← Back to sign up

Privacy Policy

HYPAX Logistic and Transport Platform

Effective date [DD Month YYYY — set before publishing]
Last updated [DD Month YYYY — set before publishing]
Version 1.0
Governing document HYPAX Terms of Service (the "Terms")
Applies to The HYPAX website and all subdomains, the HYPAX mobile and driver applications, public tracking and map pages, and our email, SMS and support channels
Privacy contact privacy@hypax.co.tz
Data Protection Officer dpo@hypax.co.tz

Before publishing — four things must be closed.

  1. Reconcile the party name. The Terms supplied to us are branded KagoAfrica / "Kago Africa (KagoAfrica.com)", while this Policy and the platform are branded HYPAX. A bundled Terms + Privacy Policy naming different companies is not enforceable as a pair. Pick one brand, or replace KagoAfrica with the HYPAX legal entity, and make the identifiers match on both documents.
  2. Fill every placeholder in square brackets: effective date, legal entity name and registration number, registered address, telephone.
  3. Close the gap in §10. The Terms promise that we "make every reasonable effort to protect private information". That promise is not yet fully met, and §10.3 says exactly where, so no reader is misled.
  4. State the other regimes. See §17.3.

1. About This Policy

1.1 Relationship to the Terms

The Terms of Service and this Privacy Policy are two separate documents that work together. The Terms govern what you may do with the Services and what each party owes the other. This Policy governs one thing only: how we collect, use, share, store and protect your personal data, and what rights you have over it.

This Policy does not restate the Terms. Where a matter is a contractual obligation rather than a data matter — payment terms, liability, suspension, dispute resolution, or what counts as misuse — it belongs in the Terms and we do not duplicate it here. We cross-refer instead. If the two ever conflict on the handling of personal data, this Policy governs.

By creating an account, downloading or using the mobile application, or using a public HYPAX page, you accept the Terms and this Policy. If you do not accept them, do not use the Platform.

1.2 Who We Are

HYPAX ("HYPAX", "we", "us", "our") operates the Platform, which connects Clients (Cargo Owners) with Transporters, drivers and agents for end-to-end haulage — from posting a load, through loading, dispatch and in-transit tracking, to delivery, escrow release and proof of delivery.

We are the data controller for the personal data described here. Where we instruct a Transporter, subcontractor or vendor to process data for us, they act as a data processor. Our legal entity name, registration number and registered address are [confirm].

1.3 Who This Policy Covers

Everyone who uses the Platform in any capacity — Cargo Owners, agents, Transporters, drivers, HYPAX staff and administrators, and visitors — and personal data about you that we receive from someone else, such as a Cargo Owner naming you as consignee or site contact for a load.

1.4 Key Terms

Term Meaning
Personal data Information relating to an identified or identifiable natural person. Excludes data genuinely anonymised so it can no longer be linked back to you.
Sensitive data The higher-risk subset the law treats specially — for example national identification numbers and precise live location.
User Content Content, documents, shipment details, images and instructions you upload to, create in or transmit through the Platform. You keep ownership of your User Content.
Verification data Identity and business records submitted so we can verify a person, a Transporter or a vehicle before it carries freight.
Third-party services Selcom; our SMS, email, mapping and routing providers; connected business systems; and our hosting and storage providers.

1.5 How This Policy Maps to the Terms

Clause in the source Terms Where it now lives
Privacy Statement — protection of private information This Policy §10, including its limits
Privacy Statement — accuracy and completeness This Policy §9.4, §14.1
Summary of Information — scope of collection This Policy §2, §3
Summary of Information — regular review and notification This Policy §17.1 · Terms §18
Summary of Information — third-party websites This Policy §6.4 · Terms §9
Children's Data This Policy §16 · Terms §1.4, §16.2
Account Credentials Terms §11.1, §11.2 · This Policy §14.3 (data effect only)
Account Termination — deletion of information Terms §11.4 · This Policy §9.3
Limitation on Your Use of Services — no mass collection Terms §6.2 · This Policy §3.6
Your Communications with Us — business purposes only Terms §9.4
Network Access and Devices Terms — no data provision needed
Intellectual Property — user identification Terms §10 · This Policy §2.1, §3.3
Licence to Use Services Terms §5
Disclaimer / liability Terms §13, §14

2. Information We Collect

We collect only these categories, and within them only the fields the relevant feature needs.

