Back to home

Legal

Privacy policy

Effective: 31 August 2026

In short

  • CargoVi is software agencies use to run their operations. We are not a party to the operations they record, and we are not a money transmitter.
  • The website sets no cookies, runs no analytics and carries no advertising pixels. The app uses only the session cookie needed to keep you signed in.
  • The customer and contact data an agency uploads belongs to that agency. We process it on their behalf and under their instructions: we do not sell it, share it, or use it to train models.
  • If an agency holds data about you and you want to access, correct or delete it, that agency is your point of contact. We help them respond to you.

1. Two different roles, and why it matters

This policy separates two situations, because the obligations are not the same and blurring them would be misleading.

  • Your account data. When an agency signs up, CargoVi acts as controller: we decide what we collect and why. This covers the agency name, its users' details and its subscription status.
  • Operational data the agency uploads. The customers, orders, payments and documents an agency enters belong to it. Towards those people the agency is the controller and decides what happens to their data; we are only the processor, handling it on the agency's behalf and following its instructions.

What that means in practice: if an agency holds data about you, we do not make decisions about it and usually have no relationship with you. Contact that agency. If you write to us, we will refer you to them and help them answer you.

2. What data we handle

Account and sign-in data. Agency name, each user's name and email, their role within the agency, and the date they joined. Passwords are handled by our authentication provider and stored hashed; nobody at CargoVi can read them.

Billing data. The plan, its status and the cycle dates. We do not store card numbers. Stripe processes payment directly and we keep only the identifiers it returns.

Operational data the agency uploads. What the agency enters in order to work:

  • About its customers: name, phone, WhatsApp, email, address and notes.
  • About the contacts an agency attaches to an order: name, phone, region, city, address, identity document and notes.
  • About orders: service, amounts, payments, internal status, receipts and claims.
  • Documents the agency uploads and attaches to an order, a customer or a contact.

Where an agency records an identity document, it is sensitive and treated as such: it is visible only to users of the agency that entered it, and its only purpose is to prevent duplicate records within that agency.

Technical data. Server logs containing IP address, browser type, timestamp and requested path, plus an internal activity history recording which user did what inside the agency. These are used to run the service, investigate problems and detect abuse.

Website contact form. If you submit it we receive your name, agency, email, optional phone and message. We use them only to reply to you.

3. Cookies and browser storage

The public website sets no cookies. The only thing it stores in your browser is your light/dark theme preference, in local storage. It identifies nobody, and you can clear it from your browser at any time.

The app uses strictly necessary cookies. These are the session cookies from our authentication provider, which keep you signed in between screens. Without them there is no way to log in, so there is no banner to accept or reject them — they do not exist to follow you.

We run no analytics, advertising, third-party pixels or embedded social widgets on either surface. We do not track across sites, and we have nothing to answer to a "do not track" signal because we do not track.

4. What we use data for

  • Providing the service: authenticating users, storing and displaying the agency's operations, generating receipts and calculating its reports.
  • Charging the subscription and managing its status.
  • Keeping the system running and secure: backups, error diagnosis, abuse prevention and account security.
  • Providing support when the agency asks for it.
  • Meeting legal obligations and responding to valid requests from competent authorities.

We do not sell personal data, do not share it for advertising, and do not use an agency's operational data to train artificial-intelligence models. Nor do we use one agency's information to build new products without its explicit permission.

5. Who we share data with

We work with the providers below. Each receives only what its function requires and is contractually bound to use it for that purpose only.

ProviderPurposeWhat it receives
SupabaseDatabase, authentication and file storageAll account and operational data, including uploaded documents
StripeSubscription billingBilling email and subscription identifiers. Card details are collected by Stripe directly and never pass through our servers
VercelHosting for the app and siteTechnical request data: IP, browser, path

We may also share data with professional advisers under a duty of confidentiality, with an authority where there is a valid legal request, and with an acquirer in a merger or sale — in that last case we will give notice far enough in advance that an agency can export its data and leave if it prefers.

6. Where data is held

Our infrastructure is in the United States and that is where data is processed. If you access the service from another country, your data is transferred to the United States, whose data-protection framework may differ from your own jurisdiction's. By using the service you agree to that transfer.

7. How long we keep it

  • Operational data: for as long as the agency keeps its account. The agency deletes it whenever it wants, from within the app.
  • When an account closes: we keep the data for 30 days to allow reactivation or an export, then remove it from active systems.
  • Backups: overwritten on cycles of up to 90 days, so deleted data may persist in a backup for that period.
  • Billing records: for as long as applicable accounting and tax rules require, regardless of account closure.
  • Technical logs: up to 12 months.

8. How we protect it

  • Per-agency isolation enforced in the database. Every row carries its agency and the access rules are applied by the database engine, not by screen code. One agency cannot read another's data even if someone tampers with the requests.
  • Encryption in transit on every connection, and encryption at rest by our database provider.
  • Irreversibly hashed passwords, handled by the authentication provider. We cannot see or recover them, only let you reset them.
  • Roles within the agency, so each user sees what they should, plus an activity history recording who did what.

No system is invulnerable. If we detect a breach affecting personal data, we will notify the affected agencies without undue delay, with what we know at that point, even if the investigation is still open.

9. Your rights

If you are a user at an agency: you can access your account data, correct it, export the agency's data and request that the account be deleted. Write to legal@cargovi.com and we will respond within 30 days at the latest.

If an agency holds data about you: it is controlled by that agency, not by us. Ask them directly. If your request reaches us, we will pass it to the relevant agency and give them the means to handle it; what we cannot do is change or delete data another company controls on our own initiative.

California residents. We do not sell or share personal information as the CCPA and CPRA use those terms, and have not done so in the past twelve months. You can exercise your rights to know, delete, correct and not be discriminated against at the same contact address. We do not process sensitive personal information to infer characteristics.

10. Minors

CargoVi is a professional tool and is not directed at anyone under 18. We do not knowingly collect data from minors as users. If you believe a minor has given us data, write to us and we will delete it.

11. Changes to this policy

If we change something substantive — a new purpose or a new subprocessor — we will notify agencies with an active account by email and in the app at least 15 days before it takes effect, and update the effective date above. Minor wording changes are published without prior notice.

12. Contact

Controller: CargoVi.

  • Privacy and legal notices: legal@cargovi.com
  • General enquiries: hola@cargovi.com

This English text is a translation provided for convenience. If it and the Spanish version ever conflict, the Spanish version governs.

Terms of service