1. Introduction and scope
This Privacy Policy explains how Trackboria LTD, a limited liability company incorporated in the Federal Republic of Nigeria ("Trackboria", "we", "us", or "our"), collects, uses, stores, shares, and protects information in connection with the Trackboria delivery operations platform (the "Service"). It should be read together with our Terms and Conditions.
This Policy applies to people who use Trackboria directly (merchant administrators and staff, and agents using the mobile app) and to people whose delivery information appears within a merchant workspace, including customers and recipients who open a public tracking link.
Trackboria LTD has its registered office at No. 9B Tinubu Road, Ilupeju, Lagos, Nigeria.
2. Our role: controller and processor
For account, billing, security, website, and platform administration data, Trackboria acts as the controller and processes information for its own operational purposes.
For merchant workspace data (such as customer records, delivery addresses, order details, and rider activity), Trackboria generally acts as a processor, handling that information on the merchant's behalf and on its documented instructions. The merchant is the controller of that information and is responsible for its lawful collection and use.
For rider identity verification, Trackboria acts as the controller. We decide that a check is required before an independent rider can join the rider network, and we decide what is done with the result. Smile Identity, Inc. ("Smile ID") carries out that check for us under the data protection terms of our agreement with it. Smile ID's own handling of the information it collects during a check is governed by that agreement and by Smile ID's own privacy notice.
3. Information we collect and why
We believe you should know exactly what information the Service processes and the reason for each category. The list below describes the information collected through normal use of Trackboria and mirrors the transparency section of our Terms and Conditions.
- Account and identity information: names, work email addresses, phone numbers, sign-in credentials, assigned roles, and account type, used to create and secure accounts, authenticate users, and apply role-based access.
- Business and merchant profile information: legal and trading name, country, timezone, currency, and billing and operations contact details, used to provision the workspace and issue accurate billing.
- Settlement and payout details: settlement bank name, account number, account name, and payment-provider subaccount identifiers, used so the payment provider settles online payments into the correct merchant's own account. Cash on delivery is handed by the rider straight to the merchant and is never routed by us.
- Customer and recipient information: names, phone numbers, email addresses, delivery addresses, landmarks, zones, postal codes, and access notes, used to plan, carry out, and confirm deliveries and to keep recipients informed.
- Order and shipment records: order references, item details, declared values, COD amounts, delivery notes, shipment states, and timeline events, used to manage the delivery lifecycle and calculate amounts due.
- Location and tracking data: precise GPS coordinates, accuracy, speed, bearing, and timestamps from agent devices and shipment updates, used to provide live tracking, route oversight, and location evidence for completed deliveries. The rider app collects an agent's precise location only while they are signed in and working an active delivery, and it continues to collect location in the background during that delivery (including when the app is minimised or the phone is locked) so customers see an accurate live ETA and dispatch can route the next job. Background location collection stops automatically as soon as the delivery is completed or cancelled, and riders can turn it off at any time through their device settings.
- Proof-of-delivery evidence: recipient confirmation details, delivery OTP verification, captured signatures or photographs, and the location and device used at capture, used to confirm deliveries, resolve disputes, and reduce fraud.
- Rider identity verification: before an independent rider can be found or booked by a business on the Trackboria network, that rider completes an identity check with Smile ID, our identity verification provider. The rider presents a government-issued identity document and a facial image, both of which are captured by Smile ID's software and sent directly to Smile ID. They do not pass through Trackboria and are not stored on our systems. Smile ID returns to us the result of the check, the date it was completed, the type of document presented, the country that issued it, and a reference identifying the check.
- Payment and billing information: plan selection, invoices, balances, payment attempts and references, and limited card metadata such as card brand and the last four digits returned by the payment provider, used to process payments and reconcile accounts. Complete card numbers are handled by the payment provider and are not stored by Trackboria.
- Device, session, and security information: IP addresses, browser and user-agent details, device identifiers, login timestamps, and session and refresh-token records, used to keep sessions secure and detect unauthorised access.
- Communications and notifications: email, SMS, WhatsApp, push, and webhook messages sent through the Service and their delivery status, used to send operational updates and confirm they were received.
- Audit, fraud, and compliance records: audit logs of significant actions (including the actor, IP address, and before-and-after values), fraud flags, and dispute records, used to maintain accountability, investigate abuse, and meet legal obligations.
- Referral and affiliate data: if you take part in our referral or affiliate program, we process your name, contact details, the merchants attributed to your referral code, and the payout details you provide (such as your mobile-money or bank account), used to track referrals, calculate commissions, and pay you. Payout details are used only to make payments to you.
