Legal
Privacy Policy
Last updated: May 21, 2026
This policy explains what personal data BP Couriers collects when you use our website, mobile app, or services, how we use it, who we share it with, how long we keep it, and the rights you have under Jamaica's Data Protection Act, 2020 (DPA).
1. Who we are
BP Couriers ("BP Couriers", "we", "us", "our") is a courier and last-mile logistics service operating in Jamaica. For the purposes of the Data Protection Act, 2020 we are the data controller of the personal data you provide when you use our services.
You can reach our data protection contact at privacy@bpcouriers.com.
2. What we collect
2.1 Account information
- Name, email address, phone number, profile photo (where provided)
- Authentication tokens issued by our identity provider (Clerk)
- Business name and trading address (for business accounts)
2.2 Delivery data
- Pickup and drop-off addresses, recipient names and phone numbers
- Parcel description, weight, dimensions, fragility flags, photos
- Scheduled pickup time, service tier, internal notes
- Geolocation data captured during driver pickup / drop-off events
- Proof-of-delivery photo and signature
2.3 Payment data
We do not store full card numbers. Payments are processed by Stripe (a PCI-DSS Level 1 certified payment processor). We retain a payment reference, last 4 digits, currency, amount, and Stripe charge identifier so we can reconcile refunds and respond to disputes.
2.4 Device and usage data
- IP address, browser type, operating system, device identifiers
- Pages visited, features used, error logs (Sentry)
- Cookies and similar technologies — see our Cookie Policy
3. Why we use it (lawful basis)
We process personal data on the lawful bases set out in §16 of the DPA:
- Contract — to provide the delivery service you booked (matching driver, navigation, status updates, billing)
- Legal obligation — tax records, business registration compliance, sanctions screening
- Legitimate interest — fraud prevention, service improvement, security monitoring, dispute resolution
- Consent — non-essential cookies, marketing emails (you can withdraw consent at any time)
4. Who we share it with
We share the minimum data required with the following categories of recipient:
- The assigned driver — name, phone number, pickup & drop-off address, parcel description and any delivery notes
- Recipients — your name and tracking link via SMS / email notifications, where applicable
- Service providers (sub-processors) — Clerk (identity), Supabase (database / storage), Stripe (payments), Resend (transactional email), Twilio (SMS), Mapbox (geocoding), Vercel (hosting), Sentry (error monitoring), Upstash (queue). Each is bound by a Data Processing Agreement.
- B2B partners — where you book through a partner's system, we share data necessary to fulfil and reconcile the delivery
- Law enforcement — only when compelled by a valid Jamaican court order or law-enforcement request
We do not sell your personal data, and we do not use it for any advertising-profiling purpose.
5. International transfers
Some of our processors store data outside Jamaica (United States, European Union). When that happens, we rely on contractual safeguards (the EU Standard Contractual Clauses or equivalent) and require the processor to match the protection standards of the DPA.
6. How long we keep it
- Active account data — for as long as you have an account with us
- Delivery records — 7 years from delivery (tax / dispute window)
- Payment receipts — 7 years (Jamaican Income Tax Act)
- Marketing data — until you withdraw consent
- Server logs / Sentry events — 90 days, then aggregated or deleted
7. Your rights under the DPA
You have the right to:
- Be informed about how we use your data (this policy)
- Access the data we hold on you
- Correct inaccurate or incomplete data
- Erase your data (where we have no overriding legal basis)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw any consent you previously gave
- Complain to the Information Commissioner of Jamaica if you believe we've mishandled your data
To exercise any of these rights, email privacy@bpcouriers.com. We'll respond within 30 days. You can also delete your account directly from your dashboard.
8. Security
We use TLS in transit, encryption at rest for the database, role-based access controls, two-factor authentication on staff accounts, audit logging of every admin action, and regular dependency security scanning. Despite these measures, no internet service can be 100% secure — if you believe an unauthorised party has accessed your account, contact us immediately.
9. Children
BP Couriers is not intended for children under 16. We do not knowingly collect personal data from anyone under that age. If you believe we have, please contact us so we can remove it.
10. Changes to this policy
We may update this policy from time to time. When we make a material change we'll update the "Last updated" date at the top of this page and notify you by email or in-app banner. Continued use of the service after changes means you accept the updated policy.