Introduction & Scope
Panvaya Logistics (“Panvaya”, “we”, “our”, or “us”) provides high-fidelity ocean container tracking, multi-carrier visibility, sailing schedule search, marine route modeling, demurrage analytics, and developer APIs.
This Privacy Policy and Legal Disclaimer describes our governance practices regarding the collection, processing, storage, protection, and transfer of personal data and customer cargo records. This policy applies to all visitors, registered users, enterprise organizations, and API subscribers accessing our websites (including panvaya.com), customer dashboards, public tracking links, and programmatic endpoints.
Information We Collect
Depending on your engagement with Panvaya, we process the following discrete categories of information:
Full name, corporate email address, organization name, account role, and salted cryptographic password hashes. Single sign-on tokens when authenticating via verified Google Workspace accounts.
Standard ISO 6346 container numbers, Bills of Lading (B/L), carrier booking references, Air Waybill (AWB) numbers, vessel IMO/MMSI identifiers, user-defined tags, internal reference IDs, and uploaded shipment documentation.
Cryptographic B2B API keys, webhook endpoint URLs, request volumes, response timestamps, query parameters, error logs, and metered quota usage.
Billing contact name, billing address, tax identification numbers, and invoice records. Credit and debit payment card transactions are tokenized directly by certified PCI-DSS Level 1 payment processors; Panvaya never stores card numbers.
Third-Party Trademarks, Carrier Brand Assets & Independence Disclaimer
All product names, logos, brand emblems, trade names, registered trademarks, and service marks referenced, listed, or catalogued across the Panvaya platform, sailing schedule engine, carrier directory, and developer APIs are the sole intellectual property of their respective owners.
Any reference to, depiction of, or mention of third-party shipping lines, ocean carriers, airlines, logistics enterprises, ports, or freight forwarders (including Standard Carrier Alpha Codes [SCAC], IATA codes, and UN/LOCODE designations) is conducted strictly for nominative, identification, representational, and navigational purposes. Such usage is solely intended to assist freight forwarders, beneficial cargo owners (BCOs), and logistics professionals in identifying relevant freight movements, sailing schedules, and container statuses.
Brand Neutrality & Visual Asset Policy: Following a trademark compliance notice received from an ocean carrier regarding logo usage, and in adherence to intellectual property standards and our carrier neutrality principles, Panvaya has proactively retired all third-party carrier logos, brand emblems, and visual trademarks across our web platform, customer dashboards, and API responses. Ocean shipping lines and air carriers are identified and referenced exclusively via standard textual names and industry-standard alphanumeric designations (such as SCAC, IATA, and UN/LOCODE codes) strictly for nominative freight identification and navigation.
Notice of Non-Affiliation and Operational Independence: Unless expressly executed pursuant to a formal, bilateral written agreement, Panvaya is an independent logistics visibility and analytics platform and has no direct integration, commercial link, official affiliation, association, authorization, sponsorship, endorsement, or agency with any ocean carrier or airline referenced herein.
Panvaya does not claim any proprietary rights in or to third-party brand marks. The reference to any carrier does not indicate, represent, or imply that such carrier has reviewed, certified, audited, or endorsed Panvaya’s data normalizations, predictive ETAs, or tracking algorithms.
How & Why We Process Information
We process customer information under strict legal bases recognized by global data protection regulations, including contractual necessity, legitimate business interests, and legal compliance:
- Core Tracking & Visibility Services: Querying public carrier sources and normalized milestone interfaces to retrieve real-time container movements, DCSA-compliant milestone logs, vessel AIS coordinates, and terminal events.
- Predictive Logistics & Route Modeling: Calculating dynamic arrival estimates (ETA), marine voyage diorama paths, port turnaround durations, and demurrage/detention financial exposure risk.
- Account Authentication & Security: Verifying credentials, managing multi-seat corporate accounts, enforcing role-based permissions, and filtering abusive or unauthorized access attempts.
- Operational Communications: Delivering mission-critical milestone alerts, exception notifications, password reset tokens, and billing statements.
