1. Introduction

This Data Policy outlines how Rideon by Citrus collects, processes, and safeguards driver data in compliance with the Kenya Data Protection Act (DPA) 2025.

2. Legal Basis & Compliance

All data processing follows the Kenya Data Protection Act 2025 and related regulations. Citrus Labs Limited is registered with the ODPC.

3. Data Collection

We collect driver identity, vehicle details, trip data, payment records, and location data through direct input and automated systems.

4. Data Usage

Data is used for fare calculation, payment processing, fraud detection, and platform performance improvement.

5. Data Sharing & Transfers

Data sharing is limited to essential third parties like M-Pesa and Google Maps, with proper safeguards in place.

6. User Rights

Drivers have the right to access, rectify, erase, object to processing, and request data portability.

7. Data Security Measures

We employ encryption, access controls, audit trails, and employee training to protect driver information.

8. Cookies & Tracking Technologies

Session cookies and fraud-prevention tokens are used. Drivers can manage cookie preferences.

9. Third-Party Processors

All vendors comply with Kenya's DPA through binding contracts that enforce data protection obligations.

10. Data Breach Protocol

Incidents are investigated within 72 hours, with prompt notification to ODPC and affected drivers.

11. Policy Updates

Last updated October 30, 2025. Updates are shared via in-app notice, email, or SMS.

12. Contact & Complaints

Contact us at legal@citruslabs.co.ke or escalate unresolved concerns to ODPC.