Legal
How EVOLV LOGISTICS LIMITED collects, uses, and protects personal information when you use DROP-IT.
Privacy Policy
Version: 1.1
Language: English
Published: Aug 12, 2026
Effective from publishing date
1. Introduction
The purpose of this Privacy Policy is to outline how EVOLV LOGISTICS LIMITED (“the Company”, "DROP-IT", "we", "us" or "our"), a company duly incorporated in the United Republic of Tanzania (Incorporation No. 189-584-873), collects, uses, stores, and protects the personal information of its customers and other users of its services.
2. Scope
This Policy applies to everyone who interacts with us in any capacity and includes, but is not limited to:
- Customers, or prospective customers who use or inquire about our services;
- Users of our website or mobile application;
- Visitors to our offices, warehouses, hubs, collection points, events, or other premises operated by or on behalf of the Company;
- Vendors, suppliers, contractors, consultants, and other service providers engaged by the Company;
- Directors, employees, or other members of our workforce;
- Business partners, affiliates, agents, representatives, and subcontractors acting for, with, or on behalf of the Company;
- Any other individual whose personal data is provided to us or processed by us in connection with the provision of our courier services.
3. Policy Statement
This section outlines how the Company manages personal information and protects users' privacy.
-
What kind of data do we collect?
-
Identity and contact information
This includes full names, phone numbers, email addresses, physical addresses, and legal identification for both senders and recipients of parcels where required; -
Business information
Where you represent a business or organization, we may collect information relating to the business, including business registration details, tax identification numbers, company and branch addresses, details of management and/or other contact persons, and information relating to products and/or services offered; -
Parcel information
This includes collection and delivery addresses, descriptions of the items, declared value, weight, size, and any specific handling requirements, proof of collection and delivery records, delivery status information, and other information necessary to facilitate transportation and delivery services; -
Location and geolocation information
This includes pickup and delivery locations, route information, live GPS coordinates obtained through your mobile device(s), or live GPS coordinates obtained through devices on Company-owned vehicles; -
Financial and payment information
This includes payment records, transaction histories, billing information, bank account details, mobile money account details, invoices, receipts, and other information required to process payments or maintain up-to-date financial records; -
Technical and device information
This includes IP addresses, browser types, device identifiers, operating system information, access times, usage data generated through your interaction with our systems.
-
Identity and contact information
-
Why do we collect this data?
-
Service delivery
Provision of courier services, to facilitate the end-to-end delivery lifecycle, including pick-up, sorting, transit, and last-mile delivery; Generate and maintain a digital audit trail of a parcel's location, providing senders and recipients with precise status updates; -
Customer support
To provide our support teams with the necessary context to troubleshoot delivery, payment, account or other issues; To investigate and resolve claims regarding damaged, delayed, or lost shipments through recorded transit data; -
Identity verification
Authenticate the identity of senders and recipients of parcels, and other individuals that may be involved in the delivery of parcels, mitigating the risk of fraud or theft; -
Payment processing
Verify billing information, process service fees, and manage customer accounts; -
Compliance
Fulfillment of mandatory obligations across several legal frameworks including (but not limited to); postal and courier regulations regarding manifest record-keeping and transport safety; and applicable data protection laws, ensuring that personal data is processed only for legitimate purposes;
-
Service delivery
-
How do we collect data?
-
Information provided directly by you
This includes: Data provided through our website or mobile application(s) when creating an account, completing KYC, or requesting deliveries; Data captured via official correspondence, including email and telephone calls, and engagement through our official social media channels; Data provided at our hubs, collection points or our head office by completing delivery forms, KYC documentation, or visitor logs; Voluntary data submitted through participation in customer satisfaction surveys or promotional registrations; -
Information provided by others
This occurs when a customer provides us with your data as the intended recipient of a parcel they need us to deliver, the processing of which is necessary in order not to prejudice the lawful purpose of the collection.
-
Information provided directly by you
Why do we process data?
-
Service delivery
To facilitate the end-to-end delivery lifecycle. This includes validating delivery instructions, calculation of tariffs, and synchronizing multi-point transit movements to ensure timely service delivery. -
KYC
To maintain a chain of custody by verifying the identity of senders and recipients of parcels, thereby mitigating the risk of mistaken or fraudulent handovers. -
Automated transactional communication
To maintain a real-time information flow between the Company and its customers, communicating; transactional metadata, delivery information and other updates via SMS or email, or both. -
Quality assurance
To provide reliable customer support, we process historical delivery and transactional data to investigate service discrepancies, resolve payment disputes, and improve our internal processes based on performance metrics and customer feedback.
How do we process data?
-
Geocoding and spatial analysis
We use spatial processing techniques to convert physical addresses into geographic coordinates. This data is then analysed against our service zones to determine delivery feasibility, calculate ETAs, allocate resources, and more. -
Automated workflows
We utilize server-side automated workflows to manage the delivery lifecycle. These process trigger immediate actions- such as calculating delivery fees based on information provided by the customer. -
Deterministic algorithmic planning
We utilize server-side processing of parcel, location, and other data, to manage our logistics workflows and coordinate routing and resource allocation. -
Statistical modelling
We utilize data aggregation to compile individual customer, parcel, and transaction data into statistical models. Through an anonymization process, we strip away personally identifiable information (PII). This allows us to analyse trends, identify weaknesses in our service delivery model, and improve our overall network efficiency without identifying individual users in reports.
Access to personal and operational data is strictly controlled and granted on a need-to-know basis to ensure confidentiality, integrity, and proper management of information.
