Swiftline® Privacy Policy

How we collect, use and protect personal data

For websites, client portals, business accounts, mobile applications, shipment systems and logistics services.

Effective date
1 February 2025
Last updated
27 July 2026
Policy owner
Swiftline- Data Protection & Compliance
Applies to
Swiftline Cargo Ltd® and Swiftline Cargo & Express Logistics Private Limited

Privacy at Swiftline

Swiftline recognises that trust is essential to every shipment and every digital interaction. We process personal data responsibly, transparently and securely, and only for legitimate business, contractual, operational, security and legal purposes.

This Privacy Policy explains what information we collect, why we use it, how it may be shared, how long it is retained, the safeguards we apply and the rights available to individuals under applicable data-protection laws.

Purpose

We use data only for clear and lawful purposes.

Security

We apply proportionate technical and organisational safeguards.

Choice

We respect applicable rights and communication preferences.

Accountability

We document, review and improve our privacy practices.

1. About this Policy

This Privacy Policy describes how Swiftline Cargo Ltd® and Swiftline Cargo & Express Logistics Private Limited (together, “Swiftline”, “we”, “us” or “our”) collect, use, disclose, transfer, store and protect personal data. It applies whenever an individual or organisation visits our websites, creates or uses an account, accesses a customer or business portal, uses a mobile or desktop application, books or manages a shipment, receives a delivery, contacts us, works with us as a service partner, or otherwise interacts with our services.

This Policy should be read together with our Terms and Conditions, Cookie Policy, Prohibited and Restricted Goods Policy, service-specific notices, contractual terms and any other privacy notice provided at the point personal data is collected.

Where local law provides stronger rights or protections than this Policy, the applicable local law will prevail.

2. Swiftline entities and responsibility

The Swiftline entity responsible for personal data depends on the service, location, contract and operational role involved.

United Kingdom

Swiftline Cargo Ltd® provides and supports courier, cargo, freight, customs, fulfilment, collection, delivery and related logistics services in the United Kingdom and internationally.

India

Swiftline Cargo & Express Logistics Private Limited provides and supports courier, cargo, freight, export, import, customs, collection, delivery, technology and related logistics services in India and internationally.

The relevant entity may act as a data controller, joint controller or processor depending on the circumstances. Swiftline entities may share data with each other where necessary to provide services, manage customer relationships, secure systems, meet legal obligations and operate the Swiftline network.

3. Scope

This Policy applies to personal data processed through:

  • Our websites and online forms;
  • Customer, business, freight-forwarder, exporter, manufacturer and partner portals;
  • Mobile, tablet, driver and delivery applications;
  • Booking, quotation, billing, payment and account systems;
  • Shipment tracking, barcode, scanning, bagging, manifesting and warehouse systems;
  • Customs-clearance, aviation-security and electronic data-interchange systems;
  • Application programming interfaces and partner integrations;
  • Email, telephone, SMS, WhatsApp, social media, chat and support channels;
  • Collection, transport, storage, screening, customs, delivery, returns and claims operations;
  • CCTV, access-control and security systems at relevant facilities.

4. Personal data we collect

4.1 Identity and contact data

  • Name, title, job role and organisation;
  • Email address, telephone number and mobile number;
  • Residential, business, collection, billing and delivery addresses;
  • Customer number, account identifier and authorised-user information;
  • Signature, photograph or image where required for proof of service;
  • Date of birth and government-issued identification where legally required;
  • Passport, tax, VAT, GST, importer/exporter, licence or registration information where required.

4.2 Account and authentication data

  • Username, encrypted password and mobile OTP verification records;
  • Account preferences, saved addresses, permissions and authorised users;
  • Login history, IP address, device identifier, browser and operating-system information;
  • Session details, security events, portal activity and audit logs;
  • Uploaded files, account communications and customer-support history.

4.3 Shipment and logistics data

  • Sender, recipient, consignee, importer, exporter and contact details;
  • Shipment description, content, declared value, insured value, weight, dimensions and piece count;
  • Country of origin, destination, route, service level and delivery instructions;
  • Tracking number, barcode, house airway bill, master airway bill, manifest, bag and pallet details;
  • Collection events, sorting events, transfer events, customs status, delivery attempts and exceptions;
  • Proof of collection, proof of delivery, signature, delivery image and location evidence;
  • Loss, damage, claim, return, prohibited-goods and investigation information.

