Go SendAm Ltd · Legal

Privacy Policy

What personal data Go SendAm collects, why we collect it, who we share it with, and how you can control it. This policy applies to everyone who uses our platforms — shippers, carriers, riders, receivers, and website visitors.

Last Updated
Version 3.0 · August 2026
Organisation
Go SendAm Ltd
Data Contact
Compliance
NDPA 2023 + GAID 2025

Overview

Go SendAm Ltd ("we," "us," or "our") operates a dispatch operations platform serving Lagos vendors, dispatch companies (carriers), riders, and package receivers. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and how you can exercise your rights over it.

This policy applies to your use of our mobile applications (used by shippers, riders, and dispatch company staff), our carrier portal at portal.gosendam.com, our public carrier profile pages at mygsa.biz, our marketing website at gosendam.com, and any communications you receive from us.

This Privacy Policy should be read alongside our Data Protection page (which sets out the standards and principles we hold ourselves to) and our Cookie Policy (which explains our use of cookies and similar technologies on our web properties). Where those pages cover the same subject as this policy, the operational detail in this policy applies to specific processing activities.

We comply with the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID) issued by the Nigeria Data Protection Commission (NDPC).

Our registered address is 100 Olokonla Road, Off Lekki-Epe Expressway, Lekki, Lagos.

1. Our Role Under the NDPA

Go SendAm operates as a Sole Data Controller for personal data of shippers, receivers, website visitors, and for account, wallet, transaction, marketing, and analytics data across all user types.

For personal data of riders — including rider identity, verification, location during active jobs, delivery performance, and ratings — we operate as a Joint Data Controller alongside the dispatch company (carrier) that hired the rider. This reflects the operational reality that carriers hire riders and share decision-making about how riders operate on the platform. A written Joint Controller Agreement between Go SendAm and each carrier allocates responsibilities under this arrangement.

Our third-party service providers, including our identity verification, cloud infrastructure, communications, and payment providers, act as Data Processors on our behalf under written contracts that meet NDPA Section 41 requirements.

For the full explanation of our data protection roles and the standards we hold ourselves to, see our Data Protection page, Section 1.

2. Personal Data We Collect

The personal data we collect depends on how you use our platform. Below is what we collect from each type of user.

Shippers

Vendors and Everyday Sellers

People and businesses who use Go SendAm to send products to their customers. We collect:

  • Name, phone number, email address
  • Business name and details (where the shipper is a business account)
  • Pickup and drop-off addresses for each delivery
  • Package descriptions and declared values you provide
  • Payment method details processed through our payment partners
  • Delivery history, ratings, and complaint records
  • Communications you send us through the app, WhatsApp, or email
  • Marketing consent status and communication preferences
Carriers

Dispatch Companies

Dispatch businesses that operate fleets of riders on our platform. We collect from the carrier business and its directors:

  • Business name, CAC number, and registered business address
  • Director details: name, National Identification Number (NIN), phone number, email address
  • Face verification data for the director during onboarding (see Section 4)
  • Bank account details for wallet payouts
  • Fleet composition — number of riders, vehicle types
  • Wallet balance, funding history, and transaction records
  • Job assignment and completion records for the fleet
  • Communications with our support team
Riders

Individual Dispatch Riders

Riders operate under a carrier. Rider data is jointly controlled by Go SendAm and the carrier. We collect:

  • Name, phone number, and National Identification Number (NIN)
  • Face verification data during onboarding (see Section 4)
  • Vehicle details (motorcycle, van, or other)
  • Live GPS location during active jobs (see Section 5)
  • Delivery performance data — completion rates, timing, incidents
  • Photos taken during job execution — proof at pickup and drop-off
  • Ratings and feedback from shippers and receivers
  • Earnings and payout records
Receivers

Package Recipients

People receiving deliveries sent by shippers. We collect the minimum needed to complete a delivery:

  • Name, phone number, and delivery address (provided by the shipper)
  • Confirmation of delivery details or price when you use our web confirmation flow
  • One-time password (OTP) confirmations at delivery
  • Ratings you provide about the delivery
Website Visitors

Anyone Browsing Our Web Properties

When you visit gosendam.com, portal.gosendam.com, or mygsa.biz without logging in, we collect:

  • IP address, device type, browser type and version, operating system
  • Pages viewed, links clicked, time spent on each page
  • Referring website, if applicable
  • Cookie consent status
  • Contact form details you submit (name, email, message)

We do not knowingly collect personal data of children under 18. Our platforms are not directed at children. If we learn that we have inadvertently collected personal data of a child, we delete it.

