Privacy
What CitiGo collects across the website and the apps, why, and for how long.
Who is responsible
The controller of the personal data described here is:
CITIGO FLEET & MOBILITY LTD
Registered in England and Wales, number 16236668
30 Naseby Street, Liverpool, England, L4 5TT
Privacy contact: support@citigo.io.
This policy covers the CitiGo website and the CitiGo customer applications for iOS and Android. Where a service is delivered by an independent provider, that provider is a separate controller for what it does — see partners and providers.
The website contact form
This website collects only what you submit through a form: name, email, country, optionally organisation and a message. It is held in a marketing system entirely separate from CitiGo's operational platform. It is used to contact you about CitiGo, is never sold, and is not shared for third-party marketing. You can ask for correction or deletion at any time and we will act on it.
The site sets no advertising or tracking cookies and embeds no third-party analytics. Your country selection is remembered in your browser and never leaves it. See cookies.
Identity, profiles and authentication
Signing in creates a CitiGo account. Authentication is performed by CitiGo's identity provider; CitiGo receives a verified identifier, a verified email address, your display name and the time you authenticated. CitiGo does not store or verify your password or your second factor — those stay with the identity provider, which is why support cannot reset or bypass them.
An account can hold more than one profile — personal, household and organisation. Profiles are kept separate: what you do in one is not visible in another, and the roles and permissions that apply are decided by CitiGo per request rather than by the app.
Raw provider tokens are held only in the device's own secure keystore and are bound to that device. CitiGo's servers hold them sealed, and they are never written to a log.
Service requests and activity
When you make a request CitiGo records what you asked for, the country and service, the answers you gave on the request form, the consents you gave, a reference number, the status and its history, and any cancellation, dispute or support contact about it.
Which fields a service asks for is set by that service and its regulator, and is shown before you submit. Your Activity shows only your own requests; a reference belonging to somebody else is indistinguishable from one that does not exist.
Location, consent and addresses
CitiGo uses two different things and treats them differently.
- Coarse location — a town, area or country. Used to show what is available where you are and to set your currency, addressing and regulatory context.
- Precise location — your device's exact position. Collected only when you explicitly ask for it, for a specific purpose, and only while the app is open. It is never collected in the background.
If you refuse the location permission, everything still works: you enter an address instead. That is a supported route rather than a degraded one.
Saved places are held encrypted. Lists show a label and coarse context — never a decrypted street address — and the full address is disclosed only at the point a fulfilment partner needs it to reach you, or when you deliberately open it yourself.
Precise coordinates and street addresses are excluded from logs, analytics and crash reports, and are never spoken aloud by the app's accessibility announcements.
Health and care information
Health services and care scheduling involve information about you or the person you are arranging care for. It is subject to additional protection under the law of every launch market, and CitiGo treats it accordingly.
- It is used only to arrange and fulfil the request you made.
- It is never used for marketing, profiling or advertising.
- It is shared only with the regulated provider delivering the care, and only what they need.
- It is not shown on a device CitiGo has detected as rooted or jailbroken, and is not cached offline on one.
- It is excluded from diagnostics and crash reporting.
Where a clinician or care provider delivers the service, they are an independent controller for the clinical record they create, under their own professional and regulatory obligations.
Payments and ledger records
CitiGo never receives your card number, CVV, PIN or bank credentials. They are entered on the payment provider's own hosted screen and CitiGo receives only a token and an outcome. There is nothing for CitiGo to store, and nothing for CitiGo to lose.
CitiGo records the amount, currency, reference, outcome and timing of each payment, and keeps a ledger of them. Some of these records are retained for a legally required period even after an account is closed — see retention.
Payments are processed by licensed payment providers. Which one applies depends on your country and the service.
Identity documents
A small number of services are required by their regulator to verify identity. Where that applies, CitiGo collects the document at that step, tells you why, and uses it only for that verification and any record the regulator requires.
It is never collected for services that do not require it, is not shown on a device detected as compromised, and is excluded from diagnostics.
