Skip to main content

Legal

Privacy Policy

Rydr Transport Technology Ltd. · Version 2.0 · Effective 1 August 2026 · NDPA 2023 Compliant · NDPC-Registered · NDPC/DCP/11362

Important Notice

THIS PRIVACY POLICY DESCRIBES HOW RYDR TRANSPORT TECHNOLOGY LTD. COLLECTS, USES, SHARES, AND PROTECTS YOUR PERSONAL DATA. IT INCLUDES SIGNIFICANT MATTERS THAT AFFECT YOUR RIGHTS, INCLUDING THE COLLECTION OF SENSITIVE PERSONAL DATA (BIOMETRIC VERIFICATION DATA AND, WHERE YOU CHOOSE TO PROVIDE IT, HEALTH DATA), AND THE TRANSFER OF YOUR DATA OUTSIDE NIGERIA FOR ESSENTIAL PROCESSING. PLEASE READ IT CAREFULLY BEFORE USING THE RYDR PLATFORM.

Section 1 — Introduction and Scope

1.1 Who We Are

Rydr Transport Technology Ltd. ("Rydr", "we", "us", or "our") is a company incorporated under the laws of the Federal Republic of Nigeria. Rydr operates a shared mobility platform (the "Platform") — a safety focused digital garage — through which independent Drivers and Riders connect, negotiate, and take Trips, supported by identity verification, QR check, live-share, SOS routing, and Trip-logging infrastructure. Rydr Transport Technology Ltd. is the Data Controller in respect of Personal Data processed on the Platform, and is registered with the Nigeria Data Protection Commission ("NDPC"), registration number NDPC/DCP/11362.

Rydr Transport Technology Ltd. is a subsidiary of a US-incorporated parent company. The US parent has no data-level access to Personal Data processed on the Platform, is not a Data Controller or Data Processor of that data, and does not receive any Personal Data of Users.

1.2 Who This Policy Applies To

This Policy applies to the Personal Data of:

  • Riders — individuals who register a Rider Account and use the Platform to search for, book, and take Trips;
  • Drivers — independent contractors who register a Driver Account, maintain an active Driver Subscription Plan, and use the Platform to offer and complete Trips;
  • Website and app visitors — individuals who visit our website or download our application without completing registration;
  • Emergency Contacts — third parties whose telephone numbers are designated by a User to receive SOS communications;
  • Referred Users — individuals who sign up using another User's referral link or code, in respect of the specific processing for the Referral Programme; and
  • Business contacts and corporate account holders — organisations that engage with Rydr in a business context.

1.3 Relationship with Other Rydr Documents

This Policy is drafted under the Nigeria Data Protection Act 2023 ("NDPA 2023") and the General Application and Implementation Directive 2025 ("GAID"), and should be read together with Rydr's Terms and Conditions of Use, Cookies Policy, and (in respect of Drivers) Drivers' Agreement. The precedence rule at the Preamble to the Terms and Conditions of Use applies.

1.4 Geographic Scope

This Policy applies to all Personal Data processed by Rydr in connection with the Platform's operation in Nigeria. Where Rydr expands into other jurisdictions, this Policy will be supplemented by a jurisdiction-specific privacy notice reflecting local data-protection law, and this Policy will be updated by notice under Section 17.

Section 2 — Definitions

Capitalised terms used in this Policy and not otherwise defined here bear the meanings given to them in Rydr's Terms and Conditions of Use. In addition:

  • "Consent" means a freely given, specific, informed, and unambiguous indication of a Data Subject's agreement to the processing of the Data Subject's Personal Data, as defined in the NDPA 2023.
  • "Data Controller" means Rydr Transport Technology Ltd.
  • "Data Processor" means a person or body that processes Personal Data on behalf of the Data Controller.
  • "Data Protection Officer" or "DPO" means the individual designated by Rydr to oversee compliance with the NDPA 2023 and this Policy (see Section 18).
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "NDPC" means the Nigeria Data Protection Commission.
  • "Personal Data" has the meaning assigned in the NDPA 2023.
  • "Processing" has the meaning assigned in the NDPA 2023.
  • "Sensitive Personal Data" has the meaning assigned in Section 30 of the NDPA 2023 and, in the context of Rydr's processing, includes Biometric Verification Data and Health Data.

