MedxGo Cookie Policy
Effective Date: June 24, 2026
Last Updated: June 24, 2026
Company: MedxGo Technologies Limited
Website: https://medxgoapp.com/
App: MedxGo Mobile Application (iOS & Android)
Jurisdiction: Federal Republic of Nigeria
TABLE OF CONTENTS
- Introduction and Scope
- What Are Cookies
- Legal Basis for Cookie Use
- Types of Cookies We Use
- Detailed Cookie Inventory
- Third-Party Cookies and Services
- Cookie Consent Mechanism
- Cookie Duration and Expiration
- How to Manage Cookies
- Cookie Use by User Type
- Cookies and Healthcare Data
- Cross-Border Cookie Transfers
- Cookie Security Measures
- Children's Privacy and Cookies
- Updates to This Cookie Policy
- Contact Information
- Regulatory Compliance
1. INTRODUCTION AND SCOPE
This Cookie Policy ("Policy") explains how MedxGo Technologies Limited ("MedxGo," "we," "us," or "our") uses cookies and similar tracking technologies on our website (https://medxgoapp.com/), mobile application, and any affiliated digital platforms (collectively, the "Platform").
This Policy is designed to comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and the guidelines issued by the Nigeria Data Protection Commission (NDPC). As MedxGo expands operations across Africa, we also adhere to applicable data protection laws in each jurisdiction, including the General Data Protection Regulation (GDPR) where relevant to our international users.
By accessing or using the MedxGo Platform, you consent to the use of cookies as described in this Policy, unless you have adjusted your browser or device settings to reject cookies. Your continued use of the Platform constitutes acceptance of this Cookie Policy.
1.1 Scope of Application
This Policy applies to:
- All visitors to the MedxGo website (https://medxgoapp.com/)
- All users of the MedxGo mobile application (iOS and Android)
- Registered Customers, Vendors, Riders, and Healthcare Providers
- Third-party service providers and partners accessing our platforms
- Any individual or entity interacting with MedxGo digital properties
1.2 Relationship with Privacy Policy
This Cookie Policy is a supplement to our Privacy Policy and should be read in conjunction with it. The Privacy Policy provides comprehensive information about how we collect, use, store, and protect your personal data. Where there is any conflict between this Cookie Policy and the Privacy Policy, the provisions most protective of your privacy shall prevail.
2. WHAT ARE COOKIES
Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit a website or use a mobile application. They are widely used to make websites and apps work more efficiently, as well as to provide information to the owners of the site or app.
Cookies serve various functions, including:
- Remembering your preferences and settings
- Enabling secure login and authentication
- Analyzing how you use the Platform to improve functionality
- Delivering personalized content and advertisements
- Tracking your journey through the Platform for analytics
- Maintaining the security and integrity of the Platform
2.1 Similar Tracking Technologies
In addition to cookies, MedxGo uses other tracking technologies that perform similar functions:
| Technology | Description | Purpose |
|---|---|---|
| Web Beacons | Small graphic images (pixel tags) embedded in web pages and emails | Track email open rates, page views, and user engagement |
| Local Storage | Browser-based storage that persists beyond session (e.g., localStorage, sessionStorage) | Store user preferences, cached data, and app state |
| Device Fingerprinting | Collection of device characteristics (screen size, OS, browser version) | Fraud prevention, security, and device identification |
| SDKs (Software Development Kits) | Integrated code libraries in mobile apps (e.g., Firebase, Facebook SDK) | Analytics, crash reporting, push notifications, attribution |
| ETags | HTTP cache validators used to track browser cache state | Optimize loading and track returning visitors |
| IndexedDB | Structured client-side database for web applications | Store larger volumes of structured data offline |
3. LEGAL BASIS FOR COOKIE USE
Under Section 25 of the Nigeria Data Protection Act 2023, MedxGo processes personal data (including data collected through cookies) based on one or more of the following legal grounds:
3.1 Consent
For non-essential cookies (analytics, marketing, and third-party tracking), we obtain your explicit, informed consent through our cookie consent banner before placing these cookies on your device. You have the right to withdraw consent at any time through your browser settings or our cookie management tool.
3.2 Legitimate Interests
For essential cookies necessary for the core functionality of the Platform (e.g., authentication, security, session management), we rely on our legitimate interest in providing a secure and functional service. These cookies cannot be disabled as they are required for the Platform to operate.
