Our Commitment
Go SendAm Ltd ("we," "us," or "our") is committed to protecting the personal data of everyone who uses our platforms. This page explains, in one place, how we approach data protection, the rights you have under Nigerian law, and the standards we hold ourselves to.
Our full processing details, including the specific purposes, legal bases, and data recipients for each activity, are set out in our Privacy Policy. This page focuses on the framework, principles, and rights that govern all of it.
We comply with the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID) issued by the Nigeria Data Protection Commission (NDPC), which replaced the Nigeria Data Protection Regulation (NDPR) with effect from 19 September 2025.
Our registered address is 100 Olokonla Road, Off Lekki-Epe Expressway, Lekki, Lagos.
1. Our Role Under the NDPA
Go SendAm operates in two distinct roles under the NDPA, depending on the type of data being processed.
For Most Personal Data
We are the sole Data Controller for personal data we collect and process directly. We determine the purposes and means of processing this data on our own.
- Shipper data (vendors and everyday sellers using our platform to send products)
- Receiver data (recipients who confirm delivery details or price)
- Account, wallet, and transaction data
- Marketing consent records
- Website and analytics data
- Support and complaint records
For Rider Data (With Carriers)
We are a Joint Controller with the carrier (dispatch company) for personal data of riders. Because carriers hire riders and share operational decision-making about assignments, performance, and remuneration, we and the carrier jointly determine how rider data is processed.
- Rider identity and verification records
- Assignment and delivery performance data
- Rider location data during active jobs
- Ratings and completion history
Where we are a Joint Controller with a carrier, a written Joint Controller Agreement between us documents how responsibilities are allocated, which party responds to specific data subject requests, and how NDPC notifications are handled. This ensures each party's role is clear to riders and to the regulator.
Our third-party service providers, including our identity verification, cloud hosting, communications, and payment providers, act as Data Processors on our behalf under written contracts that meet NDPA Section 41 requirements. They do not use the data we entrust to them for their own purposes.
2. Data Protection Principles
Every activity we carry out with personal data is guided by the seven data protection principles set out in NDPA Section 24. These principles govern how we design our platform, how we train our team, and how we assess new processing activities before they go live.
Lawfulness, Fairness, and Transparency
We process personal data only where we have a valid legal basis, act fairly toward the data subject, and disclose our processing openly through our Privacy Policy.
Purpose Limitation
Data is collected for specified, explicit, and legitimate purposes. We do not use it for purposes incompatible with what we told you at collection.
Data Minimisation
We collect only what we actually need. Data fields that are not necessary for a specific purpose are not requested.
Accuracy
We take reasonable steps to keep personal data accurate and up to date, and to correct or erase inaccurate data without delay.
Storage Limitation
Personal data is retained only for as long as necessary. Our retention schedule is set out in Section 6 of this page.
Integrity and Confidentiality
We protect personal data against unauthorised access, loss, and destruction through technical and organisational security measures set out in Section 7.
Accountability
We document our processing, review our compliance regularly, and can demonstrate to the NDPC that we operate within the NDPA at any point.
3. Your Rights as a Data Subject
Under NDPA Sections 34 to 39, you have the following rights over the personal data we hold about you. These rights apply whether you are a shipper, receiver, rider, or carrier account holder.
Right to be Informed
To know what personal data we collect about you, why we collect it, how we use it, and who we share it with.
Right of Access
To request a copy of the personal data we hold about you and information about how we are processing it.
Right to Rectification
To have inaccurate or incomplete personal data about you corrected without undue delay.
Right to Erasure
To have your personal data deleted where we no longer have a legal basis to keep it. Some data may be retained where the law requires (for example, tax and AML records).
Right to Restrict Processing
To have us pause our processing of your data in specific circumstances, such as while accuracy is being checked or you are objecting.
Right to Data Portability
To receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
Right to Object
To object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
Rights Regarding Automated Decisions
Where we make decisions about you using automated systems that have significant effects on you, you have the right to human review, to express your view, and to contest the decision.
4. How to Exercise Your Rights
To exercise any of the rights listed above, please send us a written request by email to [email protected]. Include:
- The right you are exercising (for example, "access request" or "erasure request").
