Legal
Cookies Policy
Rydr Transport Technology Ltd. · Version 2.0 · Effective 1 August 2026 · Issued under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025
Important Notice
THIS COOKIES POLICY EXPLAINS HOW RYDR TRANSPORT TECHNOLOGY LTD. USES COOKIES AND SIMILAR TRACKING TECHNOLOGIES ON THE RYDR MOBILE APPLICATION AND WEBSITE. IT IS ISSUED IN ACCORDANCE WITH THE NIGERIA DATA PROTECTION ACT 2023 AND THE GENERAL APPLICATION AND IMPLEMENTATION DIRECTIVE 2025. PLEASE READ IT CAREFULLY.
Section 1 — Introduction
Rydr Transport Technology Ltd. ("Rydr", "we", "us", or "our") is the Data Controller in respect of the Personal Data processed through cookies and similar tracking technologies deployed on the Rydr mobile application, website, and associated services (the "Platform").
This Cookies Policy is issued under the Nigeria Data Protection Act 2023 ("NDPA 2023"), the Nigeria Data Protection Commission's General Application and Implementation Directive 2025 ("GAID"), the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, and applicable consumer-protection principles under the Federal Competition and Consumer Protection Act 2018 ("FCCPA 2018").
This Cookies Policy is read together with Rydr's Privacy Policy and Rydr's Terms and Conditions of Use, each of which is incorporated by reference. Where a specific matter is addressed in more than one of those documents, the precedence rule at the Preamble to the Terms and Conditions of Use applies.
Section 2 — What Cookies and Tracking Technologies Are
A cookie is a small text file that a website or mobile application places on your device (smartphone, tablet, or computer) when you access or use it. Cookies enable a service to remember information about you or your device across a session or between sessions.
Where this Policy refers to "cookies", the reference also covers the following equivalent tracking technologies used on the Platform:
- Mobile Software Development Kits (SDKs). Code libraries embedded in the Rydr mobile application that perform functions equivalent to cookies within the mobile app environment — for example, session state, performance monitoring, and crash reporting.
- Local storage. App-based and browser-based storage mechanisms that retain preference data on your device beyond the session lifecycle.
- Device fingerprinting. A technique that combines device attributes (such as device model, operating system version, screen resolution, and time zone) to create a probabilistic device identifier. As at the date of this Policy, Rydr uses device fingerprinting solely for fraud detection and security purposes, and does not use it for advertising or cross-service profiling. Any change to this scope will be notified to Users and, where required, fresh consent will be sought under Section 12.
- Push and in-app notification tokens. Device-specific identifiers that enable the Platform to send notifications to your device — push notifications through your device operating system, and in-app notifications delivered within the Rydr application while you are using it.
Section 3 — Categories of Cookies We Use
Rydr classifies cookies and tracking technologies into four categories, following the GAID classification framework. The specific cookies and identifiers deployed within each category are technical details we do not publish for security and integrity reasons.
3.1 Strictly Necessary
Consent Required: NOThese cookies are essential for the Platform to function. Without them, core features — authentication, session security, QR Verification, payment session tokenisation, active-Trip location, and fraud detection — cannot operate. They are set automatically and cannot be disabled without disabling the Platform itself. Strictly Necessary cookies are deployed on the lawful basis of performance of contract and Rydr's legitimate interest in Platform safety and integrity.
3.2 Functional
Consent Required: YESThese cookies remember your preferences — for example, language settings, saved destinations, and notification preferences — and personalise your Platform experience. Functional cookies are deployed only after you have provided consent and are deactivated on withdrawal of consent.
3.3 Analytics and Performance
Consent Required: YESThese cookies help Rydr understand how the Platform is used in aggregate — feature engagement, session duration, performance metrics, and crash diagnostics. Data collected by analytics cookies is aggregated and is not used to build individual profiles or to serve advertising. Analytics cookies are deployed only after you have provided consent and are deactivated on withdrawal.
3.4 Marketing and Promotional
Consent Required: YES — Explicit Opt-InThese cookies are used to deliver relevant promotional communications about Rydr services and to measure the reach of Rydr's marketing communications. As at the date of this Policy, Rydr does not use marketing cookies to serve third-party advertising, to share data with advertising networks, or to build cross-service surveillance profiles. Any change to this scope will be notified to Users and, where required, fresh consent will be sought under Section 12. Marketing cookies are deployed only after your explicit opt-in consent and are deactivated immediately on withdrawal.