Saved places, trusted contacts and shared profiles
Saved places are yours, encrypted, and shown as labels and coarse context. Sharing a place is scoped, expiring and revocable, and is limited to the profile or organisation you shared it with.
A trusted contact can act for you within a scope you set, which expires and which you can revoke. Payments, security changes, data export, account closure and address disclosure can never be delegated, whatever a grant says.
In a household or organisation profile, what other members can see is determined by the profile, not by the device. Personal details and accessibility preferences are isolated to the profile they belong to.
Notifications and support
CitiGo sends notifications about requests you have made. What you receive, and how, is set in Account and can be changed at any time. Operational messages about a request in progress are not marketing and are not subject to marketing consent.
When you contact support, CitiGo holds the correspondence and links it to the request. A support ticket carries the country, service and reference — it does not carry your precise address, your payment credentials or any token.
Device security signals, diagnostics and analytics
The app records whether the device has a working secure keystore, and whether that keystore is hardware-backed, so it can decide what it is safe to store and display. It also detects whether a device appears rooted or jailbroken and restricts payment, security changes and disclosure of sensitive information on such a device.
These signals are self-reported by the device and CitiGo does not treat them as proof of anything. They are used to reduce what the app puts on screen and on disk. Authorisation is always decided by CitiGo's platform, never by the device.
Crash reports and usage diagnostics record stability and performance. They are provider- neutral and deliberately exclude tokens, session identifiers, precise coordinates, street addresses, identity documents, health information and payment credentials.
CitiGo does not track you. No advertising identifier is read, nothing is sold or shared with a data broker, and nothing is shared for cross-application advertising.
Purposes and lawful bases
Where the UK GDPR, Nigeria's NDPA, Kenya's Data Protection Act, South Africa's POPIA, the UAE's PDPL or an applicable Canadian or United States law requires a lawful basis, CitiGo relies on the following.
| What | Why | Basis |
|---|---|---|
| Account and authentication | To give you an account and keep it secure | Performance of a contract; legitimate interests in security |
| Service requests and fulfilment | To deliver what you asked for | Performance of a contract |
| Precise location | Accurate pickup or service location, when you ask | Consent, given per request |
| Health information | To arrange and deliver care you requested | Explicit consent, and the provider's own professional basis |
| Identity documents | Verification a regulator requires | Legal obligation |
| Payments and ledger | To take payment and keep required records | Performance of a contract; legal obligation |
| Notifications about a request | To tell you what is happening | Performance of a contract |
| Marketing contact from the website form | To reply to you about CitiGo | Consent |
| Diagnostics and crash reporting | To keep the app working | Legitimate interests in a functioning service |
| Fraud and safety | To protect customers and providers | Legitimate interests; legal obligation |
Where consent is the basis, you can withdraw it at any time and CitiGo will stop that processing. Withdrawal does not affect what was lawful before it.
Partners, processors and regulated providers
CitiGo shares personal data with:
- The provider delivering your service — a driver, courier, clinician, rental company or tradesperson — and only what they need to deliver it. Where they are regulated, they act as an independent controller for their own record and their own terms apply in addition to CitiGo's.
- Payment providers, who process the payment. They receive the card details directly from you; CitiGo does not pass them on because CitiGo never has them.
- Processors acting on CitiGo's instructions — hosting, identity, messaging and crash reporting — under contracts limiting them to what CitiGo asks.
- Authorities and regulators, where the law requires it.
CitiGo does not sell personal data and does not share it for third-party marketing.
International transfers
CitiGo operates across eight countries, and personal data may be processed outside the country you are in — including by hosting and identity providers operating internationally.
Where data leaves a country whose law restricts transfers, CitiGo relies on the mechanism that law provides: an adequacy or whitelisting decision where one exists, and otherwise contractual safeguards such as standard contractual clauses, together with an assessment of the destination.
To ask which mechanism applies to a particular transfer, contact support@citigo.io.