4.4 Customs and regulatory data

  • Commercial invoices, packing lists and customs declarations;
  • Product descriptions, commodity codes and country-of-origin information;
  • Import/export licences, KYC documents and authority letters;
  • Tax, duty, sanctions, restricted-party and compliance-screening information;
  • Security declarations and documents required by airlines, airports, customs or government authorities.

4.5 Financial and transaction data

  • Billing details, invoices, account balances and payment status;
  • Bank information, transaction references, refunds, credit limits and remittance records;
  • Tax records, payment disputes and debt-recovery information;
  • Fraud-prevention signals associated with a payment or account.

Payment cards are ordinarily processed by authorised payment-service providers. Swiftline does not generally store complete card numbers or card security codes.

4.6 Technical and usage data

  • IP address, device and browser details;
  • Pages, features and services accessed;
  • Clickstream, navigation, timestamps and error reports;
  • Application performance, diagnostics and security logs;
  • Cookie, analytics and session identifiers;
  • Approximate location derived from IP address and, where authorised, precise device location.

4.7 Communications data

We may retain messages and other communications sent by email, telephone, SMS, WhatsApp, chat, web forms, social media or customer-support channels. Calls may be recorded where lawful for training, service quality, security, compliance and dispute resolution.

5. Data received about other people

Customers and business users often provide personal data about senders, recipients, consignees, employees, authorised users, suppliers and other individuals. The person or organisation providing that information must ensure that it is accurate, lawfully obtained and appropriately disclosed to Swiftline.

Customers should provide only the information reasonably required for the shipment or service and should ensure that affected individuals receive any privacy notice required by law.

6. How we collect personal data

We may collect personal data:

  • Directly from the individual;
  • From a business customer, sender, recipient, consignee, account administrator or authorised representative;
  • Through our websites, portals, applications and customer-service channels;
  • From barcode scans, delivery devices, operational personnel and warehouse systems;
  • From airlines, courier partners, customs brokers, freight forwarders, carriers and delivery providers;
  • From customs, tax, border, police, aviation and other competent authorities;
  • From banks, payment providers, identity-verification and fraud-prevention providers;
  • From public business registers and other lawful public sources;
  • Through cookies and similar technologies.

7. How and why we use personal data

7.1 Delivering logistics services

  • Providing quotations and opening customer or business accounts;
  • Booking, collecting, screening, transporting, sorting, storing and delivering shipments;
  • Generating shipping labels, barcodes, manifests and electronic shipment data;
  • Managing airline, carrier, warehouse, partner and last-mile operations;
  • Performing customs clearance and regulatory submissions;
  • Providing shipment tracking, notifications and proof of delivery;
  • Handling returns, claims, loss, damage, disputes and service exceptions.

7.2 Account and customer management

  • Verifying users and maintaining account access;
  • Managing contracts, contacts, service settings and authorised users;
  • Responding to enquiries, support requests, grievances and complaints;
  • Providing invoices, statements, operational updates and service communications;
  • Monitoring service quality and relationship performance.

7.3 Payments, billing and credit

  • Processing payments, refunds and remittances;
  • Issuing invoices and managing credit facilities;
  • Recovering outstanding sums and resolving payment disputes;
  • Maintaining tax, accounting and audit records.

7.4 Security, fraud prevention and compliance

  • Protecting customer accounts, facilities, systems and shipments;
  • Detecting fraud, suspicious activity, identity misuse and unauthorised access;
  • Screening prohibited or restricted goods and sanctioned parties;
  • Investigating incidents, claims, theft, loss, damage and misconduct;
  • Complying with customs, aviation, export-control, sanctions, tax, court and law-enforcement obligations.

7.5 Improvement and analytics

  • Improving websites, portals, applications, routes and operational processes;
  • Analysing service performance, capacity, exceptions and customer experience;
  • Diagnosing technical faults and protecting platform reliability;
  • Developing new features, products and business services;
  • Creating aggregated or anonymised business insights.

7.6 Marketing and business development

Where permitted, we may send information about Swiftline services, offers, new features and business opportunities. Individuals may opt out of promotional communications at any time. Operational, legal, security, billing and shipment messages may still be sent where necessary.

