MedxGo Cookie Policy


Effective Date: June 24, 2026
Last Updated: June 24, 2026
Company: MedxGo Technologies Limited
Website: https://medxgoapp.com/
App: MedxGo Mobile Application (iOS & Android)
Jurisdiction: Federal Republic of Nigeria


TABLE OF CONTENTS

  1. Introduction and Scope
  2. What Are Cookies
  3. Legal Basis for Cookie Use
  4. Types of Cookies We Use
  5. Detailed Cookie Inventory
  6. Third-Party Cookies and Services
  7. Cookie Consent Mechanism
  8. Cookie Duration and Expiration
  9. How to Manage Cookies
  10. Cookie Use by User Type
  11. Cookies and Healthcare Data
  12. Cross-Border Cookie Transfers
  13. Cookie Security Measures
  14. Children's Privacy and Cookies
  15. Updates to This Cookie Policy
  16. Contact Information
  17. Regulatory Compliance

This Cookie Policy ("Policy") explains how MedxGo Technologies Limited ("MedxGo," "we," "us," or "our") uses cookies and similar tracking technologies on our website (https://medxgoapp.com/), mobile application, and any affiliated digital platforms (collectively, the "Platform").

This Policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and the guidelines issued by the Nigeria Data Protection Commission (NDPC). As MedxGo expands operations across Africa, we also adhere to applicable data protection laws in each jurisdiction, including the General Data Protection Regulation (GDPR) where relevant to our international users.

By accessing or using the MedxGo Platform, you consent to the use of cookies as described in this Policy, unless you have adjusted your browser or device settings to reject cookies. Your continued use of the Platform constitutes acceptance of this Cookie Policy.

1.1 Scope of Application

This Policy applies to:

  • All visitors to the MedxGo website (https://medxgoapp.com/)
  • All users of the MedxGo mobile application (iOS and Android)
  • Registered Customers, Vendors, Riders, and Healthcare Providers
  • Third-party service providers and partners accessing our platforms
  • Any individual or entity interacting with MedxGo digital properties

1.2 Relationship with Privacy Policy

This Cookie Policy is a supplement to our Privacy Policy and should be read in conjunction with it. The Privacy Policy provides comprehensive information about how we collect, use, store, and protect your personal data. Where there is any conflict between this Cookie Policy and the Privacy Policy, the provisions most protective of your privacy shall prevail.

Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit a website or use a mobile application. They are widely used to make websites and apps work more efficiently, as well as to provide information to the owners of the site or app.

Cookies serve various functions, including:

  • Remembering your preferences and settings
  • Enabling secure login and authentication
  • Analyzing how you use the Platform to improve functionality
  • Delivering personalized content and advertisements
  • Tracking your journey through the Platform for analytics
  • Maintaining the security and integrity of the Platform

2.1 Similar Tracking Technologies

In addition to cookies, MedxGo uses other tracking technologies that perform similar functions:

TechnologyDescriptionPurpose
Web BeaconsSmall graphic images (pixel tags) embedded in web pages and emailsTrack email open rates, page views, and user engagement
Local StorageBrowser-based storage that persists beyond session (e.g., localStorage, sessionStorage)Store user preferences, cached data, and app state
Device FingerprintingCollection of device characteristics (screen size, OS, browser version)Fraud prevention, security, and device identification
SDKs (Software Development Kits)Integrated code libraries in mobile apps (e.g., Firebase, Facebook SDK)Analytics, crash reporting, push notifications, attribution
ETagsHTTP cache validators used to track browser cache stateOptimize loading and track returning visitors
IndexedDBStructured client-side database for web applicationsStore larger volumes of structured data offline

Under Section 25 of the Nigeria Data Protection Act 2023, MedxGo processes personal data (including data collected through cookies) based on one or more of the following legal grounds:

3.1 Consent

For non-essential cookies (analytics, marketing, and third-party tracking), we obtain your explicit, informed consent through our cookie consent banner before placing these cookies on your device. You have the right to withdraw consent at any time through your browser settings or our cookie management tool.