Section 3 — Categories of Personal Data We Collect

We collect the following categories of Personal Data. The specific data collected depends on whether you use the Platform as a Rider, a Driver, or a visitor, and on the features you use.

3.1 Identity Data

Full legal name; date of birth; Nigerian National Identification Number (NIN); photograph (profile image, identity document image); facial biometric template derived from your NIN Verification.

3.2 Contact Data

Nigerian mobile telephone number; email address; physical address (where provided).

3.3 Authentication Data

Password, PIN, or reference to a device-supported biometric method used to authenticate to the Platform. Passwords and PINs are stored in salted, hashed form and are not held in plaintext.

3.4 Financial and Payment Data

Withdrawal Account bank account details (Drivers and any Rider who receives a payout from the Rydr Wallet); tokenised payment method identifiers held by the licensed Digital Payment Infrastructure engaged by Rydr — Rydr does not personally collect or process card numbers and details; Rydr Wallet balances, transaction history, subscription payment records, and Referral Programme earning records.

3.5 Driver Vehicle and Licensing Data

Nigerian driver's licence details; vehicle registration, make, model, colour, and year; vehicle insurance policy details; vehicle roadworthiness certificate; applicable state commercial passenger transport authorisation; vehicle photographs (front, rear, both sides with licence plate visible, and interior) submitted at onboarding.

3.6 Location Data

Real-time device location during Trip search, Trip matching, and active Trips; approximate area location used for matching. Location is collected only when the Platform is in use and where you have granted location permission on your device.

3.7 Trip and Platform Activity Data

Trip listings, booking history, Fare Negotiation exchanges, QR Verification timestamps, Trip logs (route, duration, distance), destination search data, in-Platform communications, Ratings (numeric 1 to 5) and any free-text comments accompanying a Rating, dispute submissions, cancellation and no-show records, Referral Programme linkage data (the connection between a Referring User and a Referred User during and immediately after the Attribution Period).

3.8 Safety and Emergency Data

SOS activation records, including timestamp and location coordinates; Trip Share activation records; safety incident reports; incident-related communications with Rydr's safety team.

3.9 Sensitive Personal Data — Biometric and Health

Rydr processes two categories of Sensitive Personal Data under Section 30 of the NDPA 2023:

  • Biometric Verification Data — a facial biometric template captured during onboarding and compared against the reference image linked to your NIN, for the sole purpose of confirming that you are the person identified in the NIN record.
  • Health Data — where you voluntarily choose to provide it, your blood type and allergies, for the sole purpose of disclosure to first responders on activation of the SOS feature.

Both categories are processed only on the basis of your explicit consent under Section 26 of the NDPA 2023, and only for the specified purposes. Full detail on the safeguards applicable to each is set out in Section 6 of this Policy.

3.10 Third-Party Personal Data You Provide

The telephone number of your Emergency Contact, designated in the Platform settings. Rydr does not collect the Emergency Contact's name.

3.11 Device and Technical Data

Device model, operating system and version; unique device identifier; IP address and approximate location derived from IP; application version, session logs, and crash reports; mobile network operator and connection type; cookies and similar technologies (see Section 14).

3.12 Fraud Prevention and Security Data

Fraud and abuse indicators associated with your Account; suspension, deactivation, and appeal records; a limited record of previously permanently deactivated Users maintained for fraud prevention.

Section 4 — How We Collect Personal Data

4.1 Directly from You

You provide Personal Data directly when you:

  • enter your phone number and complete onboarding, including identity resolution, OTP confirmation, and biometric NIN Verification;
  • submit KYC documentation as a Driver, including driver's licence, vehicle registration, insurance, and vehicle photographs;
  • provide your Emergency Contact's telephone number;
  • voluntarily provide Health Data for emergency response;
  • enter a destination, create a Trip listing, or negotiate a Fare;
  • make or receive a payment through the Platform;
  • submit a Rating, comment, or safety report;
  • contact Rydr customer support or the DPO;
  • activate SOS or Trip Share.

4.2 Automatically Through the Platform

When you use the Platform we automatically collect device location (with your permission), device and technical data, application session and interaction logs, and cookies and similar technologies as described in Section 14.

