Skip to main content
Peercel

Privacy Policy

What data Peercel collects, why, who it is shared with, how long it is kept, and how to exercise your rights.

Last updated : 19 September 2026

This policy describes how personal data is processed for users of the Peercel mobile application and the www.peercel.com website. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and the equivalent laws of the African countries where the service is offered, including the APDP in Côte d'Ivoire, the CDP in Senegal and the NDPR in Nigeria.

It is published at a stable URL and versioned in our code repository: every change goes through review and leaves a dated record.

Data controller and contact

The data controller is NIDEN IT SAS, a French simplified joint-stock company with its registered office at 51 rue du Pré Brochet, 95110 Sannois, France.

  • Postal address: NIDEN IT SAS, 51 rue du Pré Brochet, 95110 Sannois, France.
  • Contact for any question about personal data, including requests to exercise your rights: privacy@send.peercel.com.
  • General contact: contact@send.peercel.com.

Peercel has not appointed a data protection officer: the service meets none of the mandatory designation criteria of Article 37 GDPR. Privacy requests are handled by the team reachable at the address above, which replies within one month.

You may lodge a complaint with the French data protection authority (CNIL, 3 place de Fontenoy, 75007 Paris) or with the data protection authority of your country of residence.

Data collected by the mobile application

The table below is the reference description of our processing activities. It is what must match, point by point, the Data safety declarations on our Google Play listing and the Privacy Nutrition Labels on our App Store listing.

DataPurposeLegal basisRecipientsRetention
Identity and contact details: first name, last name, gender, date of birth, profile photo, email address, phone number, postal addressCreate and manage the account, enable matching, contact the user about a deliveryPerformance of the contract (Art. 6.1.b)Peercel; database host; transactional email providerLifetime of the account, then 30 days before permanent anonymisation
Identity document (front/back)Verify identity before sensitive operations, prevent fraud and impersonation, meet our anti-money-laundering obligationsLegal obligation (Art. 6.1.c) and legitimate interest in preventing fraud (Art. 6.1.f)Peercel (manual review by our team); file storage host5 years from the end of the relationship, under anti-money-laundering obligations
Location: declared departure and arrival cities; device position, if you allow it, when searching; position you choose to share in messagingSuggest geographically compatible travellers and parcels, rank results by proximity, make it easier to arrange the handover meetingPerformance of the contract (Art. 6.1.b)Peercel; database host; Mapbox (converting addresses into coordinates, displaying maps); the other party to the conversation, for a shared positionSearch position: used for ranking, without being saved to your account; cities: lifetime of the listing; shared position: kept with the message containing it
Photos: parcel contents, evidence submitted in a disputeDescribe the parcel, evidence its condition, investigate a disputePerformance of the contract (Art. 6.1.b)Peercel; the other party to the delivery; file storage hostLifetime of the listing; 5 years for evidence filed in a closed dispute
Phone number used for one-time codes (OTP) at sign-up and handoverVerify the number, send the recipient the parcel handover codePerformance of the contract (Art. 6.1.b)Africa's Talking and Twilio (SMS delivery)Lifetime of the account; the codes themselves expire within minutes
Payment data: bank details, card number, mobile money identifierCollect the sender's payment, pay out funds to the travellerPerformance of the contract (Art. 6.1.b)Stripe, Flutterwave, CinetPay. This data is never stored by Peercel: it is entered with the payment provider, which returns only a transaction identifier and a statusWith the provider, under its own policy; at Peercel, only the identifier and status, kept for 10 years under accounting obligations
In-app messaging: content of conversations between sender and traveller (text, photos, shared positions)Allow the meeting to be arranged without exchanging personal contact details; serve as evidence in a disputePerformance of the contract (Art. 6.1.b)Peercel; database host. Message text is encrypted at restLifetime of the account; content is replaced by a neutral placeholder at anonymisation
Device push notification tokenSend app notifications (offer received, payment confirmed, parcel delivered)Performance of the contract (Art. 6.1.b)Expo and the Apple (APNs) and Google (FCM) notification servicesUntil the device signs out or the app is uninstalled
Device identifiers, app version, operating systemSecure sessions, diagnose incidents, adapt the interfaceLegitimate interest in keeping the service secure and working (Art. 6.1.f)Peercel; Sentry (error reports)90 days
Crash reports and error tracesIdentify and fix defects in the applicationLegitimate interest in maintaining a reliable service (Art. 6.1.f)Sentry, hosted in the European Union90 days
Delivery history, ratings and comments leftCompute the trust level, display reputation, arbitrate disputesPerformance of the contract (Art. 6.1.b)Peercel; other users, for the public part of the profile5 years; ratings received by the people you dealt with remain, detached from your identity
First name, last initial, cities of departure and arrival, content of the reviewPublish testimonials on the public websiteConsent (Art. 6.1.a), withdrawable at any timePublicUntil consent is withdrawn, effective within 7 business days
Choice regarding marketing communicationsSend you newsletters and offers, only if you have agreed to itConsent (Art. 6.1.a), withdrawable at any time from the app profilePeercel; transactional email providerUntil consent is withdrawn or the account is deleted
Financial records: transactions, balance movements, withdrawalsKeep the accounts, produce supporting documents, meet anti-money-laundering obligationsLegal obligation (Art. 6.1.c)Peercel; payment providers; competent authorities upon valid legal request10 years under accounting obligations, with no early deletion possible

Peercel does not collect: your contacts, your calendar, health data, political or religious opinions, sexual orientation, or any biometric data. No data is sold, rented or transferred to third parties for advertising purposes.