Section 4 — Consent Mechanism
4.1 Consent Architecture on the Rydr Platform
Rydr obtains cookie consent in the following ways:
- Web (rydr.taxi). On first visit to Rydr's website, a Cookie Consent Banner is displayed. The Banner identifies that Rydr uses cookies, briefly describes the categories, and presents "Accept All," "Reject All," and "Manage Preferences" options in equal visual weight. Only Strictly Necessary cookies are active before you make a choice. Non-essential cookies (Functional, Analytics, Marketing) are deployed only after your affirmative selection.
- Mobile Application. At onboarding, you are presented with this Cookies Policy alongside the Terms and Conditions of Use, Privacy Policy, and (if you are onboarding as a Driver) the Drivers' Agreement. You are asked to read and accept the applicable policies before completing account activation. Only Strictly Necessary cookies and SDKs are active prior to your acceptance. Your acceptance of this Cookies Policy at onboarding constitutes consent to the deployment of Functional and Analytics cookies as described in Section 3. Marketing cookies require your separate explicit opt-in, obtained through a distinct consent presented at or after onboarding.
4.2 GAID Consent Standards Applied by Rydr
Consistent with Rydr's obligations under Sections 25 to 27 of the NDPA 2023 and the GAID:
- Consent is not obtained through pre-ticked boxes.
- Scrolling, continued use, or inactivity does not constitute consent.
- Refusal is presented with the same prominence as acceptance where a consent interface is displayed.
- Marketing consent is separate from consent to general Platform use.
- Consent records — including the choice made, the timestamp, and the version of the Cookies Policy accepted — are retained by Rydr for the purpose of demonstrating lawful processing.
4.3 Withdrawing Consent
You may withdraw your consent to Functional, Analytics, or Marketing cookies at any time. Withdrawal takes effect from the date of withdrawal and does not affect the lawfulness of processing carried out before withdrawal.
- Web. Use the Cookie Consent Banner or your browser settings to revoke previously accepted categories.
- Mobile Application. Write to Rydr's Data Protection Officer at legal@rydr.taxi specifying the category or categories for which you wish to withdraw consent. Rydr will process the withdrawal within a reasonable period and will cease deployment of the affected cookies and SDKs within the following ordinary use session.
Withdrawal of consent for Strictly Necessary cookies is not possible without discontinuing use of the Platform, because those cookies are technically required for the Platform to operate.
Section 5 — Third-Party Sub-Processors
Some cookies and SDKs deployed on the Platform are provided by third-party sub-processors engaged by Rydr for specific services. Rydr does not name individual sub-processors in this Cookies Policy for security and commercial reasons; a current register of sub-processors is available from the Data Protection Officer on request. The categories of sub-processor whose technologies may set cookies or SDKs on the Platform are:
- Licensed Digital Payment Infrastructure. For payment session tokenisation and card payment processing. Cookies and tokens set by this category enable secure Rider payment without Rydr storing full card data.
- Cloud infrastructure providers. For hosting, storage, and processing of Platform data.
- Analytics and performance monitoring providers. For aggregated usage analytics, performance monitoring, and crash reporting.
- Communications infrastructure providers. For push notification delivery, one-time password and SMS delivery, and email delivery.
All sub-processors are engaged under data-processing agreements that:
- restrict use of cookie-collected data to the purposes for which they are engaged;
- prohibit re-use of that data for the sub-processor's own advertising or commercial purposes;
- impose confidentiality and security obligations at least equivalent to those under the NDPA 2023; and
- honour User consent withdrawals transmitted through Rydr's systems.
Section 6 — Cross-Border Transfers of Cookie-Collected Data
Some sub-processors listed at Section 5 process cookie-collected data outside Nigeria. In particular, cloud infrastructure providing hosting for Platform data is located in the European Union, and communications infrastructure providing SMS, one-time password, and email delivery is provided by processors located in the United States of America.
Rydr transfers cookie-collected Personal Data to these jurisdictions on the basis of your explicit consent obtained at onboarding under Section 43(1)(f) of the NDPA 2023, and on the necessity of these transfers for performance of Rydr's contract with you under Section 25(1)(b). The consequences of consent withdrawal and the "condition of use" framing for cross-border processing are set out in Section 8 of the Privacy Policy.
Section 7 — Retention of Cookie-Collected Data
Cookie-collected Personal Data is retained in accordance with the retention framework at Section 9 of Rydr's Privacy Policy:
- Session-scoped cookies and short-term operational identifiers are retained only for the duration necessary to operate the specific feature (for example, the QR Verification session ends at Trip conclusion).
- Persistent functional, analytics, and marketing cookie data is retained for the duration of your active Account. On Account deletion, this data is handled per the deleted-account archive framework at Privacy Policy Section 9, subject to the specific exceptions listed there.
- Consent records are retained for the period necessary to demonstrate lawful processing to the NDPC.
