Privacy Policy
Last Updated: July 18, 2026
1. Introduction
Welcome to XENDMi. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website or use our mobile applications (the "Platform") and tell you about your privacy rights and how the law protects you.
2. The Data We Collect About You
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
- Contact Data includes delivery address, email address and telephone numbers.
- Government-Issued Identification. To meet Nigerian financial-services Know-Your-Customer (KYC) requirements, we collect your National Identification Number (NIN) for Tier 1 verification and, for agents or high-value senders, your Bank Verification Number (BVN) and a photograph of a government-issued ID document (driver's licence, international passport, voter's card, or national ID card). BVN is only requested where required by the Central Bank of Nigeria's tiered-KYC framework (for example, when your rolling monthly transaction volume crosses regulatory thresholds).
- Financial Data includes bank account and payment card details, and — for agents — the account credited during payouts.
- Transaction Data includes details about payments to and from you and other details of services you have purchased from us.
- Location Data includes your real-time location to facilitate package tracking and delivery services.
- Facial Images. During identity verification, Xendmi asks you to take a selfie (a single photograph of your face). See the dedicated Facial Images and Biometric Data section below for the complete explanation of how this image is collected, used, stored, shared, retained, and deleted.
- Package & Delivery Photos. Senders may upload photographs of the package being shipped. Agents upload proof-of-pickup and proof-of-delivery photographs at handover points. These images are stored under the same processor and retention rules as facial images (see Section 3).
- Device & Push Notification Data. When you enable push notifications, your device generates a token (via Firebase Cloud Messaging) that we store against your account so we can send delivery-status alerts. We also process basic device and session information (operating system, app version, IP address at time of request) for security, fraud prevention, and debugging.
3. Facial Images and Biometric Data
During identity verification (KYC), Xendmi asks you to take a selfie (a single photograph of your face). This section explains exactly how that image is handled. Xendmi does not perform facial recognition, does not create biometric templates or faceprints, does not run any automated face-matching, and does not use facial images to train any machine learning model.
- What we collect. A single selfie image (JPEG or PNG). No biometric template, no faceprint, no derived vector representation is computed or stored. We do not access live camera frames beyond capturing the single image you take and submit.
- How we use it. The selfie is used only to (a) allow a Xendmi admin to manually verify, by visual comparison against the government-issued ID document you upload, that you are a real person matching the ID, and (b) become your profile photo shown to other users so they can recognise you. We do not use it for advertising, profiling, surveillance, or any analysis beyond the manual review described above.
- Where it is stored, and who has access. The selfie is uploaded to Cloudinary, our image-hosting and storage processor, under a service agreement that requires Cloudinary to process the data only on our behalf and not to use it for any other purpose. Cloudinary acts as a data processor; Xendmi remains the data controller. The image is not shared with any other third party, is never sold, is never used for advertising, and is never provided to any machine learning or analytics provider for training.
- How long we keep it. The selfie is retained while your Xendmi account is active. When you delete your account, the image is deleted from Cloudinary, except where Nigerian financial-services KYC regulations require us to retain identity- verification records for a fixed regulatory period (typically 5–7 years). After that regulatory window, the image is permanently deleted.
- Your right to request deletion. You may request earlier deletion of your facial image at any time by emailing info@xendmi.com. We will action the deletion within a reasonable timeframe, subject only to the regulatory retention requirement above.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you (e.g., matching senders with agents).
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation.
5. Disclosures of Your Personal Data
We may share your personal data with the parties set out below for the purposes set out in section 4 above.
- Internal Third Parties: Other companies in the XENDMi Group acting as joint controllers or processors.
- External Third Parties: Service providers acting as processors based who provide IT and system administration services, payment processing, or identity verification.
- Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets.
The specific external processors we currently rely on — each bound by a service agreement to handle your data only on our instructions and only for the purpose described — are listed below. Xendmi remains the data controller in every case.
- Monnify (TeamApt Ltd., Nigeria) — payment collection, escrow, agent bank-account disbursement, and verification of your BVN / NIN against the Nigerian Interbank Settlement System bank registry during KYC.
- Termii (Nigeria) — delivery of SMS one-time passcodes to your registered phone number for sign-in and account verification.
- Zeptomail (Zoho Corporation) — delivery of transactional emails (receipts, status updates, magic-link sign-in where supported).
- Cloudinary (Cloudinary Ltd.) — image hosting and storage for your selfie, package photos, agent proof-of-pickup / proof-of-delivery photos, and government-issued ID document scans.
- Firebase Cloud Messaging (Google LLC) — delivery of in-app push notifications to your device. We share only the FCM device token and the notification payload; the token itself does not contain your personal data.
- Google Maps Platform (Google LLC) — rendering pickup / drop-off locations, route lines, and real-time agent positions on maps inside the app. Your location coordinates are transmitted to Google to fetch map tiles and place details.
- MongoDB Atlas (MongoDB Inc.) — the managed database that stores your account, delivery, and transaction records. Data is hosted in an EU region.
- Render (Render Services Inc.) — the cloud platform hosting our application servers.
6. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
7. Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
8. Account Deletion
You can request deletion of your Xendmi account and its personal data at any time, via either of the following paths:
- Inside the mobile app. Open Profile → Settings → Delete my account and confirm. Your account is deactivated immediately and its personal data is wiped within a short window, subject to the regulatory retention exception below.
- Via our website. Visit xendmi.com/delete-account and submit the deletion request form.
- By email. Write to info@xendmi.com from the email address on file and we will action the request within a reasonable timeframe.
On deletion we remove or anonymise your profile, contact information, saved addresses, wallet balance metadata, and account-linked images. Records that Nigerian financial-services and anti-money-laundering regulations require us to retain for a fixed period (typically 5–7 years) — including KYC identity documents, transaction ledgers, and payout audit trails — are moved to a restricted-access archive and permanently deleted at the end of that regulatory window.
9. Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact us in the following ways:
Email address: info@xendmi.com