RateStack

Legal

Privacy Policy

How RateStack and its website handle information. The short version: the app collects nothing, and everything you type stays on your iPhone.

Effective October 1, 2026Last updated October 1, 2026
Contents
  1. Introduction and acceptance
  2. Definitions and interpretation
  3. Identity of the controller and scope
  4. Data minimisation commitment
  5. Information processed solely on your device
  6. Information we do not collect
  7. Network communications with data providers
  8. Live market data streaming
  9. Background refresh
  10. Notifications
  11. Clipboard
  12. Spotlight, Siri, Shortcuts, and widgets
  13. User-initiated diagnostics and sharing
  14. Apple platform services
  15. The website
  16. Legal bases for processing
  17. Retention schedule
  18. Disclosure of information
  19. No sale, sharing, or targeted advertising
  20. International transfers
  21. Security
  22. Your rights
  23. Jurisdiction-specific disclosures
  24. Exercising your rights
  25. Children's privacy
  26. Do Not Track and Global Privacy Control
  27. Automated decision-making and profiling
  28. Third-party services and links
  29. Financial information disclaimer
  30. Limitation of liability
  31. Changes to this Policy
  32. General provisions
  33. Contact and complaints

At a glance

Plain-language summary

  • The RateStack app has no account, no advertising, no analytics, and no tracking.
  • The developer does not collect, receive, store, sell, or share personal data through the app.
  • Everything you enter stays on your iPhone.
  • The RateStack website uses no cookies, and collects information only if you choose to send a suggestion.

This summary is provided for convenience only and does not limit or replace the full Policy below.

01Introduction and acceptance

1.1. This Privacy Policy (the "Policy") describes, in a manner intended to be comprehensive, transparent, and accessible, the practices of the Company (as defined below) with respect to any information that relates to an identified or identifiable natural person and that may be processed in connection with:

The App and the Website are referred to collectively as the "Services".

1.2. By downloading, installing, accessing, or using the App, or by accessing, browsing, or submitting any content through the Website, you acknowledge that you have read and understood this Policy.

Where applicable law requires your consent for any processing described in this Policy, that processing will occur only where such consent has been validly obtained, and nothing in this Policy shall be construed as deeming consent to have been given where it has not.

1.3. If you do not agree with any part of this Policy, you should not use the Services. You may stop using the App at any time by deleting it from your device, which, subject to Section 5.4, removes the information the App has stored.

1.4. This Policy is to be read together with any applicable terms published by Apple Inc. governing the App Store, which govern your licence to use the App. In the event of any conflict between this Policy and mandatory provisions of applicable data protection law, the mandatory provisions of law shall prevail to the extent of the conflict.

02Definitions and interpretation

2.1. In this Policy, unless the context otherwise requires, the following expressions have the following meanings:

2.2. In this Policy:

03Identity of the controller and scope

3.1. To the extent that the Company determines the purposes and means of the processing of any Personal Data described in this Policy, the Company acts as the "controller" (or equivalent role, such as "business" under the CCPA) of that Personal Data.

3.2. The Company acknowledges that, by design, the App does not transmit Personal Data to the Company. Information stored by the App on your Device is stored under your exclusive control. The Company has no technical means of accessing, viewing, retrieving, or modifying such information, and accordingly does not act as controller or processor of information that never leaves your Device.

3.3. This Policy does not apply to the practices of Apple Inc., Third-Party Data Providers, or any other third party that the Company does not own or control, even where their services are accessed through or in connection with the Services. Those third parties are independent controllers of any information they process and are governed by their own privacy policies.

04Data minimisation commitment

4.1. The Company has designed the App in accordance with the principles of data protection by design and by default, including the principles of data minimisation, purpose limitation, and storage limitation. In particular, and without limitation, the App:

  1. does not require, offer, or support the creation of any user account, login, or profile;
  2. does not include any advertising, advertising identifiers, or advertising networks;
  3. does not include any analytics, telemetry, attribution, crash-reporting, or session-recording software development kit, whether operated by the Company or by any third party;
  4. does not link any third-party software library or package at runtime;
  5. does not request access to your location, contacts, calendars, photos, camera, microphone, health data, or motion data;
  6. does not use App Tracking Transparency, because it does not track you across apps or websites owned by other companies; and
  7. performs all currency conversion calculations locally on your Device, without transmitting the amounts you enter to any party.