8. Lawful bases

Depending on the relevant law and circumstances, Swiftline may rely on one or more of the following legal grounds:

  • Contract— where processing is necessary to provide a quotation, create an account, book or deliver a shipment, collect payment or perform another contractual obligation;
  • Legal obligation— where processing is required by customs, tax, aviation-security, sanctions, court, police, regulatory or other legal requirements;
  • Legitimate interests— where necessary to operate and improve our services, protect shipments and systems, prevent fraud, manage customer relationships, recover debts, resolve disputes or protect legal rights, provided those interests are not overridden by individual rights;
  • Consent— where required for a specific activity, including certain marketing or device-permission functions;
  • Vital interests or public-interest grounds — in limited circumstances where permitted by law.

9. Shipment, tracking, barcode and scanning data

Swiftline may assign each shipment, parcel, bag, pallet or piece a unique barcode, tracking number or other identifier. Each operational scan may record the identifier, date, time, location, processing facility, user or operator, scanner or device, shipment status, route and exception details.

This information supports chain of custody, tracking, reconciliation, manifesting, customs, bagging, warehouse control, service quality, fraud prevention and proof of collection or delivery.

Tracking data may be made available to authorised senders, recipients, account holders, consignees and service partners. Users must not attempt to access shipment information without proper authority.

10. Customs, aviation security and government requirements

International shipments are subject to customs, border-control, aviation-security, import, export, tax, sanctions and other regulatory requirements. Swiftline may submit personal and shipment data to competent authorities before, during or after transport.

The data submitted may include identity and contact details, shipment contents, values, commodity codes, origin and destination, payment information and supporting documents. Authorities process such information under their own legal powers and privacy responsibilities.

11. Automated processing and analytics

We may use automated tools to support address validation, rate calculation, routing, fraud detection, account security, prohibited-goods checks, sanctions screening, customs-data validation, duplicate detection, shipment-risk assessment and operational prioritisation.

Where applicable law grants a right relating to solely automated decisions with significant effects, individuals may request information, express their view, challenge the outcome and request human review.

12. Sharing personal data

We may share personal data where reasonably necessary with:

  • Swiftline group companies and authorised personnel;
  • Airlines, courier companies, postal operators, freight forwarders, road carriers and delivery partners;
  • Customs brokers, warehouses, fulfilment providers and screening facilities;
  • Customs, border, tax, airport, aviation-security, regulatory, police and government authorities;
  • Banks, payment processors, credit-reference and fraud-prevention providers;
  • Cloud, hosting, software, analytics, communications and cybersecurity providers;
  • Auditors, insurers, lawyers, accountants, consultants and professional advisers;
  • Debt-recovery providers and dispute-resolution bodies;
  • Potential purchasers, investors or successors in connection with a legitimate corporate transaction.

Swiftline does not sell personal data. Service providers are expected to process personal data only for authorised purposes and to maintain appropriate confidentiality and security.

13. International data transfers

Because logistics services are international, personal data may be transferred to or accessed from countries other than the country where it was collected. This may occur when a shipment, customer, recipient, airline, partner, customs authority, data centre or service provider is located abroad.

Where required, Swiftline uses appropriate transfer safeguards, which may include contractual clauses, data-processing agreements, access controls, encryption, transfer assessments and other legally recognised mechanisms.

14. Data security

Swiftline maintains technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, access or misuse. Measures may include:

  • Encryption in transit and encryption at rest where appropriate;
  • Secure hosting, firewalls and network controls;
  • Role-based access and least-privilege permissions;
  • OTP, password controls and multi-factor authentication where available;
  • Monitoring, audit logs, backups and malware protection;
  • Vulnerability management and incident-response procedures;
  • Confidentiality commitments and staff awareness;
  • Supplier due diligence and contractual security obligations.

No internet-connected system can be guaranteed to be completely secure. Customers must protect passwords, OTPs, devices and account credentials and notify Swiftline promptly of suspected unauthorised activity.

15. Personal data breaches

If Swiftline becomes aware of a personal data breach, we will assess its nature, scope, likely impact and risk. We may take steps to contain the incident, secure affected systems, investigate the cause, recover information and prevent recurrence.

Where legally required, we will notify the relevant supervisory authority and affected individuals within the applicable period.

16. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy and to meet contractual, customs, aviation, tax, accounting, insurance, security, legal-claim and regulatory requirements.

