Skip to content
Gyilo
HomePrivacyTerms

LEGAL · PRIVACY

Privacy, explained clearly.

This policy explains what information Gyilo handles, why we need it, who may receive it and the choices available to you when you use our websites, workspaces, booking and tracking experiences.

Effective 21 September 2026Applies to Gyilo servicesNigeria
ON THIS PAGE1. Scope and roles2. Information we collect3. How we use it4. Lawful bases5. Sharing6. AI-assisted features7. Retention8. Security9. Your rights10. International transfers11. Children12. Changes13. Contact

1. Scope and our data roles

This Privacy Policy applies to Gyilo’s marketing website, logistics company workspaces, rider experiences, platform administration, public booking and delivery tracking pages, and related communications (collectively, the “Services”). “Gyilo”, “we”, “us” and “our” refer to Gyilo Technologies.

For account administration, platform security, billing and direct communications, Gyilo determines why and how information is used and acts as a data controller. A logistics provider (“LP”) generally controls the customer, recipient, vendor, rider and delivery information it enters into Gyilo. For that information, Gyilo processes data on the LP’s instructions as its service provider or processor. The LP remains responsible for its own privacy notices and lawful use of that information.

If you are a customer, recipient, vendor or rider asking about information entered by an LP, contact that LP first. We will support the LP in responding where required.

2. Information we collect

Information you provide

  • Account and profile information, such as name, email address, phone number, role, password credentials and workspace details.
  • Business information, including company name, contacts, service areas, rate cards, pickup locations and operational preferences.
  • Booking and delivery information, including pickup and destination details, package notes, customer and recipient contact details, requested times, rider assignment, status updates, proof of delivery and recipient confirmation codes.
  • Payment and settlement information, including amounts, payment references, commission records, refund or dispute information and rider bank details. Payment card details are handled by the payment provider and are not stored by Gyilo.
  • Communications, support requests, form submissions and feedback.

Information collected through use

  • Device, browser, IP address, access times, pages viewed and security or diagnostic events.
  • Location information when a user chooses current location, selects a point on a map or uses location features needed for delivery operations.
  • WhatsApp message content and metadata made available through an LP’s authorised WhatsApp Business connection, where enabled.
  • Activity and audit logs showing actions such as booking changes, dispatch decisions, access changes and financial events.

3. How we use information

  • Provide, operate and maintain the Services.
  • Create and manage accounts, workspaces, roles and permissions.
  • Turn authorised customer conversations into reviewable draft orders and help users complete booking details.
  • Price, dispatch, track and confirm deliveries, including recipient-code confirmation.
  • Process and reconcile payments, commissions, refunds, rider earnings and settlements.
  • Send operational messages, account notices, password resets and support communications.
  • Protect accounts, detect abuse, investigate incidents and maintain audit records.
  • Monitor performance, troubleshoot problems and improve product usability.
  • Meet legal, regulatory, tax, accounting and dispute-resolution obligations.

4. Lawful bases

Depending on the context, we process personal data because it is necessary to perform a contract, take steps requested before entering a contract, comply with a legal obligation, protect vital interests, pursue legitimate interests that do not override individual rights, or because valid consent has been given. Where processing depends on consent, consent may be withdrawn at any time without affecting earlier lawful processing.

Gyilo’s handling of personal data is intended to follow applicable Nigerian data protection law, including the Nigeria Data Protection Act 2023.

5. When information is shared

We do not sell personal information. We may share information only as needed with:

  • The relevant LP, its authorised staff, assigned riders, vendors, customers or recipients, based on their roles and the delivery workflow.
  • Infrastructure and business service providers that help us host, secure, communicate and operate the Services.
  • Paystack for payment collection, verification, transfers, refunds and reconciliation.
  • Meta and WhatsApp for authorised business messaging features.
  • Google Maps or related mapping services for address search, coordinates, routes and map display.
  • Resend for transactional email delivery.
  • OpenRouter and selected model providers for configured AI-assisted order extraction, subject to the safeguards described below.
  • Professional advisers, regulators, courts, law-enforcement bodies or other parties when legally required or necessary to establish, exercise or defend legal claims.
  • A buyer, investor or successor in connection with a merger, financing, reorganisation or sale, subject to appropriate protections.

6. AI-assisted features

Gyilo may use language models to identify possible booking information in authorised customer conversations, such as pickup, destination, contact and package details. The website assistant also sends the question a visitor submits to our configured AI provider and may use web search to answer comparison or current-information questions. Search queries and relevant public search results may be processed by the search provider. These features produce drafts, suggestions or informational answers that may be incomplete or incorrect.

We aim to send only the content needed for the requested task and configure providers according to available privacy and security controls. Do not submit passwords, payment-card details or other sensitive information to the website assistant. LPs must not use AI features to submit content they are not authorised to process.

7. Retention

We retain information for as long as reasonably needed to provide the Services, maintain delivery and financial records, comply with law, resolve disputes and enforce agreements. The retention period depends on the information, the LP’s instructions, account status, security needs and applicable legal or accounting requirements.

When information is no longer needed, we delete, anonymise or securely isolate it, subject to backups and legal retention duties.

8. Security

We use administrative, technical and organisational measures designed to protect information, including access controls, role-based permissions, protected credentials, logging, encrypted network transport and review of important operational and financial actions. No internet service can guarantee absolute security.

Users are responsible for protecting their credentials, using accurate access roles and promptly reporting suspected unauthorised access to privacy@gyilo.com.

9. Your privacy rights

Subject to applicable law and relevant exceptions, you may ask to:

  • Receive information about the processing of your personal data.
  • Access or obtain a copy of your personal data.
  • Correct inaccurate or incomplete personal data.
  • Delete personal data or restrict certain processing.
  • Object to processing based on legitimate interests or to direct marketing.
  • Receive portable data where applicable.
  • Withdraw consent where consent is the basis for processing.
  • Complain to the Nigeria Data Protection Commission or another competent authority.

Send requests to privacy@gyilo.com. We may need to verify your identity and determine whether Gyilo or an LP is responsible for the request.

Gyilo customers can request deletion of their customer account. Gyilo Rider users can also request deletion of their rider account.

10. International transfers

Some service providers may process information outside Nigeria. Where personal data is transferred internationally, we use safeguards required by applicable law, such as an adequacy basis, contractual protections, consent where appropriate, or another lawful transfer mechanism.

11. Children

The Services are designed for businesses and adults managing or receiving deliveries. They are not directed to children, and children must not create Gyilo business or rider accounts. If we learn that personal data was collected from a child without the required authorisation, we will take appropriate steps to remove it.

12. Changes to this policy

We may update this policy as the Services or applicable requirements change. We will post the revised version here, update the effective date and provide additional notice when a material change requires it.

13. Contact us

Questions, complaints and privacy requests can be sent to:

Gyilo TechnologiesEmail: privacy@gyilo.comGeneral support: hello@gyilo.comNigeria
Gyilo

Delivery operations, connected.

ProductOverviewHow it worksSecurity
CompanyRequest accessContact
WorkspaceLP sign inPlatform admin
LegalPrivacy policyTerms & conditions
© Gyilo Technologies.Built for delivery businesses in Nigeria.