Privacy Policy
1. Who we are
TrackifyNow is a service that lets courier businesses track parcels and send SMS arrival notifications to the people receiving them.
Which company you are dealing with depends on where your courier business is based, which also determines the currency you are billed in:
| If the courier business is based in | Your provider is |
|---|---|
| Nigeria | Authecity Systems LTD, a company registered in Nigeria. 4 Soji Adepegba Close, off Allen Avenue, Ikeja, Lagos State, Nigeria |
| Anywhere else | Authecity Systems LLC, a company registered in
Minnesota, United States. 1650 West End Blvd., Suite 100, St. Louis Park, Minnesota 55416, USA |
In this policy, “we” and “TrackifyNow” mean whichever of those companies provides your service. We apply the same privacy standards in both cases.
2. Two kinds of people, two different roles
This is the most important thing to understand about how TrackifyNow handles personal data, because it decides who you should contact about it.
If you are a courier operator
You signed up, you have an account, and you use TrackifyNow to run your business. For your own account information, we are the data controller — we decide how it is used, and you deal with us directly about it.
If you are receiving a parcel
You never signed up with us, and you may never have heard of us before an SMS arrived. Your name and phone number were given to us by the courier handling your parcel. They decided to notify you; we send the message on their instructions.
For parcel recipients, the courier is the data controller and TrackifyNow is their processor. That means the courier is responsible for having a proper basis to contact you, and requests to see or delete your information should go to the courier first. We give them the tools to act on your request, and we will help if you contact us directly.
Every courier using TrackifyNow agrees, as a condition of using it, that they have a lawful basis for every phone number they enter.
3. What we collect
From courier operators
- Business name, and the country your business bills from.
- Your name, email address, and password (stored only as a secure hash — we never store the password itself and cannot see it).
- Billing records: what you bought, when, in which currency, and a reference from the payment provider. We never see or store your full card number — card details are handled entirely by our payment providers.
- Support requests you send us.
- Technical records needed to run the service securely, including the IP address a request came from, used for rate limiting and to protect accounts against password-guessing.
About parcel recipients and senders, entered by the courier
- Name, and phone number in international format.
- Optionally an email address, postal address, and a title.
- The parcel: a tracking code, a description if the courier adds one, its status, and the arrival city.
- A record of the basis on which the courier says they may contact the person, when it was captured, by which member of staff, and how — for example at drop-off.
- The messages sent, and confirmations from the mobile network about whether they were delivered.
- Where the courier uses the feature, a photograph of the parcel taken at drop-off.
4. Why we use it
| Purpose | What this means in practice |
|---|---|
| Providing the service | Recording parcels, sending arrival notifications, showing tracking pages. |
| Billing | Selling and accounting for message credits, and keeping tax records. |
| Respecting opt-outs | Keeping a record of anyone who has asked to stop receiving messages, so that we never message them again. |
| Security and abuse prevention | Rate limiting, protecting accounts, and preventing our shared sender identity being used for fraudulent messages. |
| Support | Answering questions and investigating problems. |
We do not sell personal data. We do not use it for advertising. We do not build profiles of parcel recipients, and we do not combine data across different couriers — each courier's records are technically isolated from every other courier's.
5. Who we share it with
We use a small number of service providers to run TrackifyNow. Each receives only what it needs to do its job.
| Provider | What they do | What they receive |
|---|---|---|
| Amazon Web Services | Hosting, database and file storage | All service data, stored in the United States |
| Termii | SMS delivery in Nigeria | Recipient phone number and message text |
| Africa’s Talking | Backup SMS delivery | Recipient phone number and message text |
| Stripe, PayPal | Card payments outside Nigeria | Payment details, handled directly by them |
| Paystack, Flutterwave | Card and bank payments in Nigeria | Payment details, handled directly by them |
| Amazon SES | Sending account emails | Operator email addresses |
We may also disclose personal data where we are legally required to, or to establish or defend legal claims. If our business is ever sold or reorganised, data may transfer as part of it, and this policy would continue to apply until you are told otherwise.