4.3 From Third Parties

We receive Personal Data from third parties in the following circumstances:

  • Authorised Nigerian identity data sources — subscriber records held by telecommunications operators and identity records held by the Federal Government of Nigeria, for the phone-number identity resolution step during onboarding;
  • The licensed Digital Payment Infrastructure — payment method identifiers and payment status;
  • Emergency service authorities — in the event of an SOS activation, feedback or follow-up information from the responding authority;
  • Other Users — where another User references or names you in a Rating comment, safety report, or dispute submission;
  • Corporate account administrators — where you use Rydr through a corporate account arrangement.

4.4 Inferred and Derived Data

We derive certain operational information from the data we collect, being calculations that support Trip matching, safety, quality, and integrity on the Platform. These derivations are used to operate and improve the Platform and are not sold or shared as standalone data points.

Section 5 — Purposes and Lawful Bases of Processing

Under the NDPA 2023, Rydr must have a lawful basis for every processing activity. The lawful bases we rely on are as follows. References below are to sections of the NDPA 2023.

PurposeLawful Basis
Account registration, identity resolution, and NIN VerificationExplicit consent for the specific onboarding steps (§26); performance of contract (§25(1)(b))
Biometric Verification Data processingExplicit consent under §26(2), the User's ongoing Account relationship providing the underlying context
Health Data processing (where voluntarily provided)Explicit consent under §26(2); vital interests of the Data Subject (§25(1)(d)) at the moment of an emergency
Trip search, matching, booking, negotiation, payment, and completionPerformance of contract (§25(1)(b))
Safety infrastructure operation — QR Verification, Trip logging, Trip Share, SOS routingPerformance of contract (§25(1)(b)); legitimate interest in safety (§25(1)(f)); vital interests of the Data Subject (§25(1)(d))
Emergency Contact processingLegitimate interest of Rydr in enabling safety communications (§25(1)(f)); vital interests of the User (§25(1)(d)) at the moment of an emergency
Payment processing, subscription billing, payouts, and Referral Programme calculationPerformance of contract (§25(1)(b))
Referral Programme processing of the Referred User's transaction dataExplicit consent of the Referred User (§26) captured at signup
Fraud, safety, and abuse detectionLegitimate interest (§25(1)(f))
Rating and reputation calculation, including free-text commentsPerformance of contract (§25(1)(b)); legitimate interest in Platform quality (§25(1)(f))
Marketing and promotional communicationsExplicit opt-in consent under §26, freely withdrawable at any time
Operational communications (Trip receipts, account notifications, safety alerts)Performance of contract (§25(1)(b)) — service messages required to operate the Platform
Analytics and product improvement (aggregated, non-identifying)Legitimate interest (§25(1)(f))
Legal, tax, and regulatory complianceLegal obligation (§25(1)(c))
Cross-border processing by non-Nigerian infrastructure providersExplicit consent of the User under §43(1)(f); performance of contract (§25(1)(b)) — see Section 8
Response to court orders, regulatory demands, and law enforcementLegal obligation (§25(1)(c))

5.1 Withdrawal of Consent

Where processing is based on your consent, you may withdraw that consent at any time through the in-app Privacy Control or by writing to the DPO. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Withdrawal of consent for processing that is essential to the operation of the Platform — including biometric identity binding and cross-border transfer of your data — will mean that Rydr can no longer provide the Platform to you, and your Account will be closed under Section 16 of the Terms and Conditions of Use. This consequence is disclosed at the point of consent.

Section 6 — Sensitive Personal Data: Biometric Verification and Health Data

Sensitive Personal Data under Section 30 of the NDPA 2023 receives heightened protection. Rydr processes two categories, each on the basis of your specific explicit consent obtained at collection.

6.1 Biometric Verification Data

  • What we process. A facial biometric template derived from a face capture you complete during onboarding, and compared against the reference image linked to your NIN.
  • Purpose. Confirming that you are the person identified in the NIN record. This is a core safety and anti-fraud feature of the Platform.
  • Legal basis. Your explicit consent under Section 26(2) of the NDPA 2023, obtained on a dedicated consent screen at the biometric step of onboarding.
  • Safeguards. Biometric templates are held encrypted at rest under strong industry-standard encryption; access is technically restricted and logged; and templates are not used for any purpose other than the identity binding described above.
  • Retention. For the duration of your active Account. On Account deletion, treatment is per the retention framework at Section 9.