- Fraud-prevention cookies and device fingerprints are retained beyond Account closure only to the extent necessary for the fraud-prevention purpose, consistent with the banned-user register carve-out at Privacy Policy Section 9.
- On expiry of the applicable retention period, cookie-collected Personal Data is deleted or anonymised.
Section 8 — Your Rights
You have the rights of a Data Subject under the NDPA 2023 in respect of Personal Data collected through cookies. These rights, and how to exercise them, are set out in Sections 11 and 15 of Rydr's Privacy Policy.
In particular, you may:
- Withdraw consent to any category of cookies for which consent was given (see Section 4.3).
- Request access to the Personal Data Rydr holds about you, including data collected through cookies.
- Request rectification of inaccurate cookie-collected data.
- Request erasure of cookie-collected data, subject to Rydr's legitimate interests in fraud prevention and Platform security.
- Object to processing of cookie-collected data for analytics or marketing purposes.
- Lodge a complaint with the Nigeria Data Protection Commission at info@ndpc.gov.ng or via www.ndpc.gov.ng.
Rights are exercised by written request to Rydr's Data Protection Officer at legal@rydr.taxi. Rydr will respond within thirty (30) days of receipt.
Section 9 — Managing Cookies at the Device Level
Beyond the mechanisms in Section 4, you can control certain cookie-adjacent processing through your device and browser settings.
9.1 Device Location Permissions
You can control whether the Rydr app collects precise or approximate location data through your device's operating system location permissions.
- On iOS: Settings → Privacy & Security → Location Services → Rydr.
- On Android: Settings → Apps → Rydr → Permissions → Location.
Disabling precise location will prevent Trip search, matching, QR Verification, SOS, and Trip Share from operating. Ancillary Platform features that do not require location remain available.
9.2 Advertising Identifier
You can reset or disable the advertising identifier used by analytics SDKs through your device settings.
- On iOS: Settings → Privacy & Security → Tracking, and Settings → Privacy & Security → Apple Advertising.
- On Android: Settings → Google → Ads.
Resetting the advertising identifier does not affect Strictly Necessary cookies or your ability to use the Platform.
9.3 Browser Cookie Controls
If you access Rydr through a web browser, cookies can be managed through your browser's privacy settings. Blocking all cookies through the browser will prevent Strictly Necessary cookies from functioning and will significantly impair your ability to use the Rydr web interface. Rydr recommends managing cookie preferences through the Cookie Consent Banner on rydr.taxi rather than through broad browser-level blocks.
Section 10 — Security
Rydr applies the same technical and organisational security standards to cookie-collected data as to all other Personal Data processed on the Platform, consistent with Section 39 of the NDPA 2023 and Rydr's Privacy Policy Section 10. In particular:
- All cookies and SDK-transmitted data in transit are protected by industry-standard Transport Layer Security (TLS).
- First-party cookies set by Rydr's web interface use the HttpOnly and Secure flags and, where appropriate, SameSite restrictions to reduce cross-site request forgery risk.
- QR Verification session identifiers are designed to be tamper-resistant, with cryptographic protection against pre-capture and replication, in accordance with Clause 5.6 of the Terms and Conditions of Use.
- Consent records are stored with integrity controls to prevent retroactive alteration.
Section 11 — Children
The Rydr Platform is not directed at, and is not intended for use by, individuals under the age of eighteen (18) years. Rydr does not knowingly deploy cookies or tracking technologies on devices used by children. Where Rydr becomes aware that a person under eighteen has used the Platform, Rydr will take prompt steps to delete the associated cookie-collected data. Concerns may be raised with the Data Protection Officer at the details in Section 13.
Section 12 — Changes to This Cookies Policy
Rydr may update this Cookies Policy in accordance with the amendment mechanic at Section 18.1 of the Terms and Conditions of Use, adapted so that where the addition of a new cookie category or a new class of sub-processor materially changes how Rydr processes Personal Data through cookies, fresh consent will be sought before the change takes effect. Non-material updates take effect on publication of the revised Policy. Prior versions are maintained in Rydr's policy archive and are available on request from the Data Protection Officer.
Section 13 — Contact
For queries, complaints, or rights requests relating to this Cookies Policy or Rydr's use of cookies and tracking technologies, please contact:
| Data Protection Officer Name | Oduba Olumuyiwa CDPO, AICMC, Esq. |
| Role | Data Protection Officer |
| legal@rydr.taxi | |
| NDPC Registration Number of the Company | NDPC/DCP/11362 |
Rydr Transport Technology Ltd. · Cookies Policy · Version 2.0 · Effective 1 August 2026
Governed by the Nigeria Data Protection Act 2023
This Policy is continuously accessible at https://www.rydr.taxi/legal/cookies-policy.
© Rydr Transport Technology Ltd. All rights reserved.