Legal
Privacy Policy
Last updated: Draft — based on the washerX mobile app as inspected for this website.
This page describes how the washerX mobile application handles information, based on what is implemented in the current app. It is written for customers and service providers who use washerX.
How to read this policy
washerX is a car-wash booking app. Customers request a wash at a chosen location. Service providers (“washers”) receive those jobs, manage them, and get paid through the app.
Each section is marked as either verified in the mobile app or needing business or backend confirmation. Verified means the behaviour appears in the current application code or configuration. Needs confirmation means the public-facing legal detail is not present in the app and must not be treated as a final legal statement.
Who we are
The mobile app is published under the name washerX, with application identifiers com.washrmanagementsteam.washerX on Android and iOS. That identifier is a technical package name. It is not a confirmed legal entity name.
Still to confirm
- TODO: legal entity name
- TODO: registered address
- TODO: privacy contact email
- TODO: data controller / operator for the jurisdiction where washerX operates
Account information
You can sign in or create an account from the same screens. The app stores a session (access token, refresh token, and a local user profile) on the device after a successful sign-in.
The local profile can include name, email, avatar, phone number, and role (customer or service provider). Providers may also supply a business name during setup.
- Google Sign-In: the app requests a Google ID token and sends it to the washerX API to create or resume a session.
- Email: the app can send a one-time code to your email and verify that code with the API.
- Phone: after sign-in, the app can send a one-time code by SMS or WhatsApp, then confirm it with the API.
- Apple Sign-In appears on iOS, but the current app reports that Apple Sign-In is not available yet.
- You choose a role — Customer or Service provider — and the app says you can switch roles later from settings.
Customer information
If you use washerX as a customer, the app uses your account plus the details needed to place and follow a booking.
- Display name and email (and avatar when provided by sign-in).
- Phone number, once verified.
- Bookings: wash service, vehicle type, scheduled date and time, service address and coordinates, optional notes, selected washer, price, and status.
- Wallet balance and wallet transactions, including funding and booking payments.
- In-app notifications and a device push token when notifications are enabled on the device.
Service provider information
If you use washerX as a service provider, the app collects the account details above plus information needed to appear to customers, complete jobs, and receive payouts.
- Provider profile: name, email, business name, bio, avatar, availability (available or away), and vehicle types you wash.
- Base / service-area location used for nearby matching.
- National Identification Number (NIN) plus the first and last name on that NIN, submitted for identity verification. The app tells providers the NIN is not shown on the public profile.
- Nigerian bank account details for payouts (bank, account number, resolved account name). The app creates a Paystack transfer recipient from this account.
- Bookings assigned to you, job status updates, earnings, and withdrawal history.
- Live location while a job is marked in progress, so the customer can track the washer.
Still to confirm
- The client comments that the raw NIN is sent only for the verification request and is not stored on the device after that request. Whether the backend retains NIN data needs confirmation.
Bookings
A customer booking is created through the washerX API after the customer selects a washer, vehicle type, service, date and time, and location, then pays from the wallet.
Booking status in the app includes: pending payment, requested, accepted, in progress, completed, released, rejected, and cancelled.
When a provider marks a wash complete, the customer is asked to confirm. Confirming releases the held payment to the washer.
Location
The app requests location permission. The stated purpose is to find nearby washers and to set a provider’s service area.
Customers use device location to search nearby providers within a chosen radius (5 km, 15 km, or 30 km). Booking addresses are entered with Google place search or geocoding so the job has coordinates.
Providers share a base location for matching. During an in-progress job, the provider app can broadcast live location over a tracking connection so the customer can follow the washer on a map.
Provider live tracking
Live tracking uses a Socket.IO connection on the API host under a /tracking namespace. The customer Track screen shows the washer when a job is in progress. The map can also draw a road route using Google Directions, with a straight-line fallback if that request fails.
Wallet and payments
Customers have a spending wallet. Funding starts in the app and opens a Paystack checkout. The app treats a Paystack webhook (on the backend) as the confirmation that funding succeeded.
