Privacy Policy
Draft pending legal review. Prepared during development; must be reviewed and approved by qualified counsel before launch, and completed with the operating entity's details and its full processor inventory.
What we collect
Account data. Your name, email address, country, time zone, and the version of our legal documents you accepted. Passwords are stored only as an Argon2id hash and cannot be recovered by us or by anyone else.
Usage data. The requests you make — carrier, destination, quantity, timestamps, and the records assigned to you — together with your credit ledger and any support correspondence.
Technical data. IP address, user agent, and a request identifier for each request, used for security, abuse prevention and support.
Payment data. Handled by our payment provider through a hosted, tokenised checkout. We receive confirmation of payment and display fragments such as card brand and last four digits. We never receive or store full card numbers.
What we do not collect
We do not buy personal data about you from third parties, we do not build advertising profiles, and we do not sell your data.
Why we process it
- To provide the service you asked for (performance of a contract).
- To bill you and meet accounting obligations (contract and legal obligation).
- To prevent fraud and abuse, and to meet sanctions and anti-money-laundering obligations (legitimate interests and legal obligation).
- To answer your support requests (contract and legitimate interests).
- To improve the service using aggregate, non-identifying analysis (legitimate interests).
Analytics and cookies
Cookies strictly necessary for signing in and keeping the service secure are always set. Analytics cookies are not set unless you allow them, and any analytics script is loaded only after consent and after the page is ready — never before. See our Cookie Policy.
Who we share it with
Only the processors we need to run the service: our hosting provider, our payment provider, our email provider, our error-tracking provider, and our contracted tracking-data providers. Each is bound by a data-processing agreement. The complete list, with locations, will be published here on legal review.
We disclose data to authorities only where legally required, and we push back on requests that exceed what the law requires.
How long we keep it
Account and billing records are kept for as long as the account is active and then for the period required by tax and accounting law. Request and assignment records are retained so that provenance remains auditable. Technical logs are retained for a short period for security purposes. Credit ledger and audit entries are immutable by design and are retained for the life of the account.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to processing, and to complain to a supervisory authority.
You can export your data from your settings page. To request deletion, contact us — note that we must retain certain billing and audit records where the law requires it, and we will tell you exactly what is retained and why.
Security
Passwords are hashed with Argon2id. Sessions use secure, HttpOnly cookies with CSRF protection, and you can revoke every other session yourself. API keys are stored only as hashes; the secret is shown once and cannot be recovered. Provider and carrier credentials are encrypted at rest. Two-factor authentication is available to all customers and mandatory for our staff accounts.
If a breach affects your data, we will tell you and the relevant authority within the timeframes the law requires.
International transfers
To be completed on legal review, with the transfer mechanisms used for each processor.
Contact
Data-protection enquiries: see our contact page. The controller's identity and, where applicable, its data-protection representative will be named here on legal review.
Questions about this document? Contact us.