Privacy Policy
This policy explains what personal data the Dispatch Solutions Portal collects, why we collect it, who we share it with — including the courier partners and payment providers that make shipping possible — and the rights you have over your own data.
1. Introduction
Dispatch Solutions ("we", "us", or "our") operates a multi-carrier shipping and logistics management platform (the "Portal", the "Platform", or the "Services") that lets registered businesses ("Clients", "Sellers", or "you") book, track, and reconcile shipments across a network of third-party courier and logistics partners ("Courier Partners").
We know the Portal handles sensitive information — your business's KYC and banking details, your customers' names and addresses, and payment data — so this policy is written to be read, not skimmed past. It describes, in plain terms, what we collect, why, who we share it with, and what control you have over it.
By creating an account, completing KYC, or otherwise using the Portal, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, storage, and disclosure of information as described here. If you do not agree, please do not use the Services.
This policy is drafted to meet the requirements of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023("DPDP Act"), together with such other Indian data-protection law as may apply from time to time.
Brand / trade name: Dispatch Solutions
Registered entity: Ashrey Logistics Solution LLP
LLP Identification Number (LLPIN): ACF-3345
GSTIN: 09ACEFA8738P1ZM
Registered / principal place of business: 3rd Floor, B-34, Sector 67, Noida, Gautam Buddha Nagar, Uttar Pradesh – 201301, India
2. Definitions
- Account — a Client's registered organization/tenant on the Portal, and the individual user logins within it.
- AWB — Air Waybill, the tracking identifier assigned to a single-piece (Direct B2C) shipment.
- LR — Lorry Receipt, the tracking identifier assigned to a bulk-freight (Enterprise B2B) shipment.
- Consignee — the end recipient named on a shipment booked by a Client (typically the Client's own customer).
- KYC — Know Your Customer, the identity and business-verification process completed during onboarding.
- Personal Data — any information relating to or identifying a natural person, whether directly or indirectly.
- Sensitive Personal Data or Information (SPDI) — as defined under Rule 3 of the SPDI Rules, this includes passwords; financial information such as bank account, payment instrument, or card details; physical, physiological, and mental health condition; sexual orientation; medical records and history; and biometric information. Information freely available in the public domain, or furnished under the Right to Information Act, 2005, is not SPDI.
- Data Principal — the individual to whom personal data relates, as defined under the DPDP Act (referred to in this policy simply as "you").
- Wallet — the prepaid ledger balance maintained against a Client's Account, debited for freight and related charges.
- Business Channel — a third-party storefront or ERP a Client connects to the Portal (for example Shopify, WooCommerce, Amazon, or Zoho Books) to import orders automatically.
3. Scope of this policy
This policy applies to personal data processed through the Dispatch Solutions Portal — the client web application, our public tracking pages, our APIs, and any related mobile or communication channels (including WhatsApp and SMS notifications sent on a Client's behalf). It covers data belonging to three categories of individuals:
- Client users — the people who sign in and operate a Client's Account (admins and team members).
- Consignees — the end customers named as the recipient on a Client's shipments.
- Website visitors — people who browse our public marketing site or use a public tracking link without an account.
When a Client uploads a consignee's name, address, or phone number to book a shipment, the Client is the Data Fiduciary for that information under the DPDP Act — the entity determining why and how it is processed — and Dispatch Solutions acts solely as the Client's Data Processor, processing that data only on the Client's documented instructions (see Section 8(2) of the DPDP Act) and strictly to carry out the shipment, related NDR/RTO handling, and COD reconciliation the Client has requested. Dispatch Solutions does not determine the purpose of processing consignee data and does not use it for any purpose independent of the Client's instructions. Clients are responsible for having a lawful basis (such as the consignee's own order or consent) before submitting that data to us. See Section 8.
4. Information we collect
4.1 Information you provide directly
- Account and registration data — name, work email, phone number, password, and the business name used when you sign up.
- KYC and business verification data — collected through our verification partner during onboarding: entity registration details, PAN, GSTIN, business address, authorized-signatory identity documents, and bank account details for settlements and COD remittance.
- Shipment and consignee data — every field entered when booking a shipment: order ID, product/line-item details, declared value, package weight and dimensions, pickup warehouse, and the consignee's name, phone number, email, and delivery address.
- Payment data — wallet recharge transactions are processed through our payment gateway partner; we store the transaction reference, amount, and status, but card and UPI credentials are handled directly by the gateway and are not stored on our servers.
- Support communications — anything you send us through the in-Portal assistant, support tickets, email, or phone, including call recordings where legally permitted and disclosed.
- Team and role information — names, emails, and role assignments for teammates a Client invites onto their Account.
4.2 Information collected automatically
- Log and device data — IP address, browser type, device identifiers, operating system, referring URLs, and timestamps of requests to the Portal.
- Usage data — pages viewed, features used, and actions taken within the Portal, collected to diagnose issues and improve the product.
- Cookies and similar technologies — see Section 6.
4.3 Information from third parties
- Courier Partners — tracking scans, delivery attempt outcomes, proof-of-delivery, and non-delivery reason codes for each shipment.
- Business Channel integrations — when a Client connects a store (Shopify, WooCommerce, Amazon, Zoho Books, and similar), we receive order and customer data from that platform via the authorization the Client grants, strictly to create and fulfil shipments.
- Payment gateway — confirmation of successful or failed wallet recharge transactions.
- KYC verification partner — the outcome of identity and document verification checks.
5. How we use information
We use the information described above to:
- Create and administer Accounts, authenticate sign-ins, and enforce role-based permissions.
- Complete KYC and meet our own regulatory and anti-fraud obligations before activating live shipping.