3.2 Legitimate Interests

For essential cookies necessary for the core functionality of the Platform (e.g., authentication, security, session management), we rely on our legitimate interest in providing a secure and functional service. These cookies cannot be disabled as they are required for the Platform to operate.

3.3 Contractual Necessity

Certain cookies are necessary to fulfill our contractual obligations to you, such as maintaining your shopping cart, processing orders, and enabling payment transactions. These cookies are placed based on the necessity of processing for the performance of a contract.

3.4 Legal Obligation

We may use cookies to comply with legal obligations, such as fraud prevention, regulatory reporting, and maintaining audit trails for healthcare compliance (e.g., prescription verification records under NAFDAC and PCN requirements).

MedxGo categorizes cookies into the following types based on their purpose and function. Each category is subject to different consent requirements and retention periods.

Cookie CategoryPurposeConsent RequiredExamples
Essential (Strictly Necessary)Required for core Platform functionality; enable basic features like page navigation, secure areas, and session managementNo – cannot be disabledAuthentication cookies, session cookies, security cookies, load balancing cookies
Functional (Preferences)Enable enhanced functionality and personalization; remember choices you makeYes – can be disabledLanguage preferences, location settings, preferred pharmacy, display preferences
Analytics (Performance)Collect information about how Users interact with the Platform to improve performance and user experienceYes – can be disabledGoogle Analytics, Firebase Analytics, Mixpanel, page view counters, error tracking
Marketing (Targeting)Track browsing habits to deliver relevant advertisements and measure campaign effectivenessYes – can be disabledFacebook Pixel, Google Ads, retargeting cookies, conversion tracking
Health PreferenceRemember health-related preferences, medication reminders, and wellness goalsYes – can be disabledMedication schedule reminders, health interest categories, symptom history preferences
Security & Fraud PreventionDetect and prevent fraudulent activity, unauthorized access, and security threatsNo – cannot be disabledDevice fingerprinting, CAPTCHA tokens, suspicious activity detection

4.1 Session vs. Persistent Cookies

Cookies can also be classified by duration:

TypeDurationPurposeExample
Session CookiesTemporary; deleted when browser is closedMaintain user session state during a single visitLogin session token, cart contents during browsing
Persistent CookiesRemain for a set period or until manually deletedRemember preferences across multiple visitsRemember me login, language preference, analytics user ID

4.2 First-Party vs. Third-Party Cookies

Cookies are further classified by their origin:

TypeOriginControlExample
First-Party CookiesSet directly by MedxGo on our domainFull control by MedxGoMedxGo session cookie, authentication token, wallet balance cache
Third-Party CookiesSet by external domains and services integrated into our PlatformSubject to third-party policiesGoogle Analytics, Facebook Pixel, payment processor cookies

The following table provides a comprehensive inventory of cookies and similar technologies used on the MedxGo Platform. This inventory is reviewed and updated quarterly to ensure accuracy and compliance.

5.1 Essential Cookies

These cookies are strictly necessary for the operation of the Platform. They cannot be disabled through our cookie management tool.

Cookie NameProviderPurposeDurationType
medxgo_session_idMedxGoMaintains user session state and authentication statusSessionFirst-Party
medxgo_auth_tokenMedxGoSecure authentication token for logged-in usersSessionFirst-Party
medxgo_csrf_tokenMedxGoPrevents cross-site request forgery attacksSessionFirst-Party
medxgo_secure_flagMedxGoIndicates secure connection status for HTTPS enforcementSessionFirst-Party
medxgo_cart_stateMedxGoPreserves shopping cart contents during browsing sessionSessionFirst-Party
medxgo_consent_recordMedxGoRecords cookie consent preferences to comply with NDPA13 monthsFirst-Party
AWSALB / AWSALBCORSAmazon Web ServicesLoad balancing and server routing for Platform stability7 daysThird-Party
__cf_bmCloudflareBot management and DDoS protection30 minutesThird-Party
__cfruidCloudflareRate limiting and security enforcementSessionThird-Party

5.2 Functional Cookies

These cookies enable enhanced functionality and personalization. They may be disabled, but doing so may limit certain features.

