Privacy Policy
What we collect, where it lives, who else touches it, and how to get it back or have it deleted.
Last updated 18 August 2026
Who we are
Freight Manager is operated by [Registered company name] Ltd, registered in Kigali, Rwanda, at [Registered office address], Kigali, Rwanda. In this policy “we” means that company and “you” means the freight forwarding business using the platform.
Two different relationships run through the product. For your own account and billing data we are the controller. For the shipment, client and invoice records you enter about your customers, you are the controller and we are your processor — we act on your instructions and do not use that data for our own purposes.
What we collect
- Account details — name, work email, a bcrypt hash of your password (never the password itself), and your role within the workspace.
- Company profile — company name, logo, address, website and invoice settings you enter in Settings.
- Operational records — the shipments, clients, invoices, payments and documents you create. These may contain personal data about your own customers and their consignees.
- Payment data— the mobile money number used for a charge, amounts, currency, the RWF conversion rate applied, and the gateway's transaction reference. Card numbers are entered on the gateway's side; we never receive or store them.
- Technical data — your IP address (used to rate limit login and signup), error reports, and an immutable audit log of meaningful actions taken in your workspace.
We do not run advertising trackers, third-party analytics or session replay. The only cookie the site sets is the sign-in session cookie, which is strictly necessary to keep you logged in; your light/dark theme choice is kept in your browser's local storage.
Why we process it
- To provide the service you signed up for — the contract between us.
- To bill you, and to collect the payments your own clients make to you through the platform.
- To send transactional email: verification, password resets, invoices, trial and billing notices. These are part of the service, not marketing.
- To keep the platform secure and available — rate limiting, error monitoring and audit logging, which are our legitimate interests.
- To meet legal and accounting obligations where they apply to us.
Where your data is stored
The primary database sits in the af-south-1 (Cape Town) region, so records stay on the continent you operate in. Customs and shipping documents are held in private object storage and are only ever served through signed links that expire after one hour.
Who else processes it
We use the following subprocessors. Each one only receives what it needs to do its job, and we do not sell data to anyone.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | PostgreSQL database, file storage and realtime updates | af-south-1 (Cape Town) |
| Cloudflare R2 | Customs and shipping document storage (private, signed URLs) | Global object storage |
| Vercel | Application hosting and delivery | Global edge network |
| XentriPay (Centrika) | Mobile money and card collections, subscription charges | Rwanda |
| Resend | Transactional email (verification, invoices, trial notices) | Global |
| Upstash | Rate limiting counters for login, signup and password reset | Global |
| Sentry | Error and performance monitoring | Global |
| Optional OAuth sign-in for users who choose it | Global |
How long we keep it
Your records stay for as long as your workspace is open. When a trial or a subscription ends the workspace becomes read-only — nothing is deleted, so you can subscribe later and pick up where you left off. If you ask us to close your account we delete your workspace data within 30 days, other than records we are required to retain for accounting or fraud-prevention purposes.
How we protect it
- Every record carries a tenant identifier and every query is scoped to it, so one company can never read another's data.
- Passwords are hashed with bcrypt. Sessions are signed tokens, and sign-in, signup and password reset are rate limited.
- Documents are private by default and reachable only through short-lived signed URLs, with each access written to the audit log.
- Payment webhooks are rejected unless they carry a valid HMAC signature.
Your rights
You can ask for a copy of your data, have it corrected, or have it deleted. Most of it you can get at yourself: shipments, invoices and documents export to PDF from inside the app at any time, with no request needed. For anything else, email privacy@freightmanager.africa and we will respond within 30 days.
If you are one of our customers' clients and want your details changed or removed, contact the freight forwarder you are dealing with — they control that record, and we act on their instruction.
Changes
When this policy changes materially we will email account admins before it takes effect. The date at the top always reflects the current version. See also our Terms of Service.