SourceHer
SourceHer · African Women in Media

Privacy Policy

SourceHer exists to put journalists in touch with expert sources. That means handling names, briefs, payments and — where an expert chooses to connect one — a calendar. This page says exactly what we hold, why, and what we will never do with it.

Last updated 7 September 2026

1. Who we are

SourceHer is operated by African Women in Media (“AWiM”, “we”). We are the data controller for the information described here. For anything in this document, including a request to see or delete your data, write to privacy@africanwomeninmedia.com.

2. What we collect, and why

We collect what the platform needs to work and nothing we have no use for. Each row below corresponds to something the product actually does.

WhatWhy we hold it
Your name, email address and — for journalists — the outlet you write forTo create your account, to show an expert who is asking for their time, and to reach you about a booking.
Your passwordStored only as a cryptographic hash. We cannot read it, and nobody at AWiM can tell you what it is.
Sign-in sessions: a session token, your IP address, your browser's user-agent string, and timestampsTo keep you signed in, and so an unfamiliar sign-in can be spotted.
Expert profile: specialty, location, rate card, biography, languages, links to your work, time zone and the slots you offerThis is your public listing. You write it, you edit it, and you decide what goes in it.
Bookings: which session, when, the price, and the brief the journalist writesThe brief is shared with the expert once the booking is paid — it is what they accept or decline on.
Messages between a journalist and an expertTo deliver them. Administrators can read a thread only when it is reported for moderation.
Reviews you leave after a completed sessionShown publicly on the expert's profile, under the name on your account.
Payment records: amount, currency, status, the Paystack reference and transaction id, and when money was taken, released or refundedTo run the booking, pay the expert, issue refunds and keep accounts. See section 4.
For experts who connect Google: an access token, a refresh token, their expiry, the permissions granted, and the address and id of the connected Google accountTo put confirmed sessions on your calendar. See section 3, which is specific about the limits.

We do not run advertising, we do not build behavioural profiles, we do not sell personal information, and we do not use your content to train machine-learning models.

3. Google Calendar and Google Meet

Connecting Google is optional and only offered to experts. Its single purpose is to turn a confirmed booking into a calendar event with a Google Meet link, so that you and the journalist have somewhere to meet without either of you paying for conferencing software. Nothing about the rest of SourceHer depends on it.

What we ask Google for. One permission does the work:

PermissionWhat we use it for
.../auth/calendar.eventsCreating one calendar event per confirmed booking, and deleting that event if the booking is cancelled. This is also what produces the Google Meet link, because a Meet room is created through Calendar rather than separately.
openidIdentifies which Google account you connected, so a reconnection updates the right one.
emailSo we can show you which Google account is connected. Without it the settings page could only say “connected” and leave you guessing which of your accounts it meant.

What we do with that access. Exactly two operations, both triggered by you: we create an event when you accept a booking, and we delete that event if the booking is cancelled. Each event names the session, carries the journalist’s brief in its description, and invites the two of you.

What we never do. We do not read your calendar. We do not list, open or analyse events we did not create. We do not look at your availability, your other meetings, or who else you meet with. We do not use Google data for advertising, profiling, resale, or to train or improve any machine-learning model — general-purpose or otherwise. No human at AWiM reads it, except in the narrow cases below.

Limited Use. SourceHer’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The narrow exceptions where a person may see Google data are those the policy itself allows: with your explicit consent, where it is necessary for security purposes, to comply with applicable law, or as part of an aggregated and anonymised operational summary.

Disconnecting. Use Disconnect on your profile page at any time. That deletes the tokens we hold, immediately and permanently, and we lose all access. You can also revoke it from your Google account permissions.

Disconnecting deliberately does not delete events already on your calendar. Those are real commitments to real people, and cancelling somebody’s week because they turned off an integration would be the wrong reading of that button. New bookings simply stop appearing, and are hosted by AWiM’s own calendar instead.

Signing in with Google is a separate thing and asks only for your name, email address and profile picture. It gives us no access to your calendar at all.

4. Payments

Payments are processed by Paystack. Your card number never reaches SourceHer and is never stored by us. You enter it on Paystack’s own secure checkout; they are the ones handling it, under their own privacy policy.

What we keep is the record of the transaction — the amount, the currency, its status, Paystack’s reference and transaction id, and the times money was charged, released to the expert or refunded. That is what lets us show you your bookings, pay experts correctly, and process a refund when one is due.

5. What other people can see

  • An approved expert profile is public. Everything on it — name, photograph, specialty, location, rates, biography, links and reviews — is visible to anyone on the internet and to search engines. A profile awaiting review is not public.
  • When you book someone, that expert sees your name, your outlet, your brief and your messages. They do not see your payment details.
  • A review you write appears publicly on that expert’s profile under your name.
  • AWiM administrators can see accounts, bookings and payment records in order to run the platform, approve experts and handle refunds. They can read a conversation only when it has been reported for moderation — they cannot post in one.

6. Who else handles your data

We use a small number of service providers, each for a specific job. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderWhat they do
PaystackTakes payments and issues refunds. Handles card details; we never see them.
GoogleCalendar events, Meet links, and optional sign-in — only where an expert has connected an account.
NeonHosts the database your account and bookings live in.
VercelHosts and serves the website itself.

Beyond these, we disclose personal information only where the law requires it, or where it is necessary to investigate fraud, abuse or a security incident. We do not sell your data, and we never have.

7. Email we send

We send email about things you have done: confirming a booking, telling an expert a request is waiting, resetting a password. Calendar invitations come from Google when a session is confirmed. We do not send marketing email, so there is no marketing list to unsubscribe from.

8. How long we keep it

  • Account and profile data: for as long as your account exists.
  • Bookings, messages and reviews: kept while the account exists, because they are part of a history two people share — deleting your side would remove the other person's record of a session they took part in.
  • Payment records: retained after account deletion where accounting, tax or anti-fraud obligations require it. These are transaction records, not card details.
  • Google tokens: deleted the moment you disconnect, or when your account is deleted.
  • Sign-in sessions: expire on their own, and are removed when you sign out.

9. Your rights

You can ask us to give you a copy of your data, correct it, or delete it, and you can withdraw consent for anything you opted into — the Google connection most obviously. Much of this you can do yourself: your profile is editable from your dashboard, and the Google connection is one button.

For anything else, email privacy@africanwomeninmedia.com. We will respond within 30 days. If you are unhappy with how we have handled a request, you may complain to your local data protection authority.

10. Security

Passwords are stored hashed, never in readable form. Traffic to the site is encrypted in transit. Access to production data is limited to administrators who need it. Payment card details never touch our systems at all.

No system is perfectly secure, and we would rather say so than imply otherwise. If you believe you have found a vulnerability, please tell us at privacy@africanwomeninmedia.com before disclosing it publicly.

11. Where your data is stored

SourceHer is served from infrastructure that may be located outside your country, and our providers operate internationally. Where personal information is transferred across borders, we rely on our providers’ contractual safeguards for those transfers.

12. Children

SourceHer is a professional tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, tell us and we will remove it.

13. Changes to this policy

If we change how we handle your information, we will update this page and move the date at the top. Where a change is significant — a new category of data, or a new purpose for existing data — we will tell account holders directly rather than rely on you noticing.

Questions about this document? Write to privacy@africanwomeninmedia.com. See also our Terms of Service.