Chat with us on WhatsApp

Privacy Policy

Last updated: 20 August 2026

This document covers the Mamastops app and the Mamastops web platform. Other Mamastops privacy policies:

This policy explains what personal information Mamastops collects when you use the Mamastops app for Android and iOS — listed on the stores as Mamastops, identifier com.mamastop.app — and the Mamastops web platform, how we use it, who we share it with, and the rights you have over it.

If anything here is unclear, write to us at support@mamastops.com — we will answer in plain language.

1. Who we are

Mamastops is a B2B cashless logistics platform for cross-border trucking across Southern and East Africa. We help customers place and manage the orders that move their goods, and we help transporters and their drivers plan trips, pay for fuel, parking, tolls, and border clearance at our partner stations, and stay connected with dispatch throughout the route — without carrying cash.

This platform / application is operated by multiple affiliated entities located in different countries. Depending on your country of residence or the services you use, your personal data may be collected, processed, and managed by the relevant local entity responsible for providing services in your jurisdiction.

Our operating entities are:

  • Zambia — MAMASTOP LOGISTICS SOLUTIONS LIMITED
  • Tanzania — Mamastops Logistics Solutions Tanzania Ltd
  • Rwanda — Mamastop Logistics Solutions Ltd
  • South Africa — Mamastops Logistics Solutions South Africa (Pty) Ltd
  • Mozambique — Mamastop Logistics Solutions LDA
  • General contact: support@mamastops.com.
  • Privacy / data-protection contact: support@mamastops.com (please use the subject line "Privacy"). If you are in Zambia and we cannot resolve your complaint, you may contact the Office of the Data Protection Commissioner under the Zambia Data Protection Act, 2021. Users in Tanzania, Rwanda, South Africa, or Mozambique should write to the same address and we will route the request to the relevant local entity.

2. Scope

This policy applies to:

  • the Mamastops app for Android and iOS, distributed on Google Play and the Apple App Store under the identifier com.mamastop.app;
  • the Mamastops web platform at mamastops.com and the APIs that the app talks to.

This policy does not apply to the websites or services of any partner station, shipper, or other third party we link to.

The app serves two kinds of business user, and what we collect depends on which you are: drivers, who use it on the road to carry out assigned trips and redeem services at partner stations, and customer teams, who use it to place and manage orders. You sign in the same way either way, and the home screen you land on follows your role. Where a section below applies to only one role, it says so.

3. What we collect

3.1 Information you give us

  • Account & contact: name, mobile country code and number — used to deliver one-time passwords (OTPs) and service messages over WhatsApp, with SMS as a fallback — and email address.
  • Profile: profile photo (stored on our servers).
  • Government IDs (drivers only): driver's licence number and passport number. We need these to confirm you are legally allowed to drive cross-border consignments. They are stored on our servers and are not shared with advertising or analytics providers.
  • Registration & company details: when you or your organisation register, we collect your company name, company registration number and its issuer, company type, tax identification number, and fleet size. Your email address and mobile number are each verified by a one-time password.
  • Bank account details (web platform only): account number, account name, account type, and the bank, branch, or routing code — collected on the Mamastops web platform, not in the mobile app, to pay you or your organisation and to reconcile wallet funding. Stored on our servers, never shared with advertising or analytics providers.
  • Uploaded documents (web platform only): images of vehicle, trailer, driver, identity, and company-incorporation documents, uploaded on the Mamastops web platform rather than in the mobile app. These are put through automated text recognition (OCR) so the details can be read off them rather than retyped, and a member of our team may review a document that fails automated checks.
  • Support correspondence: if you write to us through "Report a Problem" or by email, we keep the subject, body, and the reply trail.

