Who we are and what this covers
Scout is an address-verification service operated by Dojah ("Dojah", "we", "us"). Businesses ask us to confirm that a person really lives or works at an address, and a network of vetted field agents visits the address, captures evidence and returns a verdict.
This policy explains how we handle personal data in connection with:
- the Scout agent app, used by field agents;
- this website; and
- the verification service we provide to our business clients, which involves information about the people whose addresses are verified ("applicants").
Dojah is the data controller for agents' and website visitors' personal data. For applicants' data, our business client is the controller and Dojah acts as a data processor on the client's instructions; the client's own privacy notice governs why that verification was requested.
We process personal data in accordance with the Nigeria Data Protection Act 2023 and its regulations.
Information we collect from field agents
You can only use the Scout app after a Dojah operations team member has enrolled you. From enrolment onward we collect:
| Data | Where it comes from | Why |
|---|---|---|
| Name and mobile number | Entered by our operations team when you are recruited; confirmed by one-time code sent to your phone | To create your account, sign you in and contact you about work |
| Home address and territory | Typed by you, or taken from your phone's location when you choose "use my current location" | To match you to the area and state your jobs are drawn from |
| Location while working | Your phone's GPS at the moment you capture evidence, and when you open the job feed | To show distances, and to prove that evidence was captured at the address |
| Photos and evidence | Taken in the app at the address you are verifying, with time, location and integrity data attached | To produce the verification result the client is paying for, and to detect tampering |
| Device information | Your handset's identifiers, a device fingerprint, the app version, and a push-notification token | To bind your account to one device, to detect rooted or spoofed devices, and to send job notifications |
| Bank account details | Entered by you; the account name is confirmed with the bank | To pay you what you have earned |
| Identity details (BVN or NIN, and a selfie) | Entered by you, if and when we ask for an identity check | To confirm that you are who our records say. We store only a one-way, salted hash of the number, the name returned by the check, and the selfie. The number itself is never stored |
| Training and performance | Generated as you use the app: assessment scores, jobs completed, quality-review outcomes, trust score and tier | To decide which work you can take on and how it is reviewed |
| Session recordings | Recorded in the app by Microsoft Clarity: which screens you open, what you tap and scroll, and how long things take, associated with your name and mobile number | To find the places where the app is confusing or slow and fix them. Anything you type is masked before recording, and so are customers' addresses, applicants' details and evidence photos |
| Support and access requests | Sent by you through the app's "ask to be let in" form or by contacting us | To respond to you |
We do not collect data about you from data brokers or social networks.
Information about applicants
When a business client asks us to verify an address, it sends us the applicant's name, mobile number and the address to be checked. During the visit our agent may capture photographs of the premises and record what was found there. The verification result and this evidence are returned to the client that requested them.
We process this information only to perform the verification the client requested, to review the quality of our agents' work, and to prevent fraud. We do not use applicants' data for marketing and we do not sell it. Agents see an applicant's address and phone number only for a job they have claimed, and only until the job is closed.
If you are an applicant and want to exercise your rights over this data, please contact the business that requested the verification. If you contact us instead, we will help route your request and, where the law requires, act on it directly.
Website visitors
This website does not use cookies or analytics scripts. When you visit, our hosting provider (Cloudflare) processes your IP address and standard request information to serve the pages and protect against abuse. If you email us, we keep the correspondence.
Why we are allowed to use your data
We rely on the following lawful bases under the Nigeria Data Protection Act:
- Performance of a contract with you as an agent: creating your account, matching you to work, reviewing evidence and paying you.
- Legitimate interests: keeping the network honest (fraud and tamper detection, device binding, identity blacklisting), securing our systems, and improving the app (including session recordings).
- Legal obligations: keeping financial records of payments, and responding to lawful requests from authorities.
- Consent, where the law requires it — for example your phone's permission prompts for location, camera and notifications. You can withdraw these in your phone's settings; some features will then not work.
Who we share data with
We share personal data only with the parties needed to run the service:
- Our business clients receive the verification result and the evidence for the addresses they asked us to check. They do not receive agents' personal details beyond what the evidence itself shows.
- Dojah's identity and messaging services deliver one-time codes over WhatsApp or SMS and, when used, verify BVN/NIN and selfie matches.
- Google (Maps Platform and Firebase) turns addresses into map positions and delivers push notifications.
- Microsoft Clarity stores app session recordings, as described above.
- Cloud infrastructure providers (including Amazon Web Services and Cloudflare) host our systems and store evidence photos in encrypted storage.
- Banks and payment partners receive the account details needed to pay agents.
- Authorities, where we are legally required to disclose information, or to protect people from harm.
Some of these providers process data outside Nigeria. Where they do, we rely on the safeguards permitted by the Nigeria Data Protection Act, including contractual protections and transfers to countries with adequate protection.
We do not sell personal data.
How long we keep it
- Agent accounts: for as long as you are on the roster, and for up to 24 months after your account is closed, so that disputes about work and payment can be resolved.
- Evidence and verification results: for the period agreed with the client that requested them, then deleted.
- Payment records: for the period required by Nigerian financial and tax law.
- Identity hashes on the fraud list: if an account is closed for fraud, the one-way hash of the identity number is retained indefinitely so the same person cannot re-register with a new phone. The hash cannot be turned back into the number.
- Session recordings: retained by Microsoft Clarity for its standard period, currently 30 days for recordings.
How we protect it
All traffic between the app, this website and our servers is encrypted in transit. Identity numbers are never stored, only salted one-way hashes. Evidence is uploaded directly to encrypted storage using short-lived, single-purpose links, and each evidence bundle carries a cryptographic signature so tampering can be detected. Access to production data is restricted to staff who need it, and every operations decision on an agent's account is logged with who made it.
No system is perfectly secure. If we discover a breach that puts your rights at risk we will notify the Nigeria Data Protection Commission and, where required, you, within the timelines the law sets.
Your rights
Under the Nigeria Data Protection Act you can ask us to:
- access the personal data we hold about you;
- correct data that is inaccurate;
- delete your data, where we no longer have a lawful reason to keep it;
- restrict or object to certain processing, including processing based on legitimate interests;
- receive a copy of data you gave us in a portable format; and
- withdraw consent, where consent is the basis we rely on.
To exercise any of these, email hello@dojah.io from the phone number or email we have on record, or ask your operations contact. We will respond within the time the law allows and may ask you to confirm your identity first.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission if you believe we have handled your data unlawfully.
Children
Scout agents must be at least 18 years old. We do not knowingly collect data from anyone under 18, and we will delete any such data we discover.
Changes to this policy
We will update this page when our practices change. The effective date at the top tells you when it last changed. For material changes that affect agents, we will also tell you in the app.
Contact
Questions about privacy at Scout go to hello@dojah.io. Postal correspondence: Dojah, Lagos, Nigeria.