3.3 Contractual Necessity
Certain cookies are necessary to fulfill our contractual obligations to you, such as maintaining your shopping cart, processing orders, and enabling payment transactions. These cookies are placed based on the necessity of processing for the performance of a contract.
3.4 Legal Obligation
We may use cookies to comply with legal obligations, such as fraud prevention, regulatory reporting, and maintaining audit trails for healthcare compliance (e.g., prescription verification records under NAFDAC and PCN requirements).
4. TYPES OF COOKIES WE USE
MedxGo categorizes cookies into the following types based on their purpose and function. Each category is subject to different consent requirements and retention periods.
| Cookie Category | Purpose | Consent Required | Examples |
|---|---|---|---|
| Essential (Strictly Necessary) | Required for core Platform functionality; enable basic features like page navigation, secure areas, and session management | No – cannot be disabled | Authentication cookies, session cookies, security cookies, load balancing cookies |
| Functional (Preferences) | Enable enhanced functionality and personalization; remember choices you make | Yes – can be disabled | Language preferences, location settings, preferred pharmacy, display preferences |
| Analytics (Performance) | Collect information about how Users interact with the Platform to improve performance and user experience | Yes – can be disabled | Google Analytics, Firebase Analytics, Mixpanel, page view counters, error tracking |
| Marketing (Targeting) | Track browsing habits to deliver relevant advertisements and measure campaign effectiveness | Yes – can be disabled | Facebook Pixel, Google Ads, retargeting cookies, conversion tracking |
| Health Preference | Remember health-related preferences, medication reminders, and wellness goals | Yes – can be disabled | Medication schedule reminders, health interest categories, symptom history preferences |
| Security & Fraud Prevention | Detect and prevent fraudulent activity, unauthorized access, and security threats | No – cannot be disabled | Device fingerprinting, CAPTCHA tokens, suspicious activity detection |
4.1 Session vs. Persistent Cookies
Cookies can also be classified by duration:
| Type | Duration | Purpose | Example |
|---|---|---|---|
| Session Cookies | Temporary; deleted when browser is closed | Maintain user session state during a single visit | Login session token, cart contents during browsing |
| Persistent Cookies | Remain for a set period or until manually deleted | Remember preferences across multiple visits | Remember me login, language preference, analytics user ID |
4.2 First-Party vs. Third-Party Cookies
Cookies are further classified by their origin:
| Type | Origin | Control | Example |
|---|---|---|---|
| First-Party Cookies | Set directly by MedxGo on our domain | Full control by MedxGo | MedxGo session cookie, authentication token, wallet balance cache |
| Third-Party Cookies | Set by external domains and services integrated into our Platform | Subject to third-party policies | Google Analytics, Facebook Pixel, payment processor cookies |
5. DETAILED COOKIE INVENTORY
The following table provides a comprehensive inventory of cookies and similar technologies used on the MedxGo Platform. This inventory is reviewed and updated quarterly to ensure accuracy and compliance.
