Privacy policy
Last updated 2026-01-01. What we collect, why, how long we keep it, and what we will never do with it.
Written against a bill that is not yet law
Pakistan’s Personal Data Protection Bill has not been enacted. This policy is written to meet its draft requirements because they are the clearest standard available, and because the commitments below describe what our systems actually do. It will be updated when the law is passed.Who is responsible for your data
Quick Courier Services, operated by Gloging Pvt Ltd of Lahore, Pakistan, is responsible for the personal data described here. You can reach us at hello@gloging.com.
Where a merchant passes us recipient details in order for us to deliver a parcel, that merchant decides what is collected and we process it on their instruction and for that purpose only.
What we collect, and why
| Data | Purpose | Source |
|---|---|---|
| Recipient name, mobile number and address | To deliver the parcel and to let the rider contact the recipient on the day | The merchant who booked the parcel |
| Parcel location and delivery timestamps | To provide tracking, to measure our own performance and to resolve disputes | Our riders and hub scanners |
| Proof of delivery: a photograph, a signature, or the name of who received it | To evidence that delivery occurred, which protects both the merchant and the recipient | The rider at the point of delivery |
| Amount of cash collected | To account to the merchant for money collected on their behalf | The rider at the doorstep |
| Merchant contact details, CNIC or NTN, and bank account details | To verify who we are carrying for, to comply with our tax obligations, and to remit money owed | The merchant during onboarding |
| Rider CNIC, licence details and location while on shift | To verify identity, to meet our duty of care, and to dispatch and sequence work | The rider, and the rider app during a shift |
Rider location, specifically
The rider app records location while a shift is open, and stops when the shift is closed. It is used to assign work, to sequence a route, to give a recipient an accurate arrival window, and to establish where a delivery was marked complete.
It is not used to monitor a rider outside working hours. A rider can see their own location history; no rider can see another rider’s.
What we do not do
- We do not sell personal data, to anyone, in any circumstances.
- We do not use recipient mobile numbers for our own marketing. A recipient hears from us only about the parcel being delivered.
- We do not share a merchant’s customer list with another merchant, and row-level security in our database enforces that rather than relying on our code being careful.
- We do not use recipient data to build profiles or to make automated decisions about individuals.
How long we keep it
| Data | Retention | Reason |
|---|---|---|
| Parcel records and status history | Seven years | Tax and accounting obligations |
| Proof of delivery photographs | One year | Long enough for any realistic dispute |
| Rider location traces | Ninety days | Operational review and dispute resolution |
| Financial ledger records | Seven years, never deleted or altered | Statutory retention; the ledger is append-only by design |
| Recipient contact details | Two years after the last parcel | To handle a late claim or a repeat delivery |
| Audit log of who did what | Seven years, append-only | Accountability for every override and manual change |
How we protect it
- CNIC numbers, bank account numbers and IBANs are encrypted with AES-256-GCM in our application before they reach the database, so a stolen database backup contains ciphertext rather than identity documents.
- Every connection to our services is encrypted in transit with TLS.
- Database access is restricted by row-level security, so a query for one merchant cannot return another merchant’s rows even if the application code contains a mistake.
- Backups are encrypted and the ability to restore them is tested, not assumed.
- Passwords are stored as argon2id hashes, which cannot be reversed.
- Every administrative action is recorded in an append-only audit log that cannot be edited, including by us.
Messages we send
A recipient receives messages about the parcel being delivered to them: collected, out for delivery, delivered, or a failed attempt. These are transactional and necessary to the delivery.
Promotional messages are separate, require consent, and can be stopped by replying STOP. We keep a do-not-contact register and check it before any promotional send. Transactional delivery notifications continue regardless, because a recipient who has opted out of marketing still needs to know their parcel is arriving.
Your rights
You may ask us what personal data we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Write to hello@gloging.com and we will respond within thirty days.
Where you are a recipient rather than our merchant, we may need to direct part of your request to the merchant who booked the parcel, because they decided what was collected. We will tell you who that is.
Some data cannot be deleted on request: financial ledger entries and the audit trail are required for statutory retention and are append-only by design. We will explain what is being kept and why.
Who else sees it
Our own staff and riders, limited to what their role requires. A rider sees the parcels on their own run sheet and nothing else.
The merchant who booked the parcel, for their own parcels only.
Our infrastructure provider, which hosts our servers in Mumbai, India. Data is stored there because it is the nearest region with acceptable latency to Pakistan. No third party is given access to personal data for their own purposes.
A public authority, where we are required by Pakistani law to provide it.
Changes
Last updated 2026-01-01. Material changes will be notified to active merchants before they take effect.
Data questions: hello@gloging.com