Privacy Policy
How we collect, use, share, and protect your personal data — and the rights you have under the Nigeria Data Protection Act 2023
Effective date: 31 August 2026
Data controller: Comecari Limited (RC [RC-NUMBER]), [registered office address], Lagos, Nigeria (“Comecari”, “we”, “us”, “our”).
1. About this policy
Comecari operates a road-freight exchange that connects businesses and individuals who need goods moved (“Shippers”) with transport companies, truck owners, and drivers who move them (“Carriers”). We provide this service through our website, mobile applications, merchant dashboard, and related back-office systems (together, the “Platform”).
This policy explains what personal data we process when you use the Platform, why we process it, who we share it with, how long we keep it, and how you can exercise your rights. It applies to Shippers, Carriers, drivers, individual visitors, and anyone whose personal data we handle in connection with a shipment.
We process personal data in accordance with the Nigeria Data Protection Act 2023 (“NDPA”), the Nigeria Data Protection Regulation 2019 and its implementation frameworks, and the guidance of the Nigeria Data Protection Commission (“NDPC”). Where we operate in other West African markets, we also comply with applicable local data-protection law.
2. Key terms
- Personal data — any information relating to an identified or identifiable individual (a “data subject”).
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Data controller — the party that decides why and how personal data is processed. Comecari is the controller for the processing described here.
- Data processor — a third party that processes personal data on our instructions (for example, our cloud host or payment processor).
3. Personal data we collect
Depending on how you use the Platform, we collect the following categories of personal data:
- Identity and contact data — name, email address, phone number, postal and pickup/delivery addresses, profile photo, preferred language.
- Account and authentication data — username, hashed password, one-time passcodes, two-factor authentication settings, and, where you choose social sign-in, the basic profile information released to us by Google or Apple.
- Business and role data — company name, registration (RC/TIN) number, business address, role on the Platform (Shipper, Carrier, driver, fleet manager), and team-member details you add.
- Identity-verification (KYC) data — government-issued identification (e.g. NIN, driver's licence, international passport, voter's card), a selfie or liveness image, and the verification result returned by our identity-verification partner. The selfie/liveness image and any facial-match data are sensitive personal data (see section 6).
- Carrier and vehicle data — driver's licence details, vehicle registration and plate numbers, truck type and capacity, insurance and road-worthiness documents, and the tracking-device identifier fitted to a vehicle.
- Shipment and cargo data — origin and destination, route, cargo type, weight, dimensions, declared value, special-handling needs, and the names and phone numbers of pickup and delivery contacts you provide.
- Location and telematics data — GPS position, speed, and movement history reported by the tracking device fitted to a Carrier's vehicle during an active shipment; approximate device location where you enable it in the app.
- Payment data — bank-account or settlement details, payout history, transaction amounts and references, commission and invoice records. Card and bank credentials are collected and stored by our payment processor, not by Comecari; we receive a payment token and status only.
- Proof-of-delivery data — delivery photographs, recipient name, and electronic signature captured at handover.
- Communications and support data — messages sent through the Platform, support tickets, call notes, ratings, and reviews.
- Device and usage data — IP address, device and browser type, operating system, app version, identifiers, pages and features used, timestamps, and diagnostic/crash logs.
- Cookie data — see section 16.
4. How we collect your data
- Directly from you — when you register, complete your profile, submit verification documents, post or bid on a load, book a shipment, make or receive a payment, or contact support.
- Automatically — through cookies and similar technologies on the website, and through logging, analytics, and crash-reporting tools in the apps.
- From vehicle tracking devices — position and telematics data is transmitted to us by the tracking hardware fitted to Carrier vehicles, via our tracking-server provider.
- From third parties — our identity-verification partner (KYC checks), our payment processor (payment status), Google/Apple (social sign-in), and other Platform users (for example, a Shipper provides a delivery contact's name and phone number).
5. Why we process your data, and our lawful bases
Under section 25 of the NDPA we must have a lawful basis for each processing purpose. Our purposes and bases are:
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account; providing the marketplace; matching Shippers and Carriers; enabling bids, bookings, tracking, and proof of delivery | Performance of a contract with you (and taking steps at your request before entering into it) |
| Processing payments, payouts, commission, invoicing, and keeping accounting and tax records | Performance of a contract; compliance with a legal obligation (tax and company-law record-keeping) |
| Verifying your identity and a Carrier's documents (KYC); screening for fraud, sanctions, and money-laundering risk | Compliance with a legal obligation; our legitimate interest in a safe and trusted marketplace; your consent for the biometric element of verification |
| Live shipment tracking and status notifications to the parties to a booking | Performance of a contract; our legitimate interest in shipment security and service quality |
| Customer support, dispute resolution, and handling claims | Performance of a contract; our legitimate interest in resolving disputes; establishment or defence of legal claims |
| Securing the Platform, preventing abuse, and enforcing our Terms of Service | Our legitimate interest in the security and integrity of the Platform; compliance with a legal obligation |
| Service emails (e.g. security alerts, booking updates, policy changes) | Performance of a contract; compliance with a legal obligation; our legitimate interest in keeping you informed |
| Marketing emails, newsletters, and the waitlist | Your consent (which you may withdraw at any time) |
| Analytics, product research, and improving our services | Your consent (for non-essential cookies and analytics); otherwise our legitimate interest in improving the Platform, using aggregated or pseudonymised data |
| Protecting the vital interests of a person (e.g. an accident or emergency involving a shipment) | Protection of vital interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can ask us for details of that assessment, and you can object to processing based on legitimate interests (see section 11).
