This Privacy Policy applies to the CBM Shipping mobile application (Android and iOS), an internal app reserved for employees of CBM Shipping to run day-to-day shipping operations: goods receiving, shipments, deliveries, trips and containers.
There is no self-registration: accounts are issued by the company's administration to its employees only. The general public cannot create an account or use the app.
By using the app as an employee you acknowledge that you have read this policy. If you have any questions about it, you can reach us through the channels listed at the end of this page.
The CBM Shipping app is operated and managed by CBM Shipping, a shipping and logistics company, which acts as the data controller for the data described in this policy.
The app is a field interface to the company's internal system: data it displays or that is entered through it is stored on the company's central servers and is subject to the same permission controls applied to the company system.
The app handles the minimum data needed to do the job. The table below summarises the categories and their purposes:
| Data category | Examples | Purpose |
| Account & sign-in data | Username, password (for verification only), device platform type (Android / iOS) | Sign-in and session management |
| Operational work data | Shipments; sender and receiver names, phone numbers and addresses; items and amounts | Running daily shipping operations |
| Proof of delivery | Recipient name, on-screen handwritten signature, optional note | Documenting shipment handover |
| Contacts (optional, on demand) | Only the single name and number you pick | Quickly filling a shipment party |
| Map & address search | Typed search text, coordinates of the point you pick on the map | Resolving shipment party addresses |
| Notification token | Device push token (FCM) | Delivering push notifications |
| Local settings | Language, theme, last username, biometric flag | Your preferences — stored on your device only |
3.1 Account data
At sign-in, your username and password are sent to the company server over an encrypted connection for verification only. The password is never stored on the device; the server issues a session token which is kept in the device's encrypted storage. The device platform type (Android or iOS) is sent as a label for the server's session list.
3.2 Company customers' data you enter as part of your job
While registering shipments and deliveries, employees enter data belonging to the company's customers (sender and receiver names, phone numbers, addresses, and the recipient's signature). This is operational data stored in the company's central system; the company is its controller and processes it to perform and document its shipping services.
3.3 Contacts — read locally only
When you tap "pick from contacts" in the shipment form, the app asks for contacts permission to show you the picker on your device. Your contact list is never uploaded, transmitted to any server, or synced; only the single name and number you select are placed into the shipment form you are creating yourself. You may deny the permission and type the details manually.
3.4 Map & address search
To set a shipment's sender or receiver address you can search by text or tap a point on the map. The typed search text and the coordinates of the picked point are sent to the mapping provider (see Section 7) to resolve them into a readable address. The employee's own location is never requested — the app holds no location permission at all.
3.5 Server logs
Like any online service, the company server automatically records technical request data (such as IP address and request time) for security, abuse detection and auditing.
The app is deliberately free of any data collection that does not directly serve the work:
- Location: the app never asks for location permission and does not track employees, neither in the foreground nor in the background.
- Fingerprint and face data: biometric verification happens entirely inside your device's operating system; the app never accesses, stores, or transmits your biometric data (see Section 6).
- Camera and microphone: not used and never requested.
- Analytics and advertising: the app contains no analytics, tracking, or ad SDKs.
- Selling data: we do not sell any data and do not share it for marketing purposes.
The data described above is used solely for the following purposes:
- Running daily shipping operations: receiving, shipments, deliveries, trips and containers.
- Verifying the employee's identity and managing their session, permissions and branch scope.
- Documenting shipment handover (recipient name and signature) as an operational and legal record.
- Sending work-related push notifications in the app language you chose.
- Protecting the system: detecting unauthorised access and misuse, and keeping audit logs.
- Complying with applicable legal and accounting obligations.
The data is not used for marketing, profiling, or any purpose outside the scope of work.
You can resume your session with your fingerprint (or face recognition) instead of retyping your password on every launch. This feature:
- Relies on the operating system's built-in biometric prompt (Android BiometricPrompt / Apple Face ID and Touch ID).
- The app never accesses your fingerprint or face image — it only receives a pass/fail result from the OS.
- No biometric data is stored in the app or sent to any server.
- Even after a successful biometric check, the app re-validates the session with the server before entering; a suspended account cannot be opened with a fingerprint.
- Using it is optional — you can always sign in with your password.
7
Third parties & services we use
We do not sell your data. The app uses a small number of technical services, for the purposes below only:
| Service | Purpose | Data sent to it |
| Google Firebase — Cloud Messaging & Remote Config | Delivering push notifications; fetching app runtime configuration | Device push token and standard service identifiers |
| Geoapify — maps & geocoding | Rendering map tiles; address search and reverse geocoding | The typed search text and the coordinates of the picked map point |
| Legal authorities | Compliance with a court order or binding legal request | Only what is required by law |
7.1 Google Firebase
We use Firebase Cloud Messaging to deliver notifications and Firebase Remote Config to fetch runtime configuration (such as the server address). We do not use any Firebase analytics or advertising products. Data passing through these services is subject to Google's Privacy Policy.
7.2 Geoapify
A mapping and geocoding service used only when you open the map screen or search for an address. It receives what you type in the search field and the coordinates of the point you pick — never your own location. These requests are subject to the Geoapify Privacy Policy.
8
Security, storage & retention
We apply technical and organisational measures to protect the data, including:
- All server communication over HTTPS/TLS with full certificate validation.
- The session token and settings are kept in the device's encrypted storage (Android Keystore / iOS Keychain), and the password is never stored.
- Every app launch starts at the sign-in screen; a session can only be resumed with biometrics or the password.
- Permissions are enforced by the server: employees can only reach the screens and data they are allowed, and every account is isolated to its branch.
- Sign-in attempts are rate-limited to resist guessing attacks.
- Signing out immediately revokes the session token on the server and wipes it from the device.
8.1 Retention periods
- Account data: for the duration of the employee's engagement and active account with the company.
- Session tokens: limited validity (at most 180 days), revoked on sign-out or by system administration.
- Operational work records (shipments, deliveries, accounting entries): business records belonging to the company, retained according to its policies and applicable legal and accounting regulations.
- Local data on your device: wiped on sign-out, and removed entirely when the app is uninstalled.
9
Account & data deletion
App accounts are issued by the company to its employees, so their creation, suspension and deletion are managed through the company's administration. You may request deletion of your account or personal data at any time by contacting us.
The request steps, what gets deleted, and what is retained for legal reasons are detailed on the Account Deletion page.
💡 To send a deletion request directly: email
info@cbmforlogistic.com with the subject "Account Deletion Request", and we will process it within 30 days at most.
Under applicable data protection laws, you have the right to:
- Access — know what data we hold about you and obtain a copy of it.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your account and personal data as described in Section 9.
- Objection and restriction of processing — where legally applicable.
- Disable notifications — from your device settings at any time, without affecting your account.
- Complaint — with the competent data protection authority in your country.
To exercise any of these rights, contact us through the channels at the end of this page. We may verify your identity before acting on a request, to protect your account.
The CBM Shipping app is a work tool reserved exclusively for the company's adult employees (18 years or older) and is not directed to children in any way.
We do not knowingly collect any data from individuals under 18, and the app cannot be used at all without a company-issued employee account. If we learn otherwise, we will delete that data promptly.
12
Changes to this policy & contact
12.1 Changes to this policy
We may update this policy from time to time by publishing a new version on this page and updating the "Last Updated" date above. For material changes, we will notify employees via an in-app notice or through company channels.
12.2 Contact us
For any question or request related to this policy, contact us through the channels below and we will respond as soon as possible.