Sendo Legal

Privacy Policy

This policy explains what we collect when you use the Sendo website or the Customer, Courier, or Vendor apps, why we need it, who we share it with, how long we keep it, and the choices you have under the Nigeria Data Protection Act 2023 (NDPA) and other applicable law.

Last updated 3 September 2026

1. Who this policy covers

It applies to visitors of this website and to people who create accounts as customers, couriers, or vendors, including staff who a vendor authorises to use a store login. SENDO Logistics Technologies Ltd. (“Sendo”, “we”) is the controller of personal data used to operate the marketplace: matching orders, taking payment, paying couriers and vendors, preventing fraud, and supporting users.

Vendors are typically independent controllers of their own customer lists, CCTV, and in-store records. Payment processors, banks, and insurers are controllers or processors of the data they need to move money or assess a claim. When a courier or vendor uses Sendo, they must only use customer data to complete that order — not to build a private marketing list.

Privacy questions and NDPA requests: info@sendo.com with the subject “Privacy”. Our operations address is Adeola Odeku, Victoria Island, Lagos, Nigeria.

2. Data we collect

2.1 All users

  • Identity: name, phone number, email, profile photo if you add one, and language preference.
  • Account: password hashes or app-login tokens, device type, OS version, app version, advertising or analytics IDs (where the store and your settings allow), IP address, approximate network location, crash logs, and diagnostic events.
  • Support: in-app messages, emails, call recordings where we say a call may be recorded, screenshots you send, and dispute files.
  • Marketing preferences: whether you opted in or out of promotional SMS, email, or push.

2.2 Customers

  • Delivery addresses, landmarks, building names, and saved places.
  • Order history, cart contents, substitutions, ratings, tips, and promo or credit use.
  • Approximate or precise location while you browse nearby stores or track an order, if you allow it on the device.
  • Payment tokens, last-four digits, card brand, and bank or wallet identifiers processed by our payment provider. We do not store full card numbers or CVV on Sendo servers.
  • Age-gate or ID check results when you order restricted goods.

2.3 Couriers

  • Government ID, date of birth, vehicle type, plate or bicycle details, licence or rider-card images, and any background or document check the city requires.
  • Live GPS, heading, and speed-band while you are online or on a trip, so we can match jobs, show the customer the rider, and review safety or fraud events.
  • Trip history, acceptance and cancellation rates, earnings, cash-out bank account, and ratings.
  • Safety reports, accident notifications, and device integrity signals (for example mocked location).

2.4 Vendors

  • Business name, category, outlet address, opening hours, and contact people.
  • Menu or catalogue, prices, photos, allergens you enter, and stock flags.
  • Order and settlement records, bank account for payouts, and tax identifiers you provide (TIN, VAT).
  • Device or tablet identifiers if we issue or pair hardware.

2.5 Data we do not intentionally collect

We do not ask for your BVN except where a payout partner or the law requires it for that specific settlement. We do not need health diagnoses; a pharmacy order may still reveal a medicine name to the store and the courier on the ticket. Do not put unnecessary medical history in chat.

3. How we use data and our legal bases

Under the NDPA we rely on one or more of the following for each use:

  • Contract — creating your account, placing and delivering orders, calculating courier earnings, and settling vendors.
  • Legitimate interests — keeping the marketplace safe, preventing fraud, improving ETAs and ranking, training staff on anonymised examples, and measuring which marketing channels work, where those interests are not overridden by your rights.
  • Legal obligation — tax records, responding to a court order, regulator, or lawful police request, and keeping complaint files for the period the law requires.
  • Consent — optional marketing, precise website analytics cookies that are not strictly necessary, and precise customer location where the OS treats it as optional. You can withdraw consent in the app, device settings, or by writing to us. Withdrawal does not affect processing already completed.

In practice we use data to:

  • Create and secure accounts, verify phones, and prevent fake or mule accounts.
  • Place, route, track, and complete deliveries, including masked calls and chat.
  • Calculate courier earnings and vendor settlements, and handle refunds and chargebacks.
  • Show relevant stores, fees, and delivery options for your pin.
  • Send transactional SMS and push (order status). These are not marketing.
  • Send marketing only where you have agreed or the law allows a soft opt-in you can stop.
  • Improve maps, ETAs, search, and app performance.
  • Investigate safety incidents and detect mocked GPS or promo abuse.
  • Comply with Nigerian law, court orders, or regulators including the Nigeria Data Protection Commission (NDPC) and the Federal Competition and Consumer Protection Commission (FCCPC) where they have a lawful request.

4. Location

Customer location helps confirm that a store can deliver to you and to show the courier on the map. You can use a typed address instead of live GPS for browsing, but live tracking of the rider still needs the courier’s GPS. Courier location is required while you are available or on a trip; turning it off will stop new job offers and may fail a trip you already accepted.

After drop-off, live sharing with the customer stops. We retain trip traces only as long as needed for pay, support, safety, and fraud, then reduce or delete them. We do not sell live location to advertisers. We do not use courier GPS to build a public heatmap of named riders.

5. Automated decision-making

Matching (which courier sees a job), fraud scores, promo eligibility, and store ranking use automated systems. They can affect whether you see a job, whether an order is held, or how high a store appears. These systems are not “legal effects” in the court-judgment sense, but they do affect access to the Platform. If you believe a block or hold is wrong, contact support with the order or trip ID. A human on the support or trust-and-safety team can review. We do not use solely automated decisions to refuse a fundamental legal right.

