Privacy Policy
Effective date: 12 June 2026 ยท Version 1.0 ยท mydiio (Private) Limited ยท Colombo, Sri Lanka
Who We Are
mydiio (Private) Limited operates Sri Lanka's first cloud-managed in-vehicle advertising platform. We place Android tablet screens inside Colombo tuk-tuks. Passengers see advertisements from local businesses. Drivers earn passive income. Advertisers receive GPS-verified proof that their ad was displayed.
Our registered business operates in Colombo, Sri Lanka. Our contact email is mydiiomedia@gmail.com and our website is mydiio.com.
We are the data controller for all personal information collected through our platform, portals, and website.
Who This Policy Covers
This policy applies to four groups of people who interact with mydiio:
- โAdvertisers โ businesses that purchase advertising campaigns on the mydiio network, including those on our waitlist.
- โDriver partners โ tuk-tuk drivers who join the mydiio programme and host a tablet screen in their vehicle.
- โWebsite visitors โ anyone who visits mydiio.com or fills out our waitlist or interest forms.
- โPassengers โ members of the public who ride in tuk-tuks carrying a mydiio screen. Passengers are not registered users of our platform. We do not collect personal data about individual passengers. The screen they see displays advertisements; it does not capture images, audio, or identifying information about them.
Information We Collect
From advertisers
When you register an interest or create an account with mydiio as an advertiser, we may collect:
- โYour name and the name of your business
- โYour WhatsApp number and email address
- โYour business category and preferred advertising tier
- โPayment information including deposit transaction records (we do not store card numbers directly; payments are processed through our payment partners)
- โThe advertising creatives you upload โ video files and image files
- โYour campaign preferences, scheduling choices, and campaign history
- โLogin credentials for your advertiser portal account (passwords are stored in hashed, encrypted form and are never readable by our team)
From driver partners
When you join the mydiio driver programme, we collect:
- โYour name, WhatsApp number, and bank account details for payment
- โYour driver registration number and vehicle details
- โThe deposit you pay, which is tracked in our records
- โYour daily operating hours, screen uptime data, and route bonus eligibility
- โYour referral activity, including the names and contact details of drivers you refer
- โLogin credentials for your driver portal account
- โThe GPS location of your vehicle during operating hours (see Section 5 for full details)
- โDevice pairing information for the tablet installed in your vehicle
From website visitors
When you visit mydiio.com, we may collect:
- โInformation you voluntarily submit through our waitlist or driver interest forms
- โStandard web analytics data such as your browser type, approximate location (city level, derived from IP address), pages visited, and time on site
- โYour IP address for security and analytics purposes
Automatically from devices and tablets
Our tablet devices in the field generate operational data including:
- โGPS coordinates of the device, transmitted every five minutes during operating hours
- โAd play logs recording which advertisement was displayed, at what time, for how long, and at which GPS coordinates
- โDevice online and offline status updated continuously
- โRemote screenshots of the tablet screen captured automatically every thirty minutes during operating hours
- โDevice health signals including screen status and data connectivity
This operational data is tied to the vehicle and device, not to individual passengers. Screenshots capture the advertisement content being displayed, not the interior of the vehicle or its passengers.
How We Use Your Information
For advertisers:
- โTo set up and manage your advertising account and campaigns
- โTo deliver your advertisements to screens in the mydiio fleet
- โTo provide you with verified impression reports showing where, when, and how often your ad was displayed
- โTo process payments and manage billing
- โTo send you weekly performance reports and account communications
- โTo manage your loyalty points balance and category exclusivity status
- โTo contact you about your campaigns and any content review decisions
For driver partners:
- โTo manage your partnership agreement and earnings record
- โTo calculate and process your monthly payments on the 5th of each month
- โTo track your route bonus eligibility based on active screen hours
- โTo monitor tablet uptime and identify technical faults
- โTo send you daily WhatsApp updates about your screen status and earnings
- โTo manage the driver compliance programme and apply the graduated consequence system where applicable
- โTo track referral bonuses
For the platform generally:
- โTo prevent fraud and verify that ad impressions are genuine
- โTo ensure the security and integrity of the platform
- โTo improve platform features and user experience
- โTo comply with our legal obligations
GPS and Location Data
Location data is central to what mydiio does. Understanding this section is important.
"Our platform records the GPS coordinates of every tablet device in our fleet every five minutes during operating hours. This data is tied to the vehicle and device identifier, not to your personal identity as an individual."
Why we collect location data:
- โTo provide advertisers with GPS-stamped proof that their advertisement was displayed at a real location
- โTo monitor driver uptime and route activity for bonus calculations
- โTo detect when a device goes offline unexpectedly
- โTo show advertisers a live map of where their brand is travelling across Colombo
What we do not do with location data:
- โWe do not sell individual driver location data to third parties
- โWe do not share location data with any government or law enforcement authority unless compelled by a valid legal order under Sri Lankan law
- โWe do not use location data to build profiles of individual passengers
Aggregated and anonymised mobility data
Over time, the collective GPS data from our fleet builds a picture of how tuk-tuks move across Colombo. We may use this aggregated, anonymised data to produce mobility insights. Individual vehicle or driver data is not identifiable in any such output.
