This document is a draft template. Have a qualified attorney review it before relying on it for live customer relationships.

Data Retention & Deletion Policy

How long we keep your personal information and what happens when you ask us to delete it.

Version 1.0.0-draft·Effective 15 May 2026

1. Our Principles

  • We retain personal information only as long as necessary for the purpose for which it was collected.
  • Where the law requires longer retention (tax, customs, AML), we comply with the longer period.
  • When retention expires, data is either anonymised or deleted.

2. Retention Schedule

CategoryRetention periodReason
Account profileUntil deletion request + 30 days graceUser-controlled
Booking & invoice records5 years after relationship endsSARS / VAT Act
Customs & cross-border records7 yearsCustoms Act
FICA / KYC documents5 years after terminationFIC Act
GPS / tracking data24 monthsOperational dispute window
Audit log7 yearsCompliance & investigations
Marketing consentUntil withdrawnPOPIA / GDPR
Cookie consent log12 monthsPOPIA / GDPR audit
Support tickets3 yearsService quality & disputes

3. Right to Deletion

You may request deletion of your account at any time via /account/privacy. We apply a 30-day grace period during which you can cancel the request and your account remains active. After that, personal data is deleted or irreversibly anonymised, except where we are required to retain it (see schedule above).

4. Anonymisation

Where data must be retained for legal reasons but no longer needs to identify you, we anonymise it: removing names, contact details, and identifiers, while keeping aggregate operational records (route, weight, value bands) for analytics.

5. Backups

Backups are retained for up to 90 days. Deletion requests may take up to that long to propagate fully through our backup cycles.