5.1 Essential Cookies
These cookies are strictly necessary for the operation of the Platform. They cannot be disabled through our cookie management tool.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| medxgo_session_id | MedxGo | Maintains user session state and authentication status | Session | First-Party |
| medxgo_auth_token | MedxGo | Secure authentication token for logged-in users | Session | First-Party |
| medxgo_csrf_token | MedxGo | Prevents cross-site request forgery attacks | Session | First-Party |
| medxgo_secure_flag | MedxGo | Indicates secure connection status for HTTPS enforcement | Session | First-Party |
| medxgo_cart_state | MedxGo | Preserves shopping cart contents during browsing session | Session | First-Party |
| medxgo_consent_record | MedxGo | Records cookie consent preferences to comply with NDPA | 13 months | First-Party |
| AWSALB / AWSALBCORS | Amazon Web Services | Load balancing and server routing for Platform stability | 7 days | Third-Party |
| __cf_bm | Cloudflare | Bot management and DDoS protection | 30 minutes | Third-Party |
| __cfruid | Cloudflare | Rate limiting and security enforcement | Session | Third-Party |
5.2 Functional Cookies
These cookies enable enhanced functionality and personalization. They may be disabled, but doing so may limit certain features.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| medxgo_lang_pref | MedxGo | Remembers selected language (English, French, etc.) | 1 year | First-Party |
| medxgo_location_pin | MedxGo | Saves pinned delivery address for quick reordering | 1 year | First-Party |
| medxgo_pharmacy_fav | MedxGo | Stores preferred pharmacy for faster prescription fulfillment | 6 months | First-Party |
| medxgo_restaurant_fav | MedxGo | Stores preferred restaurant for quick reordering | 6 months | First-Party |
| medxgo_display_mode | MedxGo | Remembers light/dark mode preference | 1 year | First-Party |
| medxgo_notif_prefs | MedxGo | Stores push notification and email preference settings | 1 year | First-Party |
| medxgo_recent_searches | MedxGo | Caches recent product/drug searches for quick access | 30 days | First-Party |
5.3 Analytics Cookies
These cookies help us understand how Users interact with the Platform so we can improve functionality and user experience.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users for traffic analysis | 2 years | Third-Party |
| _gid | Google Analytics | Distinguishes users for daily session tracking | 24 hours | Third-Party |
| _gat | Google Analytics | Throttles request rate to analytics servers | 1 minute | Third-Party |
| _gac_ | Google Analytics | Stores campaign information for ad attribution | 90 days | Third-Party |
| firebase_session | Firebase (Google) | Mobile app session tracking and crash analytics | Session | Third-Party |
| firebase_user_id | Firebase (Google) | Anonymous user identifier for app analytics | Indefinite | Third-Party |
| mixpanel_distinct_id | Mixpanel | Unique user identifier for behavior analytics | 1 year | Third-Party |
| mp_mixpanel | Mixpanel | Event tracking for feature usage and funnel analysis | 1 year | Third-Party |
| amplitude_id | Amplitude | User identification for product analytics | 1 year | Third-Party |
| medxgo_page_views | MedxGo | Internal page view counter for performance monitoring | 30 days | First-Party |
| medxgo_error_log | MedxGo | Records JavaScript errors for debugging | 7 days | First-Party |
5.4 Marketing Cookies
These cookies track your browsing habits to deliver personalized advertisements and measure marketing campaign effectiveness.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| _fbp | Meta (Facebook) | Facebook Pixel identifier for ad targeting and retargeting | 3 months | Third-Party |
| fr | Meta (Facebook) | Facebook ad delivery and measurement | 3 months | Third-Party |
| tr | Meta (Facebook) | Facebook tracking pixel for conversion events | Session | Third-Party |
| _gcl_au | Google Ads | Google Ads conversion linker and attribution | 3 months | Third-Party |
| IDE | Google DoubleClick | Google ad personalization and remarketing | 1 year | Third-Party |
| test_cookie | Google DoubleClick | Checks if browser supports cookies for ad serving | 15 minutes | Third-Party |
| personalization_id | Twitter/X | Twitter ad personalization and tracking | 2 years | Third-Party |
| i/adsct | Twitter/X | Twitter conversion tracking pixel | Session | Third-Party |
| _tt_enable_cookie | TikTok | TikTok advertising and attribution tracking | 13 months | Third-Party |
| _ttp | TikTok | TikTok pixel for campaign measurement | 13 months | Third-Party |
| medxgo_promo_ref | MedxGo | Tracks referral source for promotional campaigns | 30 days | First-Party |
| medxgo_affiliate_id | MedxGo | Affiliate partner attribution for commission tracking | 90 days | First-Party |
5.5 Health Preference Cookies
These cookies are specific to MedxGo's health and wellness features. They store health-related preferences while maintaining privacy safeguards.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| medxgo_health_interests | MedxGo | Stores anonymized health interest categories (e.g., diabetes, fitness) | 6 months | First-Party |
| medxgo_med_reminders | MedxGo | Medication reminder schedule preferences (no specific drug names) | 1 year | First-Party |
| medxgo_symptom_history | MedxGo | Lexi AI conversation context for continuity (anonymized) | 7 days | First-Party |
| medxgo_wellness_goals | MedxGo | Wellness and fitness goal preferences | 6 months | First-Party |
| medxgo_insurance_pref | MedxGo | Preferred health insurance provider for direct billing | 1 year | First-Party |
5.6 Security & Fraud Prevention Cookies
These cookies are essential for detecting and preventing fraudulent activity, unauthorized access, and security threats. They cannot be disabled.