3.2 Information we collect automatically while you use the app

  • Precise location, on the road (latitude, longitude, accuracy), collected while the app is in the foreground — via FusedLocationProvider on Android and Core Location on iOS. The current GPS fix is attached to authenticated requests to our API as an x-location-data header so dispatch and partner stations can confirm your truck's position relative to the planned route and verify QR-redeemed services. We never ask for background location — on Android we do not request the ACCESS_BACKGROUND_LOCATION permission, and on iOS we ask only for "While Using the App" access — so the app cannot track you when it is not open.
  • Approximate location from your IP address. Where a GPS fix is unavailable, the app asks a third-party service, ip-api.com, to tell it roughly which country and city your connection is in. Only your IP address is sent — the request deliberately carries no GPS coordinates, no account identifier, and no sign-in credentials.
  • Device & connection info (x-connection-data header on each request): device model, operating-system version, app version, language, timezone, platform. Server-side we also see the IP address your request came from. We use this for support ("which build is the user on?"), troubleshooting, and abuse / fraud detection.
  • App activity & performance: screens viewed, in-app events (such as "trip started" or "QR scanned"), and crash diagnostics. Collected via Google Firebase Analytics, Firebase Crashlytics, and Matomo, our self-hosted analytics service at track.mamastops.com. Matomo records your email address and your role alongside those events, so a support request can be traced to what actually happened on your account. We also use Firebase Remote Config to turn features on and off without shipping a new build — see Section 5.
  • Advertising identifier: on Android, Firebase Analytics collects the Google Advertising ID. We do not use it to show you ads or build an ad-targeting profile — we use it only for de-duplicating analytics events. You can reset or limit this ID at any time from your Android settings (Settings → Privacy → Ads). On iOS, we do not present the App Tracking Transparency prompt and do not collect the Identifier for Advertisers (IDFA).
  • Push notification token: the app asks permission to show notifications, and Firebase Cloud Messaging issues an opaque token for your install so that trip assignments, service alerts, and account messages can be delivered to that device. The token identifies the install, not you personally, and is not used for advertising. It is cleared from your device when you log out or uninstall the app, and any copy we hold is deleted when you delete your account.

3.3 Orders, consignments, and wallet activity

When you use the app to run your organisation's business, we record what you did so that the order can be fulfilled and so there is an auditable trail of who asked for what:

  • Orders you place — what was ordered, for which route, vehicle, or consignment, when, and under which account.
  • Order and consignment status that you view or that we send you, including tracking positions of the vehicles carrying your goods.
  • Wallet activity — the balances shown to you and the transactions drawn against them.

Most of this is your organisation's commercial data rather than data about you personally, but it is linked to the account that acted, so it is covered by this policy. Your organisation can see what its own users did.

3.4 Camera

The app uses your camera only locally, on your device, to scan QR codes at partner stations (fuel, parking, tolls). Camera frames are processed on-device by Google ML Kit and are not uploaded to our servers.

3.5 What we do not collect

  • Contacts, SMS messages, or calendar entries.
  • Microphone audio.
  • Background location — on either platform.
  • Biometric data.
  • We do not sell, rent, or trade any personal data, and we do not use it for third-party advertising.

4. How we use your information

We use the data above to:

  • Operate the platform / application. Authenticate you, assign trips and consignments, track the planned route, redeem services at partner stations via QR codes, store your documents, and let you contact support.
  • Take and fulfil orders. Record the orders you place, show their status and the related consignments, and show the wallet balances your organisation has given you sight of.
  • Register you and verify your business. Confirm your email and mobile number, read your uploaded documents, and check company registration and tax details.
  • Move money. Fund and debit wallets, disburse driver money, settle tolls and fuel, and pay out to the bank account on the account.
  • Comply with logistics regulations. Verify driver licensing and cross-border paperwork.
  • Keep the platform / application safe. Detect fraudulent redemptions, account takeover, and abuse.
  • Fix bugs and improve the platform / application. Crash reports and basic in-app event analytics.
  • Communicate with you. Send one-time passwords (OTPs) for sign-in over WhatsApp (SMS fallback), push notifications about trips, service announcements over WhatsApp / email, and replies to your support requests.

We do not use your data for advertising and we do not sell, rent, or trade it.

5. Who we share it with

We share data only with the service providers we need to run Mamastops, including:

  • analytics, crash-reporting, and push-notification providers;
  • cloud hosting and database providers;
  • WhatsApp Business, SMS, and OTP gateway providers — used to deliver one-time passwords for sign-in and operational messages to the mobile number on your account;
  • payment, mobile-money, and settlement providers — Airtel Mobile Money for driver disbursements, toll vendors, banks, and the fuel network, each receiving only the transaction and payee details needed to complete a payment;
  • ip-api.com, which sees only the IP address of the connection when the app asks it for a coarse locality.

