Privacy

Privacy policy

What personal data Rydmate handles, why, who sees it, how long we keep it and the rights you have under the Nigeria Data Protection Act 2023.

Effective 18 September 2026

1. Who we are and what this covers

Rydmate is operated by PSA Systems Limited, a company registered in the Federal Republic of Nigeria and based in Abuja ("Rydmate", "we", "us"). This policy explains how we handle personal data when you use the Rydmate website, the Rydmate application, the Rydmate API, the Rydmate Terminal and a business's public website hosted by Rydmate (together, the "Service").

We process personal data in accordance with the Nigeria Data Protection Act 2023 (the "NDPA"), the regulations and guidance issued by the Nigeria Data Protection Commission (the "NDPC"), and, where they still apply, the Nigeria Data Protection Regulation 2019. Where you use the Service from outside Nigeria, we also respect the data protection law of your country to the extent it applies to us.

2. Data controller and data processor

Rydmate plays two different roles, and your rights depend on which one applies:

  • Rydmate as data controller. For the personal data of people who create accounts, sign in, contact us, visit our website or read our documentation, Rydmate decides why and how the data is processed. This policy applies in full.
  • Rydmate as data processor. A transport or logistics business that uses Rydmate (an "Operator") records its own staff, drivers, passengers and customers. For that data the Operator is the data controller and Rydmate processes it only on the Operator's instructions, under the data processing terms in our Terms of Service. If you are a passenger, customer or employee of an Operator, please direct requests about your data to that Operator first; we will help them respond.

3. The personal data we collect

Account data you give us when you register or are invited: full name, email address, phone number, password (stored only as a salted hash), profile picture if you add one, your role and which businesses you belong to.

Business records an Operator enters or generates while running its operation: staff and driver details (names, phone numbers, licence numbers and expiry dates), vehicle details, routes, trips, shifts, tickets, bookings, orders, shipments, receipts, expenses, reconciliation records and proof-of-delivery photographs and signatures. Passengers and customers appear in these records by name, phone number and, for deliveries, pickup and drop-off addresses.

Location data from GPS devices an Operator mounts on its vehicles, and from the Rydmate Terminal or driver app while a shift is running. Location is attached to a vehicle and a trip, and to the driver assigned at that time.

Payment data. Rydmate never stores card numbers, bank credentials or PINs. Electronic payments are collected by a licensed payment provider into the Operator's own account. We receive and keep the reference, amount, method, status and time of each payment so it can be reconciled.

Technical data collected automatically: IP address, browser and device type, the pages and endpoints requested, request identifiers, timestamps and error information. For the Rydmate API we record which API key made a request, the endpoint, the response status and the latency; we do not record request or response bodies.

Audit data. Sensitive actions in the Service (changing permissions, recording money, issuing refunds, creating API keys, editing records) are written to an append-only audit trail with the actor, the time, the IP address and what changed. This is how an Operator can prove what happened, and it cannot be edited or deleted by users.

Correspondence when you contact us, including messages sent through an Operator's website contact form, which are delivered to that Operator.

4. Why we use personal data and the lawful basis

Under section 25 of the NDPA we process personal data only where we have a lawful basis. We rely on:

  • Performance of a contract with you or the Operator: creating and securing accounts, running the operation, issuing tickets and receipts, tracking vehicles, reconciling money, delivering the API and webhooks, and billing.
  • Legal obligation: keeping financial and tax records, responding to lawful requests from courts and regulators, and reporting where the law requires.
  • Legitimate interests that are not overridden by your rights: keeping the Service secure, preventing fraud and abuse, enforcing rate limits, measuring usage, improving the product and defending legal claims.
  • Consent, which you may withdraw at any time, for optional communications and for any use that is not covered above. Withdrawing consent does not affect processing that already happened.

We do not sell personal data, and we do not use it for automated decisions that have legal or similarly significant effects on you.

