01 Who we are
Koggio is a multi-carrier shipping platform built and operated by SIA Mandet ("Mandet", "Koggio", "we", "us", "our"). This policy covers the marketing site at koggio.com, the application at app.koggio.com, and our related communications.
SIA Mandet
Registration number: 40203337975
VAT number: LV40203337975
Murjāņu iela 38 - 3, Rīga, LV-1064, Latvia
Email: raitis@koggio.com
We have not appointed a statutory Data Protection Officer, as we are not required to. Privacy matters reach our team directly at raitis@koggio.com.
02 Our two roles
Koggio handles personal data in two distinct capacities, and it matters which is which:
- As a controller - for data about you, our customer: the people who sign up, run the account, and pay for Koggio. We decide how that data is used, and this policy governs it.
- As a processor - for data about your customers, the recipients of your shipments. That data comes from your Shopify store and your carriers. You are the controller; we process it only to run the service for you, under the Data Processing Agreement in our Terms.
03 Data we collect
Account & profile (we are controller)
- Name, email address, and optionally phone number;
- A password, stored only as a one-way hash - never in plain text - or, if you use single sign-on, an identifier from Google or Microsoft;
- Email-verification and password-reset tokens (stored hashed), and your record of accepting these terms.
Company & billing (we are controller)
- Company name, registration and VAT number, business address, and invoicing email;
- Your plan, subscription status, and renewal dates;
- Payment is handled by our processor (Stripe) or, for Shopify App Store installs, by Shopify - we receive billing status and an identifier, not your full card number.
Shopify store & order data (we are processor)
When you connect a store, we access the data we need to fulfil shipments on your behalf:
- Recipient name, delivery address, email, and phone number;
- Order numbers, line items, order notes, and fulfilment status;
- The Shopify access token for your store (stored encrypted), and tracking and fulfilment updates we write back.
This data belongs to your customers. You are its controller; we process it as your processor.
Carrier & shipment data
- Sender and recipient details, parcel weight and dimensions on each label;
- Tracking numbers, barcodes, carrier responses, and label files;
- Tracking events (status, description, location, timestamp) and pickup / locker assignments;
- Your carrier API credentials, stored encrypted at rest.
Technical & usage data
- IP address, browser and device type, and operating system;
- Pages visited, features used, and actions taken in the app;
- Server logs and error reports used to operate and debug the service.
04 How we use your data
- Run the service - create labels, book pickups and lockers, sync tracking to Shopify, and show dispatch dashboards and analytics.
- Order merging - to combine repeat orders, we match those going to the same recipient and address using a one-way hash of the email and normalised address, so orders are grouped without exposing the underlying details.
- Branded tracking - show your customers a tracking page under your brand. Recipient contact details are not shown on that page.
- Accounts & access - authenticate users, manage roles, verify email, and enforce plan allowances.
- Billing - process subscriptions, issue invoices, and handle failed payments.
- Support - answer questions and debug shipment issues.
- Improve the product - understand how the platform is used, prioritise features, and fix bugs, using aggregated or pseudonymised data where we can.
- Security & compliance - detect abuse, protect account integrity, and meet legal obligations.
- Communicate - send transactional messages (verification, label, billing) and, with your consent, occasional product updates you can opt out of at any time.
05 Legal basis for processing
Where we act as a controller, we rely on these GDPR Article 6 bases:
- Performance of a contract (Art. 6(1)(b)) - to deliver Koggio to you, including labels, carrier communication, tracking sync, and billing.
- Legitimate interests (Art. 6(1)(f)) - security, fraud prevention, product analytics, and service improvement, balanced against your rights and kept proportionate.
- Legal obligation (Art. 6(1)(c)) - keeping invoices, shipping records, and other data required by Latvian or EU law.
- Consent (Art. 6(1)(a)) - for optional marketing emails or any non-essential cookies, withdrawable at any time.
For your customers' data, we act as processor and process only on your documented instructions under our Data Processing Agreement. You are responsible for the legal basis on which you collected that data.
07 International transfers
Koggio is built and hosted in the European Union - our application and database run in Stockholm, Sweden. We keep personal data in the EU/EEA by default.
Some sub-processors (such as Stripe, Shopify, Google, and Microsoft) or carriers may process data outside the EEA. Where that happens, we rely on one of:
- a European Commission adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified;
- Standard Contractual Clauses approved by the European Commission, with supplementary measures where needed.
You can ask us for details of the safeguards that apply to a specific transfer.
08 Data retention
We keep personal data only as long as we need it for the purpose it was collected:
- Account & company data - for your subscription, then deleted or anonymised within 30 days of termination, unless the law requires longer.
- Invoices & shipment records - retained as required by Latvian accounting and customs law (generally 5 years).
- Tracking data - retained for 24 months after delivery, then deleted.
- Support communications - retained for 3 years after the last interaction.
- Server logs - retained for up to 90 days, then purged.
When you uninstall from Shopify, or when a Shopify redaction webhook is received, we delete the relevant store and customer data on the schedule those webhooks require, except where retention is legally mandated.
09 Your rights under GDPR
As a data subject in the EU/EEA you have the rights below. To exercise any of them, email raitis@koggio.com - we respond within 30 days.
If you're unhappy with how we handle a request, you may complain to the Latvian Data State Inspectorate (Datu valsts inspekcija): www.dvi.gov.lv.
10 If you're a customer of a Koggio merchant
If you received a parcel tracked through Koggio, the store you ordered from is the controller of your data; we process it on their behalf. To access, correct, or delete your data, contact that store - they direct the request and we act on their instruction.
For Shopify stores, we support Shopify's mandatory privacy webhooks: when a store forwards a customer data request, a customer redaction, or a shop redaction, we respond on the timeline Shopify requires. Recipient contact details are never displayed on the branded tracking page.
11 Security
We apply technical and organisational measures to protect personal data, including:
- All traffic served over TLS (HTTPS enforced end to end);
- Passwords stored only as one-way hashes; carrier credentials and webhook tokens encrypted at rest;
- Strict tenant isolation - each organisation's data is scoped to its own account;
- Role-based access on the principle of least privilege, and signed, replay-protected webhooks (Shopify and Stripe signatures verified);
- Session tokens that can be revoked instantly (for example on password reset);
- Regular dependency and security reviews, with production and non-production data kept separate.
No system is perfectly secure. If you find a vulnerability, please disclose it responsibly to raitis@koggio.com and we will work with you on it.
13 Children
Koggio is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
14 Changes to this policy
We may update this policy as the service evolves or the law changes. We will communicate material changes by email to account holders at least 14 days before they take effect, and update the "Last updated" date above. Continued use of Koggio after that date means you accept the revised policy.
15 Contact
For privacy questions or to exercise your rights, contact us at:
SIA Mandet - Privacy
Murjāņu iela 38 - 3, Rīga, LV-1064, Latvia
Reg. No. 40203337975 · VAT LV40203337975
raitis@koggio.com
We aim to respond to all privacy requests within 30 days.