6. Sensitive personal data
Identity verification involves a selfie or liveness image and facial-match data, which are sensitive personal data under section 30 of the NDPA. We process this data only to confirm that you are who you say you are and to prevent impersonation and fraud, and only with your explicit consent, which you give during the verification step. If you do not wish to provide biometric verification, you will not be able to complete onboarding as a verified user. We do not use this data for any other purpose and we apply the additional safeguards described in section 14.
7. How we share your data
We share personal data only as described below. We do not sell your personal data.
- With other Platform users, to complete a booking — when you post, bid on, or are matched to a load, the other party sees the information needed to decide on and carry out the job: for a Shipper, your business name, ratings, pickup and delivery locations and contacts, and cargo details; for a Carrier, the company name, driver name, vehicle details, rating, price, and, during transit, the vehicle's live location. Ratings and reviews are shown on the marketplace.
- With our service providers (processors) — see section 8. They act only on our instructions and under a written data-processing agreement.
- With professional advisers — lawyers, auditors, insurers, and accountants, where necessary and under a duty of confidentiality.
- With authorities and in legal matters — where required by law, a court order, or a lawful request from a regulator or law-enforcement agency, and where necessary to establish, exercise, or defend legal claims.
- In a corporate transaction — if Comecari is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy and prior notice where required.
- With your consent — for any other disclosure you ask us to make.
8. Service providers and processors
We use the following categories of provider. Specific vendors may change; we keep an up-to-date list available on request to our Data Protection Officer.
| Category | Purpose | Processing location |
|---|---|---|
| Cloud hosting and databases | Running the Platform and storing data | United Kingdom / European Union |
| Payment processing | Collecting payments and making payouts | Nigeria |
| Identity verification (KYC) | Verifying identity documents and liveness | [verify — e.g. European Union / United States] |
| Vehicle tracking server | Receiving GPS/telematics data from vehicle devices | United Kingdom / European Union |
| Maps and geocoding | Displaying maps, routes, and address lookup | United States |
| Email and messaging delivery | Sending transactional and marketing messages and push notifications | United States |
| Error monitoring and analytics | Diagnosing crashes and understanding Platform usage | United States |
| Customer-relationship management | Managing sales, onboarding, and support contact | [verify — e.g. European Union / India / United States] |
| Authentication (social sign-in) | Letting you sign in with Google or Apple | United States |
9. International data transfers
Some of our providers store or process personal data outside Nigeria, as shown in section 8. Where we transfer personal data out of Nigeria, we do so only where one of the conditions in sections 41 to 43 of the NDPA is met, in particular:
- the recipient country, or the recipient itself under binding rules or an approved instrument, provides an adequate level of protection as recognised by the NDPC; or
- the transfer is made under a written contract that binds the recipient to standards comparable to the NDPA (standard contractual clauses); or
- the transfer is necessary for the performance of our contract with you, or for the establishment, exercise, or defence of legal claims, or to protect a person's vital interests; or
- you have given informed consent to the transfer.
You can ask our Data Protection Officer for a copy of the safeguards that apply to a particular transfer.
10. How long we keep your data
We keep personal data only for as long as we need it for the purposes set out in this policy. Our default retention period for records connected to a transaction, contract, payment, or verified account is seven (7) years. We chose seven years because it covers the longest of the periods that apply to our business — company and tax record-keeping obligations, anti-money-laundering record-keeping, and the limitation period for bringing a contract claim in Nigeria — with a short margin for safety.
| Data | Retention period |
|---|---|
| Account and profile data | For the life of your account, then 7 years after closure |
| Transaction, payment, invoicing, and commission records | 7 years from the date of the transaction |
| Identity-verification (KYC) records, including the biometric result | 7 years after the end of your relationship with Comecari |
| Shipment records and proof of delivery | 7 years from completion of the shipment |
| Live GPS / telematics location history | Retained in identifiable form for up to 12 months after the shipment, then deleted or aggregated; the delivered/summary route is kept with the shipment record |
| Dispute, claim, and support records | 7 years from resolution |
| Marketing consents and preferences | Until you withdraw consent or object, then a suppression record is kept so we do not contact you again |
| Website analytics and cookie data | Up to 14 months, or the shorter period set for each cookie (see section 16) |
| Server, security, and audit logs | Up to 24 months |
| Backups | On a rolling cycle; data deleted from live systems is purged from backups within 90 days |
We may keep data for longer where the law requires it, or where it is needed for an ongoing investigation, dispute, or legal claim. When a retention period ends, we securely delete the data or irreversibly anonymise it.
