Your account, your data, protected.
This page is maintained by AFRI HOST to explain how we keep your account safe, what data we collect, and the controls you have. It describes our current practices — not a third-party certification or audit report.
Shared responsibility
AFRI HOST runs on the Lovable Cloud platform, which provides the underlying hosting, database, authentication and storage infrastructure. We configure and operate the AFRI HOST application on top of that platform. Security is a shared effort: Lovable Cloud secures the platform layer, and AFRI HOST secures application access, deposit verification, withdrawal review, and member data handling.
Access & authentication
How you sign in and how we verify it is you.
- Mobile-linked accounts: every account is tied to a mobile number. This is the primary identity we use for login, deposit matching and support.
- Password protection: your account is guarded by a password you create. We do not store passwords in plain text.
- Session management: authenticated sessions are handled by the backend and expire when you sign out or after a period of inactivity.
- Your responsibility: keep your password secret, do not reuse it on other sites, and sign out on shared devices. If you suspect someone else has accessed your account, contact us immediately.
Deposit verification
Every plan is activated only after manual proof-of-payment review.
We do not activate investments automatically. When you transfer money to our Nedbank Business account, you upload a proof-of-payment (POP) image or PDF. An admin compares the POP against the bank deposit before approving the deposit. This prevents unmatched or fraudulent deposits from entering the system. You can see the status of every deposit on your dashboard.
Platform & hosting context
Where the app and your data live.
- Cloud hosting: AFRI HOST is hosted on Lovable Cloud infrastructure, which provides the serverless runtime, database, authentication and object storage services we use.
- Database protections: member data is stored in a backend database with row-level access rules. Users can only read and write their own records unless an admin action is required.
- Encrypted connections: traffic between your browser and the app is encrypted with HTTPS/TLS. Uploaded POP files are stored in encrypted object storage.
Data collection & use
What we collect, why we collect it, and who can see it.
| Data | Why we collect it | Who sees it |
|---|---|---|
| Mobile number | Login identity, deposit reference, support matching. | You and AFRI HOST admins. |
| Password hash | Authentication only. | Backend systems; never shared. |
| Banking details | Processing withdrawals to your account. | You and AFRI HOST payment admins. |
| Proof-of-payment files | Verifying that a deposit was made. | You and AFRI HOST verification admins. |
| Referral & activity data | Tracking referrals, earnings and platform activity. | You, your referrer (if any), and admins. |
We do not sell your personal information. We do not use your contact details for marketing unless you have explicitly opted in. We only share data when required to operate the platform or comply with lawful requests.
Retention & deletion
How long we keep your information.
- Account data: we keep profile, transaction and withdrawal records for as long as your account exists so we can provide support, resolve disputes and meet record-keeping obligations.
- Proof-of-payment files: POPs are retained while a deposit is pending and for a reasonable period after approval for audit and dispute purposes.
- Deletion requests: you can ask us to close your account and delete personal data that is no longer required for legal or operational purposes. Some transaction records may need to be kept for tax and audit reasons.
Your account controls
What you can do to keep your account safe.
- Use a strong, unique password and do not share it.
- Review your dashboard regularly for any deposits, withdrawals or referrals you do not recognise.
- Report suspicious activity through the AFRI HOST Assistant on your dashboard.
Incident & security contact
How to report a security concern or suspicious account activity.
If you notice unauthorised activity, a suspicious withdrawal request, or believe your account has been compromised, contact us immediately through the AFRI HOST Assistant on your dashboard. For sensitive security reports, ask the assistant to escalate to an admin privately.
When reporting, please include: your mobile number, what you noticed, when it happened, and any screenshots. We will investigate and freeze pending activity if needed.
Vulnerability reporting
Found a security weakness in the platform?
We welcome responsible disclosure. If you believe you have found a vulnerability in AFRI HOST, please report it through the AFRI HOST Assistant or by contacting an admin directly. Do not exploit the issue, do not access other members' data, and give us reasonable time to investigate and fix the problem before discussing it publicly.
Important: this Trust Center describes AFRI HOST's current practices and the controls enabled by the Lovable Cloud platform. It is not an independent security certification, audit report, or legal guarantee. Platform capabilities are subject to change by Lovable Cloud, and AFRI HOST's practices are reviewed and updated as the platform evolves.
Still have questions?
Read the FAQ or reach out through the AFRI HOST Assistant on your dashboard.