Skip to content
Koggio
Product Carriers Pricing FAQ
Get early access Book an intro call Log in
Log in Get early access

Legal

Privacy Policy

Last updated: 30 June 2026 Effective: 1 July 2026

Koggio handles shipping data for a living, so we treat privacy as part of the product. This policy explains what we collect, why, who we share it with, and the rights you have - in plain terms.

On this page
  • Who we are
  • Our two roles
  • Data we collect
  • How we use it
  • Legal basis
  • Sharing & sub-processors
  • International transfers
  • Retention
  • Your rights
  • Merchants' customers
  • Security
  • Cookies
  • Children
  • Changes
  • Contact

01 Who we are

Koggio is a multi-carrier shipping platform built and operated by SIA Mandet ("Mandet", "Koggio", "we", "us", "our"). This policy covers the marketing site at koggio.com, the application at app.koggio.com, and our related communications.

SIA Mandet Registration number: 40203337975
VAT number: LV40203337975
Murjāņu iela 38 - 3, Rīga, LV-1064, Latvia
Email: raitis@koggio.com

We have not appointed a statutory Data Protection Officer, as we are not required to. Privacy matters reach our team directly at raitis@koggio.com.

02 Our two roles

Koggio handles personal data in two distinct capacities, and it matters which is which:

  • As a controller - for data about you, our customer: the people who sign up, run the account, and pay for Koggio. We decide how that data is used, and this policy governs it.
  • As a processor - for data about your customers, the recipients of your shipments. That data comes from your Shopify store and your carriers. You are the controller; we process it only to run the service for you, under the Data Processing Agreement in our Terms.

03 Data we collect

Account & profile (we are controller)

  • Name, email address, and optionally phone number;
  • A password, stored only as a one-way hash - never in plain text - or, if you use single sign-on, an identifier from Google or Microsoft;
  • Email-verification and password-reset tokens (stored hashed), and your record of accepting these terms.

Company & billing (we are controller)

  • Company name, registration and VAT number, business address, and invoicing email;
  • Your plan, subscription status, and renewal dates;
  • Payment is handled by our processor (Stripe) or, for Shopify App Store installs, by Shopify - we receive billing status and an identifier, not your full card number.

Shopify store & order data (we are processor)

When you connect a store, we access the data we need to fulfil shipments on your behalf:

  • Recipient name, delivery address, email, and phone number;
  • Order numbers, line items, order notes, and fulfilment status;
  • The Shopify access token for your store (stored encrypted), and tracking and fulfilment updates we write back.

This data belongs to your customers. You are its controller; we process it as your processor.

Carrier & shipment data

  • Sender and recipient details, parcel weight and dimensions on each label;
  • Tracking numbers, barcodes, carrier responses, and label files;
  • Tracking events (status, description, location, timestamp) and pickup / locker assignments;
  • Your carrier API credentials, stored encrypted at rest.

Technical & usage data

  • IP address, browser and device type, and operating system;
  • Pages visited, features used, and actions taken in the app;
  • Server logs and error reports used to operate and debug the service.

04 How we use your data

  • Run the service - create labels, book pickups and lockers, sync tracking to Shopify, and show dispatch dashboards and analytics.
  • Order merging - to combine repeat orders, we match those going to the same recipient and address using a one-way hash of the email and normalised address, so orders are grouped without exposing the underlying details.
  • Branded tracking - show your customers a tracking page under your brand. Recipient contact details are not shown on that page.
  • Accounts & access - authenticate users, manage roles, verify email, and enforce plan allowances.
  • Billing - process subscriptions, issue invoices, and handle failed payments.
  • Support - answer questions and debug shipment issues.
  • Improve the product - understand how the platform is used, prioritise features, and fix bugs, using aggregated or pseudonymised data where we can.
  • Security & compliance - detect abuse, protect account integrity, and meet legal obligations.
  • Communicate - send transactional messages (verification, label, billing) and, with your consent, occasional product updates you can opt out of at any time.

05 Legal basis for processing

Where we act as a controller, we rely on these GDPR Article 6 bases:

  • Performance of a contract (Art. 6(1)(b)) - to deliver Koggio to you, including labels, carrier communication, tracking sync, and billing.
  • Legitimate interests (Art. 6(1)(f)) - security, fraud prevention, product analytics, and service improvement, balanced against your rights and kept proportionate.
  • Legal obligation (Art. 6(1)(c)) - keeping invoices, shipping records, and other data required by Latvian or EU law.
  • Consent (Art. 6(1)(a)) - for optional marketing emails or any non-essential cookies, withdrawable at any time.

For your customers' data, we act as processor and process only on your documented instructions under our Data Processing Agreement. You are responsible for the legal basis on which you collected that data.

