This Privacy Policy applies to the CBEX mobile application (Android and iOS), a customer app that lets you create domestic and international shipments, price and book them with carriers, track them, and manage your address book, wallet, invoices and shipment notifications.
The app is open to the general public: you can create an individual account or an organisation / business account directly from within the app.
By using the app you acknowledge that you have read this policy and agree to your data being processed as described in it. If you do not agree with any part of it, please do not use the app.
The CBEX app is operated and managed by CBEX Logistics, a shipping and logistics company, which acts as the data controller for the data described in this policy.
The app is an interface to the CBEX platform: the data you enter is stored on the platform's servers and is shared with carriers and customs authorities to the extent needed to move your shipment (see Section 7).
We collect the minimum data needed to provide the shipping service. The table below summarises the categories and their purposes:
| Data category | Examples | Purpose |
| Account data | Name, email, mobile number and country dial code, country, password (for verification only), account type (individual / organisation) and company name | Account creation, sign-in and session management |
| Profile & sender address | Your address (street, city, state, postal code, country), language, time zone | Used as the default sender address on your shipments |
| Shipment data | Recipient name, phone, email, company and full address; parcel dimensions, weights and contents | Pricing, booking and fulfilling the shipment |
| Customs data | Item descriptions, quantities, values and HS codes, country of origin, and documents you attach | Completing customs formalities for international shipments |
| Address book | Addresses you save for reuse | Speeding up shipment creation |
| Payments & wallet | Wallet balance, ledger movements, invoices and shipping charges | Showing your financial account and settling shipping charges |
| Location (optional) | Your coordinates when you tap "use my location", and your address search text | Filling an address from the map |
| Device & session data | Device brand and model (as a session label), platform, IP address in server logs | Security, session management and abuse detection |
| Notification token | Device push token (FCM) | Delivering shipment status notifications |
| Local settings | Language, theme, last email used to sign in | Your preferences — stored on your device only |
3.1 Account & registration data
To create an account we ask for your name, email, mobile number with country dial code, country, and a password. If you choose an organisation account we also ask for the company name. Your password is sent to the server over an encrypted connection for verification only and is never stored on your device; the server issues a session token which is kept in the device's encrypted storage.
3.2 Recipient and shipment party data
When creating a shipment you enter the recipient's details (name, phone, email, company and full address). This is other people's data, and you are responsible for having a lawful basis to provide it to us for the purpose of fulfilling the shipment. We use it solely to price, book, deliver and document the shipment.
3.3 Customs data and attached documents
For international shipments you enter item details, values and HS codes, and you may attach a commercial document (PDF or image) such as a commercial invoice. The app reads only the file you pick in order to attach it to the shipment; it is sent with the shipment record to the platform and, where required, on to the carrier and customs authorities.
3.4 Contacts — read on your device only
If you choose "pick from contacts" during registration or when filling a shipment party, the app requests contacts permission to show you a searchable list on your own device (name, phone, email, company).
- Your contact list is never uploaded to any server, never synced and never stored — it is read into the app's memory only while the picker is open.
- The only data that leaves your device is the details of the single contact you select, which then become part of the shipment you are creating.
- You can deny the permission and type the details manually; nothing else in the app is affected.
3.5 Location & maps
Location use is entirely optional and happens only when you tap the "use my location" button on the address map screen. Your coordinates are then read once and sent to the mapping provider to be resolved into a readable address that fills the form.
- There is no background location tracking, and the app does not access location while it is closed.
- We keep no record of your movements; what is saved is the resulting address within the shipment or your address book, if you choose to save it.
- You can deny the location permission and set the address by text search, by tapping the map, or by typing it manually.
3.6 Device & session data
At sign-in the app sends a short device label (manufacturer and model, e.g. "Samsung SM-A546") so it appears in your list of active sessions and you can tell where a sign-in came from. The platform server also automatically records technical request data (such as IP address and request time) for security, abuse detection and auditing.
3.7 Payments & wallet
The app displays your wallet balance, ledger movements, invoices and shipping charges as recorded on the platform. The app never asks for or stores bank card numbers or bank account details; any top-up is handled through the company's approved channels or the payment provider's own gateway page, and card data never passes through the app.
3.8 Settings stored on your device
The app stores on your device only: the session token (in encrypted storage), the interface language, the theme (light/dark), and the last email used to sign in so it can be pre-filled for you. These settings are not sent anywhere, and they are cleared on sign-out or when the app is uninstalled.
The app is deliberately free of any data collection that does not directly serve the service:
- No background location tracking: the app reads your location only at the moment you tap "use my location".
- No contact upload: your contact list never leaves your device.
- No camera or microphone: neither is used and neither permission is requested.
- No biometric data: the app does not use or access fingerprint or face recognition.
- No analytics or advertising: the app contains no analytics, behavioural tracking or ad SDKs.
- No card data: we do not collect card numbers or bank account details in the app.
- No selling of data: we do not sell your data or share it with anyone for marketing or advertising purposes.
The data described above is used solely for the following purposes:
- Providing the service: pricing shipments, booking them with carriers, issuing labels and following through to delivery.
- Customs formalities: preparing clearance data and documents for cross-border shipments.
- Managing your account: verifying your identity, managing your sessions and permissions, and showing your shipments, invoices and balance.
- Communication and notifications: shipment status and operational messages through the channels you enable (push, email, SMS, WhatsApp or in-app).
- Support: answering your questions and handling complaints and claims.
- Security: detecting unauthorised access, fraud and misuse, and keeping audit logs.
- Compliance: meeting applicable legal, accounting and customs obligations.
Your data is not used for behavioural marketing, profiling, or sale to third parties.
