MultinestOi Ocha Green Tea

Legal

Privacy Policy

What Multinest Company collects about you, why, who else sees it, how long we keep it, and what you can ask us to do about it.

Last updated 26 July 2026.

1. Who we are

to be confirmed: legal entity name, trading as Multinest Company, is the data controller for the information described here. We are registered in Ghana under company number to be confirmed: company registration number, at to be confirmed: registered office address.

Our registration with Ghana’s Data Protection Commission is to be confirmed: data protection commission number.

For anything in this policy, write to to be confirmed: privacy contact email. For everything else, support@multinestglobal.com.

2. What we collect

This is the whole of it, read off the system rather than described in general terms.

When you register as a distributor

  • Your name. Shown to the person who sponsored you and to the people you sponsor, so a network of real people is a network of names rather than numbers.
  • Your mobile number. It is your login, and there is no username here. It is where the code that confirms your account and resets your password is sent.
  • Your email address, if you give one. Optional. It is where receipts, dispatch notes, payout confirmations and earnings statements go, and it is the only record of those that survives losing your phone.
  • Your password, stored only as an Argon2 hash. We cannot read it, and neither can anyone who obtains a copy of our database.
  • Who sponsored you and where you sit in the network.

When you order

  • A delivery address, including the GhanaPost GPS code if you give one, and a contact number for the courier.
  • What you ordered, what you paid and when.

When you are paid

  • Your mobile money network and number, or bank details, as the destination for a payout.
  • What you earned, from which bonus, on which order.

Automatically, as you use the app or the site

  • A notification token for each device you sign in on, so a notification reaches the right phone.
  • Crash reports when the app fails: the error, where in the code it happened, the app version and the operating system version.
  • Sign-in records, meaning when a session was started and from what kind of device, so you and we can tell whether somebody else has been in your account.

What we never see

Your card number, and your mobile money PIN. Paying opens your payment provider’s own page, in the phone’s browser or a secure tab. Nothing in our app or on our site collects either, and there is no form anywhere that asks for them. If you are ever shown one that claims to be ours, it is not.

3. Why we are allowed to hold it

Under the Data Protection Act 2012, holding somebody’s information needs a reason. Ours are:

  • To do what you asked. A name and a delivery address are how an order reaches you; a payout destination is how money reaches you. Without these there is no service to provide.
  • Because the law requires it. Orders, payments and commissions are financial records, and tax and company law require them to be kept whether or not you remain a distributor.
  • Because we have a legitimate interest. Crash reports, sign-in records and the limits that stop somebody guessing at passwords exist to keep the platform working and your account yours.
  • Because you agreed. Notifications, and the email address you chose to give. Both can be withdrawn, by turning notifications off on your phone or asking us to remove your address, without closing your account.

4. Who else sees it

We do not sell your information and we do not share it for anybody else’s advertising. It reaches four kinds of recipient, each for one job:

  • Other distributors, narrowly. The person who sponsored you sees your name and when you joined. Your upline sees that a position exists beneath them and the volume it generates. Nobody in the network sees your phone number, your address, your bonus balance or your payout details.
  • Our service providers. The payment provider that takes your money and sends your payouts; the SMS provider that delivers your one-time codes; the email provider that delivers your receipts; Google, whose Firebase service carries notifications; our hosting and error-reporting providers. Each receives only what its job needs.
  • Couriers, who receive a name, an address and a phone number in order to deliver a parcel.
  • Authorities, where the law obliges us: a court order, a tax investigation, a regulator with the power to ask.

Some of these providers are outside Ghana. Where information leaves the country it goes to providers under contractual terms that hold them to this policy.

Crash reports are stripped before they leave. Access and refresh tokens, cookies, passwords, mobile money account numbers and phone numbers are removed, and any web address that identifies a person is replaced by the general shape of it, so a report says a page failed without saying whose page it was.

5. How long we keep it

As long as you have an account, and after it in one specific way that is worth being precise about.

When you close your account, here is how, your name, mobile number, email address, delivery addresses, payout details beyond the last four digits, notification tokens and sessions are all erased. That is not a flag on a record; the values are overwritten.

Your position in the network and your financial records stay. Other distributors were placed beneath your position and are paid partly because of where it sits, so removing it would change what they earn. Your account is not the only person it belongs to. And your orders, commission entries and payouts are records of money that actually moved and has to reconcile against payments already made, which the law requires us to keep. What remains is a numbered position and a set of amounts, and nothing in it identifies you.

Crash reports are held by our error-reporting provider for as long as their retention period runs, ninety days on the plan we use, and are not copied anywhere else. Sign-in records are kept for the life of the account and erased with it.

Backups are the one honest exception to “immediately”. We take copies of the database so that a failure does not cost anybody their orders or their earnings, and a copy taken before you closed your account still contains what was in it at that moment. Those copies are not searched or used for anything else, they age out on a schedule, and if one ever has to be restored we re-apply every closure that happened after it was taken as part of restoring it. Our restore procedure says so in as many words, because an erasure quietly undone by a restore is worse than one that never happened.

One more thing stays, and it is worth being straight about because it is the exception to everything above. Our staff keep a record of decisions they make about accounts: a suspension, a refund, a payout rejected, with the reason whoever made it wrote at the time. That record is about their conduct rather than yours, it is how we can answer “who did this and why” months later, and a member being able to erase it would mean a member being able to erase the reason they were suspended. It identifies your former position by its membership number, not by your name.

6. What you can ask us to do

Under the Data Protection Act 2012 you may ask us to:

  • Show you what we hold. Most of it is already on your screen: your profile, your orders, your bonus, your network. We will send the rest.
  • Correct something wrong. Your name, number, email and addresses are yours to change in the app. Anything else, ask us.
  • Erase it, subject to the records described above, which we cannot delete and would not be permitted to.
  • Stop using it for something. Notifications and email are the two that are genuinely optional.
  • Complain. To us first, at to be confirmed: privacy contact email, and to Ghana’s Data Protection Commission if we have not put it right.

We will answer within thirty days. We will ask you to confirm who you are first, because a request nobody checks is a way for somebody else to read or delete your account.

7. How it is protected

Passwords are hashed with Argon2 and cannot be read back. Sessions are short-lived and refreshed with single-use tokens, so a stolen one stops working. On the website the long-lived credential is held in a cookie that no script can read. Everything travels over TLS. Payment credentials never touch our systems at all.

No system is beyond reach. If information about you is ever exposed we will tell you and the Data Protection Commission, with what happened and what to do about it, rather than waiting to be asked.

8. Children

This platform is for adults. You must be 18 or over to register as a distributor, and we do not knowingly collect anything about children. If you believe we hold information about a child, write to to be confirmed: privacy contact email and we will remove it.

9. Cookies and similar

The website sets one cookie that matters: the one that keeps you signed in. It is strictly necessary, it is not readable by scripts, it is not sent to other sites, and it is cleared when you sign out.

There are no advertising cookies, no analytics, and nothing that follows you to another site. The one third-party component that runs in your browser is the error reporter, which sends a report when a page fails; it sets no cookie and it is described under “what we collect” above. The mobile app stores your session on the device and nothing else.

10. Changes to this policy

When we change it we will change the date at the top, and if the change affects what we do with your information we will tell you in the app before it takes effect rather than after.