4.2. Consistent with the foregoing, the App's privacy disclosure on the App Store states "Data Not Collected". Should the Company ever intend to introduce any processing that would render that disclosure inaccurate, the Company undertakes to update this Policy and the App Store disclosure before any version of the App containing such processing is made available.

05Information processed solely on your device

5.1. In order to provide its functionality, the App stores certain information locally on your Device, within the App's sandboxed storage and within a shared App Group container that is accessible only to the App and its own widgets. Such information is not transmitted to the Company. The categories of locally stored information are as follows:

CategoryDescriptionPurpose
Currency stacksThe currencies you add, their order, the names you give to saved stacks, and the currently active currency.To display your chosen currencies each time you open the App.
Last amountThe most recent amount or expression entered on the keypad, if the relevant setting is enabled.To restore your work when you return to the App.
Cached ratesExchange rates, cryptocurrency and metal prices, their source, and the time they were last updated.To enable offline conversion and to display data freshness.
Conversion historyA record of past conversions. This feature is disabled by default.To let you review earlier conversions if you enable the feature.
Rate alertsCurrency pairs, thresholds, and directions you configure.To deliver local notifications when a threshold is crossed.
Personal ratesCustom rates you enter, such as the rate offered by your bank or bureau.To convert using the rate you actually receive.
PreferencesAppearance, theme, rate source, haptics, rounding, widget configuration, and similar settings.To apply your preferences.
Usage recordAn elapsed-time and active-day counter used to unlock the cosmetic Gold theme, stored in the Device Keychain. The counter is derived from the standard Date header returned by the HTTPS servers listed in Section 7, so that device clock changes cannot alter it.To determine eligibility for the Gold theme. It contains no identifier and is never transmitted.
Spotlight indexNames of saved stacks, currency pairs, and currencies, indexed by the operating system on your Device. Amounts are never indexed.To let you open the App from system search.

5.2. The App displays an opaque privacy cover whenever it moves to the background or becomes inactive, so that the snapshot retained by the operating system for the app switcher does not display any amount you have entered.

5.3. Information stored on your Device may be included in backups of your Device that you choose to make through iCloud or a computer, in accordance with your own Device settings. Such backups are created and controlled by you and Apple Inc., and the Company has no access to them.

5.4. Deleting the App removes the information stored in its sandbox and App Group container. By operation of the Device's Keychain, the usage record described in Section 5.1 may persist after deletion of the App until your Device is erased or reset. The usage record contains no Personal Data within the meaning of Applicable Data Protection Law.

06Information we do not collect

6.1. For the avoidance of doubt, and without prejudice to the generality of Section 4, the Company does not collect through the App any of the following categories of information:

6.2. The amounts you type into the App, the currencies you select, and the results of any conversion are never transmitted by the App to the Company or to any third party.

07Network communications with data providers

7.1. To obtain current and historical exchange rates and prices, the App connects directly from your Device to the public services listed below. Each request consists only of the information necessary to retrieve public data (such as a base currency code, a list of currency codes, or a date range).

No request contains any account detail, identifier assigned by the Company, amount you have typed, or other Personal Data supplied by the App.

ProviderHostWhen contacted
Frankfurterapi.frankfurter.devPrimary source for official reference rates and charts.
Fawaz Ahmed Exchange APIcdn.jsdelivr.net, latest.currency-api.pages.devAutomatic fallback, or when selected.
ExchangeRate-API open accessopen.er-api.comAutomatic fallback, or when selected.
FloatRateswww.floatrates.comOnly if you select it as your rate source.
Lunoapi.luno.comOnly if you enable the optional Parallel Market source (Nigerian naira).
DolarApidolarapi.com, ve.dolarapi.comOnly if you enable the optional Parallel Market source (Argentine peso and Venezuelan bolĂ­var).
Coinbaseapi.coinbase.com, api.exchange.coinbase.com, ws-feed.exchange.coinbase.comCryptocurrency and precious metal prices, charts, and live prices.
CoinGeckoapi.coingecko.comFallback for cryptocurrency prices and charts.

7.2. As is inherent in the operation of the internet, each Third-Party Data Provider, and any content delivery network or hosting provider it uses, necessarily receives the Internet Protocol ("IP") address from which your Device connects, together with standard technical information such as the time of the request and the requested resource.