4. Sensitive Personal Data

Under NDPA Section 30, biometric data is a special category of personal data that requires additional protections. Go SendAm processes one category of sensitive personal data: face verification data, collected during identity verification for carriers (directors) and riders.

What we collect

During onboarding, we ask you to take a live photograph of your face using your device camera. This face capture is transmitted directly from your device to our identity verification provider, Prembly, over an encrypted connection. Prembly compares your face capture to the reference image held in the National Identity Management Commission (NIMC) database associated with the NIN you provided.

How it is used

Face verification is used solely to confirm that the person opening an account is the same person named on the identification document provided. It is not used for surveillance, marketing, profiling, or any other purpose.

Storage and retention

Go SendAm does not store the face capture image. The image is transmitted to Prembly, verified, and the response returned to us contains only the verification outcome (match / no match) and a similarity score. Prembly retains the face capture in accordance with their own privacy terms and applicable regulations governing identity verification providers in Nigeria.

Legal basis

We process your face verification data on two legal bases:

  • Explicit consent (NDPA Section 30(1)(a)) — you actively consent to face verification during the onboarding flow, and you may withdraw consent at any time. Withdrawal means we cannot complete your verification and your account cannot be activated.
  • Legitimate interest (NDPA Section 25(1)(f)) — fraud prevention across our platform, protecting shippers, receivers, and other carriers from bad actors.

Your rights over your face verification data

You may request to know whether we hold any verification records about you, request a copy of our verification result on file, or request deletion of any related records where you have closed your account. Contact [email protected]. Note that certain verification-related records must be retained for the periods set out in our Data Protection page to satisfy anti-money-laundering law.

5. Location Data

Location data is one of the most sensitive categories of personal data we process. This section explains exactly what location data we collect, when, and why.

Rider location during active jobs

When a rider accepts a job, our mobile application collects continuous GPS location data from the rider's device for the duration of the active job. This continuous tracking begins when the rider marks a job as accepted and ends when the job is marked complete or cancelled.

We use rider GPS location to:

  • Enable shippers and receivers to see the live location of their package during transit
  • Verify that pickup and drop-off photos are taken at the correct locations
  • Support the carrier's operational oversight of active jobs
  • Provide evidence in the event of a dispute about delivery timing or location
  • Detect and investigate anomalies (for example, extended stationary periods that may indicate an incident)

GPS collection stops when the rider is not on an active job. Our systems do not track rider location outside of active jobs.

Shipper and receiver location

We collect location data from shippers and receivers in two ways:

  • Addresses you enter — pickup and drop-off addresses provided when creating or receiving a delivery.
  • Device location for photo verification — when a rider takes a proof-of-delivery photo at your address, the photo's location metadata may be captured to confirm the photo was taken at the correct location. This is location of the delivery event, not continuous tracking of you.

Website and app usage location

When you visit our web properties or use our applications, we may infer your approximate location from your IP address. This is used for security purposes (detecting suspicious login attempts from unexpected locations) and for aggregated analytics. IP-based location is not precise geolocation.

Legal basis for location processing

Rider GPS is processed on the basis of legitimate interest (operational necessity — we cannot operate a same-day dispatch platform without knowing where the rider is during active jobs). This is explained to riders at onboarding and documented in the rider terms. Shipper and receiver location is processed on the basis of contract (delivery execution).