4. How we use information
We use the information described above to:
- Create and manage merchant workspaces and user accounts
- Authenticate users, keep sessions secure, and prevent fraud or misuse
- Run delivery workflows, assign riders, show live tracking, and record delivery events
- Manage COD verification and cash reconciliation, billing cycles, invoices, and payment follow-up
- Send operational notifications by email, SMS, WhatsApp, push, or webhook where configured
- Store, retrieve, and secure proof-of-delivery media and related delivery evidence
- Investigate disputes, support issues, delivery exceptions, and security incidents
- Improve service reliability, maintain audit trails, and comply with legal and tax obligations
5. How we share information
We share information only where it is needed to operate the Service or where the law requires it. Depending on the workflow, that can include:
- The merchant and authorised users within that merchant's workspace
- Agents, partner couriers, and delivery operators involved in a shipment
- Recipients who receive a valid public tracking link
- Payment providers such as Paystack and Flutterwave when a payment is initiated
- Infrastructure providers used for hosting, storage, notifications, maps, and delivery media access
- Smile ID, our identity verification provider, when an independent rider completes an identity check to join the rider network
- Termii, our SMS provider, when a one-time code, a tracking link or an order update is sent by text message
- Law enforcement, regulators, or other third parties where disclosure is legally required
We do not sell personal information.
6. International data transfers
Some service providers may process information outside the country where a merchant or recipient is located. Where that happens, we take reasonable steps to ensure those providers apply appropriate security and confidentiality measures consistent with this Policy and applicable law.
Smile ID is established in the United States, and rider identity checks are processed there. That transfer is governed by the data protection terms of our agreement with Smile ID, which require it to apply security and confidentiality measures consistent with this Policy.
7. Data retention
We keep information for as long as it is needed to operate the workspace, maintain billing and audit records, investigate disputes or fraud, enforce our Terms and Conditions, and meet legal or tax obligations. Retention periods vary by the type of record and the reason it is held.
When information is no longer required for these purposes, we take reasonable steps to delete it or render it anonymous.
Rider identity documents are not retained by Trackboria. The identity document and facial image submitted for a verification check are captured and held by Smile ID and are never stored on Trackboria's systems. We retain only the result of the check, the date it was completed, the type of document presented, the country that issued it, and Smile ID's reference for the check. We keep that record for as long as the rider remains available for booking on the Trackboria network, and afterwards for as long as we need it to resolve a dispute or to meet a legal, tax, or regulatory obligation. The reference allows a completed check to be traced back to Smile ID if it is ever questioned, without any identity document being held by Trackboria or shown to a business on the platform.
8. How we protect information
We use access controls, role-based permissions, token-based access, session records, hashed refresh tokens, and private media access controls to reduce the risk of unauthorised access. We restrict access to information so that it is scoped to the users and workflows that genuinely require it.
No system can be guaranteed completely secure, but the Service is designed to limit exposure and to support prompt investigation of any security incident.
9. Your rights and choices
Depending on the laws that apply to you, you may have the right to access, correct, delete, or restrict the use of personal information, or to object to certain processing.
Merchant users can review and update account information within their workspace, and merchants control most customer, order, and delivery records held in their workspace. If you are a customer or recipient and wish to correct, delete, or ask questions about delivery information connected to your order, please contact the merchant that sent the order first, as they control that information.
For requests relating to Trackboria's own account, billing, or security records, submit a request through the Help & Support form at trackboria.com/help, or email info@trackboria.com.
10. Cross-border shipments and international transfers
When a shipment crosses a border, the information needed to move it and to clear it must be shared outside the country it started in. This section explains what is shared, with whom, and why.
Who receives shipment information
For a cross-border shipment we share only what each party needs to perform its role:
- Carriers and their local agents in the origin, transit, and destination countries receive the recipient name, delivery address, contact number, parcel details, and the reference needed to move and deliver the shipment.
- The customs broker or other filing party appointed for the shipment receives the goods description, declared value, tariff classification, country of origin, the parties named on the shipment, and the supporting documents. This is the party that lodges the declaration. Trackboria does not lodge it.
- Customs authorities and border agencies receive the declaration and its supporting documents from the filing party, and may inspect a shipment and request further information at any point.
International transfers
A cross-border shipment cannot be completed without transferring personal data to the destination country, and in some cases to transit countries. The countries involved are determined by the route you select, and some of them do not provide a level of data protection equivalent to the country the data came from. Where we are able to impose terms, we use contractual data protection terms with the carriers and processors we appoint. We cannot impose terms on a customs authority or a border agency acting under its own legal powers, and disclosure to those authorities is required by law.
