Privacy Policy
Logistaan Technologies (“Logistaan”, “we”, “us”) operates a courier aggregation platform that lets merchants in Pakistan book, track and settle shipments across multiple courier companies from one place. This policy explains what personal data we handle, why, who we share it with, and how you can have it removed.
1. Our role
We handle two different kinds of personal data, and our responsibilities differ for each.
- Merchant account data — information about the businesses and people who sign up for Logistaan. We are the controller of this data: we decide what to collect and why.
- Consignee data — information about the customers our merchants ship to. We are a processor acting on the merchant's instructions. The merchant remains the controller, and we only use this data to carry out the shipment they asked for.
2. What we collect
From merchants
- Business name, owner name, contact phone number and email address
- CNIC number and identity documents uploaded for verification
- Bank account details and cheque images used for payment settlement
- Pickup addresses and contact people at those addresses
- Account credentials (passwords are stored only as salted hashes, never in readable form)
About consignees (the people receiving shipments)
- Full name
- Phone number (and a second number where the merchant provides one)
- Delivery address, city, country and postal code
- Email address
- Order contents at the level needed to ship them: product description, weight, number of pieces, declared value and cash-on-delivery amount
We do not collect payment card numbers, bank credentials, browsing behaviour, location tracking, or any special category data (health, religion, biometrics, political opinion) about consignees.
Where consignee data comes from
Either the merchant enters it directly or uploads it in a spreadsheet, or it arrives from a connected store platform. For merchants who connect a Shopify store, we receive order details through Shopify's order webhooks after the merchant installs our app and authorises the connection.
3. How we use it
- To create a consignment with the courier the merchant selects and to generate the shipping label that travels with the parcel
- To retrieve delivery status from the courier and show tracking to the merchant, and to the recipient through the public tracking page
- To calculate delivery charges and reconcile cash-on-delivery settlement
- To verify merchant identity and eligibility before an account is activated
- To provide support when a merchant raises a query about a specific shipment
- To meet legal, tax and record-keeping obligations
We do not sell personal data. We do not use consignee data for advertising, profiling or marketing, and we do not use it to build audiences or train models.
4. Who we share it with
Courier companies
To deliver a parcel, the courier needs to know where it is going and who to hand it to. When a merchant books a shipment we send the consignee's name, phone number, delivery address and city, together with the parcel details (product description, weight, pieces, and the cash-on-delivery amount where applicable), to the courier the merchant chose for that shipment.
Depending on the merchant's selection this may be TCS, Leopards Courier, PostEx, Trax, M&P, Daewoo, Daak or Tranzo. Each courier handles that data under its own privacy policy and its contract with the merchant or with us.
We do not send the consignee's email address to couriers. It is stored so the merchant can identify and search their own orders inside Logistaan.
Service providers
- Our hosting provider, which operates the servers this platform runs on
- An SMS gateway, used to send one-time verification codes to merchants
- An email provider, used for account email such as password resets
Nobody else
We do not share personal data with advertisers, data brokers or analytics networks. We disclose data to a government authority only where we are legally required to and, where the law permits, we will tell the affected merchant first.
5. If you connect a Shopify store
Installing our Shopify app authorises Logistaan to read your orders, customers, products and fulfilment records so shipments can be created from them. You can revoke this at any time by uninstalling the app from your Shopify admin.
We support Shopify's mandatory data-protection requests:
- Customer data request — if a customer asks a merchant what data is held about them, we return the shipment records matching that customer.
- Customer redaction — we erase that customer's name, email, phone and address from our records. The shipment record itself is retained without personal details, because it forms part of the delivery and financial record for a transaction that took place.
- Shop redaction — 48 hours after uninstall, we delete all order records and stored credentials for that shop.
Each of these requests is cryptographically verified before we act on it.
6. How long we keep it
- Shipment records are retained while the merchant's account is active. They are the delivery and settlement record for money that changed hands, so they cannot be deleted the moment a parcel arrives.
- Merchant account and verification data is retained while the account is active and for as long afterwards as tax and commercial record-keeping law requires.
- On a redaction request the personal fields are erased ahead of these periods, as described above.
7. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, correct it, have it deleted, object to how we use it, or receive a copy in a portable format.
If you are a consignee — someone who received or is expecting a parcel — the merchant who shipped to you is the controller of your data. Contact them first. You can also write to us at the address below and we will act on the merchant's instruction, or pass your request to them.
If you are a merchant, contact us directly and we will respond within 30 days.
8. How we protect it
- All traffic to and from the platform is encrypted in transit using TLS 1.2 or higher, with HTTP Strict Transport Security enabled.
- Passwords are stored as salted hashes and are subject to strength requirements. We can never read them.
- Access to merchant data is limited by role, and merchant accounts can only reach their own orders.
- Requests from connected platforms are verified with cryptographic signatures before they are accepted.
No system is perfectly secure. If a breach occurs that affects personal data, we will notify affected merchants and the relevant authorities as required by law.
9. Where data is held
Our servers are located in Europe. Courier partners are located in Pakistan, so consignee data necessary for delivery is transmitted there. Data is transferred only where it is needed to provide the service.
10. Cookies
We use cookies that are strictly necessary to run the service: keeping you signed in, protecting forms against cross-site request forgery, and remembering interface preferences. We do not use advertising or cross-site tracking cookies.
11. Children
Logistaan is a business service and is not directed at children. We do not knowingly collect data from anyone under 18 other than as part of a delivery address supplied by a merchant.
12. Changes to this policy
We may update this policy as the service changes. The date at the top shows when it was last revised. If a change materially affects how we handle personal data, we will notify merchants through the platform before it takes effect.
13. Contact us
For privacy questions, data requests or complaints, write to support@logistaan.com.
If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.