How long CitiGo keeps things
Retention is set per service and per country, because the requirement differs — a financial record and a browsing preference are not kept for the same length of time. The retention that applies to a request is shown before you export or close your account.
| What | How long |
|---|---|
| Website form submissions | Until you ask for deletion, or until the enquiry is closed and no longer needed |
| Account and profiles | While the account is open, then deleted subject to the periods below |
| Service requests and activity | For the period the service and its regulator require |
| Payment and ledger records | For the period financial and tax law requires, which continues after closure |
| Health information | For the period health regulation requires; the provider retains its own clinical record |
| Identity documents | Only for as long as the verifying regulation requires |
| Precise location for a request | For the request, and then only as part of its record |
| Diagnostics and crash reports | A short operational period |
CitiGo does not publish a single global number, because doing so would be inaccurate in most of these markets.
Your rights
Subject to the law where you are, you can ask CitiGo to:
- Tell you what it holds about you, and give you a copy.
- Correct anything wrong.
- Export your data. Export discloses what it contains and what is retained before you confirm, and requires you to prove it is you.
- Delete your data and close your account — subject to records CitiGo is legally required to keep.
- Object to, or restrict, a use of your data.
- Withdraw a consent. Withdrawal is carried out on the platform and confirmed to you once the erasure it requires has completed — not when the request is received.
- Complain to your country's data protection authority. Doing so does not require contacting CitiGo first.
Use Account under Privacy, or email support@citigo.io. Security changes, export and closure require you to confirm it is you.
Children and family profiles
CitiGo is not directed at children and accounts are for adults. Family and Education-and-Care are services an adult arranges for others, including children in their care.
Where a request concerns a child, the adult making it is responsible for having the authority to do so, and CitiGo collects only what the service needs. There is no child-directed content and no advertising anywhere in CitiGo.
If you believe a child has created an account, contact support@citigo.io and it will be closed.
AI Concierge
AI Concierge helps organise everyday tasks. It works from what you tell it and what is already on your account.
- It does not make regulated decisions. Availability, pricing, eligibility, fulfilment and payment outcomes are decided by CitiGo's platform and its providers, not by it.
- It can be wrong. Anything it suggests is checked against the real service before a booking is committed.
- You can always reach a person. Support is at the address on this page and does not require going through it.
- It is not used to make decisions producing legal or similarly significant effects about you.
- Health information is not used to train anything.
Security
Credentials are held in the device's own secure keystore, bound to that device, and are never written to ordinary storage — there is no plaintext fallback anywhere in the app. Saved addresses are encrypted. Traffic is HTTPS-only; the app refuses cleartext connections outright. Sensitive screens block screenshots where the platform supports it, and the app-switcher preview is obscured on both.
Access to personal data inside CitiGo is limited to those who need it, and actions on an account are recorded in an append-only audit that redacts identifiers, tokens and precise location.
No system is perfect. If CitiGo suffers a breach affecting you, it will tell you and the relevant authority within the period the applicable law requires. To report a suspected breach or a vulnerability, email support@citigo.io.
Country-specific information
Each launch market adds its own requirements, regulator and rights. CitiGo will publish that country-specific information before a service opens there. The country pages describe planned markets and operational context; they are not legal annexes.
| Country | Currency | Current position |
|---|---|---|
| Nigeria | NGN | Country information required before launch |
| Ghana | GHS | Country information required before launch |
| Kenya | KES | Country information required before launch |
| South Africa | ZAR | Country information required before launch |
| United Kingdom | GBP | Country information required before launch |
| United Arab Emirates | AED | Country information required before launch |
| Canada | CAD | Country information required before launch |
| United States | USD | Country information required before launch |
When country-specific information is approved and published, it will form part of this policy for people using CitiGo in that country.
Changes to this policy
This is version 1.0, effective 2026-09-04.
When it changes materially, CitiGo publishes the new version with a new effective date and tells account holders before it takes effect. Editorial corrections do not create a new version — a history that records punctuation is a history nobody reads.
History
- 1.0 — 2026-09-04 — First full policy covering the website and the CitiGo applications. Replaces the earlier website-only notice.