Privacy

What CitiGo collects across the website and the apps, why, and for how long.

Version 1.0 · Effective 2026-09-04

Who is responsible

The controller of the personal data described here is:

CITIGO FLEET & MOBILITY LTD
Registered in England and Wales, number 16236668
30 Naseby Street, Liverpool, England, L4 5TT

Privacy contact: support@citigo.io.

This policy covers the CitiGo website and the CitiGo customer applications for iOS and Android. Where a service is delivered by an independent provider, that provider is a separate controller for what it does — see partners and providers.

The website contact form

This website collects only what you submit through a form: name, email, country, optionally organisation and a message. It is held in a marketing system entirely separate from CitiGo's operational platform. It is used to contact you about CitiGo, is never sold, and is not shared for third-party marketing. You can ask for correction or deletion at any time and we will act on it.

The site sets no advertising or tracking cookies and embeds no third-party analytics. Your country selection is remembered in your browser and never leaves it. See cookies.

Identity, profiles and authentication

Signing in creates a CitiGo account. Authentication is performed by CitiGo's identity provider; CitiGo receives a verified identifier, a verified email address, your display name and the time you authenticated. CitiGo does not store or verify your password or your second factor — those stay with the identity provider, which is why support cannot reset or bypass them.

An account can hold more than one profile — personal, household and organisation. Profiles are kept separate: what you do in one is not visible in another, and the roles and permissions that apply are decided by CitiGo per request rather than by the app.

Raw provider tokens are held only in the device's own secure keystore and are bound to that device. CitiGo's servers hold them sealed, and they are never written to a log.

Service requests and activity

When you make a request CitiGo records what you asked for, the country and service, the answers you gave on the request form, the consents you gave, a reference number, the status and its history, and any cancellation, dispute or support contact about it.

Which fields a service asks for is set by that service and its regulator, and is shown before you submit. Your Activity shows only your own requests; a reference belonging to somebody else is indistinguishable from one that does not exist.

Location, consent and addresses

CitiGo uses two different things and treats them differently.

  • Coarse location — a town, area or country. Used to show what is available where you are and to set your currency, addressing and regulatory context.
  • Precise location — your device's exact position. Collected only when you explicitly ask for it, for a specific purpose, and only while the app is open. It is never collected in the background.

If you refuse the location permission, everything still works: you enter an address instead. That is a supported route rather than a degraded one.

Saved places are held encrypted. Lists show a label and coarse context — never a decrypted street address — and the full address is disclosed only at the point a fulfilment partner needs it to reach you, or when you deliberately open it yourself.

Precise coordinates and street addresses are excluded from logs, analytics and crash reports, and are never spoken aloud by the app's accessibility announcements.

Health and care information

Health services and care scheduling involve information about you or the person you are arranging care for. It is subject to additional protection under the law of every launch market, and CitiGo treats it accordingly.

  • It is used only to arrange and fulfil the request you made.
  • It is never used for marketing, profiling or advertising.
  • It is shared only with the regulated provider delivering the care, and only what they need.
  • It is not shown on a device CitiGo has detected as rooted or jailbroken, and is not cached offline on one.
  • It is excluded from diagnostics and crash reporting.

Where a clinician or care provider delivers the service, they are an independent controller for the clinical record they create, under their own professional and regulatory obligations.

Payments and ledger records

CitiGo never receives your card number, CVV, PIN or bank credentials. They are entered on the payment provider's own hosted screen and CitiGo receives only a token and an outcome. There is nothing for CitiGo to store, and nothing for CitiGo to lose.

CitiGo records the amount, currency, reference, outcome and timing of each payment, and keeps a ledger of them. Some of these records are retained for a legally required period even after an account is closed — see retention.

Payments are processed by licensed payment providers. Which one applies depends on your country and the service.

Identity documents

A small number of services are required by their regulator to verify identity. Where that applies, CitiGo collects the document at that step, tells you why, and uses it only for that verification and any record the regulator requires.

