Privacy Policy
Effective 1 September 2026.
Information we collect
We collect information you provide when you create an account or place an order, including your name, phone number, email address, delivery addresses, order details and payment-related information.
How we use information
We use this information to operate ZipCart, process and deliver orders, communicate about orders and accounts, improve the service, prevent misuse, and send promotional communications when you have consented to them.
Location data
For customers, ZipCart uses delivery addresses and may request device location to help select an address, determine delivery coverage and estimate delivery times. It is not shared with third parties for advertising.
For drivers, ZipCart receives location while location sharing is enabled for delivery work. The latest position is stored in ZipCart's database and mirrored to Firebase. During an active delivery, the assigned customer's app can display that live position. It is also used for dispatch and operational maps. ZipCart does not build a route-history trail: it keeps the latest position, and clears that position and the live-map entry when the driver goes offline and has no active assignment.
Delivery-proof photographs
A driver may take a photograph as evidence of a delivery attempt or completed delivery. ZipCart stores these photographs in private Cloudflare R2 storage and gives authorised order, vendor and operational views time-limited access. The configured retention period is 90 days from the delivery or attempt; the retention worker deletes the stored object before removing its database references.
Who receives data
We do not sell personal data. We share only what is needed to provide and protect the service. Providers used by the platform include:
- Stripe for payment processing;
- Clerk for identity, sign-in sessions and account management;
- Twilio for SMS and WhatsApp one-time passcodes;
- Google for sign-in, address and map services, and Android notification transport;
- Firebase for the assigned driver's live delivery position;
- Algolia for product search;
- Expo for push-notification delivery;
- Cloudflare for image and file storage and delivery;
- Sentry for error and performance diagnostics;
- Resend for transactional email;
- Neon for hosted database services;
- Shopify when an order comes from a connected merchant store; and
- Anthropic for product and supplier catalogue assistance, without customer account or order data.
We also share delivery details with the driver assigned to the order.
Retention and your rights
Account information is retained while an account is active. Order history is retained for accounting and customer-service purposes. The specific delivery-proof period is stated above. You may ask to access, correct or delete your personal data; legal and operational retention requirements may limit what can be deleted immediately.
Contact
For privacy questions or requests, email privacy@fastcommerce.app.