Customer Content Ownership & Non-Sale Pledge
Your cargo tracking records, supply chain routes, and trade volumes belong to your organization. Panvaya maintains an uncompromising data ownership pledge:
Hosting, Cloud & Sub-processors
Panvaya operates on enterprise-grade infrastructure. We engage third-party sub-processors only where strictly necessary to deliver high availability and resilient logistics intelligence:
- Enterprise Cloud Infrastructure: Dedicated cloud computing environments, managed database clusters, encrypted cloud object storage for customer documents, asynchronous message queuing, and reliable transactional delivery systems.
- Cloudflare: Network-edge DNS routing, distributed denial-of-service (DDoS) protection, Web Application Firewall (WAF), and global TLS termination.
- Payment Gateways: Certified PCI-DSS Level 1 compliant gateways (including Stripe and regional processors) for subscription management and secure tokenized transaction handling.
- Google Services: Verified OAuth 2.0 single sign-on when selected by the customer, and anonymous performance telemetry managed via Google Tag Manager.
Enterprise Security Safeguards
We enforce rigorous technical and organizational controls to protect customer records against unauthorized access, accidental loss, disclosure, or modification:
All customer traffic is enforced with modern TLS 1.3 encryption across all public web and API endpoints.
All managed databases, backups, and storage volumes are encrypted at rest using industry-standard AES-256.
Shipment records are compartmentalized with strict database row-level boundaries and organization ownership keys.
Uploaded customer documents are served via short-lived, pre-signed URLs expiring within minutes of generation.
Data Retention & Deletion Lifecycle
We retain customer data only for the period necessary to deliver contracted visibility services, fulfill accounting or tax obligations, and comply with applicable statutory retention requirements:
- Active Shipments: Maintained in real-time tracking tables while shipments remain in transit or pending final terminal discharge.
- Completed Journeys: Closed shipment records remain accessible within the customer archive for demurrage audit and carbon reporting until deleted by the customer or account closure.
- Account Deletion: Upon receiving an authenticated account termination request, user profiles, access keys, and associated private records are deleted or anonymized within 30 days, subject to customary encrypted backup rotation cycles.
Your Global Privacy Rights
Depending on your geographical jurisdiction (including the European Union under GDPR, the United Kingdom under the UK DPA, and California under the CCPA/CPRA), you may exercise the following rights:
To submit a formal Data Subject Access Request (DSAR), please contact our privacy desk at [email protected]. Requests are authenticated and addressed within 30 calendar days.
International Data Transfers
Panvaya operates internationally to provide global container visibility. Customer information may be processed across data centers in the United States, the European Union, and regional cloud availability zones. Where personal data is transferred across international jurisdictions, we ensure appropriate transfer safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Guest & Public Tracking Terms
For visitors using our public or guest container tracking interfaces without an account:
- Guest tracking lookups are processed ephemerally to return milestone results. Container numbers searched in guest mode are not indexed publicly or attributed to any personal profile.
- Fair-use rate limits are applied via anonymous IP hashing to protect upstream infrastructure and prevent automated scraping or denial-of-service abuse.
Developer API & Enterprise Webhooks
Enterprises consuming Panvaya’s B2B REST API (/api/v1/**) receive cryptographically hashed API credentials. API consumers are solely responsible for securing their API keys. Outgoing webhook notifications are signed cryptographically to enable client-side payload integrity verification.
Children’s Privacy
Panvaya is a business-to-business (B2B) commercial logistics intelligence platform. Our services are not directed to, marketed to, or intended for individuals under sixteen (16) years of age. We do not knowingly collect personal information from children.
Policy Amendments & Notifications
We may revise this Privacy Policy and Legal Disclaimer periodically to reflect enhancements in our tracking technology, upstream carrier integrations, or applicable international statutory standards. When revisions occur, the effective date will be updated at the top of this policy. For material changes affecting customer data ownership, registered users will receive advance notification via email.
Contact & Legal Inquiries
For privacy requests, enterprise Data Processing Addendum (DPA) execution, security audit inquiries, or trademark clarifications, please contact our legal and compliance desk:
Panvaya Logistics Compliance Desk
Enterprise Security, Data Privacy & Legal Affairs
Email: [email protected]