Development draftThis structure is not legal advice and requires Ontario counsel review before public launch.
Privacy foundation

Privacy policy

Deliveries involve names, phones, home addresses, location data, messages and sometimes proof images. The product is designed to minimize and protect that information.

Draft foundation · August 14, 2026
01

What the service needs

The platform may process sender and recipient contact details, structured addresses, delivery instructions, payment identifiers, driver location during active work, support records and security/audit events.

02

How data is used

Data supports quoting, booking, payment, dispatch, tracking, notification, proof, support, fraud prevention, legal compliance and service measurement.

  • Recipient tracking shows a privacy-reduced projection.
  • Driver tracking stops when offline or no active workflow exists.
  • Raw payment card data is never stored by the application.
03

First-party service analytics

Cookito records anonymous product events—such as page views, address-validation outcomes, quote and checkout steps, payment outcomes and completed orders—to understand reliability and conversion. A random browser identifier, a 30-minute session identifier and first-touch campaign parameters may be stored in local browser storage. Cookito does not record form keystrokes, names, phone numbers, email addresses, full pickup/delivery addresses or payment-card data in analytics.

  • Traffic attribution is limited to referrer hostname and UTM source, medium, campaign, content and term.
  • Analytics is stored by Cookito rather than sent to advertising pixels in this implementation.
  • The default analytics retention period is 395 days and can be shortened through production configuration.
04

Sharing and providers

A final policy must name and govern the actual payment, maps, messaging, hosting, monitoring and storage providers used in production.

05

Retention and rights

Operational records and anonymous analytics follow separate retention controls. Requests concerning access, correction or deletion can be directed to Cookito support. Final deletion/anonymization procedures, Canadian cross-border processing and PIPEDA obligations still require a privacy impact assessment and counsel review before launch.