Your data, respected
Privacy, with
nothing hidden.
This policy explains how RITZ URBAN LUXURY LIMITED handles personal data when you use the Ritz rider application, the Ritz Driver application, our website, and the mobility, ride-hailing, vehicle-hire, support, and related services made available through them.
1. Scope and data controller
RITZ URBAN LUXURY LIMITED (RC 1994458), referred to in this policy as “Ritz”, “we”, “us”, or “our”, is the data controller responsible for the personal data described here. Our registered contact address is No. 50, Ebitu Ukiwe Street, Jabi, Abuja, Federal Capital Territory, Nigeria.
This policy applies to riders, drivers, fleet owners, vehicle owners, applicants, website visitors, and anyone who contacts or otherwise interacts with Ritz. The services are presently offered in Nigeria and this policy is intended to reflect the Nigeria Data Protection Act 2023 and other applicable Nigerian requirements.
2. Personal data we collect
Data relating to all app users
- Account and contact data: name, telephone number, email address, profile photograph, city, account preferences, login method, and identifiers connected with Google or Apple sign-in where used.
- Verification and authentication data: one-time-password records, authentication tokens, password hashes, login activity, and information used to verify that an account belongs to you.
- Location and journey data: current or last-known location, pickup and destination coordinates and addresses, stops, routes, distance, estimated arrival information, and trip timestamps.
- Transaction data: fares, payment method, wallet balance, payment status, transaction references, refunds, caution deposits, insurance charges, and hire or booking information.
- Communications and feedback: in-app messages between riders and drivers, support requests, ratings, review comments, cancellation reasons, and safety reports.
- Device and technical data: device and operating-system information, app version, push-notification token, IP address and network information, usage events, crash reports, diagnostic logs, and sampled diagnostic session-replay data.
Additional rider data
We process ride requests, saved or selected places, service and vehicle preferences, ride and vehicle-hire history, the identity of assigned drivers, and the information needed to calculate and complete fares, bookings, refunds, ratings, and support requests.
Additional driver and fleet data
- Identity and eligibility: full name, address, city, photograph or selfie, driver’s licence image, licence number and expiry date, government-issued identity or other due-diligence information, languages, referral information, and verification status.
- Vehicle and fleet information: vehicle make, model, year, colour, registration or licence plate, seating capacity, interior and exterior photographs, vehicle specifications, ownership or fleet details, insurance and other eligibility documents.
- Business and payout information: bank name, account number, account-holder name, billing type, company name, registration code, VAT status and number, fleet size, earnings, commission, and settlement information.
- Work and performance information: online and offline status, availability, ride offers, acceptance and cancellation activity, journey completion, driver score, ratings, earnings, working sessions, and safety or fraud indicators.
Where device biometric authentication is enabled, the fingerprint or facial template is handled by your device’s operating system. Ritz receives only the authentication result, not the biometric template.
3. How we collect personal data
We collect data:
- directly from you when you register, complete a profile, upload documents, request a trip, make a payment, communicate, or contact support;
- automatically from your device when you use the apps, permit location access, receive notifications, or encounter an error;
- from riders, drivers, fleet owners, vehicle owners, and other people involved in a trip or safety report;
- from payment, identity, mapping, authentication, communications, analytics, cloud, and fraud-prevention providers; and
- from lawful public records, regulators, law-enforcement bodies, or other sources where verification or law requires it.
4. How and why we use personal data
Create and secure accounts; connect riders and drivers; arrange trips and hires; calculate fares and routes; process payments, refunds and earnings; and provide support. We generally rely on the performance of our contract with you.
Verify drivers, vehicles and payments; authenticate users; investigate incidents; protect users and the public; enforce our terms; and detect misuse. We rely on contract, legal obligations, vital interests, and our legitimate interests in operating a safe platform.
Monitor reliability, diagnose errors, understand feature usage, measure performance, develop services, and maintain app security. We rely on legitimate interests, while considering your rights and reasonable expectations.
Send OTPs, trip updates, payment confirmations, safety messages, service notices, support responses, and push notifications. We rely on contract, legitimate interests, legal obligations, or consent, depending on the message.
Maintain appropriate financial and operational records, respond to lawful requests, resolve disputes, protect legal claims, and meet tax, corporate, safety, and regulatory duties.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already performed lawfully, and some app features may no longer work without the relevant permission.
5. Location data
Location is central to matching, pickup, navigation, live trip progress, safety, fare and distance calculation, and nearby vehicle availability. The Ritz app uses foreground location to establish a rider’s position and selected journey points. Ritz Driver may collect precise location while a driver is online or completing a trip and, with device permission, in the background during an active trip.
A driver’s relevant live location is shared with the assigned rider, and pickup and destination information is shared with the assigned driver. Location may also be processed by Google Maps and related mapping services. You can change device permissions at any time, but disabling location may prevent ride and driver functions from working.
6. Payments and financial data
Payments may be initiated inside the apps and are processed through Paystack. Paystack receives the payment details required to complete and secure a transaction under its own privacy terms. Ritz does not store your complete card number, PIN, or card security code.