2.1 Account and Identity Data

First and last name; email address, which is also your sign-in identifier; password, stored only as a one-way salted hash; your role and department; profile photograph; date of birth where voluntarily given; sign-in dates and last activity.

2.2 Contact Data

Mobile and telephone numbers; email address; and your addresses — label, street, city, postal code, country. Mobile numbers are used for one-time sign-in codes and for operational, tracking and payment notifications.

2.3 Verification Data (sensitive)

Collected to confirm identity and the right to carry freight:

  • Individual identity — the identification type you select (national ID such as NIDA, passport, or driving licence), the identification number, and for individual owners a photograph or scan of the identity document itself.
  • Businesses — company or individual name, registration number, tax identification number (TIN), VAT number, business licence details, country of registration.
  • Drivers — name, mobile number, country, email where given, driving licence number.
  • Vehicles — licence plate, chassis number, truck type and capacity, and an uploaded vehicle registration card.

We rely on the bases in §4 for this category, and never on consent alone where the law requires another basis.

2.4 Shipment, Order and Cargo Data

Loading and delivery points with their coordinates; route and distance; cargo description, type and weight; truck type and quantity required; dates; rates and currency; customer name; your own order reference; and the status of each tender, order and shipment.

2.5 Financial, Escrow and Payment Data

  • Escrow — escrow amount, amount deposited, the virtual account for an order, the bank used, and the Transporters and invoices attached to it.
  • Invoicing — invoice number, totals, deposits, commission, payment status and dates, and your payment terms.
  • Payment references — the reference, order token, pay link and status returned by Selcom for each payment attempt.

We do not store full payment card numbers, PINs, or your online banking credentials. Card entry and wallet authorisation take place on the payment provider's own secured page.

2.6 Location and Telematics Data

  • The live position, speed and heading of a truck, recorded while tracking is active and attributed to that truck, its driver and its Transporter.
  • Movement status — loading, in transit, delivered, delayed.
  • Pickup, drop-off and transit coordinates for the loads you book.

Position is transmitted only from a driver or agent session our server has confirmed is authorised for that truck. We do not collect background location from anyone's personal device.

2.7 Tracking, Documents and User Content

  • Proof of delivery and lorry receipt records generated for an order, reachable by anyone holding that order's unguessable tracking token.
  • Uploaded User Content, including documents attached to an order.
  • Third-party payloads — order and quotation messages received from connected business systems, kept so we can evidence what was instructed and reconcile it later.

2.8 Technical, Device and Usage Data

IP address; device, browser, operating system, language and time zone; the pages and actions you use; sign-in and session events; API request logs; and diagnostic records of failed integration calls.

2.9 Notification Data

In-app notifications. For every SMS we send: the recipient's name, role, mobile number, the full message text, the channel, the provider's message reference, delivery status and any error. Email confirmations and receipts are retained in the mailbox we send from.

2.10 Activity and Audit Data

Who acted, their role, what they did, which records were affected, any amount involved, and the IP address the action came from. Free-text remarks in these records may contain the names and email addresses of the people involved.

2.11 Communications Data

Email and SMS correspondence with us, support requests, feedback on a delivery, and your marketing preferences.


3. How We Collect Information

3.1 Directly from you — when you register, complete your profile, submit verification documents, post a tender or book a load, upload documents, request a quote, make or receive a payment, use a public tracking page, or contact support.