6.2 Health Data

  • What we process. Where you voluntarily provide it, your blood type and allergies.
  • Purpose. Disclosure to first responders on your activation of the SOS feature, so that first responders can provide appropriate emergency care.
  • Legal basis. Your explicit consent under Section 26(2) of the NDPA 2023, obtained on a dedicated consent screen at the health-data step of onboarding. The vital-interests basis under Section 25(1)(d) additionally supports the disclosure to first responders at the moment of an SOS event.
  • Safeguards. Health Data is stored encrypted on Rydr's infrastructure. Access is technically restricted so that Health Data is released only on SOS activation — no Rydr staff member accesses Health Data in the ordinary course. Health Data is not used for any purpose other than the specified emergency disclosure.
  • Retention. For the duration of your active Account. On Account deletion, Health Data is deleted and is not moved to any archive.

Section 7 — How We Share Personal Data

Rydr does not sell, rent, or trade Personal Data. Rydr shares Personal Data only with the categories of recipient described below, on the basis of contractual data-processing agreements, and only to the extent necessary for the specified purpose.

7.1 Between Users on the Platform

When a Trip booking is confirmed, the Platform discloses:

  • to the Rider, the Driver's name, telephone number, profile photograph, vehicle details, cumulative Rating, and — where the Driver has completed one — the Driver's Corridor Partner status;
  • to the Driver, the Rider's name, telephone number, and destination.

The telephone numbers are shared to enable the Driver and Rider to communicate with each other in connection with the Trip. Government identifiers, financial data, and biometric data are not shared between Users.

7.2 With Trusted Contacts (Trip Share) and Emergency Contacts (SOS)

When you activate Trip Share, the Platform generates a link containing your live location and estimated arrival details for the duration of the active Trip. You may share the link with any individual you choose (each a Trusted Contact). Rydr does not collect, store, or process the identity or contact details of any Trusted Contact; you control with whom the link is shared. Trip Share terminates automatically at Trip conclusion.

When you activate SOS, the Platform transmits to your Emergency Contact your live location and — where you have voluntarily provided it — your Health Data. The Emergency Contact is the individual you designate by telephone number in the Platform settings and is distinct from any Trusted Contact.

7.3 With First Responders and Emergency Services

On activation of SOS, the Platform transmits to the emergency service your live location coordinates and, where you have voluntarily provided it, your Health Data. Disclosure to emergency services is on the basis of the vital interests of the Data Subject and your explicit consent.

7.4 With the Licensed Digital Payment Infrastructure

Rydr shares the minimum financial and transactional data necessary with the payment service provider licensed under Nigerian law and engaged by Rydr to operate the Rydr Wallet and process card payments. That provider is engaged under a data-processing agreement compliant with the NDPA 2023 and any applicable Central Bank of Nigeria data-governance requirements affecting the underlying rails.

7.5 With Identity Verification Providers

Rydr engages authorised Nigerian identity data verification services to verify your phone number, NIN, and driver's licence against official Nigerian identity infrastructure. These providers process identity data solely for the verification purpose and under data-processing agreements.

7.6 With Cloud, Communications, and Technical Infrastructure Providers

Rydr uses cloud computing, storage, messaging (SMS, one-time password delivery), email delivery, and application analytics infrastructure to operate the Platform. Providers of this infrastructure act as Data Processors, access Personal Data only to the extent required to provide their contracted services, and are bound by data-processing agreements imposing confidentiality and security obligations at least equivalent to those under the NDPA 2023. Some of these providers process Personal Data outside Nigeria — see Section 8.

7.7 With Professional Advisers

Rydr may share Personal Data with lawyers, auditors, insurers, and other professional advisers in connection with legal, financial, insurance, or corporate matters, in each case under professional confidentiality obligations.

7.8 In Connection with Corporate Transactions

In the event of a merger, acquisition, restructuring, or sale of substantially all of Rydr's assets, Personal Data may be disclosed to prospective counterparties in the context of due diligence, subject to confidentiality protections. On completion of any such transaction, the acquirer becomes bound by the same obligations to you as Rydr under this Policy and the NDPA 2023, and Rydr will notify affected Users in accordance with Clause 18.6 of the Terms and Conditions of Use.

