The two kinds of data here
This distinction matters more than anything else on the page, so it comes first.
- Your account and workspace. The details you give us to have a Kargozi login at all — your name, your email, your company’s name and tax details. We decide what to do with this, so we answer for it.
- The business records you put in. Your customers, shippers, receivers, bookings, invoices, payments and balances. This is your data about your business. We hold it and process it on your instructions. We do not sell it, mine it, train anything on it, or use it to build a picture of your trade.
If one of your customers wants to know what a courier company holds about them, the answer lies with that courier company, not with us. We will help them reach you.
What we collect
To give you an account
- Your name and email address.
- A password, stored only as a hash — we cannot read it, and neither can anyone who takes the database.
- If you turn on two-factor authentication, the secret your authenticator app needs, and your backup codes.
- Your workspace’s company name, address, state and GSTIN, because tax invoices cannot be produced without them.
Because the software is being used
- An audit record of significant actions — who changed what, and when. It keeps your IP address and browser string. This exists so that you can answer “who deleted that invoice”, which is a question every finance team eventually asks.
- Session records, so you can see where you are signed in and end a session you do not recognise.
- Ordinary server logs. They are for keeping the service up and diagnosing faults.
There are no advertising trackers, no analytics scripts and no third-party cookies on this site or in the application. The only cookie we set is the one that keeps you signed in.
Who else sees it
A short list, and it is the whole list.
- Amazon Web Services — hosting. The servers and databases run in AWS’s Mumbai region, in India.
- Resend — transactional email only: password resets, workspace invitations and the notifications you ask for. Your email address and the contents of that message, nothing more. We do not send marketing email through it.
- Carriers you choose to book with. When you dispatch a shipment to a carrier — DHL, today — we send that carrier what it needs to create the airway bill: shipper and receiver names, addresses, contact numbers, and the contents and weight of the consignment. That transfer only happens when you press the button, and the carrier then handles that data under its own terms.
We may also disclose data where the law requires it. If that ever happens and we are allowed to tell you, we will.
Kargozi does not process card payments, so no card or bank credentials pass through the service or exist in our database. Payments you record are entries in your ledger, entered by you.
Where it lives, and how it is kept apart
Every workspace’s business data sits in its own separate database schema. That is not a filter applied to a shared table that somebody could forget to write — it is a structural boundary, chosen from your session, and there is no request you can make that asks for another company’s rows.
Data is stored in India. Carrier and email providers named above may process the specific data sent to them outside India under their own terms. Carrier API credentials you enter are encrypted before they are stored.
How long we keep it
- While your workspace is open, we keep your records — you need your own invoice history, and Indian tax rules expect you to have it.
- After you close your account, tell us and we will delete your workspace data. Ask us for an export first; we would rather you left with your records than without them.
- Backups are kept on a rolling basis and age out, so deleted data can persist in a backup for a short period after it is gone from the live database.
How it is protected
- Everything travels over HTTPS. There is no unencrypted route to the service.
- Your session is an httpOnly cookie, which means no script running in the page can read it — including one that got there through someone else’s mistake.
- Passwords are hashed. Two-factor authentication is available and we recommend it.
- What each member may see and do is decided per request from their role, so removing somebody’s permission takes effect immediately rather than whenever their session happens to expire.
No system is beyond reach. If we discover a breach affecting your data, we will tell you and the relevant authority, and we will tell you what we know rather than what sounds best.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, and withdraw a consent you previously gave. Write to us and we will act on it.
If you are unhappy with how we have handled a request, say so and we will look at it again. You also have the right to complain to the Data Protection Board of India.
Children
Kargozi is business software. It is not intended for anyone under 18 and we do not knowingly create accounts for them.
Changes
When this page changes we will update the date at the top. If a change materially affects what we do with your data, we will email the workspace owner rather than rely on you noticing.
Contact
Kargozi is operated from Tamil Nadu, India. For anything on this page — including a data request or a grievance — write to hello@kargozi.com and it will reach the person responsible. You can also use the contact form.
See also our terms of service.