To support saved payment methods and repeat charges, we may retain a Paystack authorization token together with limited card metadata such as cardholder name, email, provider, brand, last four digits, and expiry month and year. We also retain transaction references, amounts, payment status, refunds, wallet activity, and driver payout details.
7. Matching, pricing and automated decisions
Ritz uses automated systems and rules to support driver matching, route and arrival estimates, pricing, driver scores, service quality, payment and fraud checks, safety monitoring, and account or trip restrictions. These systems may consider location, availability, journey history, ratings, cancellations, account activity, device signals, and payment outcomes.
If a decision has a significant effect on you, you may contact us to request an explanation, correct inaccurate information, express your view, and ask for appropriate human review, subject to applicable law.
8. When personal data is disclosed
We disclose only what is reasonably necessary to:
- Riders and drivers: enable matching, identification, pickup, communication, trip progress, safety, ratings, and completion of a journey.
- Fleet or vehicle owners: administer drivers, vehicles, bookings, compliance, earnings, and fleet operations where an account is connected to a fleet.
- Service providers: process payments through Paystack; provide maps, places, routes, and sign-in through Google; provide Apple sign-in; store uploaded images through Cloudinary; deliver push notifications through Firebase and Expo; deliver OTPs through Termii; deliver operational email through Resend or SendGrid; analyse product usage through PostHog; monitor errors and sampled diagnostic sessions through Sentry; and provide hosting, database, security, and communications infrastructure.
- Safety and legal recipients: respond to emergencies, protect a person’s vital interests, investigate fraud or incidents, enforce agreements, comply with court orders or lawful government requests, and cooperate with regulators and law enforcement.
- Professional and corporate recipients: obtain confidential legal, audit, insurance, or professional advice, or complete a genuine financing, restructuring, merger, acquisition, or transfer subject to appropriate safeguards.
We do not sell personal data. We do not disclose personal data to third parties for their independent advertising, and the apps do not integrate third-party advertising networks.
9. International processing
Some technology providers operate infrastructure outside Nigeria, so personal data may be processed in other countries. Where required, we use contractual, organisational, and technical safeguards and take reasonable steps to ensure that an overseas recipient provides an adequate level of protection consistent with applicable Nigerian law.
10. How long we retain data
We keep personal data while your account is active and for as long as it is needed for the purposes described in this policy. As a general standard, data that is no longer required will be deleted or anonymised within one year after account closure or the end of the relevant service relationship.
Certain records may be kept for longer where reasonably necessary for tax, accounting, payment reconciliation, safety, fraud prevention, dispute resolution, legal claims, regulatory compliance, or a lawful preservation request. We may retain de-identified or aggregated data that can no longer reasonably identify you.
11. How we protect personal data
We use reasonable technical and organisational safeguards designed to protect personal data, including access controls, authentication, encryption in transit where supported, restricted administrative access, monitoring, backups, and service-provider controls. No digital service can guarantee absolute security. Please protect your device, OTPs, passwords, and account credentials and notify us promptly if you suspect unauthorised access.
12. Your privacy rights
Subject to applicable law and appropriate identity verification, you may:
- ask whether we process your personal data and request access to it;
- ask us to correct incomplete or inaccurate information;
- request deletion or restriction where the legal conditions apply;
- object to processing, including processing based on legitimate interests;
- withdraw consent without affecting earlier lawful processing;
- request portable data where applicable;
- request human involvement in a significant automated decision; and
- lodge a complaint with the Nigeria Data Protection Commission.
To exercise a right, email support@ritzurbanluxury.com. We may ask for information reasonably necessary to verify your identity and protect another person’s privacy. We will respond within the period required by applicable law.
13. Account and data deletion
You may request deletion of your Ritz or Ritz Driver account and the personal data associated with it through the account settings in the applicable app. If you cannot access your account, email us at support@ritzurbanluxury.com. Deactivation alone is not treated as deletion.
After verifying the request, we will delete or de-identify account data that we are not required to retain. Limited transaction, safety, fraud, dispute, or regulatory records may remain for the reasons and periods explained in the retention section. We will also instruct relevant processors to delete data where required and technically applicable.
14. Push notifications and preferences
With your permission, we send push notifications for ride requests and progress, payments, safety, service updates, and other relevant app activity. You can control push notifications in your device settings. Essential information may still be presented inside the apps when you use them. We do not use SMS or email for promotional marketing; those channels may still be used for authentication, receipts, account security, support, or legally required notices.
15. Age requirement
Ritz and Ritz Driver are intended only for people aged 18 or older. We do not knowingly create accounts for children. If you believe a person under 18 has provided personal data, contact us so we can investigate and take appropriate action.
16. Changes to this policy
We may update this policy when our services, providers, or legal duties change. We will publish the revised policy here with a new “last updated” date and provide additional notice through the apps or another appropriate channel when a change is material.
17. Contact and complaints
RITZ URBAN LUXURY LIMITEDRC 1994458
No. 50, Ebitu Ukiwe Street
Jabi, Abuja, FCT, Nigeria
Email: support@ritzurbanluxury.com
Please contact us first so we can address your concern. You also have the right to complain to the Nigeria Data Protection Commission through its official channels at ndpc.gov.ng.