7.9 To Comply with Legal Obligations

Rydr may disclose Personal Data to law enforcement, courts, the NDPC, tax authorities, or other Nigerian governmental bodies where required by applicable law or valid legal process. Where legally permitted, Rydr will notify the affected User of the disclosure.

7.10 What Rydr Never Does

Rydr does not sell Personal Data to advertisers, data brokers, marketing services, or any third party. Rydr does not disclose Personal Data to any recipient outside the categories listed in this Section 7 except with your specific consent.

Section 8 — Cross-Border Transfers

Rydr is a Nigerian company that operates primarily in Nigeria. However, some of Rydr's Data Processors process Personal Data outside Nigeria. In particular:

  • Cloud infrastructure processing — Rydr's cloud infrastructure is located in the European Union. The European Union operates a data protection framework recognised by the NDPC as offering broadly equivalent protection to Nigerian Data Subjects.
  • Communications infrastructure (SMS, one-time password, and email delivery) — these services are provided by processors located in the United States of America. The United States does not currently benefit from an NDPC adequacy recognition, and its data-protection framework may not offer equivalent protection to Nigerian Data Subjects.

8.1 Basis for Cross-Border Transfer

Rydr transfers Personal Data to these jurisdictions on the basis of the User's explicit consent obtained at onboarding under Section 43(1)(f) of the NDPA 2023, following the User's receipt of a clear description of the categories of data transferred, the destination jurisdictions, the purposes, and the risks arising from any adequacy gap. Rydr also relies on the necessity of these transfers for performance of Rydr's contract with the User under Section 25(1)(b).

8.2 Consent as a Condition of Using the Platform

Because these transfers are necessary for the operation of the Platform's core infrastructure, your consent to cross-border transfer is a condition of registration and continued use of the Platform. A User who does not wish to consent to cross-border processing cannot register for or use the Platform. Withdrawal of consent will cause your Account to be closed under Section 16 of the Terms and Conditions of Use, and your data will be handled under the retention framework at Section 9 of this Policy.

8.3 Future Jurisdictions

As Rydr expands its Platform to new jurisdictions, Rydr will assess the data-protection framework of each new jurisdiction, implement the appropriate transfer mechanism, and publish a jurisdiction-specific privacy notice reflecting local law where required.

Section 9 — Retention

Rydr retains Personal Data only for as long as necessary for the purposes for which it was collected, or for such longer period as applicable Nigerian law requires or permits.

9.1 General Framework

During the period your Account is active, Personal Data is retained as required to provide the Platform's services and to comply with applicable legal obligations. On deletion of your Account, Rydr moves the associated Personal Data to a deleted-account archive, which is retained for the periods required under applicable Nigerian law, including tax record-keeping under the Companies Income Tax Act, statutory limitation periods for civil claims, anti-money-laundering record-keeping obligations, and regulatory retention obligations imposed by the NDPC or any other Nigerian regulator. On expiry of the applicable retention period, data in the archive is deleted.

9.2 Exceptions to the General Framework

The following categories are treated differently from the general framework:

  • Health Data — deleted at the point of Account closure and not moved to the deleted-account archive.
  • Destination search data — held for a limited period to facilitate Trip matching, then deleted.
  • One-time password records and SOS transmission caches — held for short-term security and audit purposes only.
  • Banned-user register — a limited record of previously permanently deactivated Users, retained beyond Account closure for as long as necessary for the fraud-prevention purpose.
  • Marketing consent records — retained for the duration of the consent plus a reasonable period thereafter as evidence of lawful processing.

9.3 Anonymisation

Where Personal Data is used for aggregated analytics purposes after the retention period, it is first anonymised in a manner that renders re-identification of any individual Data Subject not reasonably possible.

Section 10 — Security

Rydr implements technical, organisational, and physical safeguards designed to protect Personal Data against unauthorised access, disclosure, alteration, destruction, or accidental loss, in accordance with Section 39 of the NDPA 2023.

10.1 Technical Safeguards

Data in transit is encrypted using Transport Layer Security (TLS) at industry-standard versions and above. Data at rest is encrypted using AES-256 or equivalent standards. Rydr does not personally collect or process card numbers and details. Passwords and PINs are stored in salted, hashed form and are not held in plaintext. The Platform's QR Verification codes are designed to be tamper-resistant, with cryptographic protection against pre-capture and replication. Rydr operates automated anomaly-detection systems and commissions periodic security testing by qualified third-party specialists.