The Company does not receive this information. Any processing of it is undertaken by the relevant Third-Party Data Provider as an independent controller in accordance with its own privacy policy, and the Company accepts no responsibility for such processing.

7.3. The App may also link to the public websites of Third-Party Data Providers for attribution or information. Following such a link opens the website in your browser and is subject to that website's own terms and privacy policy.

08Live market data streaming

8.1. While the App is open and in the foreground, the App may maintain a connection to the public, keyless Coinbase Exchange market data feed in order to display cryptocurrency prices in real time. The App subscribes only to public price channels for the cryptocurrencies in your stacks. The connection carries no account, identifier, or amount, and it is closed when the App leaves the foreground.

09Background refresh

9.1. Where permitted by your Device settings, the operating system may periodically allow the App to refresh cached rates in the background, so that widgets and rate alerts remain current. Background refresh contacts only the providers listed in Section 7 and transmits nothing beyond what is described there. You may disable background refresh for the App in your Device settings at any time.

10Notifications

10.1. The App requests permission to display notifications only when you create your first rate alert. Rate alerts are evaluated entirely on your Device after rates are refreshed, and are delivered as local notifications scheduled by your Device.

The App does not use a push notification server and does not register any device token with the Company or any third party. You may withdraw notification permission at any time in your Device settings.

11Clipboard

11.1. The App writes a value to your Device's clipboard only when you expressly choose a copy action. The App does not read the contents of your clipboard in the background or without your action.

12Spotlight, Siri, Shortcuts, and widgets

12.1. Spotlight. As described in Section 5.1, the App contributes items to the on-device Spotlight index so that you may find your stacks and currencies through system search. These items are stored and processed by the operating system on your Device.

12.2. Siri and Shortcuts. The App offers intents that let you convert currencies through Siri and the Shortcuts app. When you invoke such an intent, the request is handled by Apple's systems in accordance with Apple's privacy policy, and the conversion itself is performed locally by the App. The Company does not receive your requests or their results.

12.3. Widgets. The App's Home Screen and Lock Screen widgets read cached rates and your widget configuration from the shared App Group container on your Device. Widgets do not make network requests of their own.

13User-initiated diagnostics and sharing

13.1. The App's Rate Information screen allows you to generate a short diagnostic text describing the current rate source, relevant dates, and the number of currencies loaded. It does not include any amount you have typed.

The diagnostic text is shared only if you choose to share it, using the system share sheet, to a recipient or destination of your choosing. The Company receives such information only if you elect to send it to the Company, in which case Section 15.4 applies to its handling.

13.2. Any other content you choose to share from the App through the system share sheet is transmitted by you, to recipients selected by you, and is not received by the Company unless you select the Company as a recipient.

14Apple platform services

14.1. The App is distributed through the Apple App Store. Apple Inc. processes information in connection with your App Store account, the download and installation of the App, and any App Store reviews or ratings you submit, in accordance with Apple's own privacy policy. The Company does not receive your Apple ID or payment information.

14.2. If you have chosen in your Device settings to share analytics with app developers, Apple may make available to the Company aggregated usage statistics and crash reports relating to the App.

Such information is provided by Apple in a form that does not identify you, and the Company uses it solely to understand and improve the stability and quality of the App. You may withdraw that choice at any time in your Device settings.

15The website

15.1. Hosting and security

The Website is hosted and delivered by Cloudflare, Inc. ("Cloudflare"), which acts as a Service Provider to the Company.

In order to deliver the Website securely, Cloudflare processes technical information about each request, such as your IP address, browser user agent, and the requested resource. Cloudflare may retain operational and security logs for a limited period in accordance with its own terms and privacy policy.

The Company does not use such information to identify you.

15.2. No cookies, analytics, or tracking

The Website:

To display live example rates, your browser retrieves public data directly from Frankfurter (api.frankfurter.dev) and jsDelivr (cdn.jsdelivr.net), which receive your IP address in the ordinary course as described in Section 7.2.

15.3. Suggestion form: anti-abuse measures

To protect the suggestion form against spam, abuse, and automated submissions, the Company uses the following measures, which the Company considers necessary for, and proportionate to, its legitimate interest in maintaining the security and integrity of the Website:

  1. Cloudflare Turnstile. Turnstile is loaded only after you begin interacting with the suggestion form. When loaded, it may process signals from your browser and device in order to distinguish humans from automated software, as described in Cloudflare's Turnstile privacy documentation. The Company receives only a pass or fail result.
  2. Rate limiting. Each submission attempt is counted against per-sender and global limits. To do so, the Company stores a one-way, salted cryptographic hash of your IP address, together with a counter, for no longer than 24 hours. The hash cannot reasonably be reversed to reveal your IP address and is used for no other purpose.
  3. Content validation. Submissions are size-limited and sanitised, and submissions containing links are rejected.

