Privacy Policy
How eGreen collects, uses, shares, and protects your personal data.
Last updated: September 23, 2026
1. Introduction
eGreen ("we", "our", or "us") operates the eGreen mobile application and the eGreen administration portal (together, the "Service"). The Service connects drivers with financed electric and micro-mobility vehicles and lets them manage repayments through an in-app wallet.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. By creating an account or using the Service, you consent to the practices described here.
2. Information We Collect
We collect the following categories of personal data:
- Identity data — your name, Bank Verification Number (BVN), National Identification Number (NIN), driver's licence details, and a selfie photograph used for identity verification.
- Contact data — email address, phone number, and residential address (street, city, state, country).
- Guarantor data — the name, phone number, and BVN of the guarantor ("trustie") you nominate during registration. You must obtain your guarantor's consent before providing their details.
- Location data — GPS coordinates captured during registration and, where enabled, while using vehicle features, plus the address derived from those coordinates.
- Financial data — wallet balance, virtual account details, repayment transactions, and payment history processed through our payment partners.
- Account data — sign-in credentials and identifiers provided by Google or Apple when you use third-party sign-in.
- Device and usage data — device model, operating system, app version, push notification tokens, and how you interact with the Service.
3. How We Use Your Information
We use the data we collect to:
- Create and manage your account and verify your identity (KYC/AML checks).
- Assess eligibility for vehicle financing and administer your contract.
- Provision and operate your payment wallet and virtual account, and process repayments.
- Send service communications — payment reminders, vehicle assignment notices, and security alerts — by SMS, email, and push notification.
- Detect, prevent, and investigate fraud and other prohibited activity.
- Comply with legal and regulatory obligations, and improve the Service.
4. Legal Basis for Processing
We process personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and, where applicable, the Nigeria Data Protection Regulation (NDPR). Processing is based on one or more of: your consent; the performance of a contract with you; compliance with legal obligations (including KYC/AML requirements); and our legitimate interests in operating and securing the Service.
5. How We Share Your Information
We do not sell your personal data. We share it only with the service providers needed to operate the Service, under contractual confidentiality and data-protection obligations:
Payment processing — Interswitch, for wallet provisioning, virtual accounts, and payment processing.
Identity verification — Interswitch IDV and Youverify, for BVN, NIN, and liveness checks.
Messaging — Termii, for SMS notifications and one-time passcodes.
Authentication — Google and Apple, when you choose third-party sign-in.
Cloud infrastructure — Convex and hosting providers that store and process data on our behalf.
We may also disclose personal data where required by law, court order, or regulator; to enforce our agreements; or to protect the rights, property, or safety of our users and the public. If the business is sold or merged, personal data may transfer to the acquiring entity under the same protections described here.
6. Data Retention
We retain personal data for as long as your account is active and as needed to provide the Service. After account closure we retain records for the period required by financial-services regulation, tax, and anti-fraud obligations — typically up to seven (7) years for transaction and identity records — after which data is deleted or anonymised.
7. Data Security
We use industry-standard safeguards including encryption in transit (TLS) and at rest, access controls limiting personal data to authorised personnel, and segregated production credentials. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data we will notify you and the relevant regulator as required by law.
8. Your Rights
Under the NDPA you have the right to:
To exercise any of these rights, contact us at the address in the Contact section. We may need to verify your identity before acting on a request.
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Request a portable copy of your data in a commonly used format.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
9. International Data Transfers
Some of our service providers process data outside Nigeria. Where personal data is transferred internationally we ensure appropriate safeguards are in place, consistent with the NDPA's cross-border transfer requirements.
10. Children's Privacy
The Service is not directed at anyone under 18, and we do not knowingly collect personal data from children. If we learn that a minor has provided us personal data, we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version here and update the "Last updated" date. For material changes we will also notify you through the app or by email before the change takes effect.
12. Contact Us
Questions, requests, or complaints about this Privacy Policy or our data practices can be sent to legal@egreen.global.