Privacy notice
- Controller: HexaTrack SAS; DPO reachable via the Contact page.
- Purposes: (1) display shipment status, (2) notifications and customer support, (3) security & fraud prevention, (4) aggregated statistics.
- Legal bases: contract performance (tracking), legitimate interests (security), legal obligation (retention), consent (non‑essential cookies).
- Data processed: tracking number, statuses/events, city/country, minimized shipper/consignee information, notification preferences.
- Sources: shippers/carriers/e‑commerce platforms; data entered by the user.
- Retention: technical data 13 months; security logs 6 months; support requests 24 months; inactive accounts 24 months.
- Recipients: authorized teams; hosting and support providers; authorities upon lawful request.
- International transfers: framed by SCCs or adequacy decisions; encryption in transit and at rest where possible.
- GDPR rights: access, rectification, erasure, restriction, objection, portability; right to lodge a complaint with a supervisory authority.
- Cookies/trackers: only necessary cookies by default; consent is required for any non‑essential cookie.
- AI & routing generation: some simulations may rely on third‑party providers; only minimal, pseudonymized information is transmitted.
- Security: TLS, key management, logging, regular testing, least‑privilege access.
- Updates: material changes will be communicated through a clear banner/notice.