until you revoke notification permission or delete your account.
  • Analytics data: Aggregated and anonymised data retained for 26 months (Google Analytics default).
  • Published blog posts: May remain on the platform after account deletion unless you specifically request content removal.
  • Legal and compliance records: Retained for up to 7 years as required by applicable law.

5. Third Parties & Data Sharing

We do not sell your personal data. We do not share your personal data with advertisers.

We share data only with the following trusted service providers who help us operate the platform, and only to the extent necessary:

Supabase (supabase.com) Role: Database, authentication, and backend infrastructure

Data hosted in Southeast Asia (Singapore) on AWS infrastructure. Bound by Supabase's Data Processing Agreement.

Netlify (netlify.com) Role: Website hosting and global content delivery

Netlify processes IP addresses and request logs in the normal operation of web hosting.

Google Analytics (analytics.google.com) Role: Anonymous usage analytics

Data processed by Google LLC. No personally identifiable data is shared with Google Analytics — IP addresses are anonymised.

Resend / Supabase SMTP Role: Transactional email delivery

Used for verification emails and password resets.

6. International Data Transfers

Your data is stored on servers in Singapore (AWS ap-southeast-1) via Supabase and delivered globally via Netlify's CDN. By using the IYF platform, you acknowledge that your data may be transferred to and processed in countries outside your country of residence.

For EU and UK users: transfers outside the EEA are covered by Standard Contractual Clauses (SCCs) as provided by Supabase and Netlify under their respective Data Processing Agreements.

For Nigerian users: cross-border data transfers are conducted in compliance with the transfer provisions of the Nigeria Data Protection Act 2023.

7. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data. To exercise any right, email admin@igniteyourfaith.ng with the subject line “Data Rights Request” and we will respond within 30 days.

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate or incomplete data.

Right to Erasure (“Right to be Forgotten”)

Request deletion of your personal data. We will action this within 30 days.

Right to Restrict Processing

Ask us to pause processing your data in certain circumstances.

Right to Data Portability

Request your data in a machine-readable JSON format.

Right to Object

Object to processing based on legitimate interest (e.g. leaderboard display or analytics).

Right to Withdraw Consent

Where processing is based on consent (e.g. push notifications), withdraw at any time through your browser or device settings.

Right to Lodge a Complaint
  • Nigerian members: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
  • EU members: Your national Data Protection Authority. Ireland: dataprotection.ie
  • UK members: Information Commissioner's Office — ico.org.uk
  • California residents: California Attorney General — oag.ca.gov

8. Cookies & Analytics

We use the following on the IYF platform:

Session cookies (Essential): Required for login and authentication. These cannot be disabled without breaking platform functionality.

Google Analytics cookies (Analytics): Used to understand how members use the platform in aggregate. No personally identifiable data is included. You can opt out via your browser settings or the Google Analytics opt-out browser extension.

Service worker cache (Functional): Used by our Progressive Web App (PWA) to store platform files on your device for faster loading and offline access.

We do not use advertising cookies.
We do not use third-party tracking cookies.
We do not display advertisements.

9. Children & Young People

IYF is a Catholic youth platform and warmly welcomes young Catholics. We require all members to be at least 13 years of age to create an independent account.

Members between the ages of 13 and 17 are encouraged to use the platform with the knowledge and guidance of a parent or guardian.

We do not knowingly collect personal data from children under the age of 13. If we become aware that a member is under 13, we will promptly delete their account and all associated data.

Parents or guardians with concerns about a minor's account should contact us immediately at admin@igniteyourfaith.ng.

10. How We Protect Your Data

We implement multiple layers of security to protect your personal data:

Database Security

Row Level Security (RLS) enforced on all database tables at the infrastructure level.

Encrypted Connections

HTTPS enforced on all pages with HTTP Strict Transport Security (HSTS) active.

Password Protection

Passwords stored using bcrypt hashing via Supabase Auth. Your password is never visible to us or any third party.

Security Headers

Content Security Policy achieving Grade A on independent security audits (securityheaders.com).

Rate Limiting

Authentication endpoints rate-limited to prevent brute force attacks.

Access Control

Privilege escalation protections at both the application and database level prevent unauthorised role changes.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features.

When we make significant changes, we will:

  • Update the “Last Updated” date at the top of this page
  • Notify members via a dashboard announcement or push notification where the changes are material

We encourage you to review this policy periodically. Continued use of the platform after changes are published constitutes acceptance of the updated policy.

12. Contact Us

Get in Touch

For any privacy-related questions, data rights requests, or complaints, contact us:

Email: admin@igniteyourfaith.ng
Subject Line: “Privacy Request” or “Data Rights Request”

Data Controller: Johnpaul Izu-Unamma (AugstMario)
Website: igniteyourfaith.ng

Regulatory Bodies:
Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
EU / Ireland: Data Protection Commission — dataprotection.ie
United Kingdom: Information Commissioner's Office — ico.org.uk

We aim to respond to all privacy requests within 30 days.