Overview
Quechains LLC ("QueChains", "we", "us", or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our global supply chain and logistics management platform.
This policy applies to all data subjects including platform users, organization administrators, supplier contacts, and visitors to our website. By accessing or using QueChains, you agree to be bound by this Privacy Policy.
Data We Collect
- Full name, email address, phone number
- Job title, department, and organization name
- Profile photo (if provided)
- Authentication credentials (hashed β never stored in plain text)
- Multi-factor authentication secrets (encrypted at rest)
- Shipment origins, destinations, and route details
- Cargo descriptions, HS codes, and commercial values
- Bill of Lading, invoices, packing lists, and customs documents
- Carrier assignments, vessel details, and tracking events
- Purchase orders, goods receipt notes, and supplier data
- IP address, browser type and version, device identifiers
- Pages visited, features used, and time spent on platform
- API request logs, error reports, and performance metrics
- WebSocket session data for real-time tracking features
- Cookies and similar tracking technologies (see Cookie Policy)
- Billing address and payment method details (processed by Stripe β we do not store raw card numbers)
- Invoice history and subscription plan details
- Tax identification numbers where required by law
How We Use Your Data
We use the information we collect for the following purposes, always grounded in a lawful basis:
- Providing, maintaining, and improving the QueChains platform and its features
- Processing shipments, purchase orders, and logistics workflows on your behalf
- Sending operational notifications β delays, customs alerts, delivery confirmations
- Authenticating users and enforcing role-based access controls
- Generating analytics, performance reports, and KPI dashboards for your organization
- Communicating product updates, security notices, and support responses
- Complying with legal obligations including customs, tax, and trade compliance regulations
- Detecting, investigating, and preventing fraud, abuse, and security threats
- Processing subscription billing and managing your account plan
Data Sharing & Disclosure
We share your data only in the following circumstances:
- AWS (hosting, S3 document storage, SES email delivery)
- MongoDB Atlas / PostgreSQL (database infrastructure)
- Redis Cloud (caching and real-time session management)
- Stripe (payment processing β PCI DSS compliant)
- Twilio (SMS and WhatsApp notifications)
- MarineTraffic / AviationStack (vessel and flight tracking data)
- DocuSign / Adobe Sign (document e-signature services)
We may disclose data when required to do so by law, court order, customs authority, or government regulation β including international trade compliance mandates.
In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity. We will notify affected users via email and/or in-app notification prior to any such transfer.
Data Retention
We retain your data only for as long as necessary to fulfil the purposes described in this policy, and as required by applicable law:
- Account data: retained for the duration of your subscription plus 90 days post-termination
- Shipment records: 7 years (trade compliance and audit requirements)
- Customs declarations: 10 years (regulatory mandate in most jurisdictions)
- Financial records and