| Cookie Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| medxgo_device_fingerprint | MedxGo | Creates device signature for fraud detection and account security | 1 year | First-Party |
| medxgo_login_attempts | MedxGo | Tracks failed login attempts to prevent brute force attacks | 24 hours | First-Party |
| medxgo_risk_score | MedxGo | Temporary risk assessment score for transaction security | Session | First-Party |
| medxgo_captcha_token | MedxGo | Verifies human users during suspicious activity detection | 10 minutes | First-Party |
| __stripe_sid | Stripe | Stripe fraud detection and payment security | 30 minutes | Third-Party |
| __stripe_mid | Stripe | Stripe persistent fraud prevention identifier | 1 year | Third-Party |
| m | Stripe | Stripe machine learning fraud detection | 2 years | Third-Party |
| riskified_session_id | Riskified | E-commerce fraud prevention and risk scoring | Session | Third-Party |
| riskified_device_id | Riskified | Device identification for fraud pattern analysis | 1 year | Third-Party |
6. THIRD-PARTY COOKIES AND SERVICES
MedxGo integrates with various third-party service providers who may place cookies on your device. These providers are carefully vetted and bound by data processing agreements that comply with the NDPA.
6.1 Third-Party Service Categories
| Service Category | Provider(s) | Cookie Purpose | Privacy Policy Link |
|---|---|---|---|
| Analytics | Google Analytics, Firebase, Mixpanel, Amplitude | Traffic analysis, user behavior, app performance, crash reporting | https://policies.google.com/privacy, https://mixpanel.com/legal/privacy-policy, https://amplitude.com/privacy |
| Advertising | Google Ads, Meta (Facebook), Twitter/X, TikTok | Ad targeting, retargeting, conversion tracking, campaign measurement | https://policies.google.com/privacy, https://www.facebook.com/privacy/policy, https://twitter.com/en/privacy, https://www.tiktok.com/legal/privacy-policy |
| Payment Processing | Paystack, Flutterwave, Interswitch, Stripe | Fraud prevention, payment security, transaction verification | https://paystack.com/privacy, https://flutterwave.com/privacy, https://interswitchgroup.com/privacy, https://stripe.com/privacy |
| Cloud Infrastructure | Amazon Web Services (AWS), Google Cloud | Load balancing, server routing, DDoS protection | https://aws.amazon.com/privacy, https://cloud.google.com/privacy |
| Identity Verification | Smile Identity, YouVerify, VerifyMe | KYC verification, identity fraud prevention | https://smileidentity.com/privacy, https://youverify.co/privacy, https://verifyme.ng/privacy |
| Communication | Twilio, SendGrid, Africa's Talking | SMS delivery, email tracking, voice communication logs | https://www.twilio.com/legal/privacy, https://www.twilio.com/legal/privacy, https://africastalking.com/privacy |
| Fraud Prevention | Riskified, Sift | E-commerce fraud detection, risk scoring, pattern analysis | https://www.riskified.com/privacy-policy, https://sift.com/privacy |
| CDN & Security | Cloudflare | DDoS protection, bot management, content delivery optimization | https://www.cloudflare.com/privacypolicy/ |
6.2 Third-Party Data Sharing
Third-party cookies may transmit certain data to external providers. The following table outlines what data is shared and for what purpose:
| Data Category | Shared With | Purpose | Anonymized? |
|---|---|---|---|
| IP Address | Google Analytics, Cloudflare | Geolocation analysis, security threat detection | Partially (last octet truncated for Google) |
| Device Information | Firebase, Mixpanel, Riskified | App performance analytics, fraud prevention | Yes (for analytics); No (for security) |
| Browsing Behavior | Google Analytics, Meta, TikTok | Ad targeting, campaign optimization, retargeting | Yes (aggregated/anonymized for ads) |
| Transaction Metadata | Stripe, Paystack, Flutterwave | Payment processing, fraud prevention | No (required for transaction) |
| Session Identifiers | All third-party analytics | User journey tracking, session continuity | Yes (pseudonymized IDs) |
| Ad Interaction Data | Google Ads, Meta, TikTok | Conversion tracking, ROI measurement | Yes (event-level only) |
6.3 Cross-Border Data Transfers
Some third-party providers process data outside Nigeria. Under Section 41 of the NDPA, we ensure that such transfers are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the NDPC. Users consent to such transfers by accepting this Cookie Policy.
