Privacy policy

Last updated: 4 October 2026

Who is responsible

PeaPool is run by Williams, who is the data controller: the person who decides how your information is used and is responsible for it.

The way to ask a privacy question or use any of your rights is the support form on the Help page. It works whether or not you are signed in.

  • Postal address: [Postal address — to be added before public launch]
  • Email: [PeaPool contact email — added once PeaPool has its own domain]

We follow the Nigeria Data Protection Act 2023 (NDPA). If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 also protect you.

What we collect

  • Your account: name, email address and password, and the date you agreed to the terms. We store the password only as a one-way hash, never the password itself.
  • What you choose to add to your profile: phone number, the area you usually start from, a line about yourself, and how people can pay you. All of these are optional.
  • Vehicles: type, make, model, colour, number plate and seats.
  • Activities you post: the places you type, a more exact meeting point if you give one, times, places available, price and notes. We look up map coordinates from the places you type.
  • Requests and settling up: places you ask for, any note to the host, and what you each mark about a payment, including any reference you add.
  • Messages: what you send other people about an activity, and reactions.
  • Ratings you give and receive, with any comment.
  • Safety records: reports you make or that are made about you, people you block and any reason you give, suspensions, appeals, and support requests (including the email address a signed-out person gives).
  • Your location, only when you ask: “Near me” in search asks your browser for your location, rounds it to about 100m and puts it in the search address. We don't store it against your account.
  • Notifications: the notifications we show you, your email and push choices, and, for each device where you turn on push, the address its push service gave us and the browser's user-agent string.
  • Security records: sign-ins, sign-in failures, account deletions and moderator actions, with the IP address when our hosting passes it on reliably. IP addresses are also counted briefly to limit how fast anyone can sign in, sign up or send support requests.

Why we use it, and on what basis

The law asks us to name a lawful basis for each use. Ours are:

  • To provide the service you signed up for (contract): running your account and signing you in, posting and joining activities, matching people to activities, messages, ratings, the settling-up record, notifications about your activities, and replying to your support requests.
  • Our legitimate interests in a safe, working service: safety, preventing fraud and abuse, moderating reports, blocks and suspensions, security records and rate limits, turning typed places into map positions, and showing other people only an approximate meeting point.
  • Your consent: push notifications, the optional profile details above, and your location for “Near me”. You can withdraw consent at any time in Settings or your browser, without affecting what happened before.
  • Legal obligation: responding to lawful requests from authorities, and keeping the records the law requires.

We don't sell your personal data, show advertising, or profile you for advertising. We don't make any decision about you by automated means that has a legal or similarly significant effect on you; suspensions are decided by a person.

Who sees what, and when

  • Anyone, including people without an account: your name, profile line, home area, when you joined, whether your email is verified, ratings and their comments, how many things you've hosted and joined, and activities you host. On an activity: its title, the places typed, the time, the price, any notes, the vehicle's make, model and colour for a lift, and how many people are going. The map shows the meeting point moved up to 500m from where it is.
  • A host, when you ask to join: your note, your profile line and whether your email is verified.
  • Once a place is confirmed: the host and that guest see each other's email address and phone number, and the guest sees the names of the other confirmed guests. The guest also sees the exact meeting point, the exact map position and the host's payment details.
  • Messages: in the app, only the two people in the conversation. If one of them reports a message, moderators see that message.
  • Your vehicle's number plate: only you.
  • Moderators, who are volunteers or staff we appoint and who may use the moderation tools only for safety and support: reports and the content reported, appeals, support requests, account status, the security records above, and members' names and email addresses, so they can investigate and reply.
  • Nobody is told who reported them, and someone you block is not told.

Services we use, and where your data goes

These providers process data for us. Most of them are in the United States, so your information leaves Nigeria (and the UK) to reach them.

  • Render hosts the app and the short-lived rate-limit counters, in Oregon, USA.
  • Neon hosts the database, on Amazon Web Services in Ohio, USA (us-east-2). Everything in “What we collect” that we store is kept there.
  • Resend, in the USA, sends our emails: sign-in links, verification links and notifications you have email turned on for. It receives your email address, your name and the message.
  • Web push: when you allow notifications on a device, they travel through your browser maker's push service (Google, Mozilla, Apple or Microsoft, depending on your browser). The content is encrypted so that service can't read it.
  • OpenStreetMap Nominatim, run by the OpenStreetMap Foundation on servers in the UK and EU, turns place names into map positions. Our server sends it the place names typed into activities and searches, not who typed them. We keep its answers so the same place is not looked up twice.
  • OpenStreetMap map tiles: when you view a map, your browser loads the map pictures directly from OpenStreetMap, which sees your IP address and the area you are looking at.