Cookie NameProviderPurposeDurationType
medxgo_lang_prefMedxGoRemembers selected language (English, French, etc.)1 yearFirst-Party
medxgo_location_pinMedxGoSaves pinned delivery address for quick reordering1 yearFirst-Party
medxgo_pharmacy_favMedxGoStores preferred pharmacy for faster prescription fulfillment6 monthsFirst-Party
medxgo_restaurant_favMedxGoStores preferred restaurant for quick reordering6 monthsFirst-Party
medxgo_display_modeMedxGoRemembers light/dark mode preference1 yearFirst-Party
medxgo_notif_prefsMedxGoStores push notification and email preference settings1 yearFirst-Party
medxgo_recent_searchesMedxGoCaches recent product/drug searches for quick access30 daysFirst-Party

5.3 Analytics Cookies

These cookies help us understand how Users interact with the Platform so we can improve functionality and user experience.

Cookie NameProviderPurposeDurationType
_gaGoogle AnalyticsDistinguishes unique users for traffic analysis2 yearsThird-Party
_gidGoogle AnalyticsDistinguishes users for daily session tracking24 hoursThird-Party
_gatGoogle AnalyticsThrottles request rate to analytics servers1 minuteThird-Party
_gac_Google AnalyticsStores campaign information for ad attribution90 daysThird-Party
firebase_sessionFirebase (Google)Mobile app session tracking and crash analyticsSessionThird-Party
firebase_user_idFirebase (Google)Anonymous user identifier for app analyticsIndefiniteThird-Party
mixpanel_distinct_idMixpanelUnique user identifier for behavior analytics1 yearThird-Party
mp_mixpanelMixpanelEvent tracking for feature usage and funnel analysis1 yearThird-Party
amplitude_idAmplitudeUser identification for product analytics1 yearThird-Party
medxgo_page_viewsMedxGoInternal page view counter for performance monitoring30 daysFirst-Party
medxgo_error_logMedxGoRecords JavaScript errors for debugging7 daysFirst-Party

5.4 Marketing Cookies

These cookies track your browsing habits to deliver personalized advertisements and measure marketing campaign effectiveness.

Cookie NameProviderPurposeDurationType
_fbpMeta (Facebook)Facebook Pixel identifier for ad targeting and retargeting3 monthsThird-Party
frMeta (Facebook)Facebook ad delivery and measurement3 monthsThird-Party
trMeta (Facebook)Facebook tracking pixel for conversion eventsSessionThird-Party
_gcl_auGoogle AdsGoogle Ads conversion linker and attribution3 monthsThird-Party
IDEGoogle DoubleClickGoogle ad personalization and remarketing1 yearThird-Party
test_cookieGoogle DoubleClickChecks if browser supports cookies for ad serving15 minutesThird-Party
personalization_idTwitter/XTwitter ad personalization and tracking2 yearsThird-Party
i/adsctTwitter/XTwitter conversion tracking pixelSessionThird-Party
_tt_enable_cookieTikTokTikTok advertising and attribution tracking13 monthsThird-Party
_ttpTikTokTikTok pixel for campaign measurement13 monthsThird-Party
medxgo_promo_refMedxGoTracks referral source for promotional campaigns30 daysFirst-Party
medxgo_affiliate_idMedxGoAffiliate partner attribution for commission tracking90 daysFirst-Party

5.5 Health Preference Cookies

These cookies are specific to MedxGo's health and wellness features. They store health-related preferences while maintaining privacy safeguards.

Cookie NameProviderPurposeDurationType
medxgo_health_interestsMedxGoStores anonymized health interest categories (e.g., diabetes, fitness)6 monthsFirst-Party
medxgo_med_remindersMedxGoMedication reminder schedule preferences (no specific drug names)1 yearFirst-Party
medxgo_symptom_historyMedxGoLexi AI conversation context for continuity (anonymized)7 daysFirst-Party
medxgo_wellness_goalsMedxGoWellness and fitness goal preferences6 monthsFirst-Party
medxgo_insurance_prefMedxGoPreferred health insurance provider for direct billing1 yearFirst-Party

5.6 Security & Fraud Prevention Cookies

These cookies are essential for detecting and preventing fraudulent activity, unauthorized access, and security threats. They cannot be disabled.

