Privacy Policy
What data Peercel collects, why, who it is shared with, how long it is kept, and how to exercise your rights.
Last updated : 19 September 2026
This policy describes how personal data is processed for users of the Peercel mobile application and the www.peercel.com website. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and the equivalent laws of the African countries where the service is offered, including the APDP in Côte d'Ivoire, the CDP in Senegal and the NDPR in Nigeria.
It is published at a stable URL and versioned in our code repository: every change goes through review and leaves a dated record.
Data controller and contact
The data controller is NIDEN IT SAS, a French simplified joint-stock company with its registered office at 51 rue du Pré Brochet, 95110 Sannois, France.
- Postal address: NIDEN IT SAS, 51 rue du Pré Brochet, 95110 Sannois, France.
- Contact for any question about personal data, including requests to exercise your rights: privacy@send.peercel.com.
- General contact: contact@send.peercel.com.
Peercel has not appointed a data protection officer: the service meets none of the mandatory designation criteria of Article 37 GDPR. Privacy requests are handled by the team reachable at the address above, which replies within one month.
You may lodge a complaint with the French data protection authority (CNIL, 3 place de Fontenoy, 75007 Paris) or with the data protection authority of your country of residence.
Data collected by the mobile application
The table below is the reference description of our processing activities. It is what must match, point by point, the Data safety declarations on our Google Play listing and the Privacy Nutrition Labels on our App Store listing.
| Data | Purpose | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Identity and contact details: first name, last name, gender, date of birth, profile photo, email address, phone number, postal address | Create and manage the account, enable matching, contact the user about a delivery | Performance of the contract (Art. 6.1.b) | Peercel; database host; transactional email provider | Lifetime of the account, then 30 days before permanent anonymisation |
| Identity document (front/back) | Verify identity before sensitive operations, prevent fraud and impersonation, meet our anti-money-laundering obligations | Legal obligation (Art. 6.1.c) and legitimate interest in preventing fraud (Art. 6.1.f) | Peercel (manual review by our team); file storage host | 5 years from the end of the relationship, under anti-money-laundering obligations |
| Location: declared departure and arrival cities; device position, if you allow it, when searching; position you choose to share in messaging | Suggest geographically compatible travellers and parcels, rank results by proximity, make it easier to arrange the handover meeting | Performance of the contract (Art. 6.1.b) | Peercel; database host; Mapbox (converting addresses into coordinates, displaying maps); the other party to the conversation, for a shared position | Search position: used for ranking, without being saved to your account; cities: lifetime of the listing; shared position: kept with the message containing it |
| Photos: parcel contents, evidence submitted in a dispute | Describe the parcel, evidence its condition, investigate a dispute | Performance of the contract (Art. 6.1.b) | Peercel; the other party to the delivery; file storage host | Lifetime of the listing; 5 years for evidence filed in a closed dispute |
| Phone number used for one-time codes (OTP) at sign-up and handover | Verify the number, send the recipient the parcel handover code | Performance of the contract (Art. 6.1.b) | Africa's Talking and Twilio (SMS delivery) | Lifetime of the account; the codes themselves expire within minutes |
| Payment data: bank details, card number, mobile money identifier | Collect the sender's payment, pay out funds to the traveller | Performance of the contract (Art. 6.1.b) | Stripe, Flutterwave, CinetPay. This data is never stored by Peercel: it is entered with the payment provider, which returns only a transaction identifier and a status | With the provider, under its own policy; at Peercel, only the identifier and status, kept for 10 years under accounting obligations |
| In-app messaging: content of conversations between sender and traveller (text, photos, shared positions) | Allow the meeting to be arranged without exchanging personal contact details; serve as evidence in a dispute | Performance of the contract (Art. 6.1.b) | Peercel; database host. Message text is encrypted at rest | Lifetime of the account; content is replaced by a neutral placeholder at anonymisation |
| Device push notification token | Send app notifications (offer received, payment confirmed, parcel delivered) | Performance of the contract (Art. 6.1.b) | Expo and the Apple (APNs) and Google (FCM) notification services | Until the device signs out or the app is uninstalled |
| Device identifiers, app version, operating system | Secure sessions, diagnose incidents, adapt the interface | Legitimate interest in keeping the service secure and working (Art. 6.1.f) | Peercel; Sentry (error reports) | 90 days |
| Crash reports and error traces | Identify and fix defects in the application | Legitimate interest in maintaining a reliable service (Art. 6.1.f) | Sentry, hosted in the European Union | 90 days |
| Delivery history, ratings and comments left | Compute the trust level, display reputation, arbitrate disputes | Performance of the contract (Art. 6.1.b) | Peercel; other users, for the public part of the profile | 5 years; ratings received by the people you dealt with remain, detached from your identity |
| First name, last initial, cities of departure and arrival, content of the review | Publish testimonials on the public website | Consent (Art. 6.1.a), withdrawable at any time | Public | Until consent is withdrawn, effective within 7 business days |
| Choice regarding marketing communications | Send you newsletters and offers, only if you have agreed to it | Consent (Art. 6.1.a), withdrawable at any time from the app profile | Peercel; transactional email provider | Until consent is withdrawn or the account is deleted |
| Financial records: transactions, balance movements, withdrawals | Keep the accounts, produce supporting documents, meet anti-money-laundering obligations | Legal obligation (Art. 6.1.c) | Peercel; payment providers; competent authorities upon valid legal request | 10 years under accounting obligations, with no early deletion possible |
Peercel does not collect: your contacts, your calendar, health data, political or religious opinions, sexual orientation, or any biometric data. No data is sold, rented or transferred to third parties for advertising purposes.
