CrosContri

Privacy Policy

Last updated 3 August 2026

1. Who is responsible for your data

CrosContri Travel Ltd (RC 2105937), No. 42 Local Airport Road, Ikeja, Lagos, Nigeria is the data controller for personal data collected through www.croscontri.com. You can contact us about data matters at legal@croscontri.com.

CrosContri operates under the Nigeria Data Protection Act 2023 (NDPA). This policy describes our processing activities as required by the NDPA and the Nigeria Data Protection Commission (NDPC).

2. What data we collect and why

2.1 When you create an account

Data collected: Full name, email address, password (stored as a one-way hash — never in plain text).

Why: To create and manage your account and verify your identity.

Legal basis (NDPA §25): Performance of a contract (creating your account is necessary to use the service).

2.2 When you make a booking

Data collected: For each passenger: full name, date of birth, gender, nationality, passport number, passport expiry date. For the lead passenger: email address and phone number.

Why: To create a Passenger Name Record (PNR) with the Amadeus Global Distribution System, which is required by the airline to reserve your seat. Passport details must match your travel document exactly.

Legal basis (NDPA §25): Performance of a contract (a booking cannot be made without this data).

Passport numbers, dates of birth, and gender are sensitive personal data. We never return full passport numbers to the browser — only the last four digits are shown for verification purposes.

2.3 When you pay

Data collected: Payment reference, transaction status, amount, and timestamp.

Why: To record and verify your payment and link it to your booking.

Legal basis (NDPA §25): Performance of a contract.

Card details are entered directly on Flutterwave's payment page and are never transmitted to or stored by CrosContri. Flutterwave is responsible for the security of payment card data.

2.4 When you browse the site

Data collected: IP address, browser type, pages visited, time and date of visit, referring URL. Collected via server logs.

Why: To keep the platform secure, diagnose technical issues, and understand how people use the site so we can improve it.

Legal basis (NDPA §25): Legitimate interests (maintaining platform security and improving the service).

2.5 Saved passengers and routes

Data collected: Passenger details you choose to save to your account (same fields as 2.2), and origin/destination pairs you save as favourite routes.

Why: To allow you to book faster on future occasions. You can delete saved passengers and routes at any time from your profile.

Legal basis (NDPA §25): Your consent, which you give by choosing to save the information.

3. Who we share your data with

We do not sell your personal data. We share it only where necessary:

• Amadeus GDS — to create and manage your flight booking (PNR). Passport details and passenger information are transmitted to Amadeus as required to reserve a seat. Amadeus operates globally and is subject to its own data protection obligations.

• Flutterwave — to process your payment. Flutterwave receives your email and the transaction amount. Card details are entered directly on Flutterwave's secure page.

• Email service provider — to send booking confirmations, expiry notifications, and e-tickets. Your email address and booking details are shared for this purpose only.

• NDPC and Nigerian authorities — where we are required to disclose data by law.

We require all third parties who process data on our behalf to handle it in accordance with applicable data protection law.

4. Cross-border data transfers

Amadeus operates Global Distribution System infrastructure internationally, which means your booking data is transmitted outside Nigeria. These transfers are made under standard contractual clauses that require Amadeus to protect your data to a standard equivalent to the NDPA. By making a booking, you consent to this transfer as necessary for the performance of your contract with us.

5. How long we keep your data

• Account data: for as long as your account is active, and for up to 7 years after closure to comply with Nigerian tax and commercial record-keeping requirements.

• Booking records: 7 years from the date of travel, in line with financial record-keeping obligations.

• Passport and passenger details: retained with the booking record for the same 7-year period. Saved passengers you store voluntarily are kept until you delete them.

• Browsing and session data: 90 days, then deleted.

6. How we protect your data

• All data is transmitted over HTTPS (TLS 1.2 or higher).

• Passwords are hashed using bcrypt and never stored in readable form.

• Full passport numbers are never returned to the browser; only the last four digits are displayed.

• Access to personal data is restricted to authorised team members with a legitimate need.

• We do not log sensitive fields such as passport numbers or full card details.

7. Your rights under the NDPA 2023

Under the Nigeria Data Protection Act 2023, you have the following rights:

• Right to access — you can ask us what personal data we hold about you.

• Right to correction — you can ask us to correct inaccurate data.

• Right to deletion — you can ask us to delete your data where we no longer have a legal basis to hold it. Note that we may need to retain some data to comply with our legal obligations (see Section 5).

• Right to withdraw consent — where processing is based on your consent (e.g. saved passengers), you can withdraw it at any time by deleting the data from your account or contacting us.

• Right to object — you can object to processing based on legitimate interests.

• Right to data portability — you can ask for a copy of your data in a machine-readable format.

To exercise any of these rights, contact us at legal@croscontri.com. We will respond within 30 days. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng.

8. Children

CrosContri is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has been submitted without appropriate consent, please contact us immediately at legal@croscontri.com and we will delete it.

9. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. When we do, we will update the effective date at the top of this page. Material changes will be notified to you by email or by a notice on the platform.

10. Contact us

For any privacy-related questions, requests, or complaints, email legal@croscontri.com or write to Privacy, CrosContri Travel Ltd, No. 42 Local Airport Road, Ikeja, Lagos, Nigeria.