11. Your rights under the NDPA
You have the right to:
- Be informed about how we process your personal data — this policy is part of how we meet that right.
- Access the personal data we hold about you and obtain a copy.
- Rectify personal data that is inaccurate or incomplete.
- Erase your personal data (“right to be forgotten”) where it is no longer needed, where you withdraw consent and there is no other basis, or where processing is unlawful — subject to the records we must keep by law (see section 10).
- Restrict processing while a concern about accuracy or lawfulness is being resolved.
- Object to processing based on our legitimate interests, and to direct marketing at any time.
- Data portability — receive the personal data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time, without affecting processing that already took place while consent was in force.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see section 13.
- Lodge a complaint with the NDPC, and seek a judicial remedy (see section 20).
12. How to exercise your rights
You can exercise most rights from within your account settings, or by emailing privacy@comecari.com. To close your account and request deletion, you can also use our account-deletion page. We may need to verify your identity before we act on a request. We will respond without undue delay and within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do. Exercising your rights is free unless a request is manifestly unfounded or excessive.
13. Automated decision-making and profiling
We use automated processing to run the marketplace — for example, ranking and recommending Carriers for a load, suggesting indicative rates, and scoring transactions for fraud and risk. In the ordinary course, these tools support a decision that a person makes (a Shipper chooses which bid to accept), so they are not decisions taken “solely” by automated means.
Where an automated check does directly restrict your access — for example, an automated fraud block or a failed verification — you have the right to ask for a human to review the decision, to express your point of view, and to contest the outcome. Contact privacy@comecari.com.
14. How we protect your data
We apply technical and organisational measures appropriate to the risk, as required by section 39 of the NDPA. These include encryption of data in transit (TLS 1.2 or higher) and at rest, role-based access control and the principle of least privilege, multi-factor authentication for administrative access, network segregation, secrets management, logging and monitoring, regular patching, backups, staff confidentiality obligations and training, vendor due diligence and data-processing agreements, and a data-protection impact assessment for higher-risk processing such as biometric verification and location tracking. No system can be guaranteed completely secure, but we work to protect your data and to review our controls regularly.
15. Data breaches
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of it, as required by section 40 of the NDPA. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay and tell you what happened, the likely consequences, and the steps we are taking.
16. Cookies and similar technologies
On our website we use strictly necessary cookies that are required for the site to function, and — only with your consent — analytics and preference cookies that help us understand and improve how the site is used. You choose your preference in the cookie banner shown on your first visit, and you can change it at any time in your browser settings. In our mobile apps we use similar local storage and software-development kits for authentication, crash reporting, analytics, and push notifications, subject to the permissions you grant on your device.
17. Children
The Platform is intended for use by businesses and by individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact privacy@comecari.com and we will delete it.
18. Third-party links and services
The Platform may link to or rely on third-party websites and services, including map providers, payment pages, and app stores. Those third parties are responsible for their own handling of your personal data under their own privacy notices. We encourage you to read them.
19. Changes to this policy
We may update this policy to reflect changes in our services, technology, or the law. When we make a material change, we will post the updated policy here, change the effective date, and, where appropriate, notify you by email or in the app. Please review this page from time to time.
20. Regulatory status and complaints
Comecari is enrolled with the Nigeria Data Protection Commission as a data controller [registration reference: [NDPC-REGISTRATION-NO]] and, where the applicable thresholds are met, conducts an annual data-protection audit and files the report with the NDPC through a licensed Data Protection Compliance Organisation.
If you have a concern about how we handle your personal data, please contact our Data Protection Officer first so we can try to resolve it. You also have the right to lodge a complaint with, and seek a remedy from, the NDPC:
Nigeria Data Protection Commission
No. 5 Ndjamena Crescent, off Aminu Kano Crescent, Wuse II, Abuja, Nigeria
Website: ndpc.gov.ng
Email: info@ndpc.gov.ng
21. Contact us
For any question about this policy or your personal data, contact our Data Protection Officer:
Data Protection Officer, Comecari Limited
Email: dpo@comecari.com (or privacy@comecari.com)
Address: [registered office address], Lagos, Nigeria