What the service needs
The platform may process sender and recipient contact details, structured addresses, delivery instructions, payment identifiers, driver location during active work, support records and security/audit events.
How data is used
Data supports quoting, booking, payment, dispatch, tracking, notification, proof, support, fraud prevention, legal compliance and service measurement.
- Recipient tracking shows a privacy-reduced projection.
- Driver tracking stops when offline or no active workflow exists.
- Raw payment card data is never stored by the application.
First-party service analytics
Cookito records anonymous product events—such as page views, address-validation outcomes, quote and checkout steps, payment outcomes and completed orders—to understand reliability and conversion. A random browser identifier, a 30-minute session identifier and first-touch campaign parameters may be stored in local browser storage. Cookito does not record form keystrokes, names, phone numbers, email addresses, full pickup/delivery addresses or payment-card data in analytics.
- Traffic attribution is limited to referrer hostname and UTM source, medium, campaign, content and term.
- Analytics is stored by Cookito rather than sent to advertising pixels in this implementation.
- The default analytics retention period is 395 days and can be shortened through production configuration.
Sharing and providers
A final policy must name and govern the actual payment, maps, messaging, hosting, monitoring and storage providers used in production.
Retention and rights
Operational records and anonymous analytics follow separate retention controls. Requests concerning access, correction or deletion can be directed to Cookito support. Final deletion/anonymization procedures, Canadian cross-border processing and PIPEDA obligations still require a privacy impact assessment and counsel review before launch.