It is never collected for services that do not require it, is not shown on a device detected as compromised, and is excluded from diagnostics.

Saved places, trusted contacts and shared profiles

Saved places are yours, encrypted, and shown as labels and coarse context. Sharing a place is scoped, expiring and revocable, and is limited to the profile or organisation you shared it with.

A trusted contact can act for you within a scope you set, which expires and which you can revoke. Payments, security changes, data export, account closure and address disclosure can never be delegated, whatever a grant says.

In a household or organisation profile, what other members can see is determined by the profile, not by the device. Personal details and accessibility preferences are isolated to the profile they belong to.

Notifications and support

CitiGo sends notifications about requests you have made. What you receive, and how, is set in Account and can be changed at any time. Operational messages about a request in progress are not marketing and are not subject to marketing consent.

When you contact support, CitiGo holds the correspondence and links it to the request. A support ticket carries the country, service and reference — it does not carry your precise address, your payment credentials or any token.

Device security signals, diagnostics and analytics

The app records whether the device has a working secure keystore, and whether that keystore is hardware-backed, so it can decide what it is safe to store and display. It also detects whether a device appears rooted or jailbroken and restricts payment, security changes and disclosure of sensitive information on such a device.

These signals are self-reported by the device and CitiGo does not treat them as proof of anything. They are used to reduce what the app puts on screen and on disk. Authorisation is always decided by CitiGo's platform, never by the device.

Crash reports and usage diagnostics record stability and performance. They are provider- neutral and deliberately exclude tokens, session identifiers, precise coordinates, street addresses, identity documents, health information and payment credentials.

CitiGo does not track you. No advertising identifier is read, nothing is sold or shared with a data broker, and nothing is shared for cross-application advertising.

Purposes and lawful bases

Where the UK GDPR, Nigeria's NDPA, Kenya's Data Protection Act, South Africa's POPIA, the UAE's PDPL or an applicable Canadian or United States law requires a lawful basis, CitiGo relies on the following.

WhatWhyBasis
Account and authenticationTo give you an account and keep it securePerformance of a contract; legitimate interests in security
Service requests and fulfilmentTo deliver what you asked forPerformance of a contract
Precise locationAccurate pickup or service location, when you askConsent, given per request
Health informationTo arrange and deliver care you requestedExplicit consent, and the provider's own professional basis
Identity documentsVerification a regulator requiresLegal obligation
Payments and ledgerTo take payment and keep required recordsPerformance of a contract; legal obligation
Notifications about a requestTo tell you what is happeningPerformance of a contract
Marketing contact from the website formTo reply to you about CitiGoConsent
Diagnostics and crash reportingTo keep the app workingLegitimate interests in a functioning service
Fraud and safetyTo protect customers and providersLegitimate interests; legal obligation

Where consent is the basis, you can withdraw it at any time and CitiGo will stop that processing. Withdrawal does not affect what was lawful before it.

Partners, processors and regulated providers

CitiGo shares personal data with:

  • The provider delivering your service — a driver, courier, clinician, rental company or tradesperson — and only what they need to deliver it. Where they are regulated, they act as an independent controller for their own record and their own terms apply in addition to CitiGo's.
  • Payment providers, who process the payment. They receive the card details directly from you; CitiGo does not pass them on because CitiGo never has them.
  • Processors acting on CitiGo's instructions — hosting, identity, messaging and crash reporting — under contracts limiting them to what CitiGo asks.
  • Authorities and regulators, where the law requires it.

CitiGo does not sell personal data and does not share it for third-party marketing.

International transfers

CitiGo operates across eight countries, and personal data may be processed outside the country you are in — including by hosting and identity providers operating internationally.

Where data leaves a country whose law restricts transfers, CitiGo relies on the mechanism that law provides: an adequacy or whitelisting decision where one exists, and otherwise contractual safeguards such as standard contractual clauses, together with an assessment of the destination.

To ask which mechanism applies to a particular transfer, contact support@citigo.io.