Paying for a booking debits the customer wallet. The app describes this as escrow: the amount stays held until the customer confirms the completed wash, then it can be released to the provider.
Providers see earnings, an available balance, and a transaction ledger. Withdrawals go to the saved Nigerian bank account through a payout request.
Still to confirm
- TODO: confirm the Paystack merchant / legal name that appears on customer statements.
- TODO: confirm how long payment records are retained.
Google Maps, Places, and Directions
The app uses Google Maps on device to show maps and markers. It uses Google Places to suggest addresses and resolve coordinates, and Google Directions to draw a road route while tracking.
When you type an address or view a map, that interaction is processed by Google under Google’s own terms and privacy policy, in addition to this page.
Still to confirm
- TODO: confirm the Google Cloud project owner and any data-processing terms in place with Google.
Notifications
The app has an in-app notification inbox (booking updates, washer progress, payments, new jobs, earnings, verification, and system messages).
The device can register an FCM or APNs token with the washerX API so the backend can send push notifications. Android builds may include a Firebase google-services file for FCM. iOS uses Apple Push Notification service through the Expo notifications integration.
Still to confirm
- The profile screen includes a notifications toggle. Whether that toggle is stored only on the device or also on the server needs confirmation.
Data stored on your device
The app uses on-device storage (MMKV) for session tokens, the cached user profile, an onboarding-completed flag, a cached provider bank record, a local NIN verification status, and the registered push token (with a short cooldown).
Signing out clears the auth session and signs out of Google on the device. The onboarding-completed flag is described as surviving logout until the app is reinstalled.
Still to confirm
- TODO: confirm what the washerX API stores, where it is hosted, and how long each category is retained.
Who else receives information
From the mobile app, information is sent to the washerX API and to the following services the app is built to call:
- Google — Sign-In, Maps, Places, and Directions.
- Paystack — customer wallet funding checkout and provider payout recipients / withdrawals.
- Firebase Cloud Messaging and Apple Push Notification service — device push delivery.
- The SMS or WhatsApp channel used to deliver phone one-time codes (the specific messaging vendor is not named in the app).
Still to confirm
- TODO: name the SMS / WhatsApp OTP vendor if one is contracted.
- TODO: list any other processors used only on the backend (hosting, email OTP delivery, NIN verification bureau, analytics).
Account deletion
Customers and service providers can delete an account from Profile in the washerX app. The app asks the washerX backend to deactivate the signed-in account and then signs you out. The app says you can later sign up with the same email as a new account.
Deletion can be refused while a booking is in progress. A public explanation of the process is on this website at /delete-account.
Still to confirm
- TODO: confirm how long payment, booking, and identity records are retained after deactivation.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or restrict use of your information, or to object to certain processing. The mobile app does not currently document those rights or a request process.
Still to confirm
- TODO: confirm the governing privacy law and the process for rights requests, including a contact channel.
Children
The app does not state a minimum age. washerX is built around bookings, payments, identity verification, and (for providers) NIN and bank accounts. Those flows are not designed for children.
Still to confirm
- TODO: confirm the minimum age and whether the service is offered only to adults.
International processing
Provider onboarding uses a Nigerian NIN and Nigerian bank accounts. Customer wallet amounts are handled in naira. Some connected services (including Google and Paystack) may process data on servers outside the country where you use the app.
Still to confirm
- TODO: confirm hosting region for the washerX API and any cross-border transfer terms.
Changes to this policy
When this policy is formally adopted, updates should be posted on this page with a new “Last updated” date. The mobile app currently links to a Privacy Policy in text only; it does not open a hosted policy URL yet.
Still to confirm
- TODO: decide how users will be notified of material changes.
Contact
The app asks providers to “contact support” if NIN verification keeps failing, but it does not publish an email address, phone number, or office address.
Still to confirm
- TODO: privacy email
- TODO: support email or in-app support channel
- TODO: mailing address if required