Privacy
What we collect, why we use it, and the choices you have.
Effective and last updated 2026-07-19.
Who controls your personal data
TAG-ALONG LTD operates TagRides and is the controller of personal data described in this policy. TagRides is a Lagos-first route-share platform for riders and drivers. You can contact our privacy team at privacy@tagrider.com or write to us at 6, Alh Memunatu Shelle Crescent, off Murphy Mudashiru Street, Rovers Estate, Owode-Ogombo, Lagos State, Nigeria.
This policy covers the TagRides app, website, accounts, ride services, wallet, support, and research forms. Some described features are limited, in pilot, or disabled; we identify important availability limits below.
The information we collect
Account, identity, and communication
- Name, email address, phone number, account role, profile image, and account identifiers.
- Login, session, email-verification, and phone-verification records, including OTP delivery channel and status.
- Messages, support requests, notification preferences, device push tokens, and transactional communications.
- Referral records, where the feature is used, including referrer and referred-user identifiers, roles, status, reward amount, and related timestamps.
Driver and vehicle verification
- Driver's licence, vehicle registration, roadworthiness, insurance, and other regionally required documents.
- Vehicle make, model, colour, year, image, licence plate, class, and available seats.
- Review status, rejection or review reasons, verification history, and resulting eligibility to drive or receive payouts.
Location, routes, and trip activity
- Precise or near-precise coordinates, accuracy, heading, speed, timestamps, pickup, destination, stops, and recent driver fixes while location-dependent services are in use.
- The app may request a fresh position when it opens or returns to the foreground. Web location may be approximate or use a position cached for up to 30 seconds.
- During driver availability, matching, confirmation, recovery, and active trips, driver location may be sent to our systems. During an active ride it may be shared with the matched rider together with movement, ETA, ride, and temporary session information.
- If a driver allows background location, collection may continue while an active driver session runs in the background. Driver fixes may also be stored in GPS history for ride reconstruction, audit, safety, reliability, and analytics.
- Derived information such as route-matched position, progress, distance remaining, ETA, arrival state, route deviation, and rider-driver distance.
- Ride requests, selections, offers, accepted price, participants, seats, arrival, boarding, cancellation, completion, ratings, and related timestamps and identifiers.
TagRides does not need to track a driver continuously when no driver session or location-dependent service is active. Device and platform behaviour can vary, so use your operating-system or browser settings to review or revoke foreground or background location permission. Location-dependent functions may then be unavailable.
Wallet, payment, refund, and payout data
- Wallet balances, funding references, holds, releases, ride charges, refunds, driver earnings, service fees, transfer fees, currency, status, reason, and timestamps.
- Payment-provider transaction, refund, transfer, webhook, reconciliation, error, attempt, and audit records. Signed provider webhook bodies and signatures may be retained to verify and safely process payment events.
- For drivers: account-holder name, bank, full account number at submission, payout currency, recipient token, destination version, and change time. We send the full bank details to Paystack for resolution and recipient creation. Locally, the account number is replaced with a masked value containing only the last four digits.
Card numbers, PINs, and CVVs entered in Paystack's hosted payment flow are handled by Paystack rather than stored by TagRides. New and scheduled Nigerian driver payouts are currently disabled, and no bank-change cooling duration is configured.
Pickup contact
After pickup arrival and before boarding, our systems may disclose a rider's account phone number to the selected driver for pickup coordination. The driver initiates the call through the device phone app and telephone network. The number may therefore appear in device call history, and normal caller ID may reveal the driver's number. Reveal attempts are authorised, rate-limited, and audited using user, ride, session, action, and timestamp information; the audit record does not include the phone number.
Device and operational data
- IP address, browser or device information, app version, operating system, language, region, request path, and timestamps.
- Authentication, messaging, network, security, rate-limit, crash, and diagnostic events.
- Safety and ride-integrity metadata such as ride and session identifiers, phase, location freshness and accuracy, divergence, and participant count. Precise coordinates may be processed to calculate safety signals without being written to general safety logs.
Website visitors and contributors
- Waitlist email, submission source, and time if you join the waitlist.
- Trip-fare research including origin, destination, minimum and maximum fare, time, duration, travel mode, optional notes, source, and submission time.
- IP address and request information used temporarily for rate limiting and abuse prevention.
- Basic website usage events collected through Vercel Analytics.
How we use information
- Create and secure accounts, verify contact details, and maintain sessions.
- Match riders and drivers, coordinate pickups, show trip participants, and manage ride state.
- Provide maps, route progress, ETA, arrival detection, trip completion, and safety signals.
- Calculate prices, record offers, reserve and settle fares, maintain wallets, and reconcile transactions.
- Verify drivers, vehicles, and payout destinations and enforce eligibility requirements.
- Send service, security, ride, receipt, and account communications.
- Prevent fraud, abuse, duplicate transactions, unauthorised access, and cross-trip data exposure.
- Debug and improve reliability, matching, routing, pricing suggestions, and aggregate marketplace planning.
- Keep records, respond to lawful requests, resolve disputes, and meet legal, tax, accounting, and regulatory duties.
What other users can see
For trip coordination, we share information needed to recognise and coordinate with a counterpart. Depending on role and trip stage, this can include first and last name, profile image, rating, vehicle details and licence plate, pickup and destination, seats, offer details, live or recent driver location, route progress, and ETA. General discovery profiles do not include email addresses or phone numbers.
The limited pickup-contact disclosure described above is an exception. Do not use another user's information for unrelated contact, marketing, harassment, publication, or off-platform solicitation.