- The account or profile the request relates to, so we can locate the correct records.
- Identification sufficient to confirm you are the data subject, so we do not disclose your data to the wrong person.
We respond to data subject requests within 30 calendar days, as required by NDPA Section 34. Where a request is complex or where we need additional information from you to identify the correct data, we may extend this period by up to two further months and will explain the reason.
There is no fee for exercising your rights, except where a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act, and will explain why.
Note on joint processing: where your data is processed jointly by Go SendAm and a carrier (this applies primarily to riders), you may send your request to either party. Under our Joint Controller Agreements, whichever party receives the request routes it to the party best placed to respond, and the response reflects both parties' obligations.
5. Data Categories We Handle
The specific categories of personal data we handle, and the purposes for each, are set out in detail in our Privacy Policy. In summary, we handle:
- Identity and account data — names, phone numbers, email addresses, business names, CAC numbers, director NINs, and login credentials.
- Verification data — identity verification results from our verification provider, used to confirm carrier and rider eligibility.
- Location data — pickup and delivery addresses, and rider GPS during active jobs.
- Transaction and wallet data — payment records, wallet balances, funding history, and payout records.
- Delivery and job data — job details, timestamps, proof-of-delivery photos, one-time passwords, and delivery status history.
- Communication data — in-app messages between users, support tickets, and delivery confirmation exchanges.
- Device and usage data — technical information about the devices and browsers used to access our platforms, and how users interact with our features.
- Marketing and consent records — consent given or withdrawn for marketing communications and cookies.
We do not knowingly collect personal data of children under 18. Our platforms are not directed at children.
6. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law. The retention periods below reflect Nigerian legal requirements and our internal retention discipline.
| Data Category | Retention Period | Basis |
|---|---|---|
| Carrier verification records (CAC, NIN, KYB) | 5 years after end of business relationship | Money Laundering (Prevention and Prohibition) Act 2022, Section 4 |
| Rider verification records | 5 years after rider deactivation | Money Laundering Act 2022 + Labour Act 2004 |
| Transaction, wallet, and payment records | 6 years after transaction date | Companies and Allied Matters Act 2020 + FIRS tax retention rules |
| Delivery records (job data, timestamps, proof photos, OTP logs) | 5 years after delivery completion | Dispute and evidence retention window |
| In-app messages and voice notes between users | 2 years after last message | Dispute window + NDPA storage limitation principle |
| Support tickets (Freshdesk) | 2 years after ticket closure | Customer service continuity + NDPA storage limitation |
| Marketing consent records | Duration of consent + 3 years after withdrawal | NDPA accountability principle |
| Analytics data (Google Analytics) | 14 months (GA4 default retention) | Product configuration |
| Access and audit logs | 24 months | Security incident investigation window |
| Cookie consent records | 12 months after consent given or withdrawn | GAID 2025 |
| Active account data | For duration of account | Contractual necessity |
| Account data after closure | 30 days for immediate deletion, then anonymised | NDPA Section 24(1)(e) storage limitation |
Periodic re-verification. Carrier business verification (CAC and director NIN) is repeated every 90 days to ensure records remain accurate and to confirm the carrier's continued eligibility to operate on the platform. Re-verification does not extend the retention window for previously collected verification records — those follow the 5-year AML retention rule set out above.
Where data is retained beyond the primary retention period for a legally-mandated reason (for example, tax or AML records), access to that data is restricted to the specific compliance purpose and is not used for operational purposes.
7. How We Secure Your Data
We apply technical and organisational security measures proportionate to the risk of the processing. Our security controls include:
- Encryption in transit — all data exchanged between users and our platforms is transmitted over Transport Layer Security (TLS).
- Encryption at rest — sensitive data stored in our infrastructure is encrypted at the storage layer.
- Access controls — role-based access is enforced within our systems. Team members can only access personal data required for their role, and access is logged.
- Authentication — administrative accounts require strong authentication. Password policies are enforced for all users.
- Segregation of environments — production data is segregated from development and testing environments.
- Vulnerability management — we monitor our infrastructure for security vulnerabilities and apply patches promptly.
- Vendor due diligence — third-party service providers are assessed for security before engagement and reviewed periodically thereafter.