Shared document links
The platform can generate an expiring link that lets a broker, a carrier, or a border officer view a shipment's documents without holding an account. Every link expires, can be revoked by the merchant at any time, and records each time it is opened, together with a hashed form of the network address it was opened from. We hash rather than store the address so that repeat access can be identified without keeping the address of an individual officer.
Retention of customs records
Customs and trade records are retained for the period required by the customs legislation of the countries involved, which commonly ranges from five to ten years and in some markets is longer. Where that period exceeds our standard retention period, the customs record is kept for the longer period, because we are required to be able to produce it.
11. Service providers that process information for us
We use other companies to run parts of the Service. They process information only on our instructions, only for the purpose we engaged them for, and under written terms that require them to protect it. These are the categories we rely on:
- Cloud hosting, databases, and backups, which is where the Service and its data physically run.
- Payment providers, which process card and transfer payments and hold the transaction records that go with them. Full card numbers are handled by the provider and are not stored by us.
- Messaging providers, which deliver the SMS, email, WhatsApp and push notifications you and your customers receive, including one-time codes and tracking links.
- Carriers, partner couriers and, where one is appointed, customs brokers, which receive the shipment and recipient details needed to collect, carry, clear and deliver a parcel.
- Identity and document verification providers, used to verify riders and, where required, merchant business details.
- Mapping and geocoding providers, used to turn an address into a location and to plan and display routes.
- Support, analytics and error-reporting tools, used to answer tickets and to find and fix faults in the Service.
We assess a provider before we engage it, limit it to the data it needs, and require it to delete or return that data when the engagement ends. A provider is not permitted to use the information for its own purposes or to sell it.
A current list of the specific providers we use, with the countries they process in, is available to merchants on request through support. We publish it that way rather than in this page so that the list you receive is the one in force on the day you ask.
12. Making a privacy request, and country-specific notices
This section sets out how to exercise the rights described above, what we will do, and how long it takes.
Who to ask first
For customer, order and delivery records, the merchant whose workspace holds them is the controller and we act on their instructions. Send your request to that merchant first. If you do not know which merchant holds your record, or the merchant does not respond, contact us and we will identify the workspace and pass the request on, or act on it ourselves where we are the controller. For account, billing, security and audit records we hold in our own right, we are the controller and you can come to us directly.
How to make a request, and what happens next
Submit a request through the Help and Support form or by email to info@trackboria.com. We will acknowledge it within seven (7) days and respond substantively within thirty (30) days. Where a request is complex or we have received several from you, we may extend that once by a further thirty (30) days and will tell you why before the first period ends. We will ask you for enough information to confirm your identity before we act, because disclosing or deleting a record for someone who is not its subject is itself a breach. There is no charge, unless a request is manifestly unfounded or repetitive, in which case we will tell you the charge before doing the work. If we refuse a request in whole or in part, we will tell you the reason and how to challenge it.
Country-specific notices
Where you are in Nigeria, the Nigeria Data Protection Act 2023 applies and the Nigeria Data Protection Commission is the supervisory authority. Where you are in Ghana, the Data Protection Act 2012 applies and the Data Protection Commission is the supervisory authority. Where you are in Kenya, the Data Protection Act 2019 applies and the Office of the Data Protection Commissioner is the supervisory authority. Where you are in South Africa, the Protection of Personal Information Act 2013 applies and the Information Regulator is the supervisory authority. Where you are in the European Union, the European Economic Area or the United Kingdom, the General Data Protection Regulation or the UK GDPR applies and you may complain to the supervisory authority in your country of residence. Nothing in this notice limits a right you have under the law that applies to you.
If you are not satisfied with how we have handled a request, tell us first so we can put it right. You may also complain to the supervisory authority named above for your country at any time, and you do not have to come to us first.
13. Browser storage and website data
The web app stores sign-in tokens in browser storage on the device used to sign in, so the workspace can remain authenticated between requests. Public pages, including the marketing site and public tracking pages, may generate server logs when they are opened.
Where map features are enabled, map providers may process device and location-related information under their own policies.
14. Children
The Service is intended for businesses and the people who operate them. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 years of age.
15. Changes to this notice
We may update this Policy as the product, our practices, or legal requirements change. When we make a material change, we will revise the "Last updated" date shown above and, where appropriate, communicate the update within the product or through the merchant account contact on file.
16. Contact
For privacy questions about Trackboria's platform records, use the Help & Support form at trackboria.com/help or contact info@trackboria.com, or write to Trackboria LTD, No. 9B Tinubu Road, Ilupeju, Lagos, Nigeria.