Retention periods differ according to the type of data, service, legal obligation, limitation period, active claim, fraud risk or investigation. When data is no longer required, it may be securely deleted, anonymised or archived in accordance with applicable law and our retention procedures.

17. Cookies and similar technologies

Our websites, portals and applications may use cookies, local storage, pixels and similar technologies to authenticate users, maintain secure sessions, remember preferences, prevent fraud, measure usage, diagnose errors and improve performance.

Users can manage cookies through browser or device settings. Disabling essential cookies may prevent certain services from functioning correctly. Where required, non-essential cookies will be used only after appropriate consent.

18. Location data

Swiftline may process location information to arrange collections, validate addresses, plan routes, confirm delivery, display shipment progress, protect drivers and shipments, and investigate service disputes.

Precise device location will be accessed only where necessary, permitted by law and authorised through the relevant device or application permission.

19. CCTV and premises security

Swiftline facilities, offices, warehouses and operational areas may use CCTV, access-control or other security systems for safety, crime prevention, shipment protection, access management, incident investigation and protection of people and property.

Recordings are retained for an appropriate period unless required for an investigation, legal claim, insurance matter or regulatory purpose.

20. Marketing communications

Where lawful, Swiftline may use business contact details to communicate service information, offers, product updates and other relevant business material. Recipients can unsubscribe using the option provided in the message or by contacting us.

Opting out of marketing does not stop essential shipment, customs, account, security, billing, service interruption or contractual communications.

21. Children’s data

Swiftline services are primarily intended for businesses and adults capable of entering legally binding transactions. Children should not independently create commercial shipping accounts.

Where personal data relating to a child is genuinely required for a lawful shipment, customs process or delivery, it must be supplied by an authorised parent, guardian or responsible organisation and will be used only for the relevant lawful purpose.

22. Customer and portal-user responsibilities

Customers, account administrators and portal users must:

  • Provide accurate, current and lawful information;
  • Ensure they have authority to provide personal data relating to other individuals;
  • Protect usernames, passwords, OTPs and devices;
  • Use Swiftline systems only for authorised and lawful purposes;
  • Avoid uploading unnecessary sensitive or confidential information;
  • Comply with customs, sanctions, prohibited-goods and shipping requirements;
  • Notify Swiftline promptly of unauthorised access or incorrect data;
  • Ensure authorised users follow applicable terms and privacy requirements.

23. Individual rights

Subject to applicable law and relevant exemptions, individuals may have the right to:

  • Request confirmation of whether Swiftline processes their personal data;
  • Request access to personal data;
  • Request correction of inaccurate or incomplete information;
  • Request deletion or erasure;
  • Request restriction of processing;
  • Object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Request portability of eligible data;
  • Opt out of direct marketing;
  • Request information about significant automated decisions and seek human review;
  • Nominate another person to exercise rights where permitted;
  • Raise a grievance or complain to a competent authority.

Some requests may be limited where Swiftline must retain or process information for customs, tax, security, fraud prevention, legal claims, regulatory duties or the rights of others. We may request proof of identity or authority before acting on a request.

24. Grievances and complaints

24.1 Grievance Officer

NameRavi Yadav
DesignationDirector and Grievance Officer
Telephone / WhatsApp+91 98177 17689

A privacy request or grievance should include the individual’s full name, registered contact details, relevant account or shipment reference, a clear description of the issue and any information reasonably required to verify identity and investigate the matter.

Swiftline will acknowledge, assess and respond within the period required by applicable law. Complex matters, identity checks, active legal claims, customs investigations or regulatory restrictions may require additional time.

24.2 Complaints to authorities

Individuals may also have the right to complain to the competent data-protection authority. For processing in the United Kingdom, this may include the Information Commissioner’s Office. For processing in India, this may include the authority or Data Protection Board having jurisdiction under applicable law.

We encourage individuals to contact the Grievance Officer first so that Swiftline has an opportunity to investigate and resolve the concern promptly.

26. Changes to this Policy

Swiftline may update this Policy to reflect changes in law, regulatory guidance, technology, services, security measures or business operations. The revised version will be published with an updated “Last updated” date.

Where a change materially affects how personal data is processed, Swiftline may provide additional notice through the website, portal, application, email or another appropriate channel.

27. Contact details

Swiftline Cargo Ltd®

Swiftline Cargo & Express Logistics Private Limited