5. Who we share personal data with

We share personal data only as far as is needed to run the Service, and always under written terms that require the recipient to protect it:

  • The Operator you belong to. Owners and managers of an Operator see the records their permissions allow, including staff and driver details, tickets sold and locations of the Operator's vehicles.
  • Service providers acting on our instructions: cloud hosting and backups, the payment provider that collects electronic payments, email and SMS delivery, error monitoring and customer support tools. They may process data only for the purpose we engage them for.
  • Developers and integrations an Operator authorises. When an Operator creates an API key or registers a webhook, the data those integrations receive is under the Operator's control. Webhook payloads carry identifiers, statuses and amounts, never passenger or customer contact details.
  • Authorities and courts when we are legally required to, including under the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 as amended, or to protect the rights, property or safety of Rydmate, Operators or the public.
  • A successor if Rydmate is involved in a merger, acquisition or sale of assets; we will tell you before your data becomes subject to a different privacy policy.

6. International transfers

Our servers and service providers may be located outside Nigeria. Where personal data leaves Nigeria we transfer it only as the NDPA allows: to a country the NDPC has recognised as providing adequate protection, or under binding contractual safeguards that give the data the same protection it has here, or where another condition in section 43 of the NDPA applies. You can ask us which safeguard covers a particular transfer.

7. How long we keep personal data

  • Account data: for as long as the account exists, then for up to 12 months to handle disputes and restore accidental deletions, unless the law requires longer.
  • Business records, tickets, receipts, payment and reconciliation records: for as long as the Operator's subscription is active, then for the period Nigerian tax and company law require financial records to be kept (currently six years), after which they are deleted or anonymised.
  • Location history: for the period the Operator's plan provides, after which it is summarised and the raw fixes are deleted.
  • Audit trail: for the life of the Operator's account plus the statutory retention period, because it is the record of what happened.
  • API usage and technical logs: 13 months, then deleted or anonymised.
  • Correspondence: for as long as needed to resolve the matter and for three years after.

An Operator that closes its account can ask for an export of its records before deletion.

8. Your rights

Under Part VI of the NDPA you have the right to:

  • be told what personal data we hold about you and receive a copy of it;
  • have inaccurate or incomplete data corrected;
  • have your data erased where there is no longer a lawful reason to keep it;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive the data you gave us in a structured, machine-readable form and have it moved to another provider where technically feasible;
  • withdraw consent where consent is the basis for processing;
  • not be subject to a decision based solely on automated processing that significantly affects you;
  • lodge a complaint with the Nigeria Data Protection Commission.

To exercise a right, use the contact page or write to our Data Protection Officer at the address there. We will confirm your identity, respond within the time the NDPA allows (normally 30 days) and never charge for a first request unless it is manifestly unfounded or excessive. Where Rydmate is a processor, we will pass your request to the Operator and assist them.

9. How we protect personal data

We apply the technical and organisational measures section 39 of the NDPA requires, including: encryption in transit for every connection; encryption at rest for payment provider credentials, API secrets and webhook secrets; passwords stored only as salted hashes; server-side sessions in hardened cookies; access checked by permission on every request, with cross-business requests answered as if the record did not exist; an append-only audit trail; least-privilege access for our own staff; regular backups; and security review of every release.

If a personal data breach is likely to result in a risk to your rights, we will notify the NDPC within 72 hours of becoming aware of it and inform affected Operators and individuals without undue delay, as section 40 of the NDPA requires.

10. Cookies and similar technologies

The Rydmate application uses a session cookie to keep you signed in and a CSRF cookie to protect writes; both are strictly necessary and are cleared when you sign out. We use local storage on your device to remember preferences such as a collapsed sidebar and to queue work you do while offline. We do not use advertising cookies or third-party tracking on the Service.

11. Children

The Service is for businesses and their staff. We do not knowingly create accounts for anyone under 18. A passenger or customer under 18 may appear in an Operator's records; the Operator is responsible for having a lawful basis, and for obtaining a parent's or guardian's consent where section 31 of the NDPA requires it.

12. Changes to this policy

We will update this policy when the Service or the law changes. The effective date at the top tells you when it last changed. For material changes we will notify account holders by email or in the application before they take effect.

13. How to reach us

PSA Systems Limited operates Rydmate. Questions about this policy, requests about your data and complaints go to our Data Protection Officer through the contact page. If you are not satisfied with our response you may complain to the Nigeria Data Protection Commission.