Ladevorgang läuft
Legal documentsLegal

Privacy policy

Information about personal data processed by Provanza.

Last updated: 2026-08-05EN
This legal document is currently provided in English for this language route. The Spanish version is the operator baseline and should be reviewed before production publication.

Quick summary

Controller
Alberto Cuervo Arias
GDPR rights contact
[email protected]
Purposes
Accounts, mobile installations, package tracking and alerts, workspaces, POD requests, billing, transactional communications, security, support, and consented operational improvement.
Legal bases
Contract or pre-contract steps, legal obligations, legitimate interests, and consent where required.
Supervisory authority
Spanish Data Protection Agency (AEPD).

Data categories

  • Account data: name, email, password-auth or OAuth identifiers, verification state, and timestamps.
  • Session and security data: session identifiers, IP address, user agent, and timestamps.
  • Mobile installation data: a random installation identifier, protected credential, platform, app version, build number, runtime version, update channel, locale, time zone, last activity, and account linkage when an installation is claimed after sign-in.
  • Tracking and saved consumer package data: tracking-number searches, carrier, country, language, optional postal code, custom name, status, milestones, estimated dates, weight, and route or address details returned by providers. Tracking numbers and postal codes in saved consumer-package records are encrypted at rest.
  • Notification data: consent and preferences, a push token encrypted at rest, the associated installation, generated alerts, and technical information about delivery attempts, tickets, and receipts.
  • Workspace data: organizations, memberships, invitations, roles, and operational preferences.
  • POD workflow data: carrier, tracking number, optional postal code, batch metadata, status, artifacts, failure reasons, and usage events.
  • Billing data: selected plan, Stripe customer/subscription identifiers, checkout, portal, invoices, and webhooks. Full card details are handled by Stripe.
  • Communications: email verification, password reset, invitations, welcome emails, and support messages.
  • Optional mobile analytics: only after explicit consent and while the feature is enabled, Provanza receives allowlisted interaction and outcome events, app release details, performance-duration buckets, API-failure categories, and crash categories. Raw error text, tracking numbers, package or workspace names, and POD content are not sent as analytics properties.
  • Public-site technical data: language/theme preferences, analytics consent, page views, and aggregate funnel events when analytics is accepted.

Providers, processors, and necessary third parties

The final production setup may include hosting, database, object-storage, transactional email, payment, OAuth/authentication, support, and monitoring providers. Regions, data-processing agreements, and safeguards will be reviewed against the final configuration for each provider.

When a user requests tracking or delivery evidence, Provanza may send the minimum necessary data to carrier systems or technical tracking-data providers to return the requested result.

  • Stripe for payments, checkout, subscriptions, customer portal, invoices, and webhooks.
  • Resend for transactional email when configured.
  • Better Auth for session/authentication handling; Apple and Google OAuth when configured and selected by the user.
  • Apple for Sign in with Apple and delivery of push notifications to Apple devices.
  • Expo for technical app-update delivery and push-notification transport, with notifications subsequently delivered through Apple's service.
  • Cloudflare R2 or S3-compatible storage for POD artifacts when enabled in production.
  • Google Analytics for aggregate page and conversion-event measurement when the user accepts analytics.
  • Microsoft Clarity for behavior analytics and masked session insights when the user accepts analytics.
  • DHL, FedEx, UPS, GLS, and other supported carriers when needed to obtain evidence.

Mobile app choices and permissions

  • Optional mobile analytics requires explicit consent, can be disabled in the app, and is not used for advertising or to track a person across apps or websites owned by other companies.
  • Notifications require system permission and can be disabled in the app or device settings. The push token is revoked when it is no longer needed or the associated data is deleted.
  • Camera access is used only with permission to scan tracking codes. Provanza does not upload photos or videos captured by the scanner.
  • Credentials, consent, and offline-capable local data are stored using encrypted or device-secure storage.

International transfers

Some providers may process data outside the European Economic Area. Where relevant, Provanza will rely on the provider terms, DPA, standard contractual clauses, or other mechanisms offered by each provider and confirmed for the production setup.

Retention

  • POD artifacts: visible in the workspace according to the active plan's POD history window; older PODs are not auto-removed solely because they age out of that window and may be retained while needed for the service, billing, audit, disputes, or legal claims.
  • Logs: for a limited period appropriate to security, operations, troubleshooting, and abuse prevention.
  • Usage/events: as needed for billing, audit, support, and abuse-prevention needs.
  • Saved packages, preferences, installations, and push registrations: while needed for the requested feature, until deleted or unlinked, when the account is deleted, or for a longer applicable operational or legal period.
  • Tracking queries and technical responses may be kept for a limited period to return results, refresh packages, troubleshoot, and prevent abuse.
  • Account and billing records: for contractual, tax/accounting, and legal-obligation periods.

Your rights

You can exercise access, rectification, erasure, objection, restriction, portability, and consent-withdrawal rights where applicable by contacting [email protected]. You may also complain to the AEPD if you believe processing does not comply with data-protection law.