This Privacy Policy governs all personal data processed by PASS Global Services Limited and its affiliates across all products and services, including PASSRIDE, PASS COURIER, and PASSMALL (the "PASS Super App”).
It applies to riders, drivers, delivery partners, merchants, shoppers, website visitors, and any individual interacting with PASS platforms, applications, APIs, or support channels.
By accessing or using PASS services, users acknowledge and agree to the collection and use of personal data as described in this Policy.
Personal Data refers to any information relating to an identified or identifiable individual, including name, contact details, location data, payment information, device identifiers, and government-issued identification.
Processing includes the collection, storage, use, disclosure, transfer, or deletion of personal data.
PASS collects personal data directly from users, automatically through platform usage, and from third parties where permitted by law.
Users are required to create an account to access PASS services.
Drivers and delivery partners operating under the Bring-Your-Own-Car (BYOC) and bike model must submit government-issued identification such as National ID cards, driver’s licenses, and vehicle documents.
This information is collected strictly for safety, fraud prevention, and regulatory compliance.
PASS uses camera access only when required to enable core features such as uploading profile photos, identity and vehicle documents for drivers and delivery partners, proof of delivery, and support-related images.
Camera access is user-initiated, is not used in the background, and images are collected only for the stated purpose.
Camera data is securely stored, not used for advertising, and retained only for as long as necessary in accordance with applicable laws and PASS data retention policies.
PASS collects precise location data during active trips and deliveries.
Background location data may be collected when the app is running in the background to support trip safety, navigation, fraud prevention, real-time tracking, and accurate fare or delivery fee calculation.
Location tracking automatically stops when a service is completed or when a driver or delivery partner goes offline.
PASS uses personal data to operate and improve its services.
PASS does not use personal data for unrelated purposes without user consent.
PASS processes payments through licensed third-party payment providers, including mobile money operators such as Momo, Telecel Cash, and AT Money, as well as card and POS payment gateways.
PASS does not store full payment card details on its servers.
PASS shares limited personal data with trusted third parties only as necessary to operate services.
All third-party sharing is governed by contractual and security safeguards.
For PASS COURIER and PASSMALL, PASS processes sender, recipient, merchant, and order information to facilitate logistics, order fulfillment, tracking, dispute resolution, and customer support.
Product images, delivery confirmations, and proof-of-delivery records may be retained for audit and dispute purposes.
PASS retains personal data only for as long as necessary to fulfill service delivery, safety, fraud prevention, dispute resolution, legal compliance, and regulatory obligations.
Account information is retained for the duration of the user’s account and deleted or anonymized within 30 days of deletion, except where legally required.
Trip, delivery, order, payment, invoice, and refund records may be retained for up to 7 years.
Precise location data may be retained for up to 12 months for safety investigations and dispute resolution.
Aggregated or anonymized location data may be retained longer for analytics purposes.
Customer support interactions and communication records may be retained for up to 3 years.
Identity documents may be retained for the duration of the partner’s relationship and up to 5 years after deactivation.
Device identifiers, IP addresses, and system logs may be retained for up to 24 months.
Certain data may be retained longer to comply with legal obligations or resolve disputes.
When retention is no longer required, data is securely deleted or irreversibly anonymized.
Users may delete their account within the app or request deletion through in-app support.
Personal data is deleted or anonymized within 30 days, except where legally required.
PASS services are not directed to individuals under 18 years of age.
If personal data of a child under applicable legal age is identified, it will be deleted without delay.
PASS processes personal data to detect fraud, enforce platform policies, investigate incidents, and protect users and the public.
PASS may transfer personal data across borders and implements safeguards such as standard contractual clauses.
Depending on jurisdiction, users may request access, correction, deletion, restriction, or objection to personal data processing.
PASS applies administrative, technical, and organizational security measures to protect personal data.
No system is completely secure, and users acknowledge inherent risks.
PASS may update this Privacy Policy periodically.
Material updates will be communicated through the app or other appropriate channels.
For privacy-related questions or requests, users may contact PASS through in-app support or designated privacy channels.