Privacy Policy
Last updated: July 2026 — This policy explains how Moja Ride collects, uses, and protects your personal data in compliance with ARTCI Law 2013-450 and the GDPR (EU Regulation 2016/679).
Preliminary Note
We, Moja Ride, including our subsidiaries (collectively: “MojaBus”, “we” or “us”), wish to inform you about data protection at MojaBus. The applicable data protection regulations — in particular ARTCI Law 2013-450 and EU Regulation 2016/679 (the “GDPR”) — require us to inform you transparently about the type, scope, purpose, duration, and legal basis of our data processing (cf. Art. 13 and 14 GDPR).
This Privacy Policy has a modular structure: a general part covering all personal data processing that applies whenever our website is accessed (Section 1), and a special part specific to particular processing situations (Section 2).
11. General Information
1.1 Definitions
This Privacy Policy is based on the definitions set out in Article 4 of the GDPR:
Personal data
Any information relating to an identified or identifiable natural person (“data subject”). A person is identifiable if they can be identified directly or indirectly — in particular by reference to an identifier such as a name, identification number, location data, or online identifier, or through information relating to their physical, physiological, genetic, mental, economic, cultural, or social characteristics (Art. 4(1) GDPR).
Processing
Any operation performed on personal data, whether by automated means or not. This includes in particular: collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction (Art. 4(2) GDPR).
Controller
The natural or legal person, public authority, or other body that, alone or jointly with others, determines the purposes and means of personal data processing (Art. 4(7) GDPR).
Processor
A natural or legal person, public authority, or other body that processes personal data on behalf of the controller, in particular in accordance with its instructions (Art. 4(8) GDPR).
Third party
Any natural or legal person, public authority, or other body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data (Art. 4(10) GDPR).
Consent
Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them by a statement or by a clear affirmative action (Art. 4(11) GDPR).
1.2 Controller Identity
The controller responsible for the processing of your personal data (Art. 4(7) GDPR) is:
1.3 Data Protection Officer
Our Data Protection Officer is available at all times to answer your questions. Contact details:
1.4 Legal Basis for Data Processing
Processing of personal data is permitted where at least one of the following legal bases applies:
Art. 6(1)(a) GDPR
The data subject has given consent to the processing for one or more specific purposes.
Art. 6(1)(b) GDPR
Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at their request prior to entering into a contract.
Art. 6(1)(c) GDPR
Processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., statutory retention obligations).
Art. 6(1)(d) GDPR
Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
Art. 6(1)(e) GDPR
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Art. 6(1)(f) GDPR
Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or rights of the data subject.
1.5 Categories of Recipients
Under certain conditions, we transfer your personal data to our subsidiaries, or receive personal data from them, to the extent permitted by law. We also engage national and international service providers and work with partner companies. These include:
- Carriers
- IT service providers
- Financial institutions and payment service providers
- Business partners
- Customer service providers (internal/external)
- Agency operators
- Security companies
- Travel insurers
- Other partners engaged for business operations (e.g., auditors, banks, insurance companies, lawyers, supervisory authorities, parties involved in company acquisitions)
Service providers and partner companies must ensure that appropriate technical and organizational measures are in place so that processing meets legal requirements and data subject rights are protected. We transfer personal data to public bodies (e.g., police, prosecutor’s office, supervisory authorities) where a corresponding legal obligation or authorization exists.
1.6 International Data Transfers
In the context of our business relationships, your personal data may be shared with or disclosed to third parties located outside Côte d’Ivoire (“third countries”). Where necessary, we will inform you of details of such transfers in Section 2.
Where the level of data protection in a third country may not be adequate, we ensure that adequate protection is guaranteed — for example through binding corporate rules, standard contractual clauses issued by the European Commission, certifications, or recognized codes of conduct.
To the extent required for your booking and the associated provision and processing of transport services, the transmission of necessary personal data to third countries is permitted pursuant to Art. 49(1)(b) GDPR. Please contact our Data Protection Officer for more detailed information.
1.7 Retention Period & Erasure
The retention period for collected personal data depends on the purpose for which we process the data. Data will be retained for as long as necessary to achieve the intended purpose. Where no explicit retention period is specified below, your personal data will be erased or blocked as soon as the purpose or legal basis for retention no longer applies.
Retention may be extended beyond the specified period in the event of a (pending) legal dispute, if other legal proceedings are initiated, or if retention is required by statutory provisions. When the prescribed retention period expires, personal data will be blocked or erased, unless we require further retention and a legal basis exists for it.
1.8 Automated Decision-Making (including Profiling)
We do not intend to use the personal data collected from you for processes involving automated decision-making (including profiling). If we wish to implement such procedures, we will inform you separately in accordance with the applicable legal provisions.