If you use a referral link or code, a prospective referred user may see an abbreviated version of the referrer's name and account role so they can recognise the referral.
Service providers and other recipients
We use service providers to operate TagRides. The provider and hosting configuration can change as we deploy the service, so this is a description of the main categories and providers rather than a promise that no other contracted processor is used.
- Google services, including Firebase and Google Maps: authentication, push notifications, map display, address search, geocoding, and routing.
- Paystack: hosted payment processing, bank-account resolution, recipient creation, refunds, transfers, and payment verification.
- MailerSend, KudiSMS, and, where enabled, Meta's WhatsApp services: delivery of email, OTP, and service messages.
- Cloudinary: storage and delivery of uploaded images.
- Hosting, database, messaging, and analytics providers: infrastructure used to host APIs, store records, exchange live ride messages, protect services, host the website, and understand basic website use. Current deployment options include AWS, MongoDB infrastructure, Vercel, Cloudflare, and Netlify.
- Phone and network providers: when a driver chooses to call a rider, the device dialler, mobile carrier, and telephone network process the call.
We may also disclose information when required by law, to protect a person or the service, in connection with a corporate transaction, or with your direction or consent. We do not sell personal data or share it with advertisers for targeted advertising.
Legal bases
Under the Nigeria Data Protection Act 2023, our legal bases include:
- Contract: to create your account, match and coordinate trips, maintain wallets, and process requested transactions.
- Legal obligation: for tax, accounting, regulatory, safety, consumer-protection, and lawful-disclosure duties.
- Legitimate interests: to secure the service, prevent fraud, audit access, reconcile transactions, support users, and improve reliability.
- Consent: where required for device permissions, optional profile information, or optional communications. You can withdraw consent.
Automated and derived processing
Software helps match riders and drivers, check regional seat capacity, calculate or suggest prices, map-match GPS fixes, detect arrival or completion, identify suspicious or duplicate activity, and determine whether configured verification and transaction rules are met. These outputs can affect what is shown or whether an action is available. You may contact us to question an outcome or request human review where applicable.
How long we keep information
We keep personal data only for as long as reasonably needed for the purposes above, including providing an account, completing and reconciling transactions, handling complaints, protecting the service, and meeting legal, tax, accounting, and regulatory obligations. Retention varies by record and applicable requirement.
- Account and active operational data are generally kept while the account or service relationship continues.
- Trip, wallet, payment, refund, payout, webhook, and audit records may be retained after account closure where required for financial records, disputes, fraud prevention, or law.
- Driver verification records may be retained after driving ends to demonstrate eligibility and respond to safety or regulatory matters.
- Bank details stored locally remain masked to the last four digits; recipient tokens and associated audit metadata may remain with financial records. Deletion of a bank destination can initially be a soft deletion.
- Waitlist and research submissions are kept until they are no longer needed for the stated purpose or you validly request deletion, subject to applicable exceptions.
Our retention and deletion controls are still being standardised across services, including GPS history and referral records. We assess deletion and de-identification requests against the operational and legal requirements above. Backups and legally restricted records may take longer to cycle out, and we will not describe retained records as anonymous if they remain linkable for compliance.
International transfers
Some providers process information outside Nigeria. International transfers must comply with the Nigeria Data Protection Act 2023. We assess the transfer mechanism and safeguards required for the provider and processing involved; contact us if you want information about a particular transfer.
Security
We use technical and organisational measures designed to protect personal data, including access controls, transport encryption where configured, masked bank details, signed payment webhooks, rate limits, audit records, and controls intended to reject stale or mismatched ride-location updates. No system is completely secure, and we cannot guarantee that loss, misuse, or unauthorised access will never occur.
If a personal-data breach occurs, we will investigate and notify affected people and the Nigeria Data Protection Commission when and within the period required by applicable law.
Your rights and choices
Subject to the Nigeria Data Protection Act 2023 and applicable exceptions, you may request access, correction, deletion, restriction, portability, or information about your data; object to certain processing; withdraw consent; and question certain automated outcomes. Email privacy@tagrider.com from your account email or provide enough information for us to verify your request.
You can manage location, notification, camera, and similar permissions in your device or browser settings. Revoking a permission can prevent the related feature from working. You can also ask us to remove a waitlist or research submission.
If you are dissatisfied with our response, you may complain to the Nigeria Data Protection Commission at ndpc.gov.ng.
Account deletion
The current in-app permanent-deletion control removes the core sign-in and profile account. It does not by itself erase every linked record held by driver, wallet, telemetry, referral, analytics, audit, or provider systems. To request broader erasure across TagRides services, email privacy@tagrider.com with "Delete my account" in the subject. We may need to verify your identity.
We will verify and assess the request across relevant systems. Erasure does not override legal duties or legitimate requirements to retain transaction, tax, safety, fraud-prevention, dispute, or regulatory records. We will explain any material limitation or retention that applies to the request.
Children
TagRides currently requires account holders, including riders, to be at least 18. Students who are 18 or older may use the rider service. We have not yet implemented a guardian-consent or guardian-booking flow for an under-18 rider, and drivers should not request a rider's identity document to determine age. Drivers must also meet all legal age and licensing requirements. If you believe a child has created an account or provided personal data, contact privacy@tagrider.com.
Changes to this policy
We will update the effective date when this policy changes. If a change materially affects how we use personal data, we will provide reasonable notice through the app, website, email, or another appropriate channel before it takes effect where required.
Related terms
Read the TagRides Terms of Service for the rules that apply to accounts, trips, location features, payments, pickup contact, and use of the platform.