SwiftShip Logistics
Privacy Policy
Last updated: 21 July 2026
SwiftShip Logistics ("SwiftShip", "we", "us") provides last-mile fulfillment and shipping software to Direct-to-Consumer brands in India. This policy explains what personal data we handle, why we handle it, how long we keep it, and how brands and their end-customers can exercise their rights.
1. Who is the controller?
For data received from a connected storefront (Shopify, WooCommerce, Wix), the brand is the data controller and SwiftShip is a data processor acting only on the brand's instructions. For account data belonging to SwiftShip users (brand admins, staff, drivers), SwiftShip is the controller.
2. What we collect
- Order data from the brand's storefront: order id, line items, totals, currency, COD flag.
- Shipping-address data of the end-customer: name, address, phone, email — used only to pick, pack, and deliver the parcel.
- Delivery signals: proof-of-delivery photo, OTP acknowledgment, GPS at the moment of scan events.
- Account data for portal users: name, email, hashed password, role, workplace warehouse.
- Operational telemetry: audit logs of scans, edits, and API calls for security and dispute resolution.
We do not collect payment-card data. Card processing happens off-platform.
3. Why we use it
- Fulfilling and delivering orders the brand asks us to ship.
- Providing tracking links, delivery notifications, and support to the end-customer on the brand's behalf.
- Producing invoices, reports, and SLA analytics for the brand.
- Detecting fraud, preventing abuse, and complying with legal obligations.
4. Storefront integrations
When a brand connects a Shopify, WooCommerce, or Wix store, SwiftShip receives orders, product/SKU catalogue, inventory levels, fulfillment statuses, and shipping addresses through the platform's official APIs and webhooks. We do not read products the brand hasn't opted to sync. Uninstalling the app immediately stops new data ingestion. For Shopify, we honor the mandatory customers/data_request,customers/redact, and shop/redact webhooks and delete shop and customer data within Shopify's SLA.
5. Sharing
We share personal data only with:
- The brand that owns the order.
- Delivery partners (our drivers or the courier we auto-select) — only the fields needed to complete the drop.
- Infrastructure processors we use to run the platform (managed database, transactional email, error logging), under written data-processing terms.
- Government or law enforcement, when compelled by a valid legal order.
We do not sell personal data and we do not use it to train third-party AI models.
6. Retention
Shipping and order records are retained for 7 years to satisfy Indian tax and accounting law. Proof-of-delivery images and GPS events are retained for 24 months. Account data is retained while the account is active and for 90 days after account closure, then deleted or anonymized.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted, logged, and reviewed. Every mutation in the portal writes an immutable audit-log entry.
8. Your rights
End-customers can request access, correction, or deletion of their data by contacting the brand they ordered from — the brand will forward the request and we will action it. Brand users can email privacy@swiftship.co.in directly. We respond within 30 days.
9. Contact
SwiftShip Logistics, Bengaluru, India.
Privacy contact: privacy@swiftship.co.in
Support: ops@swiftship.co.in