Driver consent
GPS monitoring is a core and disclosed element of the mydiio driver partnership. All driver partners sign a written agreement before their screen is installed. That agreement explicitly describes the monitoring programme, including GPS tracking, screenshot capture, and play log recording. By signing the agreement, drivers consent to this monitoring for the purposes described in this policy.
Advertising and Impression Data
Every time an advertisement plays on a mydiio screen, our system records an impression log containing the advertisement identifier, the vehicle identifier, the timestamp, the GPS coordinates, and the play duration.
This data is the foundation of mydiio's Radical Transparency commitment. Advertisers can view their own impression logs at any time through the Advertiser Portal. They see data about their own campaigns only. Impression data is used to generate weekly reports and to calculate billing. It is never sold to third parties in identifiable form.
How Long We Keep Your Data
- โAdvertiser account data โ retained for the duration of your contract plus three years
- โDriver partner data โ retained for the duration of your agreement plus three years; bank account details are deleted within 90 days of your agreement ending unless a payment dispute is outstanding
- โGPS and play log data โ retained for two years from the date of collection
- โRemote screenshots โ retained for 90 days
- โWebsite enquiry data โ retained for 12 months if no business relationship is established
- โWaitlist submissions โ retained until you ask us to remove them or until 24 months from submission, whichever comes first
When data is no longer required, we delete it securely from our systems.
Who We Share Data With
We do not sell your personal data. We share data only in the following circumstances.
Service providers (process data on our behalf under data protection agreements):
- โSupabase โ our cloud database and authentication provider (SOC 2 Type II compliant)
- โCloudinary โ video and image hosting for advertising creatives
- โCloudflare โ website and application hosting and DNS provider
- โResend โ email delivery service for transactional emails
- โOpenWeatherMap โ weather data for informational interstitials on tablets. No personal data is shared.
- โNewsAPI.org โ Sri Lanka news content for informational interstitials. No personal data is shared.
- โFully Kiosk Browser / Fully Cloud โ tablet device management software
- โWhatsApp Business API โ used to send automated messages to driver partners
Legal requirements
We may disclose personal data to government authorities or law enforcement if required by applicable Sri Lankan law, a court order, or a valid legal process. We will notify you of any such request to the extent permitted by law.
Business transfers
If mydiio is acquired by or merges with another company, your data may be transferred as part of that transaction. We will notify you before this happens.
Security
- โRow-Level Security (RLS) enforced at the database level โ each user can only access their own data
- โPasswords stored in hashed, encrypted form โ unreadable by anyone including our team
- โAPI tokens and secrets stored as encrypted environment variables, never in code
- โAll portal access is role-based โ staff see only the data relevant to their function
- โAll staff actions are logged with a timestamp and the identity of the person who took the action
- โDevice pairing codes expire after 30 minutes and are single-use
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at mydiiomedia@gmail.com.
Your Rights
You have the following rights regarding your personal data. To exercise any of them, contact us at mydiiomedia@gmail.com.
- โRight to access โ you can ask us for a copy of the personal data we hold about you
- โRight to correction โ if information we hold about you is inaccurate, you can ask us to correct it
- โRight to deletion โ you can ask us to delete your personal data, subject to any legal or contractual obligation to retain it
- โRight to object โ you can ask us to stop using your data for any purpose you disagree with
- โRight to portability โ you can ask for your data in a machine-readable format
We will respond to all valid requests within 30 days.
Cookies and Tracking
Our public website (mydiio.com) uses only the cookies necessary for the site to function. We do not currently use advertising trackers or third-party analytics cookies. If this changes, we will update this policy and notify registered users.
Our portal applications use session cookies to keep you logged in. These are deleted when you log out or close your browser.
Children
Our portals and services are not directed at or intended for anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us so we can delete it.
All advertising content displayed on our screens is reviewed before approval. We enforce an age-appropriate content standard and do not approve content unsuitable for a general audience including minors.
Changes to This Policy
We may update this policy as our platform evolves. When we make meaningful changes, we will notify you by email (for registered users) and post a notice on the website. The updated policy will show a new effective date at the top of this page.
Continuing to use our services after a policy update means you accept the revised terms.
Contact Us
Privacy questions
If you have questions about this policy, want to exercise your rights, or want to report a concern:
Email: mydiiomedia@gmail.com
Phone / WhatsApp: 070 747 1002
Website: mydiio.com
mydiio (Private) Limited ยท Colombo, Sri Lanka