The app requests only the permissions below. All of them are optional and you can withdraw any of them at any time from your device settings:
| Permission | When it is requested | If you decline |
| Location (while using the app) | When you tap "use my location" on the map screen | You can set the address by search, by tapping the map, or by typing it |
| Contacts | When you tap "pick from contacts" | You type the name and number manually — nothing else breaks |
| Notifications | On first launch or when you enable notifications | You will not get shipment status alerts; in-app notifications still work |
| File selection | When attaching a customs document (PDF/JPG/PNG) | You can complete the shipment without an attachment wherever it is not mandatory |
🔎 The app uses the operating system's built-in file picker and reads only the file you choose — it does not request access to the photos or media on your device.
We do not sell or rent your data. We share it only in the following cases and only to the extent necessary:
7.1 Carriers
When a shipment is booked, its data is sent to the carrier you selected so it can perform the transport and delivery. This includes sender and recipient names, phone numbers, emails and addresses, and parcel details, contents and values. The carrier processes this data under its own privacy policy.
7.2 Customs and regulatory authorities
For international shipments, shipment data, item details and attached documents are submitted to the customs authorities of the origin, transit and destination countries as required by law.
7.3 Technical service providers
We use a small number of technical service providers (see Section 8) to run the app. They process data on our behalf and only on our instructions.
7.4 Legal authorities
We may disclose data in response to a court order or a binding legal request, or to protect our rights and the safety of our users, and only to the extent required by law.
🤝 In the event of a merger, acquisition or transfer of the business, data may pass to the new entity, with this policy continuing to apply until users are notified of any change.
| Service | Purpose | Data sent to it |
| Google Firebase — Cloud Messaging | Delivering push notifications | Device push token and the notification content |
| Google Firebase — Remote Config | Fetching app runtime configuration (such as the server address) | Standard service identifiers |
| Geoapify — maps & geocoding | Rendering map tiles, address search, and turning coordinates into an address | The search text you type and the coordinates of the point you pick |
| Carriers | Transport, delivery and tracking | Shipment and party data as described in Section 7.1 |
8.1 Google Firebase
We use Firebase Cloud Messaging to deliver notifications and Firebase Remote Config to fetch runtime configuration. We do not use any Firebase analytics or advertising products. Data passing through these services is subject to Google's Privacy Policy.
8.2 Geoapify
A mapping and geocoding service used only when you open the map screen or search for an address; it receives what you type in the search field and the coordinates of the point you pick. These requests are subject to the Geoapify Privacy Policy.
9
Security, storage & retention
We apply technical and organisational measures to protect your data, including:
- All server communication over HTTPS/TLS with full certificate validation.
- The session token is kept in the device's encrypted storage (Android Keystore / iOS Keychain), and the password is never stored on the device.
- Passwords are stored on the server only as irreversible hashes.
- Permissions are enforced by the server: an account can only reach its own data and shipments.
- Signing out immediately revokes the session token on the server and wipes it from the device, and you can end all sessions on all your devices.
- Sign-in attempts are rate-limited to resist guessing attacks, and access is audit-logged.
⚠️ No method of electronic transmission or storage is 100% secure. We make reasonable efforts to protect your data, and we ask you to protect your password and never share it with anyone.
9.1 Retention periods
- Account and profile data: for as long as your account is active; deleted when a deletion request is carried out.
- Session tokens: limited validity, revoked on sign-out.
- Shipment, invoice and customs records: retained for the period required by applicable commercial, accounting and customs regulations, even after account deletion.
- Security server logs: for a limited period sufficient for security and auditing purposes.
- Local data on your device: wiped on sign-out, and removed entirely when the app is uninstalled.
10
Account & data deletion
You may request deletion of your account and personal data at any time. The request steps, what gets deleted, and what is retained for legal reasons are detailed on the Account Deletion page.
💡 To send a deletion request directly: email
info@cbexgroupllc.com with the subject "Account Deletion Request", and we will process it within 30 days at most.
Under applicable data protection laws, you have the right to:
- Access — know what data we hold about you and obtain a copy of it.
- Rectification — correct your data from within the app or by contacting us.
- Erasure — request deletion of your account and personal data as described in Section 10.
- Objection and restriction of processing — where legally applicable.
- Withdraw consent — revoke the location, contacts or notifications permissions at any time from your device settings, without affecting the rest of the service.
- Control alert channels — enable or disable push, email, SMS and WhatsApp from the notification settings in the app.
- Complaint — with the competent data protection authority in your country.
To exercise any of these rights, contact us through the channels at the end of this page. We may verify your identity before acting on a request, to protect your account.
The CBEX app is a commercial service intended for adults (18 years or older) who can enter into a shipping contract. It is not directed to children in any way and contains no content aimed at them.
We do not knowingly collect any data from individuals under 18. If we learn that an account was created by a minor, we will delete the account and its data promptly. If you are a parent or guardian and believe your child has provided us with data, please contact us and we will delete it.
13
Cross-border transfers
International shipping inherently requires shipment data to be transferred outside your country: to the carrier and to the customs authorities of the transit and destination countries. Some of the technical services listed in Section 8 also run on servers outside your country.
In all such cases we limit the transfer to the data needed to fulfil your shipment or to comply with the law, and we work with providers that maintain appropriate data protection standards.
14
Changes to this policy & contact
14.1 Changes to this policy
We may update this policy from time to time by publishing a new version on this page and updating the "Last Updated" date above. For material changes, we will notify you through an in-app notice or by email before they take effect.
14.2 Contact us
For any question or request related to this policy or to your data, contact us through the channels below and we will respond as soon as possible.