Mapping to the Google Play and App Store forms
The declarations made to the stores describe exactly the processing set out in the table above. Here is the mapping, category by category.
| Form category | Google Play — Data safety | App Store — Privacy Nutrition Label | Declared use |
|---|---|---|---|
| Personal information | Name, email address, phone number, address, other info — collected, linked to the user | Contact Info, Identifiers — linked to identity | App functionality, account management |
| Identity documents | Official ID document and photo — collected, linked to the user | Sensitive Info — linked to identity | Fraud prevention, regulatory compliance |
| Location | Approximate and precise location — collected, linked to the user | Coarse Location, Precise Location — linked to identity | App functionality (geographic matching) |
| Photos | Photos — collected, linked to the user | User Content — linked to identity | App functionality |
| Messages | In-app messages — collected, linked to the user, encrypted in transit | User Content — linked to identity | App functionality |
| Financial information | Payment info — not collected by the application; purchase history collected and linked to the user | Purchases — linked to identity; Financial Info not collected by us | App functionality, accounting obligations |
| Device identifiers and diagnostics | Device identifiers and crash logs — collected, linked to the user | Identifiers, Diagnostics — linked to identity | Analytics, fraud prevention, security |
| Advertising tracking | None — no data is shared for advertising purposes | Data Not Used to Track You | Not applicable |
All data travels encrypted (TLS). You can request the deletion of your account and your data from the Delete my account page, without installing the application.
Processors and transfers outside the European Union
Peercel relies on the following processors. Each is bound by a data processing agreement compliant with Article 28 GDPR.
| Processor | Role | Processing location | Transfer mechanism |
|---|---|---|---|
| OVH | Application server hosting | France | No transfer outside the EU |
| Supabase | Database and file storage | European Union (EU region) | No transfer outside the EU for production data |
| Sentry | Error and crash reporting | European Union (EU region) | No transfer outside the EU |
| Resend | Transactional email delivery | United States | European Commission standard contractual clauses |
| Africa's Talking, Twilio | SMS delivery | Africa, United States | Standard contractual clauses |
| Stripe | Card and bank transfer payments, business payouts | European Union and United States | Standard contractual clauses |
| Flutterwave, CinetPay | Mobile money payments and payouts | Africa | Standard contractual clauses |
| Mapbox | Mapping and converting addresses into coordinates | United States | Standard contractual clauses |
| Expo, Apple, Google | Push notification delivery | United States | Standard contractual clauses |
Judicial or administrative authorities may receive certain data upon a valid legal request. No other sharing takes place.
Your rights and how to exercise them
You have the following rights over your personal data.
- Access and portability — obtain a copy of your data in a machine-readable format. The app offers a full export from your profile; you can also request it at privacy@send.peercel.com.
- Rectification — correct inaccurate data. Most fields can be edited directly in your profile.
- Erasure — request the deletion of your data. The procedure is described on the Delete my account page and does not require installing the app.
- Restriction and objection — request that processing be frozen, or object to processing based on our legitimate interest.
- Withdrawal of consent — where processing relies on your consent, withdraw it at any time, without affecting processing already carried out.
- Complaint — refer the matter to the CNIL or to the data protection authority of your country.
Any request sent to privacy@send.peercel.com receives a reply within one month, extendable by two months for complex requests, in which case you are informed. We may ask for proof of identity where there is reasonable doubt about who is making the request.
Some rights have limits: accounting records must be kept for ten years and anti-money-laundering data for five years; they cannot be erased on request.
Retention, deletion and anonymisation
Retention periods appear in the table in section 2. They follow three rules.
- Account deletion. On a deletion request, the account is deactivated immediately: listings are withdrawn, sessions are closed, signing in is no longer possible.
- Anonymisation at day 30. Thirty days later, an automated job permanently overwrites identifying data: first name, last name, email, phone, address and date of birth are overwritten, identity documents are erased, message content is replaced by a neutral placeholder. This thirty-day window is deliberate: it allows a request made in error to be reversed, and an ongoing dispute or payment to be settled, before the data disappears.
- What remains after anonymisation. Financial records are kept for ten years under our accounting obligations, and audit logs for five years under our regulatory obligations, without directly identifying data. Ratings received by the people you dealt with remain, detached from your identity, so their reputation is not distorted.
If a delivery is under way, if funds are still in escrow or if a dispute is open, the deletion is recorded but its execution is deferred until the situation is settled. You are informed of this in the support request opened by your confirmation.
Security
Passwords are stored hashed and are never readable by our team. Traffic between the app and our servers is encrypted in transit (TLS). Message text is encrypted at rest. Access by our team members to production data is individually attributed and recorded in a tamper-evident audit trail.
We will never ask you for your password, or for a one-time code, by email, by phone or in the app's messaging.
Updates to this policy
This policy is a versioned document: every change is reviewed and dated before publication, and the date of the last update appears at the top of the page.
| Version | Date | Changes |
|---|---|---|
| 1.0 | 28 August 2026 | First publication, alongside the launch of the public website and the submission of the applications to the stores. |
| 1.1 | 19 September 2026 | Registered office address. Added gender and profile photo, device position and positions shared in messaging, the Mapbox processor and consent to marketing communications. Accounting records retention extended to ten years. |
Where a substantial change occurs — a new purpose, a new processor outside the European Union, a longer retention period — users are informed in the application before it takes effect.