Privacy Policy
Effective date: 13 May 2026 · Version 1.0
1. Who Controls Your Data
ChangaRide ("we", "us", "our") is the data controller for information collected through this platform. Our contact details are provided at the end of this policy.
2. What We Collect
We collect only what is necessary to operate the cost-sharing service:
Account Information
- Full name
- Phone number (used for OTP-based identity verification)
- Role on the platform (Driver or Passenger)
Journey Information
- Origin, destination, and stopover locations
- Departure date and time
- Number of seats and cost-sharing fare
- Journey status and booking history
Vehicle Information (Drivers)
- Vehicle make, model, and year
- Number plate
- Vehicle capacity
Technical & Device Information
- IP address and device user-agent (used to secure session continuity — see below)
- One-time password (OTP) records and verification timestamps
- Session data
Ratings & Feedback
- Ratings and comments submitted after a journey
3. Why We Collect It (Legal Bases)
| Purpose | Legal Basis |
|---|---|
| Registering and managing your account | Contract performance |
| Matching Drivers and Passengers | Contract performance |
| OTP verification and session security | Legitimate interest (security) |
| Displaying ratings to other users | Legitimate interest (trust & safety) |
| Enforcing account suspensions | Legitimate interest (platform integrity) |
| Platform analytics and improvement | Legitimate interest (service improvement) |
| Compliance with legal obligations | Legal obligation |
4. Device Fingerprinting for Session Security
To reduce the need for repeated OTP entry within an active session, we create a device fingerprint — a one-way cryptographic hash (SHA-256) of your IP address and browser/device user-agent string at the time you verify your OTP. This hash cannot be reversed to identify your device and is used solely to confirm that a returning session originates from the same device. It is discarded when a new OTP is issued.
5. Who We Share Your Data With
We share your information only as necessary to operate the service:
- Other users: Your name, origin/destination, departure time, and rating are visible to relevant Drivers or Passengers as required to arrange a journey.
- SMS gateway providers: Your phone number is shared with our OTP delivery partner solely to send you a verification code.
- Platform administrators: ChangaRide staff can access account and journey data to administer the platform and investigate complaints.
- Law enforcement: We will disclose data where required by Kenyan law or a valid court order.
We do not sell your personal data to any third party.
6. Data Retention
We retain your data for as long as your account is active and for a reasonable period thereafter to allow us to resolve disputes and comply with legal obligations. OTP records are retained for the session expiry period and then cleared. Journey records are retained for at least 12 months after the journey date for dispute resolution purposes.
7. Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include hashed passwords, OTP-based authentication, and encrypted data transmission (HTTPS). No system is completely secure; we encourage you to keep your phone secure and log out when using shared devices.
8. Your Rights
Under applicable Kenyan data protection law (the Data Protection Act, 2019), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your account and associated data, subject to our legal retention obligations.
- Object to processing based on legitimate interest.
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
To exercise these rights, contact us at the address below.
9. Children's Privacy
ChangaRide is intended for users aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has registered an account, please contact us and we will delete the account promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions or to exercise your rights, contact:
ChangaRide — Data Privacy
support@changaride.co.ke