7. COOKIE CONSENT MECHANISM
MedxGo is committed to transparent and user-friendly cookie consent management in compliance with the NDPA and NDPC guidelines.
7.1 Consent Banner
When you first visit the MedxGo website or open the mobile app, you will be presented with a cookie consent banner that:
- Clearly explains that we use cookies
- Categorizes cookies by type (Essential, Functional, Analytics, Marketing, Health)
- Provides granular control to enable or disable non-essential cookie categories
- Links to this full Cookie Policy for detailed information
- Records your consent preferences for future visits
- Allows you to change your preferences at any time
7.2 Consent Management Tool
Users can access the cookie consent management tool through:
- Website: Footer link → 'Cookie Settings' or 'Manage Cookies'
- Mobile App: Settings → Privacy → Cookie Preferences
- Direct URL: https://medxgoapp.com/cookie-settings
7.3 Consent Withdrawal
You have the right to withdraw your consent for non-essential cookies at any time. Withdrawing consent will:
- Immediately stop the placement of new non-essential cookies
- Delete existing non-essential cookies from your device (where technically possible)
- Not affect the functionality of essential cookies
- May reduce the personalization and relevance of your experience
7.4 Consent Record Keeping
In compliance with the NDPA, MedxGo maintains records of cookie consent choices for a period of 2 years. These records include:
- Timestamp of consent or withdrawal
- Cookie categories accepted or rejected
- Device/browser identifier (pseudonymized)
- IP address (anonymized)
- Consent method (banner click, settings change)
8. COOKIE DURATION AND EXPIRATION
Cookie retention periods are carefully calibrated to balance functionality with privacy. The following table summarizes maximum retention periods by cookie category:
| Cookie Category | Maximum Duration | Rationale |
|---|---|---|
| Essential (Session) | Session only | Required only for active browsing session |
| Essential (Persistent) | 13 months | Consent record retention per NDPC guidance |
| Functional | 1 year | Preference retention across reasonable period |
| Analytics | 2 years | Industry standard for longitudinal analysis (Google Analytics) |
| Marketing | 13 months | Advertising campaign measurement cycles |
| Health Preference | 1 year | Annual health preference refresh recommended |
| Security | 1 year | Device fingerprinting for fraud pattern recognition |
8.1 Automatic Expiration
All cookies are configured with automatic expiration dates. Upon expiration, cookies are either:
- Renewed with renewed consent (for non-essential cookies)
- Deleted automatically by the browser or app
- Replaced with updated versions if still required
8.2 Data Retention Post-Account Deletion
When you delete your MedxGo account:
- All first-party cookies are immediately invalidated and scheduled for deletion
- Third-party cookies remain subject to the respective provider's retention policies
- Analytics data is anonymized within 90 days of account deletion
- Marketing identifiers are removed from active targeting lists within 30 days
9. HOW TO MANAGE COOKIES
You have multiple options for managing cookies on your device. The following guidance applies to both the MedxGo Platform and general web browsing.