3.2 From your device during a trip — position, speed and heading, sent by the driver or agent application while signed in to an authorised session. This is tied to a truck rather than to a person browsing the site, which is why §2.6 treats it as telematics rather than personal location history.

3.3 From other users — a Cargo Owner may give us your name, phone number, address and document requirements as consignee or site contact; a driver may give us a vehicle's registration card; an agent may give us a driver's licence number. We rely on you having authority to supply it.

3.4 From partner systems and public sources — order and quotation confirmations from connected business systems, and business registration details from public registries.

3.5 Automatically — IP address, device and browser details, session and API logs, and integration diagnostics, as you use the Platform.

3.6 Limits on collection. Consistent with the Terms, you may not collect information from the Services — about other users, or about products and services available through them — by automated tools or manually on a mass basis, nor access the Services to monitor availability, performance or functionality, or for benchmarking or competitive purposes. Beyond being a contractual restriction, this protects every other user: mass harvesting is what turns a transport directory into a spam list. We enforce it with rate limits, request logging and the access controls in §10. If you need Platform data in bulk, ask us and we will provide it properly.


4. Legal Bases for Processing

Basis When we rely on it
Performance of a contract Registering you; verifying you, a driver, a Transporter or a vehicle; matching loads to trucks; dispatching, tracking and documenting shipments; quotations, orders and invoices; escrow; and paying Transporters, drivers, agents and staff.
Compliance with a legal obligation Tax and VAT records, invoices and payment history; customs and cross-border documentation; employment and payroll records; and disclosure required by a court, regulator or law.
Legitimate interests Fraud and abuse prevention; securing the Platform; auditing activity; resolving delivery disputes; improving routing and the driver experience; keeping vehicle and Transporter records; and operational notifications. We balance these against your rights and do not proceed where the effect on you would be undue.
Consent Marketing communications; optional health or accessibility notes for a delivery; and any sensitive-data processing not otherwise required to complete a booking. Withdrawable at any time — §12.
Vital interests or public interest Rarely, to prevent serious harm or comply with an official order.

For sensitive data (§2.3, and live position in §2.6) we rely on your explicit consent, on the necessity of establishing, exercising or defending a legal claim, on employment and social-security obligations, or on another basis the law permits — never on consent alone where the law says consent is not sufficient.


5. How We Use Your Personal Data

Purpose Data used Basis
Create and administer your account; let you sign in. Identity, Contact, Technical Contract
Verify you, a driver, a Transporter or a vehicle before it carries freight. Verification, Contact Contract; Legal obligation
Post and match cargo tenders to available trucks. Shipment, Contact, Identity Contract
Dispatch, monitor and document a shipment, including proof of delivery. Shipment, Location, Content, Technical Contract
Track a truck in transit and report progress to the parties on the order. Location, Verification, Shipment Contract; Legitimate interests
Raise quotations, orders, invoices and credit notes. Identity, Shipment, Financial Contract; Legal obligation
Hold funds in escrow, release them on satisfaction, and reconcile. Financial, Contact Contract
Take payment; pay Transporters, drivers, agents and staff. Financial, Contact, Verification Contract; Legal obligation
Meet tax, VAT, customs, employment and record-keeping requirements. Identity, Financial, Transaction Legal obligation
Send operational alerts about shipments, payments and your account. Contact, Shipment, Notification Contract; Legitimate interests
Send marketing or service updates where you asked, or the law allows. Contact, Communications Consent; Legitimate interests
Answer enquiries, support requests and complaints. All relevant to the enquiry Contract; Legitimate interests
Prevent fraud and abuse, enforce the Terms, investigate disputes. All categories, including Technical Legitimate interests; Legal obligation
Secure, maintain, test and improve the Platform. Technical, Usage Legitimate interests
Keep an audit trail of actions on the Platform. Activity, Identity, Technical Legitimate interests; Legal obligation

New purposes. We use personal data only for the purpose it was collected, unless the new purpose is compatible with it or we have a lawful basis. Where we need consent for something new, we ask first.