1.9 No Obligation to Provide Personal Data
Entering into a contract with us is not conditional on the prior provision of your personal data. There is also generally no legal or contractual obligation to provide us with your personal data; however, we may only be able to offer certain services to a limited extent, or not at all, if you do not provide the required data.
1.10 Statutory Obligation to Transmit Data
In certain cases, we may be subject to a specific regulatory or legal obligation to transmit personal data to third parties, in particular public bodies.
1.11 Data Security
We use appropriate technical and organizational measures to collect your data — taking into account the state of the art, implementation costs, and the nature, scope, context, and purpose of the processing, as well as the existing risks of a data breach — in order to protect data subjects against accidental or intentional manipulation, partial or complete loss or destruction, or unauthorized third-party access. For example, we use TLS encryption for our websites. Our security measures are continuously strengthened to keep pace with technological advances.
1.12 Your Rights
You may exercise your rights as a data subject at any time regarding your personal data, in particular by contacting us using the details in Section 1.2. Under the GDPR, data subjects have the following rights:
Right of access (Art. 15 GDPR)
You may request information about the personal data we process about you. Please specify your request clearly to help us compile the necessary data. On request, we will provide you with a copy of the data being processed. Note that your right to information may be limited in certain circumstances under regulatory provisions.
Right to rectification (Art. 16 GDPR)
If information about you is inaccurate or incomplete, you may request that it be corrected or completed.
Right to erasure (Art. 17 GDPR)
You may request the erasure of your personal data. Your right to erasure depends, among other things, on whether the data is still needed for our legal obligations.
Right to restriction of processing (Art. 18 GDPR)
You have the right to request restriction of the processing of data concerning you.
Right to data portability (Art. 20 GDPR)
You have the right to receive the data you have provided to us in a structured, commonly used, machine-readable format, or to request its transmission to another controller.
Right to object (Art. 21 GDPR)
You have the right to object at any time to the processing of your data for reasons relating to your particular situation. You may also object to receiving advertising at any time with future effect (Art. 21(2) GDPR).
Right to lodge a complaint
If you believe we have failed to comply with data protection regulations when processing your data, you may lodge a complaint with the competent supervisory authority: ARTCI — Abidjan, Marcory Anoumabo — 18 BP 2203 Abidjan 18, Côte d’Ivoire.
Right to withdraw consent
You may withdraw your consent to data processing at any time with future effect. This also applies to consent declarations issued before 25 May 2018.
22. Special Information
2.1 Visiting Our Website
Information about Moja Ride and our services is available at mojaride.com (hereinafter “Website”). When you visit our website, your personal data is processed.
2.1.1 Provision of the Website
When using the website for information purposes, we collect and store the following categories of data in server log files:
- Referral URL (the page from which the request originated)
- Name and URL of the requested page
- Date and time of the access request (server time zone)
- Browser version used
- IP address of the requesting device
- Amount of data transferred
- Operating system
- HTTP status code (success/failure)
- Time zone offset from GMT
2.1.2 Contact Forms
Data submitted via contact forms (e.g., title, name, address, company, email, time of submission, subject) is processed to respond to enquiries. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract, or Art. 6(1)(f) GDPR (legitimate interest in handling contact enquiries) in other cases. We retain contact form data and the associated IP address to meet our evidential obligations, ensure legal compliance, and prevent misuse.
2.1.3 Booking, Provision, and Processing of Transport Services
When booking transport tickets, we collect and process the following personal data categories:
- Email address
- First and last name
- Login credentials
- Payment data
- Date of birth (for services with special child fares)
- Acceptance of applicable general conditions
- Advance seat reservation information
- Luggage details
- Booking domain language
- Booking channel (Web or app)
You may optionally provide a contact phone number in case of delays or itinerary changes.
These data are processed for booking, provision, and processing of transport services — including customer service — and for compliance with legal obligations. Legal basis: Art. 6(1)(b) and (c) GDPR.
For international transport bookings, the following additional data may be collected depending on the departure and arrival location:
- Gender information
- Identity card, passport, or identification number
We transmit the above data to the relevant carrier(s), and to public bodies where a corresponding legal obligation or authorization exists. Legal basis: Art. 6(1)(b) or (c) GDPR.
Payment processors
Required payment data is transmitted to payment service providers for the secure processing of your payments:
- Paystack
26 Joel Ogunnaike Street, Ikeja GRA, Ikeja, Lagos, Nigeria — +234 201 631 6160 - Wave Côte d’Ivoire
Cocody Riviera 4, near Mansah Bank — contact@wave.com — +225 07 48 27 77 42