6. Who we share data with

  • The vendor and courier on your order — name or first name, drop-off area, phone via a masked channel where enabled, and what must be delivered.
  • Payment processors, card schemes, and banks that move customer charges and payouts.
  • Map, SMS, push-notification, crash-reporting, and cloud hosting providers that run the apps.
  • Professional advisers, insurers, or claims handlers when a claim is made.
  • Authorities when the law requires it or we believe there is a serious safety or crime risk.
  • A buyer of our business, under confidentiality, if we reorganise or sell — you would be notified if the law requires.

We do not sell personal data. Service providers are held to confidentiality and use limits by contract. Staff access is role-based. A vendor must not export customer phone numbers from tickets to WhatsApp-blast those customers.

7. Cookies and the website

The marketing site may use cookies or similar tools for load balancing, remembering a session, measuring which pages are used, and (if we enable them) advertising measurement. Strictly necessary cookies keep the site working. Analytics and advertising cookies are optional where the NDPA and browser rules require a choice.

You can block cookies in your browser; some features may then work less well. The mobile apps use device identifiers and SDKs instead of classic browser cookies. App tracking on iOS follows Apple’s App Tracking Transparency prompt where it applies. You can reset advertising IDs in system settings.

8. Retention

We keep data only as long as we have a purpose or a legal duty. Typical periods:

  • Active account profile — for the life of the account, then a short cooling period in case you reopen by mistake.
  • Order, trip, and settlement records — for the account life plus a period afterwards to handle refunds, chargebacks, tax, and disputes (often several years where tax or consumer law requires).
  • Courier GPS traces — detailed traces are kept for a shorter operational window, then aggregated or deleted except where a safety or fraud file is open.
  • Support chats — for the life of the dispute plus a training and quality period.
  • Marketing lists — until you unsubscribe or the list goes stale.
  • Failed signup attempts — a short fraud-prevention window.

When you ask us to delete an account we will erase or irreversibly anonymise what we can. We may retain what the law still requires, or what we need to establish or defend a legal claim.

9. Security

We use access controls, encryption in transit (HTTPS/TLS), hashed passwords, staff permissions, and monitoring to protect data. Payment card data is handled by PCI-DSS-aligned processors. No app is perfectly secure. Use a strong unique password, do not share OTPs (Sendo will not ask you to read an OTP to a caller), enable device lock, and tell us if you think your account was taken over.

If we become aware of a personal-data breach that is likely to result in a high risk to you, we will notify you and the NDPC as the NDPA requires.

10. Your rights

Subject to the NDPA and other applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of some processing, objection to processing based on legitimate interests, and withdrawal of consent. You may also ask for information about the categories of data we hold and the recipients we share with, in the form the law requires.

Send requests to info@sendo.com with the subject “Privacy”, the email or phone on the account, and which app you use (Customer, Courier, or Vendor). We will verify it is you — we will not hand account data to someone who cannot prove control of the number. We aim to respond within the statutory period (generally one month, extendable for complex requests as the NDPA allows).

You may lodge a complaint with the Nigeria Data Protection Commission if you are not satisfied. We would rather fix it first: use the same email so we have the ticket history.

Some rights are limited. We cannot delete a trip that is still in a chargeback, or a courier payout file we must keep for tax. We cannot hand you another user’s data.

11. Children

Sendo is not directed at children under 18. We do not knowingly create accounts for minors. If you believe a child has given us data, contact us and we will delete it where we can. Parents should not let a child complete checkout or go online as a courier.

12. International transfers

Some processors (cloud, email, crash reporting, maps) may store or access data outside Nigeria. Where that happens, we use contracts and other safeguards recognised under Nigerian data-protection rules — including NDPA transfer conditions — so your information stays protected. We will not transfer data to a country or recipient we cannot reasonably safeguard.

13. Role-specific notes

Customers. Your courier sees what they need to find you (name or first name, pin, landmark, phone via the app), not your full payment card. Ratings you leave may be shown in aggregate to the courier or vendor. Other customers do not see your address book.

Couriers. Customers see your first name, vehicle hint, photo if you uploaded one, and live map during the trip. After drop-off, live tracking stops. Vendors see that a rider is assigned, not your bank account. We keep trip records for pay and disputes. Mocked-location signals may be stored as a security event.

Vendors. Customers see your store profile, hours, menu, and ratings. We share order tickets with you and the assigned courier only. Staff logins you create are your responsibility; remove access when someone leaves. Do not paste customer lists into public chat groups.

14. Marketing

Transactional messages (your rider is arriving, your payout failed) are part of the service. Promotional messages require consent or another lawful basis. Every marketing email or SMS we send will include a way to stop. Push can be disabled in the device or in-app settings. Unsubscribing from marketing does not unsubscribe you from order updates.

15. Changes and contact

We will post updates on this page and change the “Last updated” date. If a change is material, we may also notify you in the app or by email. Questions, requests, and complaints: info@sendo.com, subject “Privacy”. Dispatch operational issues that are not privacy requests: dispatch@sendo.com. Helpline: +234 (0) 700-SENDO-NG.

These pages are provided by SENDO Logistics Technologies Ltd. to explain how the Sendo platform works. They are not a substitute for independent legal advice.

Related: Help · FAQs · Privacy · Terms · info@sendo.com