6. How We Share Your Personal Data

We do not sell your personal data. We share it only as follows.

Recipient What is shared Why When
Other users on the same order — Cargo Owner, agent, awarded Transporter, assigned driver Shipment details, contact names, addresses, status, live position in transit Each is party to the same logistics service Order open or in transit
Selcom (payment processing) Name, email, mobile or bank account, amount, payment reference Process and disburse payments, by bank transfer and mobile money A payment or payout is initiated
SMS providers — Africa's Talking, Twilio, Beem Africa, SMSC Africa Mobile number and message text Deliver operational and payment SMS An SMS is sent to you
Email providers — our SMTP service and any inbound mailbox we read Email address and message content Send confirmations, receipts and notices; receive order confirmations A message is sent or received
Mapping and routing providers — map tile and geocoding suppliers, and OSRM routing Coordinates, place names, and the text you type into a search box Draw and geocode maps; calculate routes You open a map, search, or view a route
Connected business systems (for example an Odoo instance) Order, cargo, route, quantity, date, currency and payment-term fields needed to raise an order. We do not send identity documents or national ID numbers to these systems. Raise and confirm orders you instructed An order is created or confirmed
Google — only if you choose Google sign-in Your Google email, name, profile picture, email verification status Authenticate your account You sign in with Google
Hosting and storage providers All Platform data, including uploaded documents Run the Platform and store your files Continuously
Advisers, auditors, insurers Relevant records Advice, verification of accounts, insurance As needed
A buyer or successor Relevant records Continue the business in a reorganisation, merger or sale Only on such a transaction
Law enforcement, regulators, courts As legally required Comply with a court order, regulation or legal process On legal process

Every recipient must protect your data and process it only for the stated purpose. Service providers act on our instructions under written data processing terms and may not use your data for their own purposes.

6.1 Onward disclosure by recipients. Once shipment details go to the other users on that order, or payment details go to Selcom, those recipients act as independent controllers of that data for their own purposes. Their handling is governed by their own policies and we do not control it. Please choose what you share accordingly.

6.2 Selling. We do not sell your personal data, and we do not share it for others' direct marketing.

6.3 Aggregated data. We may publish counts and trends — for example the number of loads posted by region — only where the data is aggregated so that it does not identify you or your business.

6.4 Third-party websites and applications. The Platform may link to third-party sites and applications. We do not control them and we are not responsible for their content, security or privacy statements. Please read the privacy policy of every site and application you visit, whether reached from within our website or mobile application or not. Where a third party collects data through a widget or button we embed — a map, a payment page, a sign-in — that third party's own policy applies from the moment you use it, in addition to this Policy.


7. Public Pages, Tracking Links and Aliasing

Some parts of the Platform are readable without an account. They are designed to expose the least identifying information possible, and it is important that you understand them.

7.1 Shipment tracking. A tracking page is reachable by its tracking token — a long random reference created for that order. It shows the shipment's status and route, and the generated lorry receipt or proof of delivery, including the driver name and mobile number recorded on that document. Anyone holding the link can read it, so treat it as confidential and do not publish it. If a document should not be visible, ask us to reissue the link.

7.2 Maps. The map and geocoding pages are open to visitors. They display order and town locations, and a customer name may appear as a label on an order. Vehicle positions are shown as fleet labels rather than as named individuals.

7.3 Aliasing before payment. Until an order is paid, Transporters, trucks and orders are shown to other users under a rotating alias rather than their real name or plate, and real names are revealed only once payment is confirmed. This limits what a party can learn about a competing or unrelated party before a contract exists.

7.4 Tender references. Cargo Owners see a daily-rotating reference for a transport offer in place of the Transporter's identity until an award is made.

We review what each public page exposes. If you believe one is showing more about you or your business than it should, contact us and we will restrict it.