15.4. Suggestion form: content you submit

If you submit a suggestion, the Company processes the text of your message and, only if you choose to provide it, your email address.

This information is transmitted through Cloudflare's email service to the Company's email inbox, which is hosted by Google LLC as a Service Provider to the Company. The Company uses this information solely to read, consider, and, where you have provided an email address, respond to your suggestion.

If immediate delivery fails, your submission is held temporarily in encrypted storage operated by Cloudflare for no longer than 30 days. It is deleted upon successful delivery or upon expiry of that period, whichever occurs first.

You should not include sensitive information or Personal Data of third parties in any suggestion.

15.5. Email correspondence

If you contact the Company by email, the Company processes your email address, the content of your message, and any information you choose to include, solely for the purpose of responding to you and maintaining a record of the correspondence.

16Legal bases for processing

16.1. Where the GDPR, the UK GDPR, or comparable law applies, the Company relies on the following legal bases for the limited processing it performs:

Processing activityLegal basis
Delivering and securing the Website (Section 15.1)Legitimate interests in providing a secure and functioning website (Article 6(1)(f)).
Anti-abuse measures (Section 15.3)Legitimate interests in preventing spam, fraud, and abuse (Article 6(1)(f)).
Handling suggestions and email correspondence (Sections 15.4 and 15.5)Legitimate interests in receiving and responding to feedback (Article 6(1)(f)); where you request a reply, taking steps at your request (Article 6(1)(b)).
Aggregated analytics and crash reports provided by Apple (Section 14.2)Your consent given to Apple in your Device settings (Article 6(1)(a)), and legitimate interests in improving the App (Article 6(1)(f)).
Compliance with legal obligations (Section 18)Compliance with a legal obligation (Article 6(1)(c)).

16.2. Where the Company relies on legitimate interests, it has carried out a balancing assessment and concluded that its interests are not overridden by your interests or fundamental rights and freedoms, having regard to the minimal nature of the information processed and the safeguards described in this Policy. You have the right to object to such processing as described in Section 22.

17Retention schedule

InformationRetention period
Information stored by the App on your DeviceUntil you delete it within the App or delete the App, subject to Section 5.4. The Company never holds a copy.
Rate-limiting hashes and countersNo longer than 24 hours.
Undelivered suggestions held for retryUntil delivered, and in any event no longer than 30 days.
Delivered suggestions and email correspondenceFor as long as reasonably necessary to consider and respond to them and to maintain a record of the correspondence, after which they are deleted.
Cloudflare operational and security logsIn accordance with Cloudflare's standard retention periods.

17.1. Notwithstanding the foregoing, the Company may retain information for longer where required to do so by law, or where reasonably necessary to establish, exercise, or defend legal claims.

18Disclosure of information

18.1. The Company does not disclose Personal Data to third parties except as follows:

  1. Service Providers. To Cloudflare and Google LLC, solely to the extent necessary for them to provide hosting, security, email delivery, and email storage services to the Company, subject to contractual obligations of confidentiality and data protection.
  2. Legal requirements. Where the Company believes in good faith that disclosure is required by applicable law, regulation, legal process, or enforceable governmental request, or is necessary to protect the rights, property, or safety of the Company, its users, or the public, including to detect, prevent, or address fraud, security, or technical issues.
  3. Corporate transactions. In connection with any merger, acquisition, reorganisation, financing, sale of assets, or similar transaction, or in contemplation of any of the foregoing, provided that any recipient is bound to treat the information in a manner consistent with this Policy.
  4. With your direction. Where you direct the Company to disclose information, or otherwise consent to such disclosure.

18.2. Because the App does not transmit Personal Data to the Company, the Company holds no App data that could be the subject of any disclosure described in this Section.

19No sale, sharing, or targeted advertising

19.1. The Company does not sell Personal Data, does not share Personal Data for cross-context behavioural advertising, does not engage in targeted advertising, and has not done so in the twelve (12) months preceding the effective date of this Policy. The Company has no actual knowledge of selling or sharing the Personal Data of consumers under sixteen (16) years of age.