9.1 Platform-Specific Cookie Controls
MedxGo provides built-in controls for managing cookie preferences:
| Platform | Access Path | Actions Available |
|---|---|---|
| Website (Desktop) | Footer → 'Cookie Settings' or 'Manage Cookies' | Enable/disable each cookie category; view current consent status; withdraw all non-essential consent |
| Website (Mobile Browser) | Menu → Settings → Privacy → Cookies | Same as desktop with mobile-optimized interface |
| iOS App | Settings → Privacy & Security → Cookie Preferences | Toggle categories on/off; reset all preferences; export consent record |
| Android App | Settings → Privacy → Cookie Management | Toggle categories on/off; clear app cache; reset all preferences |
9.2 Browser-Level Cookie Controls
You can also manage cookies through your web browser settings:
| Browser | Path to Cookie Settings | Capabilities |
|---|---|---|
| Google Chrome | Settings → Privacy and Security → Cookies and other site data | Block all, block third-party, clear on exit, site-specific exceptions |
| Mozilla Firefox | Settings → Privacy & Security → Cookies and Site Data | Standard/Strict/Custom protection levels, delete cookies on close |
| Apple Safari | Preferences → Privacy → Cookies and website data | Prevent cross-site tracking, block all cookies, manage website data |
| Microsoft Edge | Settings → Cookies and site permissions → Manage and delete cookies | Block third-party, clear on exit, preloaded site exceptions |
| Opera | Settings → Privacy & Security → Cookies | Block all, block third-party, clear on exit |
9.3 Mobile Device Controls
For mobile app cookie and tracking management:
| Device/OS | Path to Controls | Capabilities |
|---|---|---|
| iOS (iPhone/iPad) | Settings → Privacy → Tracking → 'Allow Apps to Request to Track' | Disable cross-app tracking, reset advertising identifier, limit ad tracking |
| Android | Settings → Privacy → Ads → 'Opt out of Ads Personalization' | Reset advertising ID, opt out of personalized ads, delete advertising ID |
| Both Platforms | Settings → Privacy → Location Services | Disable location tracking for specific apps or system-wide |
9.4 Impact of Disabling Cookies
Disabling certain cookies may affect your experience on the MedxGo Platform:
| Cookie Category Disabled | Impact on Platform Functionality |
|---|---|
| Essential | Platform will not function; login, checkout, and security features will fail |
| Functional | Preferences not remembered; must re-select language, location, and pharmacy each visit |
| Analytics | No impact on functionality; we lose ability to improve Platform based on your usage |
| Marketing | No impact on functionality; ads will be less relevant; promotional offers may not be personalized |
| Health Preference | Medication reminders and wellness recommendations will not be personalized |
| Security | Increased fraud risk; additional verification steps may be required for transactions |
10. COOKIE USE BY USER TYPE
MedxGo serves multiple user types, and cookie usage varies based on the features and functionality each user group accesses.
10.1 Customers (End Users)
- Essential cookies for login, session management, and checkout
- Functional cookies for saved addresses, preferred pharmacies, and restaurant favorites
- Analytics cookies for order behavior, search patterns, and feature usage
- Marketing cookies for personalized promotions and retargeting
- Health preference cookies for medication reminders and wellness goals
- Security cookies for payment fraud prevention and account protection
10.2 Pharmacy Vendors
- Essential cookies for dashboard authentication and session management
- Functional cookies for inventory display preferences and order notification settings
- Analytics cookies for sales performance, order volume, and customer ratings
- Security cookies for prescription verification audit trails and compliance logging
10.3 Restaurant Vendors
- Essential cookies for dashboard access and menu management
- Functional cookies for operating hours, promotional settings, and notification preferences
- Analytics cookies for order analytics, peak time analysis, and customer feedback
10.4 Riders
- Essential cookies for app authentication and delivery session management
- Functional cookies for route preferences, notification settings, and availability status
- Analytics cookies for delivery completion rates, earnings tracking, and performance metrics
- Location cookies for real-time GPS tracking during active delivery sessions
10.5 Healthcare Providers
- Essential cookies for telemedicine portal authentication and session security
- Functional cookies for consultation preferences, availability scheduling, and notification settings
- Security cookies for patient data access logging and HIPAA-equivalent compliance monitoring
- No marketing or analytics cookies that could compromise patient confidentiality
11. COOKIES AND HEALTHCARE DATA
Given MedxGo's role as a health-tech platform processing sensitive personal data (including Healthcare Data under the NDPA), we implement enhanced safeguards for cookies that may interact with health-related information.
11.1 Health Data Protection Principles
All cookies related to health features are designed and operated according to the following principles:
Data Minimization: Health-related cookies store only the minimum necessary data (e.g., reminder preferences, not specific medication names or dosages).
Pseudonymization: Health preference cookies use pseudonymized identifiers that cannot directly identify the user without additional data.
Encryption: All health-related cookie data is encrypted at rest and in transit using AES-256 encryption.
No Third-Party Sharing: Health preference cookies are never shared with third-party advertisers or analytics providers.
Short Retention: Health-related cookies have shorter retention periods (maximum 6-12 months) compared to general cookies.
Separate Consent: Users provide separate, explicit consent for health-related cookies beyond general analytics consent.