10.2 Organisational Safeguards

Rydr maintains a designated Data Protection Officer, role-based access controls limiting staff access to Personal Data to a strict need-to-know basis, mandatory data-protection training for staff with access to Personal Data, binding data-processing agreements with all Data Processors and sub-processors, an internal breach-response plan and register, and periodic internal and external data-protection audits under a monitoring and evaluation schedule aligned with the requirements of the GAID.

10.3 Data Breach Notification

Where a Personal Data breach occurs on the Platform and is likely to result in a risk to Data Subjects, Rydr will notify the NDPC without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach, in accordance with Section 40 of the NDPA 2023. Where a breach is likely to result in a high risk to Data Subjects, Rydr will additionally notify affected Data Subjects without undue delay. You may report a suspected breach affecting your Personal Data to legal@rydr.taxi.

Section 11 — Your Rights as a Data Subject

You have the following rights in relation to your Personal Data under the NDPA 2023. Rights are exercised as set out in Section 15.

RightWhat It Means
Access (§34)You may request confirmation of whether Rydr processes Personal Data about you, and receive a copy of that data together with information about how it is used.
Rectification (§35)You may request correction of inaccurate or incomplete Personal Data. Most profile information is directly updatable through your in-app Account settings.
Erasure (§36)You may request deletion of your Personal Data where it is no longer necessary for the purpose for which it was collected, where you withdraw the consent on which processing is based, or where processing is unlawful. This right is subject to Rydr's retention framework at Section 9 and to any legal obligation to retain specific categories of data.
Restriction (§35)You may request that Rydr restrict the processing of your Personal Data in certain circumstances, such as while a rectification or objection is being resolved.
Portability (§37)Where processing is based on contract or consent and carried out by automated means, you may receive your Personal Data in a structured, commonly used, machine-readable format.
Objection (§36)You may object to processing based on Rydr's legitimate interest, including processing for direct marketing. Rydr will cease such processing unless Rydr can demonstrate compelling legitimate grounds that override your interests.
Human review of automated decisions (§37)You may request that a decision based solely on automated processing that produces legal or similarly significant effects on you be reviewed by a Rydr staff member. See also Section 13.
Withdraw consent (§26(5))Where processing is based on your consent, you may withdraw that consent at any time. The consequences of withdrawal, including for cross-border processing, are described at Sections 5.1 and 8.2.
Complaint to NDPC (§46)You may lodge a complaint with the Nigeria Data Protection Commission at any time. Contact details are at Section 16.

Rydr will verify your identity before processing any rights request, will respond within thirty (30) days of receipt, and will process rights requests free of charge unless they are manifestly unfounded or excessive.

Section 12 — Children's Privacy

The Rydr Platform is not directed at, and is not intended for use by, individuals under the age of eighteen (18) years. Rydr does not knowingly collect Personal Data from any person under eighteen. All Users are required at registration to confirm that they are at least eighteen years of age.

Where Rydr becomes aware that Personal Data has been collected from a person under the age of eighteen, Rydr will take prompt steps to delete such data. A parent or guardian who believes a child has registered on the Platform may contact the DPO at the details in Section 18.

Section 13 — Automated Decision-Making and Profiling

The Platform uses automated processing in certain operational functions, including matching, verification, calculation, safety, and integrity functions.

Where automated processing may contribute to a decision that produces legal or similarly significant effects on a User — including Account suspension, Account deactivation, withholding of Wallet balances, or removal from the Referral Programme — Rydr applies a human review safeguard: no such action is taken solely on the basis of automated processing. A Rydr staff member reviews the specific decision affecting the User, and the User is notified of the action, the general reason for it, and the User's right to respond and to seek internal review under Section 16 of the Terms and Conditions of Use and to escalate under Section 17 of the Terms and Conditions of Use, in each case consistent with Section 37 of the NDPA 2023.

You may request human review of any specific automated decision affecting your Platform access, earnings, or reputation by writing to the DPO. Rydr will complete the review within the periods specified in Clause 16.5 of the Terms and Conditions of Use.