Cookie NameProviderPurposeDurationType
medxgo_device_fingerprintMedxGoCreates device signature for fraud detection and account security1 yearFirst-Party
medxgo_login_attemptsMedxGoTracks failed login attempts to prevent brute force attacks24 hoursFirst-Party
medxgo_risk_scoreMedxGoTemporary risk assessment score for transaction securitySessionFirst-Party
medxgo_captcha_tokenMedxGoVerifies human users during suspicious activity detection10 minutesFirst-Party
__stripe_sidStripeStripe fraud detection and payment security30 minutesThird-Party
__stripe_midStripeStripe persistent fraud prevention identifier1 yearThird-Party
mStripeStripe machine learning fraud detection2 yearsThird-Party
riskified_session_idRiskifiedE-commerce fraud prevention and risk scoringSessionThird-Party
riskified_device_idRiskifiedDevice identification for fraud pattern analysis1 yearThird-Party

MedxGo integrates with various third-party service providers who may place cookies on your device. These providers are carefully vetted and bound by data processing agreements that comply with the NDPA.

6.1 Third-Party Service Categories

Service CategoryProvider(s)Cookie PurposePrivacy Policy Link
AnalyticsGoogle Analytics, Firebase, Mixpanel, AmplitudeTraffic analysis, user behavior, app performance, crash reportinghttps://policies.google.com/privacy, https://mixpanel.com/legal/privacy-policy, https://amplitude.com/privacy
AdvertisingGoogle Ads, Meta (Facebook), Twitter/X, TikTokAd targeting, retargeting, conversion tracking, campaign measurementhttps://policies.google.com/privacy, https://www.facebook.com/privacy/policy, https://twitter.com/en/privacy, https://www.tiktok.com/legal/privacy-policy
Payment ProcessingPaystack, Flutterwave, Interswitch, StripeFraud prevention, payment security, transaction verificationhttps://paystack.com/privacy, https://flutterwave.com/privacy, https://interswitchgroup.com/privacy, https://stripe.com/privacy
Cloud InfrastructureAmazon Web Services (AWS), Google CloudLoad balancing, server routing, DDoS protectionhttps://aws.amazon.com/privacy, https://cloud.google.com/privacy
Identity VerificationSmile Identity, YouVerify, VerifyMeKYC verification, identity fraud preventionhttps://smileidentity.com/privacy, https://youverify.co/privacy, https://verifyme.ng/privacy
CommunicationTwilio, SendGrid, Africa's TalkingSMS delivery, email tracking, voice communication logshttps://www.twilio.com/legal/privacy, https://www.twilio.com/legal/privacy, https://africastalking.com/privacy
Fraud PreventionRiskified, SiftE-commerce fraud detection, risk scoring, pattern analysishttps://www.riskified.com/privacy-policy, https://sift.com/privacy
CDN & SecurityCloudflareDDoS protection, bot management, content delivery optimizationhttps://www.cloudflare.com/privacypolicy/

6.2 Third-Party Data Sharing

Third-party cookies may transmit certain data to external providers. The following table outlines what data is shared and for what purpose:

Data CategoryShared WithPurposeAnonymized?
IP AddressGoogle Analytics, CloudflareGeolocation analysis, security threat detectionPartially (last octet truncated for Google)
Device InformationFirebase, Mixpanel, RiskifiedApp performance analytics, fraud preventionYes (for analytics); No (for security)
Browsing BehaviorGoogle Analytics, Meta, TikTokAd targeting, campaign optimization, retargetingYes (aggregated/anonymized for ads)
Transaction MetadataStripe, Paystack, FlutterwavePayment processing, fraud preventionNo (required for transaction)
Session IdentifiersAll third-party analyticsUser journey tracking, session continuityYes (pseudonymized IDs)
Ad Interaction DataGoogle Ads, Meta, TikTokConversion tracking, ROI measurementYes (event-level only)

6.3 Cross-Border Data Transfers

Some third-party providers process data outside Nigeria. Under Section 41 of the NDPA, we ensure that such transfers are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the NDPC. Users consent to such transfers by accepting this Cookie Policy.

