Sep 19, 2026 ·
1. Introduction
Mzienet Systems Ltd ("we", "us", "our"), a company registered and operating in Abeokuta, Nigeria with RC8241400, operates the MCT Ride platform — a ride-sharing service consisting of the MCT Ride Rider mobile application, the MCT Ride Driver mobile application, the website at mctride.com, and all associated backend services (collectively, the "Platform"). This Privacy Policy explains how we collect, use, store, share and protect your personal data when you access or use the Platform, whether as a rider, driver or visitor.
This Policy is issued in compliance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR). By creating an account or using the Platform, you acknowledge that you have read and understood this Policy.
Key Definitions • Personal Data — any information that relates to an identified or identifiable individual, including name, email, phone number, location data, financial information and identification documents.• Data Controller — Mzienet Systems Ltd, which determines the purposes and means of processing your personal data. • Data Subject — you, the individual whose personal data is processed through the Platform. • Processing — any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, transfer and deletion.• Rider — a user who requests and takes rides through the Platform.
• Driver
— a user who provides ride services through the Platform. • KYC — Know Your
Customer, the identity and vehicle verification process required for drivers.
We collect the following categories of personal data depending on whether you are a rider, driver or visitor.
• Full
name (first name and last name)
• Email
address
• Mobile
phone number and country code
• Username
and password (password stored as a cryptographic hash, never in plain text)
• Profile
photograph
• Country
of registration
Drivers are required to submit identity and vehicle documents before they can accept rides. These include:
• Government-issued identification (driver's licence, national ID or equivalent)
• Vehicle registration documents
• Vehicle insurance documents
• Vehicle photographs
• Additional documents as required by the dynamic KYC form (set by the platform administrator)
For drivers, we collect: vehicle brand, model, colour, year of manufacture, service category and any form data associated with vehicle verification.
• Riders:
pickup coordinates, destination coordinates and reverse-geocoded addresses each
time a ride is requested.
• Drivers: real-time GPS coordinates streamed to our servers while the driver is online
(updated approximately every 50 metres of movement), including when the app is
running in the background. Ride tracking data (GPS coordinates recorded
throughout each active ride) is stored as ride location records.
• Wallet
balance and transaction history (deposits, withdrawals, ride payments,
commissions and tips)
• Payment
method details as processed through third-party payment gateways (we do not
store full card numbers; gateway-specific tokens and transaction references are
retained)
• Withdrawal
method information (bank details or other payout channel data submitted by
drivers)
• Coupon
usage records
• In-ride
chat messages exchanged between riders and drivers
• Support
ticket content, including text messages and file attachments
• SOS
emergency alerts raised during rides
• Device
token for push notifications (Firebase Cloud Messaging)
• IP
address
• App
version, device type, operating system
• Login
timestamps and session data
• Ride
history: pickup and destination locations, distance, duration, fare amounts,
bid amounts, OTP codes, ride status, cancellation reasons and review ratings
• Bid
history for drivers
• Online/offline
status and timestamps for drivers
We collect personal data you provide when you register an account, complete your profile, submit KYC or vehicle verification documents, create or respond to support tickets, send in-ride messages, or update your account settings.
When you use the Platform, we automatically collect location data (via GPS and the device's location services), device tokens for push notifications, IP addresses, login activity and app usage patterns. For drivers, the foreground location service continuously streams GPS coordinates to our servers while the driver is toggled online, even when the app is in the background.
We receive limited data from third-party authentication providers when you use social login (Google Sign-In or Apple Sign-In). This typically includes your name, email address and a unique identifier from the provider. We also receive payment confirmation data from third-party payment gateways when you complete transactions through the Platform.
Under the Nigeria Data Protection Act 2023, we process your personal data on the following lawful bases.
|
Data Category |
Purpose |
Lawful Basis (NDPA) |
|
Account information (name, email, phone) |
Create and manage your account, authenticate your identity, communicate service updates |
Performance of contract; Consent |
|
Location data (GPS coordinates) |
Match riders with nearby drivers, calculate fares and distances, provide real-time ride tracking, ensure rider safety |
Performance of contract; Legitimate interest (safety) |
|
KYC and vehicle documents |
Verify driver identity and vehicle fitness, comply with transport regulations |
Legal obligation; Performance of contract |
|
Financial and transaction data |
Process ride payments, manage wallet balances, calculate and deduct commissions, process driver withdrawals |
Performance of contract; Legal obligation |
|
Communication data (in-ride chat, support tickets) |
Facilitate rider-driver communication during rides, provide customer support, resolve disputes |
Performance of contract; Legitimate interest |
|
Device and technical data (FCM tokens, IP address) |
Deliver push notifications, maintain platform security, detect fraud |
Legitimate interest (security); Performance of contract |
|
Usage and ride data (ride history, bids, reviews) |
Provide ride services, improve platform quality, enforce cancellation policies, display driver ratings |
Performance of contract; Legitimate interest |
|
SOS emergency alerts |
Ensure the safety of riders and drivers during rides |
Vital interest; Legitimate interest (safety) |
Where consent is the lawful basis, you may withdraw your consent at any time by contacting us (see Section 9). Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
We do not sell your personal data. We share your data only in the following circumstances.
