1. Scope
This notice applies to the 360 Prime Express public website, its customer delivery-request flow, the separate business delivery enquiry form, the customer and operational mobile app, and the backend services that support delivery requests. Third-party services such as Hubtel and Paystack apply their own privacy terms when they provide messaging or hosted transaction services.
2. Information we collect
Public website
The public pages do not use analytics, advertising pixels, or third-party fonts. Delivery details and business-form details are not stored in local storage or session storage. After successful phone verification, the site uses essential signed cookies for request completion and order-scoped tracking as described below. Our hosting and security providers may process standard network information, such as an IP address, user agent, requested path, and time, to deliver and protect the service.
Website customer delivery requests
While you build a request, selected location references, pickup or drop-off order, item category, and any item description are kept in the current page's memory. They are sent to the server when you ask for a quote preview so the server can resolve trusted locations, validate coverage, and calculate pricing. The application does not save that preview as an anonymous delivery enquiry. Closing or refreshing the page before submission clears the in-page draft, although infrastructure providers may retain limited request metadata in security logs.
Your Ghana phone number and consent are sent only when you ask for a four-digit verification code. The verification service processes the normalised number, challenge timing and status, attempt counters, and keyed phone and network identifiers. Failed verification counters are keyed to a pseudonymous phone identifier and enforce a cumulative daily limit even when replacement codes are requested. The application database stores a keyed digest of the one-time code rather than the plain code. Hubtel processes the phone number and message to deliver the SMS.
Entering a phone number or requesting a code does not create an account. After the correct code is verified, the service creates a customer account for a new number or reuses the existing account for a recognised number. The profile records the verified phone number, account status, consent time, and applicable terms version.
Successful verification sets a signed __session request cookie that expires after 15 minutes. When you submit, it is replaced by an order-scoped tracking cookie that expires after no more than 30 days and permits this browser to view only that submitted enquiry and its resulting order without a second login. In production both uses are marked HttpOnly, Secure, and SameSite=Strict with Path=/, so page scripts cannot read them and browsers restrict when they are sent. The signed payload contains bounded account, enquiry, and order identifiers plus an expiry; it does not contain the phone number, route, one-time code, or payment credentials. Submission stores the account-linked delivery enquiry, trusted stops, item details, quote or review status, timestamps, consent record, the selected payment method and status, and—if online checkout is prepared—the Paystack transaction reference.
Business delivery enquiries
The form collects business name, contact name, Ghana phone number, optional business email, usual pickup area, expected weekly delivery volume, optional notes, and your consent. Do not put passwords, one-time codes, payment credentials, national identification numbers, or unrelated personal details in the notes.
For abuse prevention, the application database stores a keyed, pseudonymous network fingerprint and short-lived request counters rather than a raw IP address. Infrastructure providers may still process network metadata in their security logs.
Mobile app and deliveries
The app may process account and verified phone information, name, saved addresses, trusted pickup and drop-off coordinates, item details and optional photos, delivery contact number, quotes, payment status and provider reference, assigned rider information, order status history, chat messages and images, device notification tokens, and support actions.
3. How information is used
- Validate delivery-only routes, provide a quote preview, and create a delivery enquiry when you submit.
- Send and verify one-time codes, create or reuse the correct customer account, and protect the short completion session.
- Review and respond to a separate business delivery setup request.
- Create paid orders, operate deliveries, send milestones, and support order conversations.
- Prevent abuse, investigate errors, protect users, and maintain service integrity.
- Meet legal, accounting, security, and dispute-resolution obligations where applicable.
4. How information is shared
Information is shared only as needed to provide and protect the service. Relevant recipients may include assigned riders, authorised dispatch or support staff, and infrastructure or transaction providers acting for the service. Hubtel supports phone verification, Paystack hosts payment checkout, and Firebase/Google Cloud supports application infrastructure and route pricing. We do not sell delivery-request or business-enquiry details or use them for third-party advertising.
5. Business-form retention and separation
The business delivery form is separate from the customer delivery-request and phone-verification flow. It does not create a customer account or book a delivery. A new business enquiry receives a deletion date 180 days after submission, and a scheduled server process removes expired records. Short-lived anti-abuse counters are also removed after they are no longer required. If a business relationship begins, information needed for that relationship may be recorded separately and retained under the operational account policy.
6. Delivery, verification, and account retention
A route preview is not retained in the application database as an anonymous delivery enquiry. The one-time code expires after 10 minutes, and its stored digest is removed immediately after successful verification. Expired challenge records are removed by a daily scheduled process. Pseudonymous phone and network quota records receive a deletion time 48 hours after creation and are removed after expiry; an additional managed database expiry policy may be enabled as defence in depth. These security records do not extend the usable code.
The pre-submission website session expires after 15 minutes; the replacement order-scoped tracking session expires after no more than 30 days. Access also fails if the account is disabled or no longer active. Once submitted, account, delivery-enquiry, order, payment-status, and delivery-history records are retained only as long as reasonably needed for service, support, fraud prevention, accounting, and applicable legal obligations. Retention requirements may differ by record type. Optional uploaded images and chat content should not contain information unrelated to the delivery.
7. Account deletion
A customer may use the account deletion page without first signing in. The page sends a one-time code to the account phone, then creates a signed, HttpOnly deletion session for ten minutes after successful verification. Deletion is blocked while an order remains active so deliveries, recipients, riders, and payments are not left without an accountable customer.
After confirmation, the service permanently removes the customer authentication identity, profile, saved addresses, notification tokens, temporary checkout and quote records, account-linked item photos, delivery conversations, attachments, and related verification records. Where completed transaction records must remain for payment reconciliation, accounting, fraud prevention, or legal obligations, personal identity, phone, route, coordinates, notes, and comments are removed and the record is marked as belonging to a deleted customer. Staff, rider, and business account closure requires assisted review because operational responsibilities may need to be transferred.
8. Security
Controls include digest-protected and attempt-limited phone codes, short-lived signed website sessions, exact-origin checks, trusted server-side location resolution, role-based data access, server-only pricing and order transitions, hosted payment, signed webhooks, strict input validation, rate limits, restrictive website security headers, and server-only storage for customer and business requests. No system can guarantee zero risk; controls and dependencies require ongoing review.
8. Your choices and requests
You can leave the customer request before phone verification, refresh the page to clear its in-memory draft, or choose not to submit the separate business form. For a question about an account, delivery, correction, or deletion request, use the official Support path inside the app so the request can be connected to your verified account. We may need to verify identity and retain information where a legitimate operational or legal requirement applies.
9. Children
The service is not designed to collect business enquiries from children. A parent or guardian should contact official support if they believe a child submitted personal information without appropriate permission.
10. Changes to this notice
Material changes will be published on this page with a new effective date. Review the current notice before submitting information.
11. Contact
Use the authenticated Support request inside the app for an account or delivery privacy matter. For a business enquiry, use the protected business delivery form and avoid including sensitive information in the notes.