8. International Transfers

Your data is primarily processed in Tanzania. Logistics routes cross borders and some suppliers process data outside Tanzania — for example a global map or email provider, or a payment or SMS provider operating regionally — so a limited amount of your data may be processed elsewhere.

Where that happens we rely on an appropriate transfer safeguard, such as standard contractual clauses or another lawful mechanism, together with encryption in transit, and restrict the transferred data to what the service genuinely requires. Contact us for the safeguard applicable to a particular transfer.


9. Retention and Deletion

We keep personal data only as long as §5 requires, and for as long as the law requires.

Data Retention
Account and profile data Life of the account, then [confirm — period] before deletion or anonymisation
Verification and identity documents Life of the account, plus the period needed to evidence that verification was properly performed
Tenders, orders, shipments, proof of delivery Life of the order, retained afterwards as the operational and dispute record
Invoices, payments, escrow, payroll As required by tax, VAT, accounting and employment law — [confirm — commonly at least 5–7 years]
Live position data [confirm — currently kept for the life of the tracking record; a short fixed window is recommended]
SMS records, activity logs, API logs, diagnostics [confirm — currently kept indefinitely; a defined period such as 12–24 months is recommended]
One-time sign-in codes The validity period of the code. The code is never stored in readable form — only a hash with a salt

9.1 Current limitation. [confirm — the Platform does not yet apply automatic time limits to position data, activity logs, API diagnostics, SMS records or one-time sign-in codes. Until that exists, these are kept until the record or the account is deleted, and account deletion is actioned on request. Adopt a defined schedule before publishing.]

9.2 Deletion and anonymisation. When data is no longer needed we delete it or anonymise it so it can no longer identify you.

9.3 On termination. The Terms let us suspend or discontinue services, and terminate your account, with or without notice. Where we terminate an account we delete or anonymise your personal data, except where tax, employment, customs or dispute obligations require us to keep it — in which case we keep it only for that purpose and tell you. Our no-liability commitment in the Terms for suspension or discontinuance does not extend to retaining your data indefinitely against your wishes where the law requires us to delete it.

9.4 Accuracy. It is very important that the personal data we hold about you is accurate and current. Please keep us informed of any change during your relationship with us. Inaccurate verification data can prevent a load from being released.


10. Security

10.1 Measures We Apply

  • Encryption in transit over HTTPS/TLS, with encrypted database connections.
  • Role-based access control. Users see only records their role permits. Administrators and operations staff hold broader access than Cargo Owners, agents, Transporters or drivers, and administrative actions are written to an audit log.
  • Strong sign-in. Passwords are stored as salted one-way hashes. One-time codes are stored hashed with a salt, an expiry and an attempt limit. Sign-in can be verified by second factor or by Google. Accounts and API access use expiring tokens with per-endpoint authentication.
  • Protected credentials. Payment, SMS, email, map and partner-system secrets are held in a restricted configuration area, are never written to application logs, and are not exposed in source code.
  • Integrity controls. Records created through an integration are locked against silent alteration. Payment, invoice and payout references are kept permanently as an audit trail against disputes.
  • Monitoring and testing. We monitor access and integration failures and test our systems regularly.

10.2 No Absolute Security

No method of transmission or storage is completely secure. As the Terms state, we make no warranty, express, implied or otherwise, that we will prevent every unauthorised access to your private information or User Content, and we are not responsible for the acts of third parties who gain such access.

10.3 Known Limitations to Remediate

[confirm — a Policy must not promise protection the Platform does not yet provide. Close these before publishing:

  • Uploaded documents are served from public object storage. Identity documents, vehicle registration cards and generated lorry receipts and proofs of delivery are served without signed, expiring, access-controlled links. Serve them only through short-lived authorised URLs. This is the most serious item in this Policy.
  • Several public map, geocode and route endpoints require no authentication, and one exposes a customer name despite its own documentation saying otherwise. Require authentication or remove the field.
  • One live-fleet code path collects real GPS positions for public output. Remove it or gate it behind authorisation.
  • Temporary passwords for staff and agents are emailed in readable form. Replace with a one-time password-reset link.
  • The application runs with debug mode enabled, a hard-coded secret key, and unrestricted cross-origin requests. Disable these in production and rotate the key. Note that daily aliasing (§7.3, §7.4) is derived from that key, so rotating it changes previously issued aliases.
  • Identity document uploads are not validated by file type or size, unlike registration card uploads. Apply the same checks.