06 Sharing & sub-processors

We do not sell personal data. We share it only with the providers we need to run Koggio, each bound by appropriate data-protection terms. Our current sub-processors:

ProviderPurposeRegion
Fly.io Application & database hosting (compute, PostgreSQL, Redis) EU - Stockholm
Stripe Subscription billing and card processing for direct sign-ups EU / US
Shopify Order source; billing for App Store installs; mandatory privacy webhooks EU / US
Carriers DHL Express, DPD, SmartPosti, FedEx, Omniva, Venipak and others - label & delivery EU / carrier HQ
Google / Microsoft Optional single sign-on (only if you choose it) EU / US

Carriers receive only what they need to move a parcel - recipient name, address, parcel dimensions, and contact details for delivery notifications. We keep an up-to-date sub-processor list and will tell you about material changes. We may also disclose data to competent authorities where required by law or valid court order, and will notify you where legally permitted.

07 International transfers

Koggio is built and hosted in the European Union - our application and database run in Stockholm, Sweden. We keep personal data in the EU/EEA by default.

Some sub-processors (such as Stripe, Shopify, Google, and Microsoft) or carriers may process data outside the EEA. Where that happens, we rely on one of:

  • a European Commission adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified;
  • Standard Contractual Clauses approved by the European Commission, with supplementary measures where needed.

You can ask us for details of the safeguards that apply to a specific transfer.

08 Data retention

We keep personal data only as long as we need it for the purpose it was collected:

  • Account & company data - for your subscription, then deleted or anonymised within 30 days of termination, unless the law requires longer.
  • Invoices & shipment records - retained as required by Latvian accounting and customs law (generally 5 years).
  • Tracking data - retained for 24 months after delivery, then deleted.
  • Support communications - retained for 3 years after the last interaction.
  • Server logs - retained for up to 90 days, then purged.

When you uninstall from Shopify, or when a Shopify redaction webhook is received, we delete the relevant store and customer data on the schedule those webhooks require, except where retention is legally mandated.

09 Your rights under GDPR

As a data subject in the EU/EEA you have the rights below. To exercise any of them, email raitis@koggio.com - we respond within 30 days.

Access (Art. 15) Get a copy of the personal data we hold about you.
Rectification (Art. 16) Have inaccurate or incomplete data corrected.
Erasure (Art. 17) Have your data deleted, subject to legal retention.
Restriction (Art. 18) Pause processing while a dispute is resolved.
Portability (Art. 20) Receive your data in a structured, machine-readable format.
Objection (Art. 21) Object to processing based on legitimate interests or to direct marketing.

If you're unhappy with how we handle a request, you may complain to the Latvian Data State Inspectorate (Datu valsts inspekcija): www.dvi.gov.lv.

10 If you're a customer of a Koggio merchant

If you received a parcel tracked through Koggio, the store you ordered from is the controller of your data; we process it on their behalf. To access, correct, or delete your data, contact that store - they direct the request and we act on their instruction.

For Shopify stores, we support Shopify's mandatory privacy webhooks: when a store forwards a customer data request, a customer redaction, or a shop redaction, we respond on the timeline Shopify requires. Recipient contact details are never displayed on the branded tracking page.

11 Security

We apply technical and organisational measures to protect personal data, including:

  • All traffic served over TLS (HTTPS enforced end to end);
  • Passwords stored only as one-way hashes; carrier credentials and webhook tokens encrypted at rest;
  • Strict tenant isolation - each organisation's data is scoped to its own account;
  • Role-based access on the principle of least privilege, and signed, replay-protected webhooks (Shopify and Stripe signatures verified);
  • Session tokens that can be revoked instantly (for example on password reset);
  • Regular dependency and security reviews, with production and non-production data kept separate.

No system is perfectly secure. If you find a vulnerability, please disclose it responsibly to raitis@koggio.com and we will work with you on it.

12 Cookies

koggio.com (this marketing site) uses no advertising or third-party tracking cookies.

app.koggio.com uses only strictly necessary cookies and browser storage to keep you signed in and to protect the session (authentication and CSRF protection). We do not set analytics or advertising cookies without your consent. Blocking necessary cookies will stop the app from working.

13 Children

Koggio is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

14 Changes to this policy

We may update this policy as the service evolves or the law changes. We will communicate material changes by email to account holders at least 14 days before they take effect, and update the "Last updated" date above. Continued use of Koggio after that date means you accept the revised policy.

15 Contact

For privacy questions or to exercise your rights, contact us at:

SIA Mandet - Privacy Murjāņu iela 38 - 3, Rīga, LV-1064, Latvia
Reg. No. 40203337975 · VAT LV40203337975
raitis@koggio.com

We aim to respond to all privacy requests within 30 days.

Koggio

Multi-carrier shipping ops for Baltic Shopify stores. Labels, tracking, and pickups on your own contracts - no per-label fee.

Get early access
Product
Overview Carriers Order merging Pricing FAQ
Get started
Get early access Book an intro call Log in Contact
Legal
Terms Privacy
© 2026 Koggio · Built by Mandet · Rīga
Early access

Good call. Let's get you set up.

A few details and you're on the list. We onboard our first stores by hand, so a real person (not an autoresponder) gets back to you, usually within a day.

No spam, no per-label fees. Just a reply from a human.

Request received.

Thanks! Check your inbox for a confirmation. We'll be in touch shortly to set you up.