MedxGo is committed to transparent and user-friendly cookie consent management in compliance with the NDPA and NDPC guidelines.

7.1 Consent Banner

When you first visit the MedxGo website or open the mobile app, you will be presented with a cookie consent banner that:

  • Clearly explains that we use cookies
  • Categorizes cookies by type (Essential, Functional, Analytics, Marketing, Health)
  • Provides granular control to enable or disable non-essential cookie categories
  • Links to this full Cookie Policy for detailed information
  • Records your consent preferences for future visits
  • Allows you to change your preferences at any time

7.2 Consent Management Tool

Users can access the cookie consent management tool through:

  • Website: Footer link → 'Cookie Settings' or 'Manage Cookies'
  • Mobile App: Settings → Privacy → Cookie Preferences
  • Direct URL: https://medxgoapp.com/cookie-settings

7.3 Consent Withdrawal

You have the right to withdraw your consent for non-essential cookies at any time. Withdrawing consent will:

  • Immediately stop the placement of new non-essential cookies
  • Delete existing non-essential cookies from your device (where technically possible)
  • Not affect the functionality of essential cookies
  • May reduce the personalization and relevance of your experience

7.4 Consent Record Keeping

In compliance with the NDPA, MedxGo maintains records of cookie consent choices for a period of 2 years. These records include:

  • Timestamp of consent or withdrawal
  • Cookie categories accepted or rejected
  • Device/browser identifier (pseudonymized)
  • IP address (anonymized)
  • Consent method (banner click, settings change)

Cookie retention periods are carefully calibrated to balance functionality with privacy. The following table summarizes maximum retention periods by cookie category:

Cookie CategoryMaximum DurationRationale
Essential (Session)Session onlyRequired only for active browsing session
Essential (Persistent)13 monthsConsent record retention per NDPC guidance
Functional1 yearPreference retention across reasonable period
Analytics2 yearsIndustry standard for longitudinal analysis (Google Analytics)
Marketing13 monthsAdvertising campaign measurement cycles
Health Preference1 yearAnnual health preference refresh recommended
Security1 yearDevice fingerprinting for fraud pattern recognition

8.1 Automatic Expiration

All cookies are configured with automatic expiration dates. Upon expiration, cookies are either:

  • Renewed with renewed consent (for non-essential cookies)
  • Deleted automatically by the browser or app
  • Replaced with updated versions if still required

8.2 Data Retention Post-Account Deletion

When you delete your MedxGo account:

  • All first-party cookies are immediately invalidated and scheduled for deletion
  • Third-party cookies remain subject to the respective provider's retention policies
  • Analytics data is anonymized within 90 days of account deletion
  • Marketing identifiers are removed from active targeting lists within 30 days

You have multiple options for managing cookies on your device. The following guidance applies to both the MedxGo Platform and general web browsing.

9.1 Platform-Specific Cookie Controls

MedxGo provides built-in controls for managing cookie preferences:

PlatformAccess PathActions Available
Website (Desktop)Footer → 'Cookie Settings' or 'Manage Cookies'Enable/disable each cookie category; view current consent status; withdraw all non-essential consent
Website (Mobile Browser)Menu → Settings → Privacy → CookiesSame as desktop with mobile-optimized interface
iOS AppSettings → Privacy & Security → Cookie PreferencesToggle categories on/off; reset all preferences; export consent record
Android AppSettings → Privacy → Cookie ManagementToggle categories on/off; clear app cache; reset all preferences

9.2 Browser-Level Cookie Controls

You can also manage cookies through your web browser settings:

BrowserPath to Cookie SettingsCapabilities
Google ChromeSettings → Privacy and Security → Cookies and other site dataBlock all, block third-party, clear on exit, site-specific exceptions
Mozilla FirefoxSettings → Privacy & Security → Cookies and Site DataStandard/Strict/Custom protection levels, delete cookies on close
Apple SafariPreferences → Privacy → Cookies and website dataPrevent cross-site tracking, block all cookies, manage website data
Microsoft EdgeSettings → Cookies and site permissions → Manage and delete cookiesBlock third-party, clear on exit, preloaded site exceptions
OperaSettings → Privacy & Security → CookiesBlock all, block third-party, clear on exit

