← ParcelPilotBD

Privacy Policy

Last updated: 30 July 2026

Who we are

ParcelPilotBD ("we", "us") provides COD reconciliation and courier operations tools for Shopify merchants in Bangladesh. Contact (including privacy requests): parcelpilotbd@gmail.com.

For data processed through the Shopify app, the merchant who installs the app is the data controller and ParcelPilotBD acts as their processor.

This website

If you join the waitlist we store your email address with our email provider (Kit) solely to notify you about ParcelPilotBD's launch and early-access offer. We do not sell it, share it, or use it for anything else. Unsubscribe anytime via the link in any email. This site uses the Meta Pixel and Meta Conversions API to measure whether our advertising on Facebook and Instagram reaches merchants (page views, clicks on "Install on Shopify", and waitlist signups). Meta may set cookies for this purpose; see Meta's privacy policy. We do not send your email address or any other personal data to Meta.

The Shopify app

What we access from your Shopify store, and why

DataWhy we need it
Order number, order date, order totalTo match courier payout statement lines to your orders and verify the courier paid the correct amount.
Customer namePrinted on the parcel label and sent to the courier as the recipient name when you book a parcel.
Customer phone numberRequired by every Bangladeshi courier to book a delivery. Also used, only when you choose to run a fraud check, to look up that number's delivery history.
Shipping addressSent to the courier as the delivery address, and used to derive the destination division for courier performance statistics.
Fulfillment statusTo show which orders still need to be booked.

We request read-only access to orders and customers. We do not request or hold write access to your orders, products, inventory, or customers. We do not access payment details, and we never sell personal data or use it to train machine-learning models.

Data we send to third parties on your instruction

The app exists to connect your store to couriers, so some customer data necessarily leaves our systems. This only ever happens as a result of an action you take:

Each courier is an independent data controller for the data it receives, under its own privacy policy and its own agreement with you.

Sub-processors

ProviderPurposeLocation
RailwayApplication hosting and databaseUnited States
CloudflareWebsite hosting, DNS, waitlist storageGlobal edge network
SentryError monitoring (technical diagnostics; no customer personal data is intentionally sent)United States
KitWaitlist email only — not used for app dataUnited States

Your courier credentials

Courier API keys and, where a courier offers no API alternative, merchant-panel logins, are encrypted at rest with AES-256-GCM and are only ever transmitted to that courier's own systems to perform actions you request. They are never logged, never shown back to you in full, and are deleted when you disconnect the courier or uninstall the app. You can remove them at any time from Settings.

How long we keep data

DataRetention
Fraud-check results24 hours, then refreshed or discarded
Courier webhook delivery log60 days
Reconciliation statements, shipments, courier credentials, settingsUntil you uninstall the app or delete them yourself
All shop data after uninstallDeleted immediately on the uninstall webhook, and again on Shopify's shop/redact request (~48 hours later)

Security

All traffic is encrypted in transit with TLS. Courier credentials are encrypted at rest with AES-256-GCM using a key held only in our server environment. Access to production systems is limited to the app's operator, protected by strong unique credentials and two-factor authentication. Test and production data are kept separate, and backups inherit the same encryption at rest. Access to protected customer data happens through the application, which authenticates every request and scopes each query to the requesting shop; our hosting provider records database connection and infrastructure logs. We have an incident-response process: if a breach affects your data, we will notify you and, where required, the relevant authority without undue delay.

Automated decisions

The fraud check feature reports a customer's past delivery history from courier records and shows a risk indicator. It does not decide anything automatically. No order is cancelled, held, or refused by the app; the merchant reviews the information and decides. Consequently the app performs no automated decision-making producing legal or similarly significant effects on the customer.

Your rights and requests

We support Shopify's mandatory privacy webhooks. When Shopify sends us a customers/data_request, customers/redact, or shop/redact request on behalf of a merchant or customer, we action it within 30 days — customer records are erased or anonymised, and shop data is deleted in full.

Merchants and customers may also contact parcelpilotbd@gmail.com to access, correct, export, or delete personal data. We respond within 30 days.

Changes

If we make a material change to how we handle personal data, we will update this page and notify installed merchants in the app before the change takes effect.