11.2 Lexi AI and Cookies
Lexi AI interactions may generate cookies for session continuity and preference memory. These cookies:
- Do not store the content of health-related conversations
- Retain only anonymized interaction metadata (e.g., number of sessions, feature usage)
- Are never used for marketing or advertising purposes
- Are deleted within 7 days of the last interaction
- Require explicit consent separate from general analytics consent
11.3 Prescription Data and Cookies
Prescription data is NEVER stored in cookies. The prescription upload and verification process:
- Uses session-only cookies for upload progress tracking
- Stores prescription images in encrypted cloud storage, not in browser cookies
- Does not use persistent cookies to track prescription history
Requires re-authentication for each prescription upload session
12. CROSS-BORDER COOKIE TRANSFERS
As MedxGo expands across Africa and integrates with global third-party services, cookie data may be transferred across international borders.
12.1 Transfer Mechanisms
Under Section 41 of the NDPA, MedxGo ensures that international cookie data transfers are protected by:
Standard Contractual Clauses (SCCs): Legally binding contracts approved by the NDPC with all third-party providers processing data outside Nigeria.
Adequacy Decisions: Reliance on NDPC adequacy decisions for recipient countries with equivalent data protection standards.
Data Localization: Primary cookie data storage for Nigerian users remains within Nigeria; only necessary analytics and security data is transferred.
Transparency: Users are informed of potential cross-border transfers in the cookie consent banner and this Policy.
12.2 Third-Party Provider Locations
The following table outlines the geographic locations of key third-party cookie providers:
| Provider | Service | Data Processing Location | Safeguard |
|---|---|---|---|
| Google (Analytics, Ads, Firebase) | Analytics, advertising, app analytics | United States, Ireland, Singapore | SCCs; data minimization; IP anonymization |
| Meta (Facebook) | Advertising, retargeting | United States, Ireland | SCCs; limited data sharing |
| Stripe | Payment processing, fraud prevention | United States, Ireland | SCCs; PCI-DSS compliance; encryption |
| Paystack | Payment processing | Nigeria, South Africa | Local processing; NDPA compliance |
| Flutterwave | Payment processing | Nigeria, United States, United Kingdom | SCCs; local data residency where possible |
| Mixpanel | Product analytics | United States | SCCs; pseudonymized data only |
| Cloudflare | CDN, security | United States, global edge locations | SCCs; minimal data retention |
| AWS | Cloud infrastructure | Nigeria, South Africa, Ireland, United States | SCCs; regional data residency options |
13. COOKIE SECURITY MEASURES
MedxGo implements robust technical and organizational measures to protect cookie data from unauthorized access, alteration, or deletion.
13.1 Technical Security Measures
| Measure | Implementation | Purpose |
|---|---|---|
| Secure Flag | All cookies marked with 'Secure' attribute | Ensures cookies are only transmitted over HTTPS connections |
| HttpOnly Flag | Essential and security cookies marked HttpOnly | Prevents JavaScript access to cookies, mitigating XSS attacks |
| SameSite Attribute | All cookies set with SameSite=Lax or SameSite=Strict | Prevents cross-site request forgery (CSRF) attacks |
| Encryption | AES-256 encryption for cookie values containing sensitive data | Protects cookie contents if intercepted |
| Signature Validation | HMAC-SHA256 signatures on state cookies | Ensures cookie integrity and prevents tampering |
| Domain Restriction | Cookies scoped to medxgoapp.com and subdomains only | Prevents cross-domain cookie leakage |
| Rate Limiting | Cookie-based request throttling for API endpoints | Prevents brute force and automated attacks |
| Regular Rotation | Session tokens and CSRF tokens rotated every 15 minutes | Limits window of compromise if token is stolen |
13.2 Organizational Security Measures
- Access to cookie configuration and management tools restricted to authorized engineering and security personnel
- Regular security audits of cookie implementation by third-party penetration testers
- Cookie policy and implementation reviewed quarterly by the Data Protection Officer
- Incident response procedures include cookie compromise assessment and remediation
- Employee training on cookie security and privacy implications as part of NDPA compliance program
14. CHILDREN'S PRIVACY AND COOKIES
MedxGo does not knowingly collect personal data from children under 16 through cookies or any other means. Our cookie practices for minors include:
- Age verification during account creation prevents underage users from accessing the Platform
- If a child under 16 is discovered to have an account, all associated cookies are immediately deleted
- Marketing and analytics cookies are never placed on devices identified as belonging to children
- Health preference cookies for pediatric users require explicit parental consent and are limited to general wellness categories only
- Location tracking cookies for minors are disabled by default and require separate parental authorization
Parents or guardians who believe their child has interacted with our Platform without appropriate consent should contact us immediately at privacy@medxgoapp.com.