9.3 Mobile Device Controls

For mobile app cookie and tracking management:

Device/OSPath to ControlsCapabilities
iOS (iPhone/iPad)Settings → Privacy → Tracking → 'Allow Apps to Request to Track'Disable cross-app tracking, reset advertising identifier, limit ad tracking
AndroidSettings → Privacy → Ads → 'Opt out of Ads Personalization'Reset advertising ID, opt out of personalized ads, delete advertising ID
Both PlatformsSettings → Privacy → Location ServicesDisable location tracking for specific apps or system-wide

9.4 Impact of Disabling Cookies

Disabling certain cookies may affect your experience on the MedxGo Platform:

Cookie Category DisabledImpact on Platform Functionality
EssentialPlatform will not function; login, checkout, and security features will fail
FunctionalPreferences not remembered; must re-select language, location, and pharmacy each visit
AnalyticsNo impact on functionality; we lose ability to improve Platform based on your usage
MarketingNo impact on functionality; ads will be less relevant; promotional offers may not be personalized
Health PreferenceMedication reminders and wellness recommendations will not be personalized
SecurityIncreased fraud risk; additional verification steps may be required for transactions

MedxGo serves multiple user types, and cookie usage varies based on the features and functionality each user group accesses.

10.1 Customers (End Users)

  • Essential cookies for login, session management, and checkout
  • Functional cookies for saved addresses, preferred pharmacies, and restaurant favorites
  • Analytics cookies for order behavior, search patterns, and feature usage
  • Marketing cookies for personalized promotions and retargeting
  • Health preference cookies for medication reminders and wellness goals
  • Security cookies for payment fraud prevention and account protection

10.2 Pharmacy Vendors

  • Essential cookies for dashboard authentication and session management
  • Functional cookies for inventory display preferences and order notification settings
  • Analytics cookies for sales performance, order volume, and customer ratings
  • Security cookies for prescription verification audit trails and compliance logging

10.3 Restaurant Vendors

  • Essential cookies for dashboard access and menu management
  • Functional cookies for operating hours, promotional settings, and notification preferences
  • Analytics cookies for order analytics, peak time analysis, and customer feedback

10.4 Riders

  • Essential cookies for app authentication and delivery session management
  • Functional cookies for route preferences, notification settings, and availability status
  • Analytics cookies for delivery completion rates, earnings tracking, and performance metrics
  • Location cookies for real-time GPS tracking during active delivery sessions

10.5 Healthcare Providers

  • Essential cookies for telemedicine portal authentication and session security
  • Functional cookies for consultation preferences, availability scheduling, and notification settings
  • Security cookies for patient data access logging and HIPAA-equivalent compliance monitoring
  • No marketing or analytics cookies that could compromise patient confidentiality

Given MedxGo's role as a health-tech platform processing sensitive personal data (including Healthcare Data under the NDPA), we implement enhanced safeguards for cookies that may interact with health-related information.

11.1 Health Data Protection Principles

All cookies related to health features are designed and operated according to the following principles:

Data Minimization: Health-related cookies store only the minimum necessary data (e.g., reminder preferences, not specific medication names or dosages).

Pseudonymization: Health preference cookies use pseudonymized identifiers that cannot directly identify the user without additional data.

Encryption: All health-related cookie data is encrypted at rest and in transit using AES-256 encryption.

No Third-Party Sharing: Health preference cookies are never shared with third-party advertisers or analytics providers.

Short Retention: Health-related cookies have shorter retention periods (maximum 6-12 months) compared to general cookies.

Separate Consent: Users provide separate, explicit consent for health-related cookies beyond general analytics consent.