19.2. Because the Company does not sell or share Personal Data, it does not offer a mechanism to opt out of such sale or sharing. Should this ever change, the Company will provide all notices and opt-out mechanisms required by Applicable Data Protection Law before any sale or sharing occurs.

20International transfers

20.1. The Company's Service Providers operate global infrastructure, and information processed in connection with the Website may accordingly be transferred to, stored in, or processed in countries other than the country in which you reside, including the United States, which may not provide a level of data protection equivalent to that of your country.

20.2. Where Applicable Data Protection Law restricts such transfers, the Company relies on appropriate safeguards, which may include:

You may request further information about these safeguards by contacting the Company as set out in Section 33.

21Security

21.1. The Company implements technical and organisational measures appropriate to the risk, including:

21.2. No method of transmission over the internet or method of electronic storage is completely secure. While the Company strives to protect the limited information it processes, the Company cannot guarantee its absolute security, and you acknowledge that you provide any information at your own risk.

21.3. In the event of a personal data breach affecting information processed by the Company, the Company will notify the competent supervisory authority and affected individuals where, and within the time, required by Applicable Data Protection Law.

22Your rights

22.1. Subject to the conditions, limitations, and exceptions set out in Applicable Data Protection Law, you may have some or all of the following rights in respect of Personal Data processed by the Company:

  1. the right to be informed about the processing of your Personal Data, which this Policy is intended to satisfy;
  2. the right of access, including the right to obtain confirmation of whether your Personal Data is processed and a copy of it;
  3. the right to rectification of inaccurate or incomplete Personal Data;
  4. the right to erasure, sometimes known as the "right to be forgotten";
  5. the right to restriction of processing;
  6. the right to data portability;
  7. the right to object to processing based on legitimate interests;
  8. the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
  9. the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and
  10. the right to lodge a complaint with a supervisory authority.

22.2. Because the App stores information only on your Device, you exercise complete and immediate control over that information without any request to the Company: you may view, edit, or delete it within the App, or delete it entirely by deleting the App. The Company holds no copy of App information and therefore cannot provide access to, correct, port, or erase it on your behalf.

22.3. The Company will not discriminate or retaliate against you for exercising any of your rights, including by denying services, charging different prices, or providing a different level or quality of service.

23Jurisdiction-specific disclosures

23.1. Nigeria

If you are located in Nigeria, you have the rights of a data subject under the NDPA, including the rights to be informed, to access, to rectification, to erasure, to restriction, to data portability, and to object, and you may lodge a complaint with the Nigeria Data Protection Commission.

23.2. European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 22 under the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection, as applicable.

You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, the supervisory authority is the Information Commissioner's Office.

23.3. California and other United States states

If you are a California resident, the CCPA provides you with:

In the preceding twelve (12) months, the Company has collected, solely through the Website and email, the following categories of personal information as defined by the CCPA:

Such information was collected from you directly, for the business purposes of providing and securing the Website and responding to your communications, and was disclosed only to Service Providers. The Company does not collect or process sensitive personal information for the purpose of inferring characteristics about you.

Residents of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, and other states with comprehensive privacy laws may have similar rights.

Where applicable, these include the right to appeal a refusal to act on a request by contacting the Company as set out in Section 33 and, if the appeal is denied, to contact the attorney general of your state.

You may designate an authorised agent to make a request on your behalf, subject to verification.

23.4. Other jurisdictions

If you are located elsewhere, you may have rights under the data protection law of your country, such as the rights to access, correct, or delete Personal Data and to complain to your local data protection authority. The Company will honour such rights as required by that law.

24Exercising your rights

24.1. To exercise any right described in this Policy in respect of information held by the Company, contact the Company at [email protected], stating the right you wish to exercise and providing sufficient information to allow the Company to locate the relevant information, such as the email address from which you corresponded.

24.2. The Company may need to verify your identity before acting on your request, and will do so using information it already holds wherever possible.

The Company will respond within the period required by Applicable Data Protection Law, which is generally one (1) month under the GDPR and forty-five (45) days under the CCPA, and may extend that period where permitted by law, in which case the Company will inform you of the extension and the reasons for it.

24.3. Requests are handled free of charge, except that the Company may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive, as permitted by Applicable Data Protection Law.