15. UPDATES TO THIS COOKIE POLICY
MedxGo reserves the right to update this Cookie Policy to reflect changes in technology, legal requirements, or our business practices.
15.1 Notification of Changes
Material changes to this Cookie Policy will be communicated through:
- Email notification to registered Users at least 30 days before the effective date
- In-app notification banner upon next login
- Prominent posting on the MedxGo website
- Updated cookie consent banner requiring renewed consent where applicable
15.2 Change Log
A summary of material changes to this Cookie Policy will be maintained in the following table:
| Version | Effective Date | Changes Made |
|---|---|---|
| 1.0 | June 24, 2026 | Initial publication of Cookie Policy |
| — | — | — |
This table will be updated with each material revision to the Cookie Policy.
16. CONTACT INFORMATION
For questions, concerns, or requests related to this Cookie Policy or our cookie practices, please contact us:
MedxGo Technologies Limited
Website: https://medxgoapp.com/
Email: privacy@medxgoapp.com
Cookie-Specific Inquiries: cookies@medxgoapp.com
Data Protection Officer: dpo@medxgoapp.com
Phone: +234-XXX-XXX-XXXX
Business Hours: Monday–Friday, 8:00 AM–8:00 PM WAT; Saturday–Sunday, 9:00 AM–5:00 PM WAT
Registered Address: [Address], Lagos, Nigeria
16.1 Cookie Complaints
If you believe your cookie-related privacy rights have been violated, you may:
- Contact our Data Protection Officer at dpo@medxgoapp.com for resolution
- Lodge a complaint with the Nigeria Data Protection Commission at info@ndpc.gov.ng
- Seek judicial remedies under Section 55 of the NDPA
17. REGULATORY COMPLIANCE
MedxGo's cookie practices are designed to comply with the following regulatory frameworks:
17.1 Nigerian Regulatory Framework
- Nigeria Data Protection Act 2023 (NDPA) – Sections 24, 25, 30, 41
- Nigeria Data Protection Regulation 2019 (NDPR) – Part 3 (Data Subject Rights)
- NDPC Guidelines on Data Processing – Cookie consent and transparency requirements
- Federal Competition and Consumer Protection Act 2018 – Transparent data practices
- Cybercrimes (Prohibition, Prevention, etc.) Act 2015 – Security and unauthorized access prevention
17.2 African Expansion Compliance
As MedxGo expands across Africa, cookie practices will be adapted to comply with:
South Africa: Protection of Personal Information Act (POPIA) – Section 11 (Consent), Section 69 (Direct Marketing)
Kenya: Data Protection Act 2019 – Section 30 (Consent), Section 31 (Data Subject Rights)
Ghana: Data Protection Act 2012 (Act 843) – Section 3 (Privacy Principles)
Egypt: Personal Data Protection Law – Articles 4-6 (Processing Conditions)
Rwanda: Law No. 058/2021 on Data Protection and Privacy – Articles 12-15 (Consent Requirements)
17.3 International Standards
MedxGo also aligns with international best practices and standards:
- General Data Protection Regulation (GDPR) – Articles 5, 6, 7 (Lawfulness, Fairness, Transparency, Consent)
- ePrivacy Directive (EU Cookie Directive) – Transparency and consent requirements
- ISO/IEC 27001:2013 – Information security management including cookie security
- ISO/IEC 27701:2019 – Privacy information management for cookie data processing
- IAB Transparency and Consent Framework – Industry standard for digital advertising consent
17.4 Regulatory Registrations
MedxGo is registered with the following regulatory bodies:
- Nigeria Data Protection Commission (NDPC) – Data Controller Registration: [Registration Number]
- Corporate Affairs Commission (CAC) – [Registration Number]
- Tax Identification Number (TIN) – [TIN]
© 2026 MedxGo Technologies Limited. All Rights Reserved.
Document Version: 1.0
Effective Date: June 24, 2026
Review Date: June 24, 2027 (or earlier if required by regulatory changes)
Approved By: Board of Directors, MedxGo Technologies Limited
Data Protection Officer Certification: Certified compliant with NDPA 2023 and NDPC guidelines