How long CitiGo keeps things

Retention is set per service and per country, because the requirement differs — a financial record and a browsing preference are not kept for the same length of time. The retention that applies to a request is shown before you export or close your account.

WhatHow long
Website form submissionsUntil you ask for deletion, or until the enquiry is closed and no longer needed
Account and profilesWhile the account is open, then deleted subject to the periods below
Service requests and activityFor the period the service and its regulator require
Payment and ledger recordsFor the period financial and tax law requires, which continues after closure
Health informationFor the period health regulation requires; the provider retains its own clinical record
Identity documentsOnly for as long as the verifying regulation requires
Precise location for a requestFor the request, and then only as part of its record
Diagnostics and crash reportsA short operational period

CitiGo does not publish a single global number, because doing so would be inaccurate in most of these markets.

Your rights

Subject to the law where you are, you can ask CitiGo to:

  • Tell you what it holds about you, and give you a copy.
  • Correct anything wrong.
  • Export your data. Export discloses what it contains and what is retained before you confirm, and requires you to prove it is you.
  • Delete your data and close your account — subject to records CitiGo is legally required to keep.
  • Object to, or restrict, a use of your data.
  • Withdraw a consent. Withdrawal is carried out on the platform and confirmed to you once the erasure it requires has completed — not when the request is received.
  • Complain to your country's data protection authority. Doing so does not require contacting CitiGo first.

Use Account under Privacy, or email support@citigo.io. Security changes, export and closure require you to confirm it is you.

Children and family profiles

CitiGo is not directed at children and accounts are for adults. Family and Education-and-Care are services an adult arranges for others, including children in their care.

Where a request concerns a child, the adult making it is responsible for having the authority to do so, and CitiGo collects only what the service needs. There is no child-directed content and no advertising anywhere in CitiGo.

If you believe a child has created an account, contact support@citigo.io and it will be closed.

AI Concierge

AI Concierge helps organise everyday tasks. It works from what you tell it and what is already on your account.

  • It does not make regulated decisions. Availability, pricing, eligibility, fulfilment and payment outcomes are decided by CitiGo's platform and its providers, not by it.
  • It can be wrong. Anything it suggests is checked against the real service before a booking is committed.
  • You can always reach a person. Support is at the address on this page and does not require going through it.
  • It is not used to make decisions producing legal or similarly significant effects about you.
  • Health information is not used to train anything.

Security

Credentials are held in the device's own secure keystore, bound to that device, and are never written to ordinary storage — there is no plaintext fallback anywhere in the app. Saved addresses are encrypted. Traffic is HTTPS-only; the app refuses cleartext connections outright. Sensitive screens block screenshots where the platform supports it, and the app-switcher preview is obscured on both.

Access to personal data inside CitiGo is limited to those who need it, and actions on an account are recorded in an append-only audit that redacts identifiers, tokens and precise location.

No system is perfect. If CitiGo suffers a breach affecting you, it will tell you and the relevant authority within the period the applicable law requires. To report a suspected breach or a vulnerability, email support@citigo.io.

Country-specific information

Each launch market adds its own requirements, regulator and rights. CitiGo will publish that country-specific information before a service opens there. The country pages describe planned markets and operational context; they are not legal annexes.

CountryCurrencyCurrent position
NigeriaNGNCountry information required before launch
GhanaGHSCountry information required before launch
KenyaKESCountry information required before launch
South AfricaZARCountry information required before launch
United KingdomGBPCountry information required before launch
United Arab EmiratesAEDCountry information required before launch
CanadaCADCountry information required before launch
United StatesUSDCountry information required before launch

When country-specific information is approved and published, it will form part of this policy for people using CitiGo in that country.

Changes to this policy

This is version 1.0, effective 2026-09-04.

When it changes materially, CitiGo publishes the new version with a new effective date and tells account holders before it takes effect. Editorial corrections do not create a new version — a history that records punctuation is a history nobody reads.

History

  • 1.0 — 2026-09-04 — First full policy covering the website and the CitiGo applications. Replaces the earlier website-only notice.