๐Ÿ›บ Pilot launch open in Colombo โ€” 10 Pioneer spots remaining ยท Claim yours โ†’
Legal Document

Privacy Policy

Effective date: 12 June 2026 ยท Version 1.0 ยท mydiio (Private) Limited ยท Colombo, Sri Lanka

We believe you have a right to know exactly what we do with information about you. This policy explains what we collect, why we collect it, who we share it with, and what rights you have. We have written it to be read by a person, not a lawyer. If anything is unclear, write to us at mydiiomedia@gmail.com and we will explain it plainly.
Section 01

Who We Are

mydiio (Private) Limited operates Sri Lanka's first cloud-managed in-vehicle advertising platform. We place Android tablet screens inside Colombo tuk-tuks. Passengers see advertisements from local businesses. Drivers earn passive income. Advertisers receive GPS-verified proof that their ad was displayed.

Our registered business operates in Colombo, Sri Lanka. Our contact email is mydiiomedia@gmail.com and our website is mydiio.com.

We are the data controller for all personal information collected through our platform, portals, and website.

Section 02

Who This Policy Covers

This policy applies to four groups of people who interact with mydiio:

  • โ—Advertisers โ€” businesses that purchase advertising campaigns on the mydiio network, including those on our waitlist.
  • โ—Driver partners โ€” tuk-tuk drivers who join the mydiio programme and host a tablet screen in their vehicle.
  • โ—Website visitors โ€” anyone who visits mydiio.com or fills out our waitlist or interest forms.
  • โ—Passengers โ€” members of the public who ride in tuk-tuks carrying a mydiio screen. Passengers are not registered users of our platform. We do not collect personal data about individual passengers. The screen they see displays advertisements; it does not capture images, audio, or identifying information about them.
Section 03

Information We Collect

From advertisers

When you register an interest or create an account with mydiio as an advertiser, we may collect:

  • โ—Your name and the name of your business
  • โ—Your WhatsApp number and email address
  • โ—Your business category and preferred advertising tier
  • โ—Payment information including deposit transaction records (we do not store card numbers directly; payments are processed through our payment partners)
  • โ—The advertising creatives you upload โ€” video files and image files
  • โ—Your campaign preferences, scheduling choices, and campaign history
  • โ—Login credentials for your advertiser portal account (passwords are stored in hashed, encrypted form and are never readable by our team)

From driver partners

When you join the mydiio driver programme, we collect:

  • โ—Your name, WhatsApp number, and bank account details for payment
  • โ—Your driver registration number and vehicle details
  • โ—The deposit you pay, which is tracked in our records
  • โ—Your daily operating hours, screen uptime data, and route bonus eligibility
  • โ—Your referral activity, including the names and contact details of drivers you refer
  • โ—Login credentials for your driver portal account
  • โ—The GPS location of your vehicle during operating hours (see Section 5 for full details)
  • โ—Device pairing information for the tablet installed in your vehicle

From website visitors

When you visit mydiio.com, we may collect:

  • โ—Information you voluntarily submit through our waitlist or driver interest forms
  • โ—Standard web analytics data such as your browser type, approximate location (city level, derived from IP address), pages visited, and time on site
  • โ—Your IP address for security and analytics purposes

Automatically from devices and tablets

Our tablet devices in the field generate operational data including:

  • โ—GPS coordinates of the device, transmitted every five minutes during operating hours
  • โ—Ad play logs recording which advertisement was displayed, at what time, for how long, and at which GPS coordinates
  • โ—Device online and offline status updated continuously
  • โ—Remote screenshots of the tablet screen captured automatically every thirty minutes during operating hours
  • โ—Device health signals including screen status and data connectivity

This operational data is tied to the vehicle and device, not to individual passengers. Screenshots capture the advertisement content being displayed, not the interior of the vehicle or its passengers.

Section 04

How We Use Your Information

For advertisers:

  • โ—To set up and manage your advertising account and campaigns
  • โ—To deliver your advertisements to screens in the mydiio fleet
  • โ—To provide you with verified impression reports showing where, when, and how often your ad was displayed
  • โ—To process payments and manage billing
  • โ—To send you weekly performance reports and account communications
  • โ—To manage your loyalty points balance and category exclusivity status
  • โ—To contact you about your campaigns and any content review decisions

For driver partners:

  • โ—To manage your partnership agreement and earnings record
  • โ—To calculate and process your monthly payments on the 5th of each month
  • โ—To track your route bonus eligibility based on active screen hours
  • โ—To monitor tablet uptime and identify technical faults
  • โ—To send you daily WhatsApp updates about your screen status and earnings
  • โ—To manage the driver compliance programme and apply the graduated consequence system where applicable
  • โ—To track referral bonuses

For the platform generally:

  • โ—To prevent fraud and verify that ad impressions are genuine
  • โ—To ensure the security and integrity of the platform
  • โ—To improve platform features and user experience
  • โ—To comply with our legal obligations
Section 05

GPS and Location Data

Location data is central to what mydiio does. Understanding this section is important.

"Our platform records the GPS coordinates of every tablet device in our fleet every five minutes during operating hours. This data is tied to the vehicle and device identifier, not to your personal identity as an individual."