The NDPA and the UK GDPR allow personal data to be sent abroad only with protection in place. We rely on each provider's data processing agreement and the contractual safeguards in it, and on the transfer being necessary to provide the service you asked us for. Your browser's push service and the map tiles are reached by your own browser when you use those features.

How long we keep it

A daily job deletes what has passed its period.

  • Sign-in sessions end after 30 days, or when you sign out.
  • Sign-in links stop working after 15 minutes and email verification links after 24 hours. Used links are deleted after 1 day.
  • Notifications you have read: 90 days. Unread ones stay until you read them.
  • Records of emails and push notifications sent or failed: 90 days.
  • Resolved reports and decided appeals: 1 year after review, and longer while the person reported is still suspended, because they are the evidence for the suspension.
  • Support requests, including the email address a signed-out person gives: 1 year after we resolve them. Open ones stay until they are dealt with.
  • Security records of sign-ins and connections: 1 year. Other security records, such as moderation decisions and account deletions: 2 years.
  • Rate-limit counts expire on their own, within a day.
  • Push subscriptions are removed when the push service says the device has gone, or when you turn push off.
  • Everything else, including your profile, activities, messages and ratings, is kept while your account exists.
  • Backups of the database are kept for a limited period by our database provider and then overwritten.

When you delete your account

You can delete your account in Settings. You confirm with your password, or, if you sign in by email link, by having signed in within the last few minutes.

Deleted straight away: your name, email address, phone, profile line, home area, payment details and password; your sign-ins and sign-in links; push subscriptions; vehicles; blocks you made and blocks against you; reactions; and your notifications. Activities you were hosting that have not happened yet are cancelled and the guests told, and your places on other people's activities are released and the hosts told.

Kept, without your name: your account becomes “Deleted user”, and some things other people still rely on stay attached to it:

  • Messages you sent stay with the person who received them, shown as from “Deleted user”. Their copy of the conversation is their record too.
  • Ratings you gave or received keep their score, but the comment is removed.
  • Past activities you hosted stay in the guests' history, with your notes and exact meeting details removed. Notes and payment references you wrote on requests are removed.
  • Reports and appeals are kept for moderation, for the periods above. Security records are kept for their periods, with your email address replaced.
  • Support requests you sent stay for moderators, with your email address removed: what you asked and our reply, until their period above ends.

A suspended account can't be deleted from Settings, because that would erase the evidence behind the suspension. Ask in your appeal on the suspension page; we delete it once the matter is closed, unless we need to keep it for a legal claim.

Your rights

You have the right to:

  • See your data: “Download my data” in Settings gives you a copy of what we hold about you as a JSON file. Suspended accounts can download it from the suspension page. Reports made about you are left out so as not to reveal who made them; ask and we will send a redacted copy.
  • Correct it: edit your profile in Settings.
  • Have it erased: “Delete my account” in Settings, as described above.
  • Object to a use, ask us to restrict it, or take your data elsewhere: ask through the support form. The download is in a machine-readable format you can take with you.
  • Withdraw consent: turn push notifications off in Settings, and clear any optional profile detail there.

We reply to requests within 30 days. If you are not happy with how we handle your information, you can complain to the Nigeria Data Protection Commission or, in the UK, the Information Commissioner's Office.

Security and breaches

Passwords are stored only as one-way hashes, sign-in links expire quickly, contact details are shown only once a place is confirmed, and limits on repeated attempts slow down anyone guessing passwords.

If a breach is likely to put your rights at risk, we will tell the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and the people affected without undue delay where the law requires.

Under-18s

PeaPool is for people aged 18 and over. We don't knowingly hold data about anyone younger, and we delete an account if we learn it belongs to someone under 18.

Cookies and your device

We set one sign-in cookie, which lasts 30 days, and keep your light or dark theme choice in your browser's storage. There are no advertising or analytics trackers.

Changes to this policy

Before a material change to this policy, we will tell you by in-app notification and by email at least 14 days before it takes effect, and ask you to accept it the next time you sign in. The date at the top always shows when it last changed.

If anything here is unclear, contact us through the support form at /help.