Privacy Policy

Policy on protection of clients' personal data

The website is located at parcelsapp.com ("site"), along with mobile applications, provide online tracking services for parcels and shipments. We respect your privacy and take your security seriously online. To provide you with the best service and timely updates, we record a variety of information when you visit our site.

To better protect your privacy, we provide the Privacy Policy below, explaining our online practices for collecting information and how you can change how we collect and use your information. We use your Personal Information only to ensure the work and improvement of the Site. By using the site, you agree to the collection and use of information in accordance with this policy.

By using the site and/or associated "Parcels" mobile app for iOS and Android, the Customer (User) confirms that he has read the conditions of this Privacy Policy with due diligence and accepts them, without any additional comments.

The administration reserves the right to change, add or delete the clauses of this Agreement at any time without notifying the Clients.

Objectives of collecting and processing personal information of clients

The site collects and stores only those personal data that are necessary to provide services and/or sell goods and/or provide other valuable services to site visitors.

Personal information of the Client can be used for the following purposes:

Google Sign-In and Authentication Data

We offer the option to sign in using your Google account. Authentication is securely handled by Clerk.com, a third-party authentication service provider. When you choose to sign in with Google, we access the following information from your Google account:

How we use this data:

Data storage and handling: Your name and email address are stored securely in our database. Google Sign-In does not grant Parcels access to your Gmail messages. Clerk.com handles the authentication process and may store authentication tokens in accordance with their own privacy policy. We do not have access to your Google account password.

Your control: You can manage your notification preferences at any time from your account settings. You may also revoke our application's access to your Google account through your Google Account permissions page.

Optional import from forwarded emails

If you choose Email Import in the mobile app, you can create a temporary address ending in @parcelsapp.com for that app installation. You may forward individual order or delivery emails to it, or set up a forwarding rule in your own email service. This feature does not connect to or read your mailbox. A forwarding rule you create with your email service remains under your control; deleting the temporary address in the app does not remove that rule.

Mailgun, a Sinch Email service operating in the United States, receives the forwarded message and sends it to our server. A forwarded message can contain its headers, sender and recipient addresses, subject, body, links and attachments, including personal information about you or others. We use it to find orders, shipments and tracking numbers and to present findings for your review. Mailgun handles the message and delivery metadata under its own processing and retention terms.

We encrypt admitted messages on our server. When a message produces a finding, we erase its original content after processing. If we cannot recognize a finding, we keep the encrypted original for up to seven days from receipt to diagnose and improve the import parser, then erase it automatically. An unfinished processing attempt is erased within 24 hours. Forwarding setup notices are handled separately and their usable code or link expires after one hour. Deleting the temporary address erases any retained message content and pending findings earlier.

To fix recognition errors, an authorized developer may manually access the full content of a specific unrecognized message and provide it to OpenAI for analysis and parser improvement. Access is limited to an individual message and recorded with the operator, reason and time. The message provided to OpenAI is processed under its data processing terms; the seven-day deletion period for our encrypted original does not control retention of a copy at OpenAI. Incoming messages are not automatically sent to an AI service.

After a corrected parser is released, we may manually reprocess an unrecognized message before its original seven-day deadline. Newly recognized orders and tracking numbers appear only as findings for you to review; nothing is added to your parcel list without your choice. Pending findings expire after 30 days or when you delete the temporary address. Orders and parcels you choose to add then follow the app's ordinary data lifecycle. Message content is not stored on your phone or included in product analytics, crash reports or ordinary support reports.

A temporary address is tied to one app installation and expires after 30 days without authenticated activity. If you uninstall the app, an email-service forwarding rule may continue to send messages until you remove it yourself; messages to an expired or deleted address are not admitted into our import queue. For questions or a data request, contact support@parcelsapp.com.

Terms of processing of the user's personal information and its transfer to third parties

With regard to the user's personal information, its confidentiality remains, except for cases of voluntary provision by the user of information about himself for general access to an unlimited number of persons.

The site has the right to transfer the user's personal information to third parties in the following cases:

Cookie We Use

receive-cookie-deprecation – Placed by Google ad services (DoubleClick / AdSense) as part of Chrome’s “Privacy Sandbox” testing. It simply stores the value “1” to signal that the page is taking part in Google’s experiment for serving and measuring ads without traditional third-party cookies. It holds no personal data or profiling information. Typical lifetime: ≈ 6 months, after which it is automatically removed or renewed.

__eoi – Set by Google AdSense. Used purely for security and anti-fraud checks (for example, to detect invalid clicks on ads). Does not contain any personal profile data. Typical lifetime: about six months.

FCCDCF – Set by Google’s Funding Choices consent-management banner. Stores your current cookie-consent choices (the IAB “TCF” string and Google-specific signals) so the banner doesn’t ask you again on every page. Typical lifetime: up to 13 months, then removed automatically or whenever you clear or change your consent settings.

_parcel_session – First-party session cookie generated by our Ruby on Rails application. Keeps you signed in and remembers basic site preferences as you navigate between pages. Contains only a random session ID, not personal data. It expires automatically when you close your browser (or after a period of inactivity if you chose “Remember me”).

__gads – Set by Google AdSense / DoubleClick. Helps count ad impressions, limit how often the same ad is shown and detect click-fraud. Contains only a random identifier, not personal data. Typical lifetime: 13 months.

__gpi – First-party cookie dropped by Google AdSense when ads load on our domain. Records information needed to measure and optimise ad performance. Stores a pseudonymous ID, no personal profile data. Typical lifetime: 13 months.

_ga – Set by Google Analytics 4. Primary visitor-ID cookie that lets us recognise returning users and compile anonymous statistics (page-views, session length, etc.). Contains a random client identifier, no names or emails. Lifetime: 2 years.

_ga_Z5RCF4F7T8 – Companion cookie for the GA-4 property “G-Z5RCF4F7T8.” Keeps session state for that specific Analytics property. Same content as _ga but scoped to the property. Lifetime: 2 years.

FCNEC – Set by Google’s Funding Choices consent banner. Stores whether you have closed the banner and which non-essential categories you toggled off, so the banner doesn’t pop up again on every page. Lifetime: up to 13 months (or until you clear/change consent).

European Representative under Article 27 of GDPR

We have appointed EU Rep as our Representative under Article 27 of the EU General Data Protection Regulation (“GDPR”). All GDPR queries from EU Data Subjects or Data Protection authorities should be submitted to eurep.ie via their dedicated form. BizLegal Ltd trading as EU Rep have their registered office at 27 Cork Road, Midleton Co. Cork, Ireland. Company number 635921.

Cookie Policy

We use cookies to analyze traffic, select the right content and advertising for you, and give you the opportunity to share information in social networks. We share information about your activities on the site of Google's partners: social networks and advertising and web analytics companies. Our partners can combine this information with the information you provided, as well as with the data they received when you used their services. To protect your privacy, we restrict the use of these tools.

When you visit our site, use our services, applications, tools, go through our advertising links and exchange messages with us (for example, by e-mail), we or our authorized service providers can use cookies and other similar technologies to store information to allow you to perform the desired actions more efficiently, faster and more safely. This page will give you a more complete understanding of these technologies and how we apply them on our websites, services, applications and tools. Below are the main points of our policy of using cookies and similar technologies, which you should familiarize yourself with.

Use of cookies by third-party service providers

We can cooperate with other companies, usually called "service providers", who can place - with our permission - cookies and similar elements used to store information on our websites, and also integrate them into our services, applications and tools . These service providers help us in the exploitation of our websites, applications, services and tools, and help you to perform the desired actions more efficiently, faster and more safely.

Third-party vendors, including Google and Yandex, use cookies to show you ads based on previous visits to our site. Cookies advertising preferences allow the company Yandex, Google and its partners to show ads in view of your visits to our and / or other sites. Users may opt out of personalized advertising by visiting Ads Settings. Alternatively, you canopt out of a third-party vendor's use of cookies for personalized advertising by visiting www.aboutads.info.

Our websites, services, applications and tools can use the services of third parties, such as ad networks and exchanges, for promotional purposes. These ad networks and exchanges, in turn, can use "other" cookies, and similar technology elements to collect the information they need to provide you with relevant services. They can also collect other data about you, such as the device ID, IP address and advertising ID (IDFA), which can be used to customize the advertisements displayed on our and other websites to your best interests.

We do not control the use of the above technologies by third parties, even if they use our technologies to collect or store data. Information about the collection, storage and sharing of data with them can be found in terms of the provision of services by these companies, their privacy policy, and also in the relevant documents of these companies concerning permits, notifications and the right to choose. We do not make any assurance about the policies and practices of third-party advertisers, ad networks and exchanges, and third parties associated with them.

Measures used to protect user personal information

The site takes necessary and sufficient organizational and technical measures to protect the user's personal information from unauthorized or accidental access, destruction, modification, blocking, copying, distribution, as well as from other improper actions of third parties with it.

Additional conditions

The Service has the right to make changes to this Privacy Policy without the Client's consent and notification. Such changes come into force from the date of their publication on the site.

The Client must get acquainted with the changes introduced in time and confirms his responsibility for the consequences of untimely acquaintance with them.