10.4 Breach Notification

We have procedures to detect, contain and investigate a suspected personal data breach. Where a breach is likely to result in a risk to your rights and freedoms, we will notify you and the competent authority within the time required by law, and tell you what we know and what we are doing about it.


11. Your Rights

Subject to the Tanzania Data Protection Act, 2022 and any other law applying to you, you may:

Right What it means
Be informed Be told why we process your data and on what basis. This Policy is our answer.
Access Get a copy of the personal data we hold about you and what we do with it.
Rectification Have inaccurate or incomplete data corrected or completed.
Erasure Ask us to delete your data where there is no overriding reason to keep it.
Restriction Ask us to limit how we use your data while a dispute or investigation is resolved.
Object Object to processing based on legitimate interests, and to direct marketing at any time.
Portability Receive your data in a structured, commonly used, machine-readable format, or have it sent to another provider.
Withdraw consent Withdraw consent at any time where we rely on it, without affecting processing already carried out.
Human review Ask for human review of an automated decision that significantly affects you.
Complain Lodge a complaint with the competent supervisory authority.

How to exercise a right. Email privacy@hypax.co.tz with the subject "Data rights request". Say which right you want and how to identify your account or order. We may ask you to confirm your identity first.

Limits. Some rights are limited where a legal, tax, employment or dispute obligation requires us to keep the data, or where the record belongs to another party — for example a consignee's details, which we hold for the Cargo Owner who instructed the load. We aim to respond within the time the law allows and do not charge unless a request is manifestly unfounded or excessive.

Where the data came from elsewhere. If your data came from a Cargo Owner, Transporter or partner system, tell us and we will point you to them for anything we cannot change ourselves.


12. Consent and Marketing

Where we rely on consent, you may withdraw it at any time by emailing privacy@hypax.co.tz or using the unsubscribe link in any marketing message. Withdrawal does not affect processing carried out before it, and it does not affect processing we rely on for another basis — you can still use the Platform.

Marketing is sent only where you have asked for it or the law otherwise allows, every message carries an unsubscribe route, and we do not sell or share your contact details for anyone else's marketing.


13. Automated Decision-Making

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on you. Prices, route matching, Transporter allocation and payment status follow contractual rates, stated rules and human review, and are not derived from a model that evaluates you. We may use rules to flag transactions or accounts for human review, but a person decides the outcome, and you may ask for that review.


14. What We Ask of You

The Terms set out your general obligations as a user. This section covers only the ones that affect your personal data.

14.1 Keep your data accurate. Keep your identity, contact, verification, vehicle and business records current, and tell us of any change — see §9.4. An out-of-date licence or registration card can prevent a vehicle being released, and out-of-date contact details mean operational and payment messages never reach you.

14.2 Submit only what you have the right to submit. By posting a tender, awarding an order, or uploading documents, you confirm the information is accurate, that you have authority to supply it, and that you hold the rights needed for us to process and share it. Do not submit another person's personal data unless the law allows it and you have their authority. Where a load requires a contact or consignee, provide only the details genuinely needed for the carriage.

14.3 Keep your credentials secure. Enable every verification factor available, do not share one-time sign-in codes, and tell us immediately if you suspect your account has been compromised. Credential security, and our position on liability if a third party interferes with your credentials, are dealt with in the Terms — we state them only here because the subject is your account data.

14.4 We can hold data back. Where an order is unpaid, we withhold a party's names, documents and commercial details until payment is confirmed. This protects you as well as the payee.


