SendSimply

Privacy Policy

This Privacy Policy explains how SendSimply collects, uses, stores, and shares your personal information. It applies to all users of our platform, including customers, merchants, and couriers. We are committed to handling your data responsibly and in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

SendSimply is the data controller for the personal information you provide when using our platform. We are based in Colchester, Essex, United Kingdom. If you have any queries about how we handle your data, please contact our Data Protection Lead at privacy@sendsimply.co.uk.

2. Information We Collect

2.1 Information You Give Us

  • Full name, email address, phone number, and date of birth.
  • Delivery and collection addresses.
  • Account login credentials (passwords are stored in encrypted form and never readable by us).
  • Payment details (processed and stored securely by our payment provider — we do not hold card numbers).
  • Package descriptions, photographs, and declared values.
  • Communications you send us via support channels.

2.2 Information We Collect Automatically

  • Device type, operating system, and browser.
  • IP address and approximate location at the time of login or order placement.
  • App usage data: pages visited, features used, time spent.
  • Order history, delivery preferences, and rating/review data.
  • Cookies and similar tracking technologies (see Section 7).

2.3 Information from Third Parties

  • Address verification data from mapping providers (Google Maps).
  • Payment status confirmations from our payment processor (Stripe).
  • Identity verification data where required by law.

3. How & Why We Use Your Information

We process your data under the following legal bases:

Contract Performance

  • To create and manage your account.
  • To process, route, and complete delivery orders.
  • To communicate order status, tracking updates, and confirmations.
  • To process payments and issue refunds.

Legitimate Interests

  • To detect and prevent fraud, abuse, and security incidents.
  • To improve our platform, pricing models, and service quality.
  • To analyse usage patterns and develop new features.
  • To manage and respond to complaints and disputes.

Legal Obligation

  • To comply with applicable tax, financial reporting, and regulatory requirements.
  • To respond to lawful requests from law enforcement or regulatory bodies.

Consent

  • To send marketing emails, SMS, or push notifications (only where you have opted in).
  • To process optional SMS delivery notifications.
  • You may withdraw consent at any time — see Section 8.

4. Sharing Your Information

We do not sell your personal data. We share it only as necessary:

  • Couriers — your name, phone number, and delivery address are shared with the assigned courier to complete your order. They are contractually bound to use this data only for delivery purposes.
  • Payment processors — Stripe processes payment data under their own privacy policy and PCI-DSS standards.
  • Mapping providers — address and route data is shared with Google Maps for geocoding and navigation.
  • SMS providers — your phone number is shared with ClickSend solely to deliver order status notifications, where you have opted in.
  • Analytics — aggregated, anonymised usage data may be analysed internally or by trusted analytics partners.
  • Legal authorities — we will disclose information where required by law, court order, or regulatory request.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to equivalent protections.

5. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

  • Active account data: retained for the lifetime of your account plus 12 months after closure.
  • Order and transaction records: retained for 7 years to comply with financial and tax obligations.
  • Support correspondence: retained for 3 years.
  • Marketing consent records: retained for the period of consent plus 12 months.
  • Anonymised analytics data: may be retained indefinitely as it cannot identify you.

When data is no longer required, it is securely deleted or anonymised.

6. Data Security

We take the security of your personal data seriously. Our measures include:

  • All data in transit is encrypted using TLS (HTTPS).
  • Passwords are hashed using bcrypt — we cannot read your password.
  • API keys and sensitive credentials are hashed and salted before storage.
  • Database access is restricted to authorised personnel only.
  • We conduct regular reviews of our security practices.
  • In the event of a data breach that poses a risk to your rights, we will notify you and the ICO within 72 hours as required by UK GDPR.

7. Cookies & Tracking

What We Use

We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how our platform is used. We do not use third-party advertising cookies.

Types of Cookies

  • Essential cookies — required for the platform to function (login sessions, security tokens). Cannot be disabled.
  • Preference cookies — store your settings such as language and notification preferences.
  • Analytics cookies — anonymous data about how pages are used, to help us improve the service.

You can manage cookies through your browser settings. Disabling essential cookies will prevent you from logging in.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure (‘right to be forgotten’) — request deletion of your data, subject to legal retention obligations.
  • Right to restriction — ask us to limit how we process your data in certain circumstances.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — withdraw marketing consent at any time without affecting prior processing.
  • Rights related to automated decision-making — we do not make solely automated decisions that have significant legal effects on you.

To exercise any of these rights, email us at privacy@sendsimply.co.uk. We will respond within one calendar month. We may ask you to verify your identity before processing your request.

9. International Transfers

Some of our service providers (such as our payment processor and mapping provider) may process data in countries outside the UK. Where this occurs, we ensure appropriate safeguards are in place — such as the UK International Data Transfer Agreement or UK adequacy decisions — to protect your data to the same standard as within the UK.

10. Children's Privacy

Our platform is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us immediately and we will delete it.

11. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at privacy@sendsimply.co.uk. If you remain dissatisfied, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

Website: ico.org.uk
Phone: 0303 123 1113

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or in-app notice at least 14 days before the changes take effect. The date at the top of this page will always reflect the most recent revision.

13. Contact

Data Protection Lead
privacy@sendsimply.co.uk
SendSimply, Colchester, Essex, United Kingdom

Read the Terms of Service.