11.2 Lexi AI and Cookies

Lexi AI interactions may generate cookies for session continuity and preference memory. These cookies:

  • Do not store the content of health-related conversations
  • Retain only anonymized interaction metadata (e.g., number of sessions, feature usage)
  • Are never used for marketing or advertising purposes
  • Are deleted within 7 days of the last interaction
  • Require explicit consent separate from general analytics consent

11.3 Prescription Data and Cookies

Prescription data is NEVER stored in cookies. The prescription upload and verification process:

  • Uses session-only cookies for upload progress tracking
  • Stores prescription images in encrypted cloud storage, not in browser cookies
  • Does not use persistent cookies to track prescription history

Requires re-authentication for each prescription upload session

As MedxGo expands across Africa and integrates with global third-party services, cookie data may be transferred across international borders.

12.1 Transfer Mechanisms

Under Section 41 of the NDPA, MedxGo ensures that international cookie data transfers are protected by:

Standard Contractual Clauses (SCCs): Legally binding contracts approved by the NDPC with all third-party providers processing data outside Nigeria.

Adequacy Decisions: Reliance on NDPC adequacy decisions for recipient countries with equivalent data protection standards.

Data Localization: Primary cookie data storage for Nigerian users remains within Nigeria; only necessary analytics and security data is transferred.

Transparency: Users are informed of potential cross-border transfers in the cookie consent banner and this Policy.

12.2 Third-Party Provider Locations

The following table outlines the geographic locations of key third-party cookie providers:

ProviderServiceData Processing LocationSafeguard
Google (Analytics, Ads, Firebase)Analytics, advertising, app analyticsUnited States, Ireland, SingaporeSCCs; data minimization; IP anonymization
Meta (Facebook)Advertising, retargetingUnited States, IrelandSCCs; limited data sharing
StripePayment processing, fraud preventionUnited States, IrelandSCCs; PCI-DSS compliance; encryption
PaystackPayment processingNigeria, South AfricaLocal processing; NDPA compliance
FlutterwavePayment processingNigeria, United States, United KingdomSCCs; local data residency where possible
MixpanelProduct analyticsUnited StatesSCCs; pseudonymized data only
CloudflareCDN, securityUnited States, global edge locationsSCCs; minimal data retention
AWSCloud infrastructureNigeria, South Africa, Ireland, United StatesSCCs; regional data residency options

MedxGo implements robust technical and organizational measures to protect cookie data from unauthorized access, alteration, or deletion.

13.1 Technical Security Measures

MeasureImplementationPurpose
Secure FlagAll cookies marked with 'Secure' attributeEnsures cookies are only transmitted over HTTPS connections
HttpOnly FlagEssential and security cookies marked HttpOnlyPrevents JavaScript access to cookies, mitigating XSS attacks
SameSite AttributeAll cookies set with SameSite=Lax or SameSite=StrictPrevents cross-site request forgery (CSRF) attacks
EncryptionAES-256 encryption for cookie values containing sensitive dataProtects cookie contents if intercepted
Signature ValidationHMAC-SHA256 signatures on state cookiesEnsures cookie integrity and prevents tampering
Domain RestrictionCookies scoped to medxgoapp.com and subdomains onlyPrevents cross-domain cookie leakage
Rate LimitingCookie-based request throttling for API endpointsPrevents brute force and automated attacks
Regular RotationSession tokens and CSRF tokens rotated every 15 minutesLimits window of compromise if token is stolen

13.2 Organizational Security Measures

  • Access to cookie configuration and management tools restricted to authorized engineering and security personnel
  • Regular security audits of cookie implementation by third-party penetration testers
  • Cookie policy and implementation reviewed quarterly by the Data Protection Officer
  • Incident response procedures include cookie compromise assessment and remediation
  • Employee training on cookie security and privacy implications as part of NDPA compliance program

MedxGo does not knowingly collect personal data from children under 16 through cookies or any other means. Our cookie practices for minors include:

  • Age verification during account creation prevents underage users from accessing the Platform
  • If a child under 16 is discovered to have an account, all associated cookies are immediately deleted
  • Marketing and analytics cookies are never placed on devices identified as belonging to children
  • Health preference cookies for pediatric users require explicit parental consent and are limited to general wellness categories only
  • Location tracking cookies for minors are disabled by default and require separate parental authorization

Parents or guardians who believe their child has interacted with our Platform without appropriate consent should contact us immediately at privacy@medxgoapp.com.