These providers process only the data needed for their service and under appropriate confidentiality and data-protection terms. Details of a specific provider are available on request.

We may also share data when we are legally required to (a court order or a lawful request from a regulator, or to defend our legal rights), and with a successor entity in the event of a merger or acquisition (we will tell you before that happens).

6. International transfers

Mamastops operates across multiple African jurisdictions through the entities listed in Section 1. Some of our processors — notably Google (Firebase) and WhatsApp Business — operate data centres outside the country where your data is collected. When we send your data to them, we rely on the processor's contractual safeguards and on the lawful-transfer mechanisms permitted by the data-protection law of your local operating entity (for example, the Zambia Data Protection Act, 2021, or the South African Protection of Personal Information Act (POPIA)). If you are in a jurisdiction with stricter transfer rules (e.g. the EU/EEA under the GDPR), the same contractual safeguards apply and you keep the rights described in Section 8.

7. Lawful basis

We process your data on the following bases:

  • Contract — to deliver the service your organisation has contracted for: taking and fulfilling orders, assigning trips, redeeming services, and settling what is owed.
  • Legal obligation — to comply with logistics, transport, and cross-border regulations and to retain records as required by tax and accounting law.
  • Legitimate interest — fraud prevention, platform / application security, and product improvement, balanced against your privacy.
  • Consent — we ask you to accept these terms and this policy during registration, before the account is created, and we record that you did. Consent also covers anything optional we may introduce later, such as marketing messages. You can withdraw consent at any time by writing to support@mamastops.com; withdrawing it does not affect processing we must carry out under a contract or a legal obligation.

8. Your rights

You have the right to:

  • Access the personal data we hold about you and obtain a copy of it;
  • Correct data that is wrong or incomplete (you can edit most profile fields yourself in the app);
  • Delete your account and the personal data tied to it (see Section 9);

To exercise any of these rights, email support@mamastops.com with the subject line "Privacy". We will respond within 30 days of receiving your request.

9. How to delete your account

To delete your account and the personal data tied to it, email support@mamastops.com with the subject "Delete my account", from the email address or using the mobile number registered to the account. We may ask one question to confirm you own the account before we act — we will never ask for your password or a one-time password. We complete verified requests within 30 days.

Full instructions, including what is deleted and what we are required to keep, are at mamastops.com/delete-account. Uninstalling the app does not delete your account.

When you delete your account we:

  • log you out and clear your authentication tokens from the device;
  • delete any push notification token we hold for your installs;
  • delete or anonymise your profile, contact details, and document references;
  • retain a minimum amount of trip and transaction data only for as long as we are required to under logistics, tax, and accounting regulations (see Section 10).

10. How long we keep your data

We keep your data only for as long as we need it for the purposes described in this policy.

  • Account data (profile, contact details, documents) is kept while your account is active and removed after closure, subject to any legal hold.
  • Authentication tokens on your device are kept until you log out or delete the account.
  • Trip and transaction records are kept for as long as required for commercial-logistics, tax, and accounting record-keeping under applicable law.
  • Support correspondence is kept for a reasonable period after our last reply.
  • Analytics and crash data held by our service providers are kept according to their standard retention periods.

If a category is not listed above, we keep it only as long as needed for the purposes described in Section 4.

11. How we protect your data

  • All traffic between the platform / application and our servers is over HTTPS / TLS.
  • On the device, your authentication tokens are held in the platform's secure credential store — Android EncryptedSharedPreferences (AES-256-GCM) and the iOS Keychain.
  • On our servers, data is encrypted at rest and access is restricted to the engineering and operations staff who need it for their job.
  • We review our security posture regularly and require the same of our processors.

No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law.

12. Children

The Mamastops app is a business application — for licensed commercial drivers and for authorised staff of our customers — and is not directed to anyone under 18. We do not knowingly collect personal information from a child. If you believe a child has used the app, please contact support@mamastops.com and we will delete the account.

13. Changes to this policy

We will update this page when our practices change. Material changes will also be announced inside the app the next time you log in. The Last updated date at the top of this page tells you when the current version took effect.

14. Contact

Mamastops (see Section 1 for the local operating entity in your jurisdiction)

Email: support@mamastops.com