Privacy Policy
Last updated 27 September 2026
What we collect
We collect only what you choose to send us. This site has no account registration, no newsletter, and no third-party advertising trackers.
Contact form: your name, email address, optional company name, and your message.
Support chat (TrackShipLog Care): the messages you send in the live support desk, associated with an anonymous identifier that lets you reopen the conversation later. A human support agent reads these messages.
Shipment tracking: the tracking number you enter, together with the shipment record it matches. We do not require you to identify yourself to look up a shipment.
Server logs: standard request metadata such as IP address, user agent, and timestamp, retained briefly for security and abuse prevention.
Why we collect it
To respond to enquiries, to resolve support tickets, to operate the shipment tracking you request, and to protect the service against spam and abuse.
We do not sell personal information. We do not use it for advertising. We do not share it with data brokers.
Tracking numbers and shipment records
A tracking number functions as a lookup key. Anyone who has a tracking number can view the shipment record associated with it, so please do not treat a tracking number as a password and avoid publishing one publicly if your shipment contents are sensitive.
Shipment records contain logistics information (status, checkpoints, origin, destination, fees) and are not intended to be personal data. They are visible to anyone holding the tracking number.
Live support conversations
Messages you send in the live support desk are stored against an anonymous identifier and read by our support staff. They are not anonymised or aggregated automatically.
Because the conversation is tied to a browser session, clearing your browser storage, or switching devices or browsers, starts a new conversation and hides the previous one from the widget.
Live chat is not suitable for transmitting payment details, passwords, or government identifiers. Please do not send them.
How long we keep it
Enquiries and support tickets are retained for as long as needed to serve the commercial relationship and to meet legal obligations, and are then deleted or anonymised.
Live chat transcripts follow the same schedule as the ticket queue they belong to.
Rate-limiting records are held for the length of the limiting window only, on the order of minutes.
Who processes it for us
We use a small number of infrastructure providers, each acting as a processor under contract:
Google Firebase (Firestore database, Firebase Authentication for the administrator portal) — infrastructure
Cloudinary (image and media storage) — infrastructure
A web host such as Vercel or Netlify (application hosting and content delivery) — infrastructure
Resend (transactional email delivery, if enabled) — communications
An error-reporting service (Sentry, if enabled) — reliability
Our own support staff, who read live chat messages and support tickets in order to answer you
Where your data is held
Data is stored with the providers listed above, which may process it in the United States or other regions. Where personal data is transferred outside your country, we rely on the providers’ standard transfer safeguards.
Security
Shipment writes, support and contact records, settings, and the administrator registry are protected by Firestore security rules that deny all access by default. Public submissions are strictly validated and rate limited. Administrator access requires authenticated credentials and an explicit administrator record; two-factor authentication is recommended on the Firebase account.
No system is perfectly secure. If you believe your data has been compromised, contact us immediately.
Cookies
This site does not set advertising or analytics cookies. The live support desk signs you in anonymously so you can reopen your conversation; Firebase stores that anonymous session in your browser. It carries no name, email address, or other identifier, and it is the only client-side storage we use. The administrator portal additionally stores a signed-in session token for staff accounts.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing.
To exercise any of these rights, email us from the address you used. We will verify your identity before acting on a request, and we will respond within the timeframe required by the law that applies to you.
Children
This service is a business tool and is not directed at children under 16. We do not knowingly collect personal information from children.
Changes and contact
We may update this policy as the service changes. The date at the top reflects the most recent revision.
Questions, requests, and complaints: use the contact form on this site.