MedxGo reserves the right to update this Cookie Policy to reflect changes in technology, legal requirements, or our business practices.

15.1 Notification of Changes

Material changes to this Cookie Policy will be communicated through:

  • Email notification to registered Users at least 30 days before the effective date
  • In-app notification banner upon next login
  • Prominent posting on the MedxGo website
  • Updated cookie consent banner requiring renewed consent where applicable

15.2 Change Log

A summary of material changes to this Cookie Policy will be maintained in the following table:

VersionEffective DateChanges Made
1.0June 24, 2026Initial publication of Cookie Policy

This table will be updated with each material revision to the Cookie Policy.

For questions, concerns, or requests related to this Cookie Policy or our cookie practices, please contact us:

MedxGo Technologies Limited

Website: https://medxgoapp.com/

Email: privacy@medxgoapp.com

Cookie-Specific Inquiries: cookies@medxgoapp.com

Data Protection Officer: dpo@medxgoapp.com

Phone: +234-XXX-XXX-XXXX

Business Hours: Monday–Friday, 8:00 AM–8:00 PM WAT; Saturday–Sunday, 9:00 AM–5:00 PM WAT

Registered Address: [Address], Lagos, Nigeria

16.1 Cookie Complaints

If you believe your cookie-related privacy rights have been violated, you may:

  • Contact our Data Protection Officer at dpo@medxgoapp.com for resolution
  • Lodge a complaint with the Nigeria Data Protection Commission at info@ndpc.gov.ng
  • Seek judicial remedies under Section 55 of the NDPA

MedxGo's cookie practices are designed to comply with the following regulatory frameworks:

17.1 Nigerian Regulatory Framework

  • Nigeria Data Protection Act 2023 (NDPA) – Sections 24, 25, 30, 41
  • Nigeria Data Protection Regulation 2019 (NDPR) – Part 3 (Data Subject Rights)
  • NDPC Guidelines on Data Processing – Cookie consent and transparency requirements
  • Federal Competition and Consumer Protection Act 2018 – Transparent data practices
  • Cybercrimes (Prohibition, Prevention, etc.) Act 2015 – Security and unauthorized access prevention

17.2 African Expansion Compliance

As MedxGo expands across Africa, cookie practices will be adapted to comply with:

South Africa: Protection of Personal Information Act (POPIA) – Section 11 (Consent), Section 69 (Direct Marketing)

Kenya: Data Protection Act 2019 – Section 30 (Consent), Section 31 (Data Subject Rights)

Ghana: Data Protection Act 2012 (Act 843) – Section 3 (Privacy Principles)

Egypt: Personal Data Protection Law – Articles 4-6 (Processing Conditions)

Rwanda: Law No. 058/2021 on Data Protection and Privacy – Articles 12-15 (Consent Requirements)

17.3 International Standards

MedxGo also aligns with international best practices and standards:

  • General Data Protection Regulation (GDPR) – Articles 5, 6, 7 (Lawfulness, Fairness, Transparency, Consent)
  • ePrivacy Directive (EU Cookie Directive) – Transparency and consent requirements
  • ISO/IEC 27001:2013 – Information security management including cookie security
  • ISO/IEC 27701:2019 – Privacy information management for cookie data processing
  • IAB Transparency and Consent Framework – Industry standard for digital advertising consent

17.4 Regulatory Registrations

MedxGo is registered with the following regulatory bodies:

  • Nigeria Data Protection Commission (NDPC) – Data Controller Registration: [Registration Number]
  • Corporate Affairs Commission (CAC) – [Registration Number]
  • Tax Identification Number (TIN) – [TIN]

© 2026 MedxGo Technologies Limited. All Rights Reserved.

Document Version: 1.0
Effective Date: June 24, 2026
Review Date: June 24, 2027 (or earlier if required by regulatory changes)
Approved By: Board of Directors, MedxGo Technologies Limited
Data Protection Officer Certification: Certified compliant with NDPA 2023 and NDPC guidelines