6. Automated Decision-Making

NDPA Section 37 gives you rights in relation to decisions made about you using automated systems where those decisions have significant effects on you. The following automated processes operate on our platform:

Automated identity verification

During onboarding, we use our identity verification provider to automatically match your submitted details (CAC number, NIN, face capture) against government databases. An initial rejection based on this automated match can be reviewed by a human on request. Contact [email protected] to request human review.

Rider assignment

Job assignment to riders may involve automated matching based on rider availability, proximity, historical completion performance, and job characteristics. Decisions that have significant effects on the rider (for example, deactivation from the platform) are not fully automated and involve human review before being finalised.

Fraud and anomaly detection

Our platform monitors patterns of activity to detect suspicious behaviour — for example, unusual account access, atypical payment patterns, or delivery irregularities. Where automated detection triggers an account restriction, you have the right to request human review of the restriction.

We do not currently use automated decision-making for profiling users for marketing purposes.

7. Who We Share Data With

We share personal data with the third-party service providers listed below. Each acts as a Data Processor on our behalf under a written contract that meets NDPA Section 41 requirements. They are contractually bound to process data only on our documented instructions, to apply appropriate security measures, and to assist us with our NDPA obligations.

Prembly
Nigeria
PurposeIdentity and business verification — CAC checks, NIN checks, and face verification during onboarding.
Data sharedBusiness names, CAC numbers, director names, NINs, phone numbers, face capture images (during verification only).
Termii
Nigeria
PurposeSMS delivery for OTP codes, delivery notifications, and account communications.
Data sharedPhone numbers and SMS message content.
Nomba
Nigeria
PurposePayment processing for carrier wallet funding.
Data sharedBusiness name, transaction amounts, payment method details.
Flutterwave
Nigeria
PurposePayment processing for carrier wallet funding.
Data sharedBusiness name, transaction amounts, payment method details.
Freshdesk
Cross-border transfer
PurposeSupport ticket management and customer communications.
Data sharedName, email address, phone number, support ticket content and history.
Amazon Web Services (AWS)
Cross-border transfer
PurposeCloud infrastructure — application hosting, database storage, and file storage for our platform.
Data sharedAll operational personal data (as processor, not for AWS's own purposes).
Cloudflare
Cross-border transfer
PurposeContent delivery, bot management, and security protection for our web properties.
Data sharedIP addresses, device information, and network-level traffic data.
GoHighLevel
Cross-border transfer
PurposeMarketing website hosting for gosendam.com.
Data sharedWebsite form submissions (name, email, message), and analytics on marketing site visits.
Google Analytics
Cross-border transfer
PurposeWebsite usage analytics — page views, feature interactions, and error events, processed only where users have consented via our cookie banner.
Data sharedIP address (anonymised where possible), device information, page interaction events.

We do not sell your personal data to advertisers, data brokers, or any other third party. We do not share your personal data with any party outside those listed above, except where we are legally compelled to do so (for example, by court order, valid law enforcement request, or regulatory investigation).

When we add a new sub-processor that processes personal data in a materially different way, we update this list and, where the change is significant, notify affected users.

8. How Long We Keep Your Data

We keep personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law. The full retention schedule — with the specific period and legal source for each data category — is set out in our Data Protection page.

See our Data Protection page, Section 6 for the full retention schedule.

Summary of key retention periods

  • Carrier and rider verification records — 5 years after end of business relationship (Money Laundering Act 2022).
  • Transaction and wallet records — 6 years (Companies and Allied Matters Act + tax retention).
  • Delivery records including photos and OTP logs — 5 years after delivery completion.
  • Support tickets — 2 years after closure.
  • Marketing consent records — For the duration of consent, plus 3 years after withdrawal.
  • Access and audit logs — 24 months.
  • Analytics data — 14 months (Google Analytics default).
  • Account data after closure — 30 days for immediate deletion of primary records, then anonymised for aggregate use.

Carrier business verification (CAC and director NIN) is repeated every 90 days to confirm records remain accurate and the carrier remains eligible to operate on the platform.

Go SendAm employees cannot retrieve stored NIN or CAC numbers after verification is complete. These identifiers are transmitted directly to our identity verification provider during onboarding and are not retained in a form retrievable by our team.

