Privacy Policy
Effective date: 3 April 2026 · Last updated: 13 August 2026
This Privacy Policy describes how GetLift (“we”, “us”, or “our”) collects, uses, stores, and shares personal information when you use the GetLift mobile application, related websites (including this site), and our services (collectively, the “Services”). GetLift operates a technology platform connecting riders, drivers, and transport operators for inter-city and related travel, primarily in Nigeria.
1. Who is responsible?
The GetLift service is operated by VendPlug (Nigeria). Website: https://getlift.ng/. For privacy-related requests you may contact us at support@getlift.ng or +234 803 886 1283, or use the in-app support flow where available.
2. Information we collect
Depending on how you use GetLift, we may collect:
- Account and contact data: phone number (often in E.164 format), OTP verification events, and optional profile details such as display name or email if you provide them.
- Identity and vehicle data (drivers): information and documents submitted for KYC (e.g. NIN, licence details, vehicle information, photographs) as required to operate safely and comply with our rules.
- Optional rider identity data: if you choose to verify your rider profile, a selfie and a government-issued ID photograph (for example NIN slip, driver’s licence, national ID, passport, or voter’s card). This is not required to book. Images are reviewed by GetLift staff; we do not use automated third-party NIN APIs for optional rider verification.
- Operator verification data: company documents, fleet photographs, and related records submitted so a transport company can list public-line trips.
- Trip and booking data: routes, schedules, seat selections, prices and fee breakdowns as shown in the product, preset house-rule codes, booking status, trip-start confirmation answers, arrival or completion signals, ratings, and messages needed to run trips.
- Share and flyer data: when someone opens a public trip link or a trip flyer image, we may record that the page or poster was requested, whether the request looks like a social-app preview crawler, and an optional short source tag (for example driver, rider, or admin). Public URLs do not include your account id.
- Passenger and safety data (where applicable): when you book a trip we may collect passenger name, address, and next-of-kin name and phone (and for certain operator-run “public line” trips also passenger phone and related notes) for identification, meeting coordination, manifests, and passenger safety. For public-line bookings you will be asked to agree before we use that data for the trip. For private cost-share bookings these fields are required to complete the booking and are shared with the driver for that trip and with GetLift support where needed.
- Payment data: wallet top-ups and payouts are processed by payment partners (e.g. Paystack). We do not store your full card number on GetLift servers; we receive tokens, references, and transaction status needed to operate wallets and ledgers.
- Technical data: device type, app version, push notification tokens, IP address, and logs used for security, fraud prevention, and reliability.
- Communications: messages you send to support, dispute notes, and records needed to resolve incidents.
- Safety and risk signals: account risk flags, optional rider verification state, incident outcomes, and related internal notes used to protect users on the platform.
3. How we use information
We use personal data to:
- create and secure accounts (including OTP and SMS from providers such as Termii or others we configure);
- match riders and drivers, display trips, and operate bookings and escrow;
- show house rules, ratings, and trip details on listings, share pages, and flyers;
- generate public trip posters and link-preview images so a WhatsApp or Instagram post can fill seats;
- measure which shared trips are opened (so we can tell which flyers are worth making);
- send service notifications, including asking a rider whether a private trip started;
- verify drivers, vehicles, and operator companies where required;
- review optional rider identity submissions and show a Verified badge to drivers when approved;
- share necessary booking or manifest details with drivers, operators, or crew where the product requires it;
- process payments, settlements, refunds, and chargebacks in line with our Terms;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and respond to lawful requests;
- improve the Services and communicate service-related notices.
4. SMS and OTP
By providing your phone number, you agree to receive automated OTP and service messages as needed to verify your identity and protect your account. Message frequency varies. Message and data rates may apply depending on your carrier. You can contact support if you need help managing verification.
5. Sharing
We may share information with:
- Other users where needed to perform a trip (e.g. driver/rider contact or trip details).
- Operators you book with, including manifest fields where applicable and where you have consented.
- Service providers who host infrastructure, deliver notifications, process payments, or help us detect fraud — under appropriate contracts and safeguards.
- Authorities when required by law or to protect rights, safety, and security.
Public trip pages and flyers are public by design. A shareable listing may show route, fare, seats left, pickup label, house rules, and (where the product shows them) driver or company name, vehicle, and ratings. Anyone with the link — including people without the app — can see that page or image. Do not put information in a listing that you are not willing to share that widely.
We do not sell your personal information.
6. Retention
We keep data only as long as needed for the purposes above, including legal, tax, and accounting requirements, dispute resolution, and fraud prevention. Some records may be retained longer where the law requires.
7. Security
We use administrative, technical, and organisational measures designed to protect personal data. No method of transmission or storage is 100% secure; we encourage strong device security and prompt reporting of suspicious activity.
8. Your rights
Depending on applicable law (including the Nigeria Data Protection Act where it applies), you may have rights to access, correct, delete, or restrict processing of your personal data, or to object to certain processing. You may also have the right to lodge a complaint with a supervisory authority. To exercise rights, contact us through support in the app or the contact channel we publish for your region.
9. International transfers
Our service providers may process data in Nigeria and other countries. Where we transfer personal data, we take steps designed to ensure appropriate safeguards consistent with applicable law.
10. Children
GetLift is not directed at children under the minimum age required to enter a binding contract in your jurisdiction. We do not knowingly collect personal information from children.
11. Push notifications
If you allow notifications, we may send service messages such as booking updates, payout status, dispute notices, and the private-trip prompt “Did your trip start?”. You can disable notifications in your device settings; some account and security messages may still be delivered by SMS.
12. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and adjust the “Last updated” date. Continued use of the Services after changes means you accept the updated policy, except where your consent is required for material changes under applicable law.
13. Contact
Website: https://getlift.ng/. Operator: VendPlug. Address: Jos, Nigeria. Phone: +234 803 886 1283. Email: support@getlift.ng. You can also use the in-app support flow in the GetLift application where available.
This document is provided for transparency and does not constitute legal advice. You should have it reviewed by qualified counsel for your business and jurisdiction.