Skip to main content

Legal

Privacy Policy

Last updated

Introduction

Bagster operates a logistics platform connecting verified carriers with e-commerce businesses for shipping from Turkey and China to African destinations. This Privacy Policy explains what personal data we process when you use bagster.io, the partner portal, carrier dashboard, public tracking pages, and related APIs.

By using the services, you acknowledge this policy. Controllers and processors may include Bagster and its service providers (hosting, authentication, email).

Information We Collect

We collect information you provide and information generated by use of the platform:

  • **Account data**: Name, email, phone, company name, and authentication credentials for carriers, partners, admins, and org seats.
  • **Shipment data**: Origin/destination countries, weight and dimensions, order references, recipient name, phone, address, optional email, delivery instructions, HS codes, declared value, and tracking numbers.
  • **Tracking privacy controls**: Optional tracking PINs (stored hashed) used to unlock recipient PII on public tracking pages.
  • **Partner integration data**: API keys (stored hashed), webhook URLs and secrets (encrypted at rest), store connection metadata for Shopify/WooCommerce installs.
  • **Operational data**: Order status history, POD photos and GPS pings when provided by carriers, invoices, disputes, and support messages.
  • **Technical data**: IP address, device/browser metadata, request IDs, and security logs needed to operate and protect the service.

We do not offer cash-on-delivery. Customer card charges and carrier payouts are handled through operator-controlled admin workflows and third-party processors where configured — not by automated partner payout APIs.

How We Use Your Information

We use personal data to:

  • Create, assign, track, and complete shipments
  • Authenticate users and API clients; enforce rate limits and abuse controls
  • Notify carriers, partners, and recipients of status changes (email/SMS/WhatsApp when configured)
  • Operate partner webhooks, invoices, and analytics scoped to your API key
  • Detect fraud, security incidents, and operational exceptions
  • Improve product reliability and support investigations
  • Comply with legal obligations

Public tracking pages redact recipient contact details until an authorized unlock (PIN or other ownership proof).

Information Sharing

We share data only as needed to run logistics:

  • **Carriers**: Shipment and recipient details required for pickup and delivery
  • **Partners / API clients**: Order and tracking data scoped to their API key or org seat
  • **Infrastructure providers**: Hosting, database, authentication, email/SMS, monitoring (under contract)
  • **Legal / safety**: When required by law or to protect rights, users, or the platform
  • **Business transfers**: In connection with a merger, acquisition, or asset sale

We do not sell personal information.

Data Security

We apply technical and organizational measures including:

  • TLS in transit; encrypted secrets for webhooks and sensitive configuration
  • Hashed API keys and hashed tracking PINs
  • Session timeout cookies, CSRF protection on browser mutations, and role-based admin access
  • Audit logging on high-value administrative and financial tables
  • Rate limiting and fail-closed webhook verification where secrets are required

No internet transmission is perfectly secure. Report suspected incidents to privacy@bagster.io.

Retention

Shipment, tracking, invoice, and audit records are retained for operational, dispute, and legal reasons. Cleanup jobs remove or archive selected operational logs on schedules defined in our systems. You may request deletion subject to lawful retention needs (active shipments, financial records, fraud investigations).

Your Rights

Depending on your jurisdiction, you may request access, correction, deletion, restriction, objection, or portability of personal data we hold about you.

Contact privacy@bagster.io. We may need to verify your identity and the scope of the request (for example tracking number + PIN, or authenticated account).

Cookies and similar technologies

We use essential cookies for authentication and security (Supabase auth cookies, bagster_session timeout metadata, csrf_token). Analytics or marketing tags are only used if enabled for the deployment. See our Cookie Policy for details.

International transfers

Data may be processed in regions where our infrastructure and carriers operate (including Turkey, China corridors, African destinations, and cloud regions used by our providers). Appropriate safeguards are applied where required.

Contact

Privacy: privacy@bagster.io

Support: support@bagster.io

API: api@bagster.io

Bagster Logistics — Istanbul, Turkey (operations hub).