GoGo

Privacy Policy

Last Updated: 27 September 2026

Erste Graceland Limited (RC 440057; TIN 01875023-0001) operates GoGo from its registered office at No. 10 Oduyemi Street, Awolowo Way, opposite Ikeja Government Headquarters, Ikeja, Lagos, Nigeria. We are dedicated to respecting and safeguarding your personal data. This Privacy Policy outlines how we collect, use, process, disclose, and protect your information when you visit our website or use our mobile application (collectively, the "Platform").

By accessing or using the Platform, you acknowledge and agree to the data handling practices described in this policy, designed strictly in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR).

1. Information We Collect

We may collect and process information about you in several ways to operate, secure, and improve our services:

  • Personal Data: Your name, phone number, and email address provided during account registration and profile setup.
  • Identity & KYC Data: Your Bank Verification Number (BVN) and/or National Identity Number (NIN), date of birth, and a selfie/face image for identity verification and liveness checks required to satisfy Know Your Customer (KYC) and Anti-Money Laundering (AML) legal obligations.
  • Camera & Microphone: Accessed only when you explicitly initiate or answer an audio/video call or capture a KYC selfie for identity verification. In audio/video calls, the camera is off by default and can only be activated by you. Calls are peer-to-peer (P2P) and are never recorded or stored on our servers.
  • Chat Messages & Call History: In-app chat messages, media sent within buyer–seller chats, and call history logs (timestamps, call status, and participants).
  • Transaction & Wallet Data: Details of payments, top-ups, transfers, withdrawals, marketplace transactions, food orders, and savings activity within the GoGo Wallet.
  • Location Data: Approximate or precise location data collected strictly with your explicit device permission, only when you browse nearby sellers, go through delivery checkout or, as a seller, set the location of your shop.
  • Shopping & Browsing Activity: When you are signed in to GoGoDrop on the web or in the app, the products you view, save, search, and browse to support order fulfillment and personalized recommendations.
  • Device & Diagnostics Data: Device push tokens (for sending you transaction alerts and notifications) and crash diagnostics to monitor system stability and resolve technical bugs.

2. Age Eligibility (Children)

GoGo is designed and intended strictly for individuals aged 18 and over. We do not knowingly collect, solicit, or process personal data from children or individuals under the age of 18. If we become aware that an account has been registered by or on behalf of a minor, we will promptly terminate the account and take steps to delete any associated personal information.

3. How We Use Your Information

We process your personal information for specific, lawful purposes in accordance with the NDPA 2023:

  • Create, authenticate, and manage your GoGo account.
  • Verify your identity in compliance with Central Bank of Nigeria (CBN) rules and AML/CFT regulations.
  • Process wallet transactions, peer-to-peer transfers, and withdrawals to verified bank accounts.
  • Facilitate buyer–seller communication, marketplace transactions, food orders, and logistics fulfillment.
  • Send transactional notifications, critical security alerts, and system updates via push notifications, SMS, or email.
  • Provide customer support, resolve disputes, and protect users against fraud and unauthorized activity.
  • Fulfill statutory, regulatory, and legal duties under the laws of the Federal Republic of Nigeria.

4. Third-Party Data Processors

We do not sell, rent, or trade your personal data. We only share personal data with trusted third-party processors bound by strict confidentiality and data protection agreements compliant with the NDPA 2023. These partners include:

  • Google: For Google Sign-in authentication, Firebase Cloud Messaging (FCM) for push notifications, and Firebase Crashlytics for crash reports and platform stability diagnostics.
  • Payment Processors: Bachs and Paystack for processing wallet funding, card payments, and bank transfers.
  • Identity Verification Providers: Prembly for validating government identity credentials (BVN, NIN) and facial liveness checks.
  • Call Relay Servers: When two devices cannot connect directly, a call may be relayed through TURN servers we operate. Relayed audio and video stay encrypted end to end and are never recorded, inspected or stored.
  • GoGoDrop Suppliers & Fulfillment Partners: Zendrop and verified suppliers receive recipient names, contact numbers, and delivery addresses solely to package and deliver international goods.
  • Communication Providers: Resend (transactional email) and BulkSMS Nigeria (SMS notifications and one-time verification codes).
  • Logistics Partners: Verified third-party delivery dispatchers for delivering marketplace and food orders.

We may also disclose your data where legally mandated to do so by court order, law enforcement, or statutory regulatory bodies in Nigeria.

5. Data Retention

We retain your personal data only as long as necessary for the legitimate purposes outlined in this policy or as mandated by applicable statutory retention laws:

  • Chat Messages: In-app chat messages between buyers and sellers are retained for 12 months, after which they are permanently deleted.
  • Call History: Call metadata and logs are retained for 12 months, after which they are permanently deleted.
  • GoGoDrop Shopping Activity: Browsing activity and viewed products used for product suggestions are retained for 120 days and automatically cleared thereafter.
  • Financial & KYC Records: Transaction histories, wallet ledgers, and KYC verification records are retained for a minimum of 5 years after account closure to fulfill regulatory obligations mandated by the Central Bank of Nigeria (CBN) and Anti-Money Laundering (AML) laws.

6. Security

We implement rigorous administrative, technical, and physical safeguards to preserve the confidentiality, integrity, and availability of your data:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using modern Transport Layer Security (HTTPS/TLS).
  • Delivery Address Protection: GoGoDrop delivery addresses are encrypted before they are stored in our database.
  • Access Controls: Role-based access controls and internal audit logging limit operational systems to authorized personnel with a legitimate business need, and sensitive actions such as payouts require a one-time code.

7. Account Deletion and Your NDPA Rights

Under the Nigeria Data Protection Act (NDPA) 2023, you have enforceable rights regarding your personal information, including the rights to access, rectify, object to processing, and request erasure of your data.

How to Delete Your Account:

  • In the App: Open the GoGo app, navigate to Profile → Delete account, and follow the verification prompts.
  • On the Web: You can submit an account deletion request online anytime at our dedicated Account Deletion Page (https://gogoapp.com.ng/delete-account).

What is Deleted vs. Retained: Upon initiating account deletion, your profile, active sessions, saved addresses, chat messages, and marketing preferences are deleted or permanently anonymized within 30 days. As required by CBN and AML regulations, financial transaction ledgers and KYC compliance records must be retained for at least 5 years following account closure.

8. Contact Us

If you have questions, comments, or wish to exercise your data rights under the NDPA, please contact our Data Protection team at:

Erste Graceland Limited
Email: info@gogoapp.com.ng
Office: No. 10 Oduyemi Street, Awolowo Way, opposite Ikeja Government Headquarters, Ikeja, Lagos, Nigeria