15. Cookies and Similar Technologies

The Platform relies on a small number of strictly necessary technologies: a session cookie that keeps you signed in, a cookie protecting forms against cross-site request forgery, and — in the mobile and driver applications — a token held in the device's local storage. These are not advertising or analytics cookies.

We run no third-party advertising and no cross-site tracking. Map, payment and sign-in providers set their own cookies or process data when you use their widgets, and their policies apply from that point.

If you block or restrict cookies, sign-in and session-dependent features will not work. The rest of the Platform remains available.


16. Children's Data

The Platform is a business service, is not intended for children, and the Terms require you to be 18 or older. We do not knowingly collect data relating to children, with or without parental consent.

Where a load requires a person under 18 to be present at a site, that is a matter for the Cargo Owner and the Transporter under the Terms — it is not a reason for us to collect that child's data. If you believe a child has provided us with personal data, contact privacy@hypax.co.tz and we will delete it.


17. Changes to This Policy and How to Reach Us

17.1 Review and Notification

This Policy is reviewed regularly, and any change to the Platform prompts a review. When we update it we will change the "Last updated" date and post the updated Policy on our website and in the mobile applications. For material changes we will also notify registered users by email or in the Platform, and by a notice at sign-in. Previous versions are available on request.

By continuing to use the applications after being notified of a change, you accept the updated Policy.

17.2 Contact, Complaints and Enforcement

HYPAX — Data Protection / Privacy Team Email: privacy@hypax.co.tz · Data Protection Officer: dpo@hypax.co.tz Postal address: [registered address] · Telephone: [telephone] Website: https://hypax.co.tz

We will acknowledge your request, investigate it, and respond as promptly as we can, telling you if we need more information.

If you are not satisfied with our response, you may complain to the competent data protection authority where you live or work, including the Tanzania Data Protection Commissioner where processing takes place in Tanzania. We would rather you come to us first, but you are not required to.

17.3 Framework

This Policy gives effect to the Tanzania Data Protection Act, 2022 and its regulations. Where we operate under other data protection law — for example the GDPR or UK GDPR for users in the EEA or UK — that law also applies. [confirm — state the additional regimes, the lead supervisory authority, and any representative or adequacy position for users outside Tanzania.]


Appendix A — Quick Reference

Question Answer
Who is the controller? HYPAX, operator of the Platform — [legal entity and registration number].
What data do you collect? Identity, contact, verification, shipment, financial, location, content, technical, notification, audit and communications data — §2.
Do you collect ID documents? Yes — ID type, number, and for individual owners a copy of the document — §2.3.
Do you track vehicles? Yes — position, speed and heading during a trip, tied to the truck, driver and Transporter — §2.6.
What are the legal bases? Contract, legal obligation, legitimate interests, and consent where required — §4.
Who do you share data with? Users on the same order; Selcom; SMS, email, map and routing providers; connected business systems; our host; and authorities — §6.
Do you sell my data? No — §6.2.
Can a stranger see my load? Only someone holding its tracking token; the order is aliased until payment is confirmed — §7.
Can I be bulk-scraped? No — and the Terms prohibit you from trying — §3.6.
Do you send data abroad? Yes, limited data, for maps, email and payments — §8.
How long do you keep data? Only as needed, plus statutory periods; see the table and the flagged gap — §9.
How do you protect data? Encryption, role-based access, hashed passwords and codes, secret management, audit logging — §10.
What are my rights? Access, information, rectification, erasure, restriction, objection, portability, withdrawal of consent, human review, complaint — §11.
Can I use it without cookies? Partly — sign-in and sessions need them — §15.
Do you handle children's data? No; the service is 18+ — §16.
How do I complain? privacy@hypax.co.tz, then the competent supervisory authority — §17.2.
© 2026 HYPAX Cargo Logistic and Transportation system
Install the HYPAX app

Get faster access to tenders, orders and live tracking from your home screen or desktop.