-
Management
Management personnel may access personal and operational data required to oversee the Company’s delivery operations, ensuring targeted service quality, manage risks, and fulfil legal and regulatory obligations. -
Administration
Administrative personnel may process personal, operational, or financial data necessary for their duties. However, they do not have access to privileged administrative functions within our platform, including user account administration, audit logs, and access controls. -
Couriers
Our couriers may access only the information necessary to complete deliveries assigned to them, including sender and recipient details, contact information, pickup and delivery addresses, parcel information, and delivery instructions relating to those assigned deliveries. -
Others
Agents, contractors, consultants, and other persons acting on behalf of the Company are not permitted to access personal data unless such access is specifically authorized by the Company’s Personal Data Protection Officer, and necessary for the performance of an approved task.
We implement a multi-layered data protection strategy to protect personal and operational data from unauthorized access, distribution, alteration, or destruction. Our security measures include:
-
Access controls
Access to our database infrastructure is governed by robust authentication protocols. All devices are password protected. -
Data redaction and scoping
Prior to transmitting data to third-party service providers, we filter to isolate and remove any data points that are not strictly essential for the third party's specific task. -
Data backup
-
Point-to-point recovery
Our database management system maintains rolling copies of all data for a period of seven (7) days. This allows us to restore the system to any specific moment within the last week in the event of a technical failure. -
Audit log
We maintain detailed, time-stamped log of all database operations and system-level transactions which serve as a critical recovery tool. -
Off-site recovery
We maintain secondary copies of data offline in the event of a failure of our cloud-based database management system. -
Employee training
All employees (and agents) undergo orientation on how to handle customer information safely. This ensures employees (and agents) understand the importance of confidentiality.
-
Point-to-point recovery
-
Physical safeguards
Access to physical records are securely stored in lockable cabinets with access limited to authorized personnel only.
In accordance with applicable law, you have the following rights:
-
Right to Access
You have the right to view and obtain a copy of the personal data we hold about you. For your convenience, much of this information is accessible directly through your account. -
Right to Rectification
You have the right to request correction of inaccurate, incomplete or otherwise irrelevant personal data. -
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data, subject to regulatory obligations that require retention of the same. -
Right to Restrict Processing
You have the right to request that we temporarily suspend the processing of your personal data. Restricting this processing may result in the immediate suspension of our services to you. -
Right to Object
You have the right to object to the processing of your personal data for purposes other than the provision of courier services. This includes: marketing; and analytics and research.
If you have any concerns, complaints, or objections regarding our collection, use, or processing of your personal data, you may contact us by email at info [at] dropit [dot] co [dot] tz with the subject line “Data Privacy”. We may request additional information to verify your identity before processing your request.
4. Roles and Responsibilities
This section outlines the roles and responsibilities of the Company and its customers, with respect to the provision of courier services.
-
Roles
The Company serves as a custodian of personal data (the "data controller") and is responsible for defining data protection objectives, policies, and processes, and ensuring that data is processed and disseminated lawfully. -
Responsibilities
-
Compliance
Ensuring all activities are carried out in compliance with applicable laws and regulations. -
Policy Enforcement
Actively implement and update this Privacy Policy to reflect changing business and technological environments the Company operates in. -
Resource Allocation
Dedicating the necessary technical and human resources to maintain our database security.
-
Compliance
-
Roles
The customer is the individual, or entity, whose personal (and operational) information is collected and processed by the Company (the "data subject"). -
Responsibilities
-
Provide information
Providing personal (and business) information that is accurate, complete, and up-to-date. -
Account security
Maintaining the confidentiality of account credentials. -
Provide timely updates
Promptly notify the Company or updating their profile if there are changes to their contact or other information. -
Compliance
Adhere to the Company's Terms of Service and this Privacy Policy, and exercise their rights in a lawful and transparent manner.
-
Provide information
5. Procedures
This section provides a step-by-step overview of the operational processes involved in collection and processing of personal data.
-
Collection methods
The Company collects personal and other information through various touchpoints. This primarily occurs via our website when users create an account and use our website to request, track, or pay for deliveries, or communicate other information with us. We also collect information through direct communication, by phone, email or through our social media accounts. -
Consent
-
Web-based consent
By creating an account through our website, you consent to the processing of your personal data. -
Contractual consent
By engaging the Company in-person or off-line to handle and deliver parcels on your behalf, you consent to the processing of your personal data.
-
Web-based consent
-
During the delivery lifecycle
The Company processes personal, parcel and transactional data during the provision of courier services. This enables the Company to plan asset allocation and utilization, and enable automated communications and real-time tracking. -
After the delivery lifecycle
The Company may process historical data for internal analytical processes, such as evaluating service performance against regulatory standards.
For more details, see section 3.2 above.
6. Acknowledgement
By accessing or using the company’s services and/or website, the customer hereby acknowledges that they have read, understood, and agree to be bound by this Privacy Policy in its entirety. The customer acknowledges that their continued use of our services constitutes a binding agreement to our data collection, processing, and security practices as described herein.
The customer further acknowledges and agrees to indemnify, defend, and hold harmless the company, its officers, employees, and agents against any and all claims, losses, liabilities, damages, costs and expenses (including legal fees) arising out of or related to the customer’s breach of this Privacy Policy, provision of inaccurate or fraudulent personal data, misuse of the services, or violation of applicable law.
7. Governing Law
This Privacy Policy, and any dispute or claim arising out of or in connection with them, their subject matter, or their formation, shall be governed by and construed in accordance with the laws of the United Republic of Tanzania.