25Children's privacy

25.1. The App is rated 4+ and is suitable for a general audience. The Services are not directed to children under the age of thirteen (13), or such higher age as may be prescribed by Applicable Data Protection Law in your jurisdiction, for the purpose of collecting Personal Data.

Because the App collects no Personal Data from any user, it collects none from children. The Company does not knowingly collect Personal Data from children through the Website.

If you believe that a child has submitted Personal Data through the Website, please contact the Company and the Company will delete it promptly.

26Do Not Track and Global Privacy Control

26.1. Because the Services do not track users over time or across third-party websites or services, the Services' behaviour does not change in response to "Do Not Track" signals. The Company does not sell or share Personal Data and would treat any Global Privacy Control signal as a valid request to opt out of such sale or sharing, were any to occur.

27Automated decision-making and profiling

27.1. The Company does not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. The automated anti-abuse checks described in Section 15.3 operate solely to accept or decline a website form submission and do not produce any such effect.

28Third-party services and links

28.1. The Services may contain references or links to websites and services operated by third parties, including Third-Party Data Providers and Apple Inc. The Company does not control, and is not responsible for, the content, privacy practices, or security of any third-party website or service.

The inclusion of any link does not imply endorsement. You are encouraged to review the privacy policy of every third-party website or service you visit.

29Financial information disclaimer

29.1. The App is an informational tool. The Company is not a bank, payment institution, money transmitter, broker, dealer, exchange, or financial adviser, and it does not hold funds, execute transactions, or provide financial, investment, tax, or legal advice.

The Company does not receive or process any non-public personal financial information, and the App's personal rates and conversion amounts never leave your Device.

29.2. All rates and prices displayed by the Services are indicative reference values obtained from third parties, are provided "as is" and "as available", may be delayed, incomplete, or inaccurate, and may differ from the rates offered by banks, bureaux, exchanges, or transfer services. You should not rely on them as the sole basis for any financial decision.

30Limitation of liability

30.1. To the maximum extent permitted by applicable law, and without excluding or limiting any liability that cannot lawfully be excluded or limited, including liability under Applicable Data Protection Law that cannot be limited by agreement, the Company shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits, revenue, data, or goodwill, arising out of or in connection with this Policy or the processing of information by any third party described in this Policy.

31Changes to this Policy

31.1. The Company may amend this Policy from time to time to reflect changes in the Services, in Applicable Data Protection Law, or in the Company's practices. The amended Policy will be published on this page with a revised "Last updated" date.

Where an amendment materially affects the way in which Personal Data is processed, the Company will provide such additional notice, and obtain such consent, as is required by Applicable Data Protection Law before the amendment takes effect.

Your continued use of the Services after an amendment takes effect constitutes your acknowledgement of the amended Policy, save where your consent is required by law.

31.2. The Company encourages you to review this Policy periodically. Prior versions are available on request.

32General provisions

32.1. Severability. If any provision of this Policy is held by a court or authority of competent jurisdiction to be invalid, unlawful, or unenforceable, that provision shall be enforced to the maximum extent permissible and the remaining provisions shall continue in full force and effect.

32.2. No waiver. No failure or delay by the Company in exercising any right under this Policy shall operate as a waiver of that right.

32.3. Language. This Policy is drafted in the English language. Any translation is provided for convenience only, and in the event of any inconsistency the English version shall prevail to the extent permitted by law.

32.4. No third-party rights. Except as expressly provided by Applicable Data Protection Law, this Policy does not create any right enforceable by any person who is not a party to it.

32.5. Governing law. Without prejudice to any mandatory rights you may have under the laws of your country of residence, and without depriving you of the protection afforded by mandatory provisions of the law of that country, this Policy shall be governed by the laws of the Federal Republic of Nigeria.

32.6. Entire statement. This Policy constitutes the entire statement of the Company's practices regarding the processing of information in connection with the Services and supersedes all prior versions.

33Contact and complaints

33.1. All questions, comments, requests, and complaints regarding this Policy or the Company's privacy practices should be directed to:

BeggiBeggi

Attention: Privacy (RateStack)

Email: [email protected]

33.2. The Company will acknowledge and respond to your communication within the periods described in Section 24. If you are not satisfied with the Company's response, you have the right to lodge a complaint with the competent data protection supervisory authority, as described in Section 23, without prejudice to any other administrative or judicial remedy available to you.