6. Where your data is stored
TrackifyNow’s systems run in Amazon Web Services in the United States (Ohio region). This means personal data about people in Nigeria is stored outside Nigeria.
We protect it in transit and at rest, we restrict access to it, and we require our providers to apply appropriate safeguards. Nigerian data protection law places conditions on transfers of this kind and we comply with the applicable requirements.
7. How long we keep it
We keep personal data only as long as it is needed, and we are specific about what that means:
- While your account is open, we keep your operator account data and your parcel records.
- When a courier closes their account, there is a 30-day grace period in which the closure can be reversed. After that, we permanently delete customer records, parcel records, messages, delivery confirmations and any parcel photographs, including the underlying image files.
- Financial records are kept after an account is deleted — payments, credit purchases and the transaction ledger. These are needed for accounting and tax. They contain amounts, dates, currencies and provider references, and no longer identify any individual once the associated people have been deleted.
- Opt-out records are kept permanently. This is deliberate, and it is worth explaining. If someone asks us to stop messaging them, the only way to guarantee we never message them again is to remember the number indefinitely. Deleting that record would quietly re-enable messaging to a person who asked us to stop. The record holds the phone number and the fact that messaging is blocked, and nothing else.
8. Your rights
Depending on where you live, you have rights over your personal data. These generally include the right to know what we hold, to get a copy, to have it corrected, to have it deleted, and to object to how it is used.
- Courier operators can export all of their data from within the app at any time, and can request account closure from Billing.
- Parcel recipients should contact the courier who arranged their parcel, since that courier controls the record. If you do not know who they are, or they do not respond, contact us and we will help.
We respond to requests within 30 days. We will not charge you for a request or treat you differently for making one. If you are unhappy with how we handle it, you may complain to your data protection authority — in Nigeria, the Nigeria Data Protection Commission.
Regional notes
- Nigeria (NDPA). The rights above are the ones the Nigeria Data Protection Act gives you, and they are the baseline we apply to everyone.
- EEA / UK (GDPR). If you are in the European Economic Area or the UK, you additionally have the rights to restrict processing, to data portability, and to object to processing based on legitimate interests. The lawful bases we rely on are: performance of a contract (providing the service to operators), legal obligation (financial records), and legitimate interests (security, abuse prevention, and honouring opt-outs).
- California (CCPA/CPRA). We do not sell or share personal information as those terms are defined in California law, and we have not done so in the preceding 12 months. California residents may exercise the access, deletion and correction rights above; we do not discriminate for exercising them.
9. Stopping messages
If you no longer want to receive parcel notifications, tell the courier who is handling your parcel, or contact us at the address below and we will block your number.
An opt-out always wins. Once a number is blocked, our system refuses to send to it regardless of any other instruction, including a later one from the courier. This is enforced automatically, not by policy alone.
Messages we send are transactional notifications about a specific parcel someone is sending to you. We do not send marketing messages.
10. Security
- All traffic to and from TrackifyNow is encrypted in transit.
- Passwords are stored only as secure hashes and are checked against known breached-password lists at signup.
- Each courier’s data is isolated at the database level, so one courier cannot see another’s customers, parcels or messages.
- Parcel photographs are stored privately and are only reachable through short-lived links.
- Access to production systems is limited to the people who operate them.
No service can promise perfect security, but we take this seriously and keep it under review.
11. Changes to this policy
If we change this policy materially, we will tell account holders by email before the change takes effect. Every version carries a version number and effective date at the top of the page, so you can see what applied and when.
12. Contact us
For any privacy question, or to make a request about your data:
Email: privacy@trackifynow.com
General enquiries: hello@trackifynow.com
Please tell us whether you are a courier operator or someone who received a parcel notification, so that we can find the right records quickly.