Privacy Policy & Permissions
How L-LINK collects, uses, and protects your personal information when you use the Local Link rider application.
How L-LINK collects, uses, and protects your personal information when you use the Local Link rider application.
This Privacy Policy is written in plain language and complies with the Protection of Personal Information Act, 2013 (POPIA) of South Africa. By downloading and using the L-LINK rider app you agree to the practices described here.
The responsible party for your personal information
L-LINK (trading as Local Link) is a South African e-hailing platform connecting riders with independent driver-partners. We operate the Local Link rider application available on Android and iOS.
| Company | L-LINK (Pty) Ltd |
| Trading As | Local Link |
| Country | Republic of South Africa |
| Information Officer | privacy@llink.co.za |
| POPIA Regulator | Information Regulator of South Africa — www.justice.gov.za/inforeg/ |
Every permission the L-LINK rider app requests — and the specific reason
The app requests the following device permissions. We only request permissions that are directly necessary for the service. You can manage these in your device settings at any time, though disabling some will limit app functionality.
Precise Location
ACCESS_FINE_LOCATION
Used to detect your exact pickup point, show your position on the map, calculate route distance and fare estimates, and allow the driver to navigate to you accurately. Location is shared with the assigned driver in real time during a trip.
RequiredApproximate Location
ACCESS_COARSE_LOCATION
Requested alongside precise location as a fallback. Used to determine your general area for service availability checks and to pre-load nearby map tiles before precise GPS fixes.
RequiredPush Notifications
POST_NOTIFICATIONS
Allows the app to deliver real-time alerts: driver accepted your request, driver is nearby, trip has started, payment confirmed, and promotional offers. Uses Firebase Cloud Messaging (FCM). You can opt out in device notification settings.
RequiredInternet Access
INTERNET
Required for all core app functionality: connecting to Firebase (authentication, real-time ride tracking, Firestore database), loading map tiles from Google Maps, processing payments via Paystack, and receiving push notifications.
RequiredNetwork State
ACCESS_NETWORK_STATE
Allows the app to check whether your device is connected to the internet before attempting to load data, preventing unnecessary errors and providing offline status messages.
SystemCamera & Photo Library
CAMERA / READ_MEDIA_IMAGES
Used only when you choose to upload a profile photo. The app opens your camera or photo gallery via the system picker — we never access your camera or photos in the background. Profile photos are stored securely on Firebase Storage.
OptionalVibration
VIBRATE
Used to vibrate the device when important notifications arrive (driver accepted, driver arrived, trip completed) to ensure you don't miss critical updates even when your phone is on silent.
SystemWake Lock
WAKE_LOCK
Keeps the processor briefly awake when a background notification arrives (e.g. driver accepted your ride request) so the app can process and display the alert even when the screen is off.
SystemBoot Completed
RECEIVE_BOOT_COMPLETED
Allows the notification service to re-register with Firebase Cloud Messaging after your device restarts, ensuring you continue to receive ride updates and alerts without needing to manually reopen the app.
SystemYou are in control. All permissions marked Optional can be denied without affecting your ability to book rides. Permissions marked Required are necessary for the core service. System permissions are granted automatically by Android and do not require your explicit approval.
What data we gather and from where
| Category | Specific Data | Source | Purpose |
|---|---|---|---|
| Identity | Full name, profile photo | You provide it | Account identification, shown to your driver |
| Contact | Mobile phone number, email address | Registration | OTP authentication, account recovery, service communications |
| Location | GPS coordinates (pickup, destination, live trip tracking) | Device sensors | Matching you with a driver, navigation, fare calculation |
| Trip | Pickup/drop-off addresses, route, distance, duration, fare, timestamps | App usage | Service delivery, billing, trip history, dispute resolution |
| Payment | Payment method (cash/card/wallet), transaction reference | App & Paystack | Processing and recording payment. Card details are handled exclusively by Paystack — we never store raw card numbers. |
| Device | FCM token, device type, OS version, app version | Automatic | Delivering push notifications, debugging, compatibility |
| Usage | Screens visited, actions taken, session timestamps | App analytics | Improving the app, identifying errors |
| Ratings | Star rating and optional comment for drivers | You provide it | Quality control, driver performance monitoring |
We do not collect: precise background location when the app is closed, contacts, call logs, SMS content, biometrics, financial account details, or any sensitive personal information beyond what is listed above.
Our lawful basis for processing under POPIA
Under POPIA, our lawful grounds for processing are: performance of a contract (the ride service), legitimate interest (safety, fraud prevention), legal obligation (tax records), and consent (marketing communications).
Third parties who may receive your information
| Recipient | Data Shared | Purpose |
|---|---|---|
| Assigned Driver | First name, profile photo, pickup location, destination area | To enable the driver to navigate to you and identify you |
| Google (Maps & Firebase) | Location data, usage analytics, FCM tokens | Map rendering, real-time database, push notifications, authentication |
| Paystack | Transaction amount, payment method reference | Secure payment processing. Governed by Paystack's privacy policy. |
| L-LINK Admin Team | Trip records, account details (access-controlled) | Customer support, dispute resolution, platform operations |
| Law Enforcement | As legally required | Compliance with lawful orders or to protect safety |
We do not sell your personal information to any third party. We do not share your data with advertisers or data brokers.
How long we keep your information
| Data Type | Retention Period | Reason |
|---|---|---|
| Account & profile | Until account deletion + 30 days | Account recovery window |
| Trip records | 5 years | South African tax and consumer protection law |
| Payment records | 5 years | VAT Act and SARB requirements |
| Location history | 90 days rolling | Dispute resolution and safety investigations |
| Chat messages | 30 days after trip completion | Dispute resolution |
| Push notification tokens | Until app uninstall or token refresh | Service delivery |
| Marketing consent | Until consent withdrawn | Compliance with POPIA consent rules |
When the retention period expires, data is securely deleted from our Firebase databases. Backups are purged within 30 days thereafter.
Technical and organisational security measures
The Protection of Personal Information Act, 2013 gives you the following rights
Right to Access
Request a copy of the personal information we hold about you
Right to Correct
Ask us to correct inaccurate or outdated personal information
Right to Delete
Request deletion of your account and associated personal data
Right to Object
Object to processing of your data for direct marketing at any time
Data Portability
Request your trip and account data in a structured, machine-readable format
Right to Restrict
Ask us to limit how we use your data while a complaint is being investigated
To exercise any of these rights, contact our Information Officer at privacy@llink.co.za. We will respond within 30 days as required by POPIA. If you are unsatisfied with our response you may lodge a complaint with the Information Regulator of South Africa.
Our policy regarding minors
The L-LINK rider app is intended for users who are 18 years of age or older. We do not knowingly collect personal information from persons under 18. If you believe a minor has created an account, please contact us immediately at privacy@llink.co.za and we will delete the account and associated data promptly.
How we notify you of updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes we will:
Continued use of the app after the effective date constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account at any time.
Questions about your privacy, data requests, or complaints?
Our Information Officer is here to help.
We aim to respond to all privacy requests within 5 business days.
Formal POPIA requests will receive a full response within 30 days.