When a ride is matched, we share limited information between the rider and driver to facilitate the trip: the rider sees the driver's name, profile photo, vehicle details, rating and real-time location; the driver sees the rider's name, pickup and destination addresses and the ride OTP. In-ride chat messages are visible to both parties.
We share transaction data with third-party payment gateways to process ride payments, deposits and withdrawals. These gateways include providers such as Paystack, Flutterwave, Stripe and others configured on the Platform. Each gateway processes data under its own privacy policy and applicable regulations.
We use the following categories of service providers who process data on our behalf under data processing agreements:
• Google Maps Platform — for geocoding, distance calculation, directions and place search (location data is sent to Google’s APIs)
• Pusher — for real-time event delivery between riders, drivers and the server (event payloads transit through Pusher’s infrastructure)
• Firebase Cloud Messaging — for delivering push notifications (device tokens and notification payloads are processed by Google Firebase)
• Social login providers (Google, Apple) — for authentication when you choose social sign-in
We may disclose your personal data where required by law, regulation, legal process or enforceable government request, or where necessary to protect the rights, property or safety of Mzienet Systems Ltd, our users or the public.
In the event of a merger, acquisition or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.
|
Data Type |
Retention Period |
|
Account information |
Retained for the life of your account and for up to 12 months after account deletion, unless a longer period is required by law |
|
Ride history and transaction records |
Retained for a minimum of 6 years after the transaction date to comply with Nigerian tax and financial record-keeping requirements |
|
KYC and vehicle verification documents |
Retained for the life of the driver account and for up to 24 months after account deletion or document rejection |
|
Location and ride tracking data |
Retained for 12 months after the ride is completed, then anonymised or deleted |
|
In-ride chat messages |
Retained for 6 months after the ride is completed |
|
Support ticket data |
Retained for 24 months after ticket closure |
|
Device tokens |
Deleted when you log out, delete your account or revoke notification permissions |
|
SOS alert records |
Retained for 24 months or as required for legal proceedings |
Your data is stored on servers operated by our hosting provider. Data may be transferred to and stored on servers located outside Nigeria when processed by our third-party service providers (Google, Pusher, Firebase, payment gateways). Where such transfers occur, we ensure that appropriate safeguards are in place as required by the NDPA, including confirming that the receiving country provides an adequate level of data protection or that the transfer is covered by standard contractual clauses.
You may request deletion of your account through the app (Profile & Settings → Delete Account) or by contacting us. Upon deletion, we will remove or anonymise your personal data within the retention periods stated above, except where retention is required by law.
As a data subject under the Nigeria Data Protection Act 2023, you have the following rights.
Right of Access — You may request a copy of the personal data we hold about you.
Right to Rectification — You may request correction of inaccurate or incomplete personal data. You can update your name, email, phone number and profile photo directly in the app via Profile Settings.
Right to Erasure (Deletion) — You may request deletion of your personal data, subject to the retention periods in Section 6 and any overriding legal obligations. Account deletion is available directly in the app.
Right to Data Portability — You may request that we provide your personal data in a structured, commonly used and machine-readable format, or that we transmit it directly to another controller where technically feasible.
Right to Object — You may object to the processing of your personal data where processing is based on our legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
Right to Restrict Processing — You may request that we restrict processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have contested.
Right to Withdraw Consent — Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
Right to Lodge a Complaint — You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been violated.
To exercise any of these rights, contact us using the details in Section 9. We will respond to your request within 30 days. We may request additional information to verify your identity before fulfilling your request.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction.
Authentication and Access Control — All API requests are authenticated using Laravel Sanctum personal access tokens. A separate developer token is validated on every request. Rider and driver authentication are isolated through separate token permissions to prevent cross-access. Two-factor authentication (Google Authenticator) is available for driver accounts.
Encryption and Secure Storage — Passwords are stored as bcrypt hashes and are never transmitted or stored in plain text. Sensitive tokens are stored using secure device storage. All data in transit between the mobile apps and our servers is encrypted using TLS/SSL. Bad SSL certificates are rejected by the mobile applications.
OTP Verification — A unique 4-digit OTP is generated for each ride and must be verified at pickup to prevent unauthorised pickups. Email and SMS verification codes are used during registration and password reset.
Access Restrictions — Administrative access to the backend is controlled through role-based permissions (Spatie Laravel-Permission). Admin actions are logged and auditable. Only authorised personnel have access to personal data.
Incident Response — In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and affected data subjects in accordance with the NDPA's breach notification requirements.
The MCT Ride Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us immediately.
The MCT Ride website (mctride.com) may use cookies and similar tracking technologies to maintain session state, remember preferences and analyse site usage. The mobile applications use local storage (SharedPreferences and secure storage) to persist authentication tokens and user preferences on the device. You can manage cookie preferences through your browser settings; disabling cookies may affect the functionality of the web platform.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. When we make material changes, we will notify you through the Platform (via push notification or in-app notice) or by email before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised. Continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy.
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a privacy concern, please contact us:
Data Controller: Mzienet Systems Ltd Address: 1st Floor Deyoonu, Eleweran Abeokuta, Ogun State, Nigeria Email: support@mctride.com Website: https://mctride.com