GoJuip Privacy Policy
Last updated: 9 May 2026
This policy explains what personal data GoJuip ("we", "us") collects through the GoJuip Rider, Driver, and Operations apps, why we collect it, who we share it with, and the rights you have under the Nigeria Data Protection Act 2023 (NDPR) and the EU GDPR where applicable.
1. Who we are
GoJuip is operated under the legal entity associated with the Firebase project gojuip-62710. For privacy enquiries, contact privacy@goju.app.
2. Data we collect
- Account data — name, phone number, email, profile photo, and authentication token issued by Firebase Authentication.
- Driver-only KYC — driving licence, vehicle papers, vehicle inspection photos, NIN, bank account details for payouts.
- Location — pickup and drop-off coordinates, and the driver's live position during a trip. Location data is collected only while the app has the OS permission and a trip is active.
- Trip and payment metadata — fare, route polyline, ratings, chat / call timestamps, payment provider references.
- Device telemetry — app version, crash logs, FCM push token, Crashlytics identifiers.
3. How we use it
- Match riders with nearby drivers and route the trip.
- Process fares, wallet top-ups, and driver payouts via licensed gateways (Paystack, Flutterwave, Stripe).
- Compute pricing, surge, ratings, and dispute outcomes.
- Detect fraud and abusive behaviour.
- Provide safety features (panic alerts, masked-number calling, share-trip link).
- Comply with regulatory and tax obligations.
4. Who we share with
- The other party of your trip — the rider and the assigned driver see each other's first name, rating, vehicle, and approximate location for the duration of the trip only.
- Payment gateways — only the minimum data needed to settle a charge or payout.
- Service providers — Google Firebase (hosting, database, push), Google Maps (geocoding, routing).
- Authorities — when compelled by a lawful court order or regulator request.
- Emergency contacts — only when the rider triggers Panic and only the contacts the rider has saved.
We do not sell your personal data.
5. Retention
- Trip and payment records are retained for 7 years to satisfy financial-audit requirements.
- Chat and voice-call signaling artefacts are retained for 90 days, then deleted.
- Crashlytics logs are retained for 90 days.
- Account profile data is retained until you delete your account (see "Your rights" below).
6. Security
- All traffic is encrypted in transit (TLS).
- Database access is gated by Firebase Authentication and per-collection security rules.
- Driver KYC documents and inspection photos are accessible only to the owning driver and the GoJuip compliance team.
- Payment secrets and webhook keys are stored in
config_secretswith superadmin-only access.
7. Your rights
Under NDPR and GDPR you have the right to access, correct, port, and erase your personal data, and to object to or restrict processing.
You may also email privacy@goju.app to exercise any of the above rights. We respond within 30 days.
8. Children
GoJuip is not intended for users under 18. We do not knowingly collect data from minors.
9. Changes
We will update this page when our practices change. Material changes are surfaced inside the app via in-app notification.
10. Contact
Privacy enquiries: privacy@goju.app
Data Protection Officer: dpo@goju.app