Mapping to the Google Play and App Store forms

The declarations made to the stores describe exactly the processing set out in the table above. Here is the mapping, category by category.

Form categoryGoogle Play — Data safetyApp Store — Privacy Nutrition LabelDeclared use
Personal informationName, email address, phone number, address, other info — collected, linked to the userContact Info, Identifiers — linked to identityApp functionality, account management
Identity documentsOfficial ID document and photo — collected, linked to the userSensitive Info — linked to identityFraud prevention, regulatory compliance
LocationApproximate and precise location — collected, linked to the userCoarse Location, Precise Location — linked to identityApp functionality (geographic matching)
PhotosPhotos — collected, linked to the userUser Content — linked to identityApp functionality
MessagesIn-app messages — collected, linked to the user, encrypted in transitUser Content — linked to identityApp functionality
Financial informationPayment info — not collected by the application; purchase history collected and linked to the userPurchases — linked to identity; Financial Info not collected by usApp functionality, accounting obligations
Device identifiers and diagnosticsDevice identifiers and crash logs — collected, linked to the userIdentifiers, Diagnostics — linked to identityAnalytics, fraud prevention, security
Advertising trackingNone — no data is shared for advertising purposesData Not Used to Track YouNot applicable

All data travels encrypted (TLS). You can request the deletion of your account and your data from the Delete my account page, without installing the application.

Processors and transfers outside the European Union

Peercel relies on the following processors. Each is bound by a data processing agreement compliant with Article 28 GDPR.

ProcessorRoleProcessing locationTransfer mechanism
OVHApplication server hostingFranceNo transfer outside the EU
SupabaseDatabase and file storageEuropean Union (EU region)No transfer outside the EU for production data
SentryError and crash reportingEuropean Union (EU region)No transfer outside the EU
ResendTransactional email deliveryUnited StatesEuropean Commission standard contractual clauses
Africa's Talking, TwilioSMS deliveryAfrica, United StatesStandard contractual clauses
StripeCard and bank transfer payments, business payoutsEuropean Union and United StatesStandard contractual clauses
Flutterwave, CinetPayMobile money payments and payoutsAfricaStandard contractual clauses
MapboxMapping and converting addresses into coordinatesUnited StatesStandard contractual clauses
Expo, Apple, GooglePush notification deliveryUnited StatesStandard contractual clauses

Judicial or administrative authorities may receive certain data upon a valid legal request. No other sharing takes place.

Your rights and how to exercise them

You have the following rights over your personal data.

  • Access and portability — obtain a copy of your data in a machine-readable format. The app offers a full export from your profile; you can also request it at privacy@send.peercel.com.
  • Rectification — correct inaccurate data. Most fields can be edited directly in your profile.
  • Erasure — request the deletion of your data. The procedure is described on the Delete my account page and does not require installing the app.
  • Restriction and objection — request that processing be frozen, or object to processing based on our legitimate interest.
  • Withdrawal of consent — where processing relies on your consent, withdraw it at any time, without affecting processing already carried out.
  • Complaint — refer the matter to the CNIL or to the data protection authority of your country.

Any request sent to privacy@send.peercel.com receives a reply within one month, extendable by two months for complex requests, in which case you are informed. We may ask for proof of identity where there is reasonable doubt about who is making the request.

Some rights have limits: accounting records must be kept for ten years and anti-money-laundering data for five years; they cannot be erased on request.

Retention, deletion and anonymisation

Retention periods appear in the table in section 2. They follow three rules.

  1. Account deletion. On a deletion request, the account is deactivated immediately: listings are withdrawn, sessions are closed, signing in is no longer possible.
  2. Anonymisation at day 30. Thirty days later, an automated job permanently overwrites identifying data: first name, last name, email, phone, address and date of birth are overwritten, identity documents are erased, message content is replaced by a neutral placeholder. This thirty-day window is deliberate: it allows a request made in error to be reversed, and an ongoing dispute or payment to be settled, before the data disappears.
  3. What remains after anonymisation. Financial records are kept for ten years under our accounting obligations, and audit logs for five years under our regulatory obligations, without directly identifying data. Ratings received by the people you dealt with remain, detached from your identity, so their reputation is not distorted.

If a delivery is under way, if funds are still in escrow or if a dispute is open, the deletion is recorded but its execution is deferred until the situation is settled. You are informed of this in the support request opened by your confirmation.

Security

Passwords are stored hashed and are never readable by our team. Traffic between the app and our servers is encrypted in transit (TLS). Message text is encrypted at rest. Access by our team members to production data is individually attributed and recorded in a tamper-evident audit trail.

We will never ask you for your password, or for a one-time code, by email, by phone or in the app's messaging.

Updates to this policy

This policy is a versioned document: every change is reviewed and dated before publication, and the date of the last update appears at the top of the page.

VersionDateChanges
1.028 August 2026First publication, alongside the launch of the public website and the submission of the applications to the stores.
1.119 September 2026Registered office address. Added gender and profile photo, device position and positions shared in messaging, the Mapbox processor and consent to marketing communications. Accounting records retention extended to ten years.

Where a substantial change occurs — a new purpose, a new processor outside the European Union, a longer retention period — users are informed in the application before it takes effect.