Privacy Policy
CROWN WHEELS LTD (RC 9632213) • Draft — pending legal review
This platform (“we,” “us,” “the platform”) is operated as a private car hire and sales business in Nigeria. This policy explains what personal data we collect when you use the platform, why we collect it, how long we keep it, and what rights you have over it, in line with the Nigeria Data Protection Act, 2023(the “NDPA”) — the Act of the National Assembly that replaced the earlier Nigeria Data Protection Regulation (NDPR 2019) and established the Nigeria Data Protection Commission (NDPC) as regulator.
What we collect and why
| Data | Why we collect it | When |
|---|---|---|
| Full name, phone number, email | To create your account, process bookings, and contact you about them | When you register |
| Emergency contact name and phone number | Exclusively for the SOS emergency-alert feature | When you register (optional, but required to use SOS) |
| Booking details (dates, pickup location, hire type) | To process and fulfil your booking | When you make a booking |
| Payment proof (screenshot/photo of your bank transfer) | To verify your payment before confirming a booking | When you upload proof of payment |
| Live GPS location | Only when you tap the SOS button, or if you enable voluntary trip sharing | Only during an active, confirmed trip |
| Reviews and ratings you submit | To display on the platform after a completed hire | When you choose to leave a review |
We do not collect payment card details — all payments go directly to our bank account by transfer, and we never see or store your banking credentials.
Emergency Contact Data — a special note
If you provide an emergency contact's name and phone number, please make sure that person has agreed to be listed. We will only ever use their details to send them an automated alert if you personally trigger the SOS button during an active trip — never for marketing, never shared with any other party, and never used for any other purpose.
Emergency contact details and live GPS location captured during an SOS event are not formally listed as “sensitive personal data” under the NDPA's own statutory definition (which centers on categories like health, biometric, and genetic data) — but given how safety-critical this data is, we choose to handle it with the same heightened care as if it were, regardless of what the law strictly requires.
Lawful basis for processing
We process your personal data on these grounds, as required by the NDPA:
- Performance of a contract — processing your booking, payment, and trip details is necessary to provide the hire or sale you've requested.
- Protection of vital interests — SOS location and emergency-contact data is processed to protect your safety or another person's safety during an emergency; this is not something we ask you to separately “consent” to in the moment, since a genuine emergency cannot depend on a consent prompt.
- Legitimate interest — for basic fraud prevention on payment verification (e.g., flagging a duplicate payment screenshot).
- Consent — for anything not covered above (e.g., voluntary trip-sharing), which you can withdraw at any time as easily as you gave it.
How long we keep your data
The NDPA does not set one fixed retention period for every kind of data — instead it requires that we only keep personal data for as long as it's actually necessary for the purpose we collected it for (“storage limitation”). Here's how that applies to each kind of data we hold:
- Payment records (proof of payment, booking amounts): kept for 7 years, in line with standard Nigerian business tax and accounting record-keeping practice. This applies even if you delete your account.
- SOS emergency event records: kept indefinitely and never deleted, even on request — these are safety incident records.
- Live trip-sharing links: automatically stop working at the end of your booking window, and the underlying location history is deleted within 30 days.
- General account data (name, email, saved preferences): kept while your account is active. If inactive for 24 months, we review it for deletion or anonymization, subject to the exceptions above.
Your rights
Under the NDPA, you have the right to:
- Access the personal data we hold about you — your booking history and receipts are already available in your account at any time.
- Correct inaccurate data — update your phone, email, or emergency contact directly in your account.
- Request deletion (“right to be forgotten”) of your account and general profile data, where we're not required to keep it for another lawful reason.
- Object to processing you disagree with, and withdraw consent at any time for anything based on consent.
- Ask questions about how your data is used, or exercise any of the above — contact us at olarindeg7@gmail.com.
If you believe we've mishandled your data, you also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Who we share data with
- Drivers see the pickup location, your name, and phone number for bookings assigned to them — nothing more.
- Resend processes the content of notification emails we send you as our messaging provider. We do not send automated WhatsApp messages — a WhatsApp link on our site simply opens a normal chat with us on your own device.
- Cloudinary stores uploaded images (car photos, payment proof) on our behalf.
- Supabase and Neon provide our authentication and database infrastructure.
- We do not sell your data to anyone, ever.
International data transfer: some providers above host infrastructure outside Nigeria. The NDPA restricts transferring personal data outside Nigeria unless adequate safeguards are in place. We rely on the contractual data-protection safeguards each provider offers as part of their standard commercial terms.
If something goes wrong
If we ever experience a data breach that could put your rights or safety at risk, we are required by the NDPA to notify the NDPC within 72 hours of becoming aware of it, and to notify you directly, without undue delay, if the risk to you is high.