- Incident response — we operate a personal data breach response process consistent with NDPA Section 40, described in Section 11 of this page.
Despite our controls, no system is entirely immune from security incidents. Where we detect a personal data breach that affects your rights, we notify you as required by NDPA Section 40.
8. Sub-Processors and Service Providers
To operate our platforms, we engage third-party service providers that process personal data on our behalf under written contracts. These sub-processors act as Data Processors and are contractually bound to process data only on our documented instructions, to apply appropriate security measures, and to assist us in meeting our obligations under the NDPA.
Our current sub-processors are:
We update this list when we add or remove sub-processors. Where we intend to engage a new sub-processor that processes a materially different category of personal data, we notify affected users where the change is significant.
9. International Data Transfers
Some of the sub-processors we engage operate infrastructure outside Nigeria. This means certain personal data may be transferred to, or accessed from, countries outside Nigeria in the course of delivering our service.
Where we transfer personal data outside Nigeria, we do so only where one of the safeguards permitted under NDPA Section 41 is in place:
- Adequacy determination — a determination by the NDPC that the destination country provides an adequate level of protection.
- Standard contractual clauses — clauses that impose data protection obligations on the recipient equivalent to those under the NDPA.
- Binding corporate rules or codes of conduct where applicable.
- Explicit consent of the data subject, after being informed of the risks.
We assess each new sub-processor for the appropriate safeguard before engagement and document our assessment. If you would like to know which safeguard applies to a specific transfer, contact us at [email protected].
10. Automated Decision-Making
Some processing on our platforms involves automated systems. NDPA Section 37 gives you specific rights in relation to automated decisions that have significant effects on you.
Automated identity verification
During carrier and rider onboarding, we use our identity verification provider to automatically match submitted CAC and NIN details against government databases. If the match fails, an initial rejection is generated automatically. You have the right to request human review of this decision by contacting our support team.
Rider assignment and performance
Where automated systems influence rider assignment or performance measurement, decisions that have significant effects on the rider (for example, deactivation) are subject to human review before being finalised. Riders have the right to be informed of the logic, request review, and contest the decision.
We do not use automated decisions to profile users for marketing purposes without their consent.
11. Personal Data Breaches
A personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
If we become aware of a personal data breach, we:
- Contain and investigate — take immediate steps to contain the breach, assess its scope, and identify affected data subjects.
- Notify the NDPC — where the breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as required by NDPA Section 40.
- Notify affected data subjects — where the breach is likely to result in a high risk to your rights and freedoms, we notify you directly without undue delay, describing the nature of the breach, its likely consequences, and the steps we are taking.
- Document and review — record the incident, our response, and the outcome, and use the review to strengthen our controls.
Where we act as Joint Controllers with a carrier, the Joint Controller Agreement between us allocates responsibility for breach notifications. Whichever party is best placed to respond takes the lead, and the other party assists.
12. Data Protection Governance
Data protection at Go SendAm is a whole-organisation responsibility. Our governance framework includes:
- Designated data protection contact — a named contact for all data protection matters, reachable at [email protected]. Where our processing activities require the formal appointment of a Data Protection Officer under NDPA Section 32, we will make that appointment and publish contact details for the DPO.
- Records of processing — we maintain records of our processing activities, sub-processors, and transfers as required by NDPA Section 26.
- Data protection impact assessments — we assess new processing activities that pose higher risks to data subjects before they go live.
- Team training — team members who handle personal data receive training on their responsibilities under the NDPA.
- Vendor management — sub-processors are assessed before engagement and reviewed periodically.
- Regulatory registration — where NDPA requires registration as a Data Controller of Major Importance, we will maintain that registration.
13. Complaints and Regulatory Oversight
If you are not satisfied with how we have handled your personal data, please contact us first at [email protected]. We take complaints seriously and aim to resolve them promptly.
If you remain dissatisfied after contacting us, you have the right to complain to the Nigeria Data Protection Commission at any time. The NDPC is the regulatory authority responsible for data protection in Nigeria.
Exercising your right to complain to the NDPC does not affect any other remedy available to you.
14. Contact Us
Questions about data protection at Go SendAm, or requests to exercise your rights, can be sent to us at: