Privacy Policy
Your trust matters to us. Learn how we collect, use, and protect your information when you use Bezal's courier API services.
1. Information We Collect
To provide you with reliable courier API services, we collect certain information when you interact with our platform. This includes data you actively provide such as email, phone number, username, payment information and data we automatically collect to ensure security and performance.
When you use our API, we automatically collect technical data necessary to operate, secure, and improve our services such as endpint accessed, the origin and destination request
2. How We Use Your Information
The data we collect is used exclusively to facilitate service provision, maintain security, and continuously improve our platform. Specific uses include: servive delivery, optimization, debugging and troubleshooting, security, communications like alerts and updates, legal compliance.
We NEVER sell your personal data to third parties or use it for advertising purposes.
3. Cookies & Session Management
We use cookies, session tokens, and similar technologies to provide a secure, seamless experience across our website and API dashboard. These are essential for the proper functioning of our services.
Types of Cookies & Session Data We Use
| Type | Purpose | Duration |
|---|---|---|
| Session Cookies | Authenticate your login, maintain active session state, and store temporary preferences during your visit | Until browser is closed |
| Authentication Tokens (JWT) | Securely identify your API requests, manage rate limits, and authorize access to protected endpoints | 24 hours or until logout |
| Security Cookies | CSRF protection tokens, request validation, and bot detection mechanisms | Session-based |
| Preference Cookies | Store dashboard layout preferences, language selection, and API key visibility settings | 30 days |
| Analytics Cookies | Anonymous usage statistics to improve platform performance (GDPR-compliant, no PII collected) | 12 months |
Your Control: Most browsers allow you to block or delete cookies, but please note that doing so may prevent you from logging in or using critical features of our API dashboard.
4. Data Security & Protection
We implement enterprise-grade security measures to protect your information from unauthorized access, alteration, or destruction.
- Encryption at rest — All sensitive data is encrypted using AES-256 encryption
- Encryption in transit — TLS 1.3 for all API endpoints and web dashboard traffic
In the unlikely event of a data breach, we will notify affected users within 72 hours as required by applicable data protection regulations (GDPR, CCPA, etc.).
5. When We Share Your Data
We share your information only when strictly necessary to provide our services or comply with legal obligations:
- Payment Processors — Payment information is shared with gateways for transaction processing
- Legal Compliance — When required by law, court order, or to enforce our terms of service
- Service Providers — Cloud hosting, analytics, and support tools that are contractually bound to maintain confidentiality
Important: All third-party service providers sign Data Processing Agreements (DPAs) that comply with GDPR and other privacy regulations.
6. Your Privacy Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right to Access — Request a copy of all personal data we hold about you
- Right to Rectification — Correct inaccurate or incomplete information
- Right to Deletion ("Right to be Forgotten") — Request deletion of your data, subject to legal retention requirements
- Right to Object/Restrict Processing — Limit how we use your data in certain circumstances
To exercise any of these rights, please contact our Data Protection Officer at romaxdesigns@gmail.com. We will respond within 30 days.
Questions About Your Privacy?
Our Data Protection Team is available to answer any questions about how we handle your information.
Contact Privacy TeamOr email us directly: romaxdesigns@gmail.com