9. International Data Transfers

Some of the sub-processors we engage — including AWS, Freshdesk, Cloudflare, GoHighLevel, and Google Analytics — operate infrastructure outside Nigeria. This means certain personal data may be transferred to, or accessed from, countries outside Nigeria in the course of delivering our service.

Where we transfer personal data outside Nigeria, we do so only where a safeguard permitted under NDPA Section 41 is in place. This includes standard contractual clauses, adequacy determinations by the NDPC, and explicit consent where applicable.

For our full approach to international transfers, see our Data Protection page, Section 9. If you want to know the specific safeguard applied to a specific transfer, contact [email protected].

10. Your Rights

Under NDPA Sections 34 to 39, you have the right to access, correct, delete, restrict, port, and object to processing of your personal data, as well as rights in relation to automated decisions.

For the full explanation of each right and how to exercise it, see our Data Protection page, Section 3. Requests to exercise your rights can be sent to [email protected]. We respond within 30 calendar days as required by NDPA Section 34.

11. Marketing Communications

We may send you marketing communications — for example, updates about new features, service tips, and offers — only where you have consented to receive them.

Consent

You consent to marketing communications by opting in during account creation, updating your preferences in your account settings, or by responding affirmatively to a consent request from us. Consent is optional and separate from your consent to essential platform communications (delivery notifications, security alerts, transaction receipts, and legal notices).

Withdrawing consent

You can withdraw consent to marketing communications at any time by:

  • Clicking the "unsubscribe" link at the bottom of any marketing email we send you.
  • Updating your marketing preferences in your account settings.
  • Emailing [email protected] with the subject line "unsubscribe from marketing."

Withdrawing consent to marketing does not affect the lawfulness of processing before your withdrawal, and does not affect our ability to send you essential platform communications required for you to use the service.

12. How We Protect Your Data

We apply technical and organisational security measures proportionate to the risk of the processing. Our controls include:

  • Encryption in transit using Transport Layer Security (TLS) for all data exchanged between users and our platforms.
  • Encryption at rest for sensitive data stored in our cloud infrastructure.
  • Role-based access control — team members can only access personal data required for their role, and access is logged.
  • Strong authentication — administrative accounts require strong authentication controls.
  • Segregated environments — production data is separated from development and testing environments.
  • Vendor security assessment before engaging any new sub-processor.
  • Regular vulnerability monitoring and patch management.
  • Incident response process aligned with NDPA Section 40.

For more detail on our security approach, see our Data Protection page, Section 7.

13. Personal Data Breaches

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we:

  • Notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by NDPA Section 40.
  • Notify affected data subjects directly and without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • Take immediate steps to contain the breach, investigate its scope, and prevent recurrence.
  • Document the incident, our response, and lessons learned.

Where we act as Joint Controllers with a carrier, the Joint Controller Agreement between us allocates responsibility for breach notifications and response.

14. Changes to This Policy

We update this Privacy Policy when our processing activities change, when we add or remove sub-processors, or when regulatory requirements change. When we do, we update the version number and "Last Updated" date at the top of this page.

For material changes — such as the introduction of a new category of processing, a new type of personal data collected, or a new significant sub-processor — we notify affected users through the app, by email, or through a prominent notice on our platforms, at least 14 days before the change takes effect.

Your continued use of our platforms after the effective date of any update constitutes acceptance of the updated policy. If you disagree with a material change, you can close your account before the effective date.

15. Contact Us

Questions about this Privacy Policy, requests to exercise your rights, or complaints about how we handle your personal data can be sent to us at:

Address
100 Olokonla Road, Off Lekki-Epe Expressway, Lekki, Lagos

If you are not satisfied with our response to a complaint, you have the right to complain to the Nigeria Data Protection Commission at any time. Exercising your right to complain to the NDPC does not affect any other remedy available to you.

Go SendAm Ltd · Privacy Policy v3.0 · August 2026 · Compliant with the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025 (GAID)