Zendrun
Legal · v0.1 draft · 7 September 2026

Privacy Policy

What we collect, why, who sees it, how long we keep it, and your rights under the Nigeria Data Protection Act 2023.

Draft
Written for the prototype so the product and the terms say the same thing. It is not legal advice and has not been reviewed by a Nigerian lawyer. Review before launch, particularly the NDPA, CBN and consumer-protection parts.

1. Who is responsible

Zendrun Technologies Ltd (in formation), Lagos, is the data controller. Our data protection contact is privacy@zendrun.com. We are registering with the Nigeria Data Protection Commission as a data controller of major importance where the thresholds apply.

2. What we collect

  • Account: name, phone number, verified backup email, handle, areas, transport, task types, availability, photo, bio.
  • Optional, private attributes: gender and religion, if you choose to declare them. Never shown on your profile, never searchable, never used for ranking. Used only to decide whether you can accept an errand whose requester asked for a runner of that gender (privacy) or religion (religious materials). You can clear them any time.
  • Identity verification: your NIN, BVN, ID images, liveness video, proof of address, guarantor details, and the results returned by our verification providers. Sensitive; processed only for verification and fraud prevention.
  • Money: wallet ledger, escrow holds, payouts, bank account details, transaction references from our payment partner.
  • Errands: briefs, review outcomes, check-ins and their evidence: photos, receipts, timestamps, GPS positions at check-in, handover codes, in-app messages, ratings, disputes.
  • Device and usage: device identifiers, app version, IP address, crash logs, pages used. Location is collected only during an active errand for check-ins, never in the background outside one.

3. Why, and the legal basis

  • Running the marketplace, escrow and payouts: performance of our contract with you.
  • Identity verification, fraud prevention, dispute resolution: legal obligation (AML and KYC rules) and our legitimate interest in a safe marketplace.
  • Staff review of errands and bios: performance of the contract and legitimate interest. Zendrun staff read the brief, your answers to the checks, attachments and reports; they do not read your messages or identity documents. A take-down can be appealed within 7 days.
  • Notifications about your errands: performance of the contract. Product news: consent, which you can withdraw in account settings.
  • Analytics and improvement: legitimate interest, using aggregated or pseudonymised data where possible.

4. Who sees what

Other users. Your public runner page shows your name, photo, handle, tier, rating and counts, areas, task types, transport, availability and gear. It never shows your number, email, ID numbers, bank details, address or the errands you did for whom. A requester and runner on the same errand see each other's name and photo and can message in-app; contact details are not exchanged by us.

Providers. Verification providers (currently Smile ID or Dojah) for NIN, BVN and liveness checks; payment partners (Paystack or Flutterwave) for wallets and payouts; email and push providers, and a one-time-code provider used once to confirm the phone number; cloud hosting; the AI provider that runs errand review, which receives briefs and review context but no identity documents. Each acts under contract and only for the purpose we set.

Authorities. Where the law requires, or to establish or defend legal claims. We tell you unless prohibited.

We do not sell personal data.

5. How long we keep it

  • Account data: while the account is open, then 90 days.
  • Check-in evidence (photos, receipts, locations): 180 days after settlement, or until a dispute is closed, then deleted.
  • Identity verification records: 5 years after the account closes, as anti-money-laundering rules require.
  • Financial ledger: 6 years, as tax and financial-records rules require.
  • Messages: 7 days after the errand settles, longer while a dispute is open, then deleted.

6. Your rights

Under the NDPA you can ask to access, correct, delete, or receive a copy of your data, object to or restrict processing, and withdraw consent where consent is the basis. Most of this is self-service in account settings; the rest by email to privacy@zendrun.com. We answer within 30 days. Deletion is subject to the retention rules above and to having no open errands, nothing fronted and nothing in escrow. You can complain to the Nigeria Data Protection Commission.

7. Security

Encryption in transit and at rest, access limited by role and logged, identity documents stored separately from the main database with stricter access, and no passwords to steal: login is by one-time code to your verified phone or email. If a breach is likely to harm you we notify you and the Commission within 72 hours of becoming aware.

8. Where data goes

Our servers and some providers are outside Nigeria. Transfers rely on the recipient country's adequacy, contractual safeguards, or your consent where required by the NDPA.

9. Children

Zendrun is for adults. We do not knowingly collect data from anyone under 18; accounts found to belong to minors are closed and their data deleted.

10. Changes

We announce changes in-app and by email 14 days before they take effect. This version: 0.1 draft, 7 September 2026.

Zendrun Technologies Ltd (in formation) · questions to legal@zendrun.com. Changes are announced in-app and by email 14 days before they take effect, except where the law requires sooner.