Why we collect location data:

  • โ—To provide advertisers with GPS-stamped proof that their advertisement was displayed at a real location
  • โ—To monitor driver uptime and route activity for bonus calculations
  • โ—To detect when a device goes offline unexpectedly
  • โ—To show advertisers a live map of where their brand is travelling across Colombo

What we do not do with location data:

  • โ—We do not sell individual driver location data to third parties
  • โ—We do not share location data with any government or law enforcement authority unless compelled by a valid legal order under Sri Lankan law
  • โ—We do not use location data to build profiles of individual passengers

Aggregated and anonymised mobility data

Over time, the collective GPS data from our fleet builds a picture of how tuk-tuks move across Colombo. We may use this aggregated, anonymised data to produce mobility insights. Individual vehicle or driver data is not identifiable in any such output.

Driver consent

GPS monitoring is a core and disclosed element of the mydiio driver partnership. All driver partners sign a written agreement before their screen is installed. That agreement explicitly describes the monitoring programme, including GPS tracking, screenshot capture, and play log recording. By signing the agreement, drivers consent to this monitoring for the purposes described in this policy.

Section 06

Advertising and Impression Data

Every time an advertisement plays on a mydiio screen, our system records an impression log containing the advertisement identifier, the vehicle identifier, the timestamp, the GPS coordinates, and the play duration.

This data is the foundation of mydiio's Radical Transparency commitment. Advertisers can view their own impression logs at any time through the Advertiser Portal. They see data about their own campaigns only. Impression data is used to generate weekly reports and to calculate billing. It is never sold to third parties in identifiable form.

Section 07

How Long We Keep Your Data

  • โ—Advertiser account data โ€” retained for the duration of your contract plus three years
  • โ—Driver partner data โ€” retained for the duration of your agreement plus three years; bank account details are deleted within 90 days of your agreement ending unless a payment dispute is outstanding
  • โ—GPS and play log data โ€” retained for two years from the date of collection
  • โ—Remote screenshots โ€” retained for 90 days
  • โ—Website enquiry data โ€” retained for 12 months if no business relationship is established
  • โ—Waitlist submissions โ€” retained until you ask us to remove them or until 24 months from submission, whichever comes first

When data is no longer required, we delete it securely from our systems.

Section 08

Who We Share Data With

We do not sell your personal data. We share data only in the following circumstances.

Service providers (process data on our behalf under data protection agreements):

  • โ—Supabase โ€” our cloud database and authentication provider (SOC 2 Type II compliant)
  • โ—Cloudinary โ€” video and image hosting for advertising creatives
  • โ—Cloudflare โ€” website and application hosting and DNS provider
  • โ—Resend โ€” email delivery service for transactional emails
  • โ—OpenWeatherMap โ€” weather data for informational interstitials on tablets. No personal data is shared.
  • โ—NewsAPI.org โ€” Sri Lanka news content for informational interstitials. No personal data is shared.
  • โ—Fully Kiosk Browser / Fully Cloud โ€” tablet device management software
  • โ—WhatsApp Business API โ€” used to send automated messages to driver partners

Legal requirements

We may disclose personal data to government authorities or law enforcement if required by applicable Sri Lankan law, a court order, or a valid legal process. We will notify you of any such request to the extent permitted by law.

Business transfers

If mydiio is acquired by or merges with another company, your data may be transferred as part of that transaction. We will notify you before this happens.

Section 09

Security

  • โ—Row-Level Security (RLS) enforced at the database level โ€” each user can only access their own data
  • โ—Passwords stored in hashed, encrypted form โ€” unreadable by anyone including our team
  • โ—API tokens and secrets stored as encrypted environment variables, never in code
  • โ—All portal access is role-based โ€” staff see only the data relevant to their function
  • โ—All staff actions are logged with a timestamp and the identity of the person who took the action
  • โ—Device pairing codes expire after 30 minutes and are single-use

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at mydiiomedia@gmail.com.

Section 10

Your Rights

You have the following rights regarding your personal data. To exercise any of them, contact us at mydiiomedia@gmail.com.

  • โ—Right to access โ€” you can ask us for a copy of the personal data we hold about you
  • โ—Right to correction โ€” if information we hold about you is inaccurate, you can ask us to correct it
  • โ—Right to deletion โ€” you can ask us to delete your personal data, subject to any legal or contractual obligation to retain it
  • โ—Right to object โ€” you can ask us to stop using your data for any purpose you disagree with
  • โ—Right to portability โ€” you can ask for your data in a machine-readable format

We will respond to all valid requests within 30 days.

Section 11

Cookies and Tracking

Our public website (mydiio.com) uses only the cookies necessary for the site to function. We do not currently use advertising trackers or third-party analytics cookies. If this changes, we will update this policy and notify registered users.

Our portal applications use session cookies to keep you logged in. These are deleted when you log out or close your browser.

Section 12

Children

Our portals and services are not directed at or intended for anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us so we can delete it.

All advertising content displayed on our screens is reviewed before approval. We enforce an age-appropriate content standard and do not approve content unsuitable for a general audience including minors.

Section 13

Changes to This Policy

We may update this policy as our platform evolves. When we make meaningful changes, we will notify you by email (for registered users) and post a notice on the website. The updated policy will show a new effective date at the top of this page.

Continuing to use our services after a policy update means you accept the revised terms.

Section 14

Contact Us

Privacy questions

If you have questions about this policy, want to exercise your rights, or want to report a concern:

Email: mydiiomedia@gmail.com

Phone / WhatsApp: 070 747 1002

Website: mydiio.com

mydiio (Private) Limited ยท Colombo, Sri Lanka

ยฉ 2026 mydiio ยท Colombo ยท Sri LankaBuilt in Colombo, for Colombo