- Book, route, and track shipments — including sharing the minimum necessary consignee details with the Courier Partner assigned to that shipment.
- Operate the Wallet: calculate freight, surcharges, and GST; process recharges; and produce an auditable transaction ledger.
- Run Smart Allocation and Risk Ops — automated courier selection and consignee trust-scoring, both computed from a Client's own historical order and delivery outcomes.
- Send transactional notifications — order confirmations, dispatch and delivery updates, NDR alerts, and wallet threshold warnings — by email, SMS, or WhatsApp (via our value-added-services provider) where a Client has enabled these.
- Provide customer support and respond to inquiries, complaints, and grievances.
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms & Conditions.
- Analyze aggregated, de-identified usage patterns to improve the Portal's reliability and features.
- Comply with tax, accounting, and other legal obligations, and respond to lawful requests from public authorities.
- With separate, specific consent, send product updates and marketing communications, which you may opt out of at any time.
8. Consignee / end-customer data
Consignees do not create an account with us — their data reaches us because a Client booked a shipment to them. We use it strictly to fulfil, track, and support that shipment: sharing it with the assigned Courier Partner, computing a Risk Ops trust signal from their own delivery history, and sending shipment-status notifications where the Client has enabled them.
A consignee who wants to exercise a data-privacy right (access, correction, or deletion) over information tied to their shipment should first contact the Client they ordered from, since the Client controls that relationship. Where required by law, we will also action a verified request directly — see Section 11.
9. Data storage, security & transfers
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data involved, including:
- Encryption of data in transit (TLS) between your browser, our servers, and integrated partners.
- Encryption of sensitive fields — including KYC documents and bank details — at rest.
- Role-based access control, so Portal staff and Client team members only see data relevant to their assigned role and organization.
- Isolation of each Client's data by organization, enforced at the application and database layer.
- Logging and monitoring of authentication and access to sensitive records.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify affected Clients and the relevant authorities as required under Rule 8 of the SPDI Rules and the DPDP Act, including the Data Protection Board of India where applicable.
Our infrastructure is hosted in India. Where a sub-processor or Courier Partner processes data outside India in the course of an international shipment, we require contractual safeguards consistent with the DPDP Act and other applicable Indian data-protection law before any such cross-border transfer takes place.
10. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, and in any event no longer than required by applicable tax, accounting, and consumer-protection law.
| Data category | Typical retention |
|---|---|
| Active Account and shipment records | For the life of the Account, to preserve order and wallet history. |
| KYC documents | As required by applicable know-your-customer and anti-money-laundering regulation, even after Account closure. |
| Wallet and billing ledger | Per statutory financial record-keeping requirements. |
| Closed Account data | Retained for a limited post-closure window to resolve outstanding disputes or legal obligations, then deleted or anonymized. |
| Support communications | Retained for a reasonable period to maintain service-quality records. |
| First-party analytics telemetry | Deleted after 90 days. |
| Login history | Deleted after 90 days (see Portal Security logs). |
11. Your rights and choices
As a Data Principal under the DPDP Act, and subject to its exemptions and any applicable retention obligation, you may:
- Access a summary of the personal data we hold about you and how it has been processed, including the identities of parties it has been shared with.
- Correct, complete, and update inaccurate or incomplete data — most Account and profile fields can be edited directly in the Portal under Settings.
- Request erasure of your personal data once it is no longer necessary for the purpose it was collected for, subject to our legal obligation to retain certain records (such as KYC and financial data) for the periods described in Section 10.
- Withdraw consent for optional processing — including preferences and analytics storage via the cookie banner / Cookies preferences, and marketing communications — at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Manage sessions — review and revoke active sign-ins under Portal Settings → Security logs.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.
- Lodge a grievance with our Grievance Officer (Section 15) and, if unresolved, escalate it to the Data Protection Board of India.
To exercise any of these rights, contact us at privacy@dispatch.co.in. We will verify your identity before acting on a request and will respond within the time limit prescribed by the DPDP Act and its rules.
12. Children's privacy
The Portal is a business tool intended for use by individuals who are at least 18 years old and authorized to act on behalf of a registered business. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly.
13. Third-party links and services
The Portal may link to, or integrate with, third-party websites and services — Courier Partner tracking pages, payment gateways, and connected Business Channels among them. This policy does not cover those third parties' own data practices; we encourage you to review their respective privacy policies.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the revised policy with an updated "Last updated" date, and where a change is material, we will provide additional notice — such as an in-Portal banner or an email — before it takes effect. Continued use of the Portal after a change takes effect constitutes acceptance of the revised policy.
15. Grievance officer & contact us
In accordance with Rule 5(9) of the SPDI Rules and Section 13 of the DPDP Act, we have appointed a Grievance Officer to address privacy-related complaints:
Email: grievance@dispatch.co.in
Entity: Dispatch Solutions
Registered office: 3rd Floor, B-34, Sector 67, Noida, Gautam Buddha Nagar, Uttar Pradesh – 201301, India
For general privacy questions, write to privacy@dispatch.co.in. We aim to acknowledge every request within 48 hours and resolve it within the time limit prescribed by the DPDP Act and its rules.
16. Governing law
This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000, the SPDI Rules, and the DPDP Act. Any dispute arising out of or in connection with this policy is subject to the exclusive jurisdiction of the courts at Gautam Buddha Nagar (Noida), Uttar Pradesh, India, without prejudice to any right to approach the Data Protection Board of India or another competent authority directly.
Read the companion document: Privacy Policy · Terms & Conditions
Questions? legal@dispatch.co.in

