1. Data Controller
The controller of personal data is:
CourierAPP — Stylianos Gerantidis (Sole Proprietorship)
Address: Anaxagora 23, Heraklion, Crete, 71306, Greece
Contact Email: info@courierapp.gr
2. Information We Collect
2.1 Personal Information
We collect the following information when you create an account, use the service or contact us:
- Full name
- Email address
- Phone number
- Pickup and delivery address
- Payment details (processed directly by Stripe — we do not store card numbers)
- Recipient details (name, phone, address — provided by you)
- VAT number and company name (for businesses requesting a VAT invoice)
- Support communication content (emails, chat messages)
- Location data (see section 2.4)
2.2 Shipment Information
- Parcel content description
- Dimensions and weight
- Declared content value (for insurance)
- HS code (for non-EU shipments)
- Parcel photos in the event of a damage report
2.3 Technical Information
- IP address
- Browser/device type and version
- Operating system
- Pages you visit and time spent
- Cookies and similar technologies (see section 7)
2.4 Location Data
Customer App: With your permission, we use your device location to pinpoint you on the map and pre-fill the pickup address. Access happens only while you are using the app, and you can revoke it at any time from your device settings.
Driver/Partner App: We collect the precise location (GPS) of our drivers, including background location when the driver is “online”. Because our app is about deliveries, our drivers need to know the pickup and delivery points. In addition, as a company we need to know our drivers’ current location in order to manage them accordingly (assign the nearest order, provide live shipment tracking, and manage our fleet).
3. How We Use the Information
- Providing and operating the Service (shipment bookings, pickups, deliveries)
- Processing payments through Stripe
- Transferring necessary details to courier partners (addresses, pickup/delivery phones, customs details)
- Communication for shipment updates (push notifications, email, SMS)
- Customer support and managing damage/loss claims
- Improving and personalising the user experience
- Statistical analysis and upgrading our services
- Using location data to assign the nearest order to a driver, for live shipment tracking and fleet management
- Compliance with legal obligations (invoicing, customs, AML)
4. Sharing Data with Third Parties
We do not sell your personal data. We share data only in the following cases:
4.1 Courier Partners
To carry out the shipment, we transfer the necessary details (names, addresses, phones, content description) to partner courier companies such as DHL. The courier companies act as independent controllers under their own privacy policies.
4.2 Service Providers
- Stripe — payment processing (PCI-DSS Level 1 certified)
- Hostinger — website and email hosting
- Google — Search Console, Analytics
- Crisp — live chat support
- Meta — Facebook Pixel (analytics & advertising)
4.3 Legal Authorities
When required by a lawful request, court order, or to comply with mandatory legislation (e.g. customs checks).
5. International Data Transfers
Because we provide services in 38 countries, your data may be transferred to:
- Countries within the EEA/EU (covered by GDPR)
- Countries outside the EEA (e.g. United Kingdom, Switzerland, Norway) — based on adequacy decisions or Standard Contractual Clauses (SCCs)
6. Retention Period
- Account data: as long as you keep an active account + 5 years after deletion (for accounting/tax reasons)
- Shipment data: 5 years from the shipment date
- Support communication: 2 years
- Billing data: 10 years (tax obligation)
7. Cookies & Similar Technologies
We use:
- Functional cookies: necessary for the Platform to operate
- Analytics cookies: for statistics (Google Analytics)
- Advertising cookies: for targeted advertising (Meta Pixel) — you can disable them
You can manage cookies from your browser settings.
8. Data Security
We take technical and organisational security measures:
- SSL/TLS encryption for all communication
- 2FA (Two-Factor Authentication) for administrative accounts
- Wordfence Web Application Firewall
- Regular security scans
- Restricted data access for authorised personnel only
9. Your Rights (GDPR)
Under the GDPR (Regulation 2016/679), you have the right to:
- Access: what data we hold about you
- Rectification: of inaccurate data
- Erasure (right to be forgotten): deletion of personal data
- Portability: receive your data in a structured format
- Objection: to processing for certain purposes (e.g. marketing)
- Restriction of processing: pause processing
- Complaint: to the Hellenic Data Protection Authority (www.dpa.gr)
To exercise your rights: info@courierapp.gr
10. Children
The Service is intended for individuals over 18. We do not knowingly collect data from minors without parental consent.
11. Amendments
This Policy may be updated periodically. Material changes are communicated via email or an in-app notification at least 30 days before they take effect.
12. Contact
Email: info@courierapp.gr
Address: Anaxagora 23, Heraklion, Crete, 71306, Greece