Section 14 — Cookies and Tracking Technologies

Rydr uses cookies, mobile SDKs, and similar technologies on the Platform. Detailed treatment is set out in Rydr's Cookies Policy, presented alongside this Policy at onboarding and continuously accessible in the Platform and on the Rydr website.

At a summary level, cookies and similar technologies fall into four categories:

CategoryConsent Required?Purpose
Strictly NecessaryNo — required for the Platform to functionSession authentication, security tokens, fraud-prevention signals, QR session management.
FunctionalYes — with your consentPreferences (language, notification settings, saved destinations, Emergency Contact list).
AnalyticsYes — with your consentAggregated usage patterns, feature engagement, session duration, crash reports. Data is aggregated and not used for individual profiling or advertising.
MarketingYes — with your explicit opt-in consentDelivery of relevant promotional communications about Rydr services. You may opt out at any time.

In accordance with the GAID, Rydr uses non-essential cookies and tracking technologies only with your prior opt-in consent. Pre-ticked boxes and inactivity do not constitute consent.

Section 15 — How to Exercise Your Rights

15.1 In Writing to the DPO

You may exercise any right under Section 11 by writing to the Data Protection Officer at legal@rydr.taxi. Please include your full name and registered Account email address, the specific right you wish to exercise, sufficient detail to identify the data and processing activity in question, and appropriate identity verification.

Rydr will acknowledge your request within five (5) business days and provide a substantive response within thirty (30) days of receipt.

15.2 Account Deletion

You may delete your Account at any time through the in-app settings or by written notice to legal@rydr.taxi. Account deletion does not affect any outstanding payment obligation. On deletion, your Personal Data is handled under the retention framework at Section 9.

Section 16 — Complaints and Regulatory Recourse

16.1 Internal Complaint Resolution

If you are concerned about how Rydr handles your Personal Data, please contact the Data Protection Officer at legal@rydr.taxi in the first instance. Rydr will investigate the concern in good faith, provide a written response within thirty (30) days, and take remedial action where appropriate.

16.2 Nigeria Data Protection Commission (NDPC)

You have the right to lodge a complaint with the NDPC at any time if you believe Rydr has processed your Personal Data in breach of the NDPA 2023.

Nigeria Data Protection Commission (NDPC) Website: www.ndpc.gov.ng Contact: info@ndpc.gov.ng

16.3 Federal Competition and Consumer Protection Commission (FCCPC)

For complaints relating to your rights as a consumer of Rydr's services, you may also contact the Federal Competition and Consumer Protection Commission under the Federal Competition and Consumer Protection Act 2018.

Section 17 — Changes to This Policy

Rydr may update this Policy in accordance with the amendment mechanic at Section 18.1 of the Terms and Conditions of Use, adapted as follows for data-protection matters: where the NDPA 2023 requires fresh consent for a material change, Rydr will obtain that consent before the change takes effect. Silence, inactivity, or continued use of the Platform does not constitute consent to a material change affecting the lawful basis or purpose of processing (Section 26(3) of the NDPA 2023). Prior versions of this Policy are maintained in Rydr's policy archive and are available on request from the DPO.

Section 18 — Data Protection Officer

Rydr has appointed a Data Protection Officer in accordance with Section 32 of the NDPA 2023. The DPO is responsible for overseeing Rydr's compliance with this Policy and the NDPA 2023.

Data Protection Officer NameOduba Olumuyiwa CDPO, AICMC, Esq.
RoleData Protection Officer
Emaillegal@rydr.taxi
NDPC Registration Number of the CompanyNDPC/DCP/11362

For urgent safety concerns, please use the in-app SOS feature or the in-Platform safety support channel. For account or platform support, please contact support@rydr.taxi.

Rydr Transport Technology Ltd. · Privacy Policy · Version 2.0 · Effective 1 August 2026

Governed by the Nigeria Data Protection Act 2023 · Registered with the NDPC · NDPC/DCP/11362

This Policy is continuously accessible at https://www.rydr.taxi/legal/privacy-policy.

© Rydr Transport Technology Ltd. All rights reserved.

We use cookies

Strictly necessary cookies keep the site secure and working, and are always on. Functional, analytics, and marketing cookies are set only if you accept them.

Read our Cookies Policy. You can withdraw consent at any time.