Privacy Policy

Last updated: 2026-06-04 Effective date: 2026-06-04


1. Introduction

This Privacy Policy describes how we collect, use, and share information when you use our shipping, order-management, and tracking services (the "Service").

By using the Service, you agree to the practices described in this policy.


2. Information we collect

We collect the following categories of information:

2.1 Account information

When you create an account, we collect your name, email address, password (stored in hashed form), organisation or company name, and your role within the organisation.

2.2 Connected store information

When you connect an e-commerce platform (such as Shopify or WooCommerce), we collect the store identifier, OAuth access and refresh tokens, the permissions you grant, and connection metadata (status, last sync time, error logs).

2.3 Order and customer information

To provide shipping, labelling, and tracking services, we receive from your connected stores:

  • Order details: order number, dates, financial status, payment method, totals, currency
  • Line items: product names, SKUs, quantities, prices, weights, product and variant identifiers
  • Recipient information: name, email, phone, shipping and/or billing address

2.4 Shipment, tracking, and delivery information

When you plan and ship an order, we store the route (origin, intermediate stops, destination), assigned courier or vendor, tracking identifier, status transitions, geocoded locations, proof-of-delivery files, and delivery-attempt records (including reasons for failed attempts).

2.5 Webhook data

We log the payload, headers, and authentication result of every webhook delivered to or from the Service, for security auditing and reliable processing.

2.6 API credentials

If you generate API keys to access the Service programmatically, we store a hashed representation of each key and a display prefix. Plaintext keys are shown to you once at creation and are never persisted.

2.7 Audit logs

We record every state-changing action performed in the Service, including the user, IP address, user-agent, timestamp, and a before/after snapshot of the affected record.

2.8 Public tracking page activity

Our public tracking pages are accessible without login. We may log IP address, user-agent, and approximate location of viewers, and we may use a third-party geocoding service to display route maps. We do not set tracking cookies on these pages.


3. How we use information

We use the information we collect to:

  • Operate, maintain, and improve the Service
  • Synchronise orders and products from your connected stores
  • Generate shipping labels, plan shipment routes, and assign shipments to couriers
  • Reconcile any data missed by real-time updates
  • Render customer-facing tracking pages and send transactional tracking emails
  • Notify your team of shipment status changes
  • Authenticate requests and verify the integrity of incoming data
  • Detect, prevent, and respond to abuse, fraud, and security incidents
  • Comply with legal obligations

We do not sell personal information. We do not use personal information for third-party advertising.


4. Legal basis for processing

Where applicable law (such as the EU General Data Protection Regulation or the UK GDPR) requires a legal basis for processing, we rely on:

  • Performance of a contract — to provide the Service you signed up for
  • Legitimate interests — to keep the Service secure, prevent abuse, and improve the product
  • Consent — for any optional processing (e.g. marketing communications)
  • Legal obligation — to comply with applicable law

5. How we share information

We share personal information only with the following categories of recipients, and only the data they need to perform their function:

RecipientPurpose
Shipping carriers and couriersTo perform physical delivery of shipments
E-commerce platformsTo write back order and tracking updates to your store
Transactional email providersTo send tracking-link emails to your customers
Mapping and geocoding providersTo display route maps on tracking pages
Cloud hosting and infrastructure providersTo operate the Service
Professional advisors and authoritiesWhen required by law or in connection with a corporate transaction

We require all third parties that process personal data on our behalf to do so only on our documented instructions and to protect the data with appropriate technical and organisational measures.


6. Data security

We use industry-standard safeguards to protect personal information, including:

  • Encryption of credentials and sensitive data at rest
  • Encryption of all data in transit (HTTPS / TLS)
  • Cryptographic verification of incoming webhooks
  • Hashed storage of passwords and API keys (plaintext is never persisted)
  • Role-based access controls
  • Audit logging of state-changing actions
  • Secure secret management for application credentials

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any relevant supervisory authority within the timeframes required by applicable law.


7. Data retention

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, or as required by law. Specific retention windows are:

  • Account and organisation data — for the life of your account, plus a brief recovery period after deletion
  • Store connection credentials — until you disconnect the store, plus a brief recovery period
  • Order, shipment, and tracking data — for the life of your account, unless you request earlier deletion
  • Webhook payloads — for a limited audit window
  • Audit logs — for a limited compliance window
  • Proof-of-delivery files — for the life of the related shipment, unless you request earlier deletion

We may retain anonymised or aggregated data indefinitely.


8. Your rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your information, subject to our legal retention obligations
  • Export your information in a portable format
  • Object to or restrict certain processing activities
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

To exercise these rights, contact us at the email address at the bottom of this policy. We respond within 30 days.

If you are a merchant using the Service through Shopify, you can also request a data export, customer data deletion, or full shop data deletion through Shopify's compliance tools. We will action these requests as required by Shopify's platform terms.


9. International data transfers

Your information may be transferred to and processed in countries other than your own. Where applicable law requires, we use standard contractual clauses or other lawful transfer mechanisms to protect your information in transit.


10. Cookies and similar technologies

We use first-party session cookies for authentication. We do not use third-party advertising or analytics cookies. The public tracking page does not set cookies.


11. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it.


12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email and / or by a prominent notice in the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent change.


13. Contact

For any privacy-related question, complaint, or request, contact us at smartdeliverydev@gmail.com.


This policy is provided for informational purposes and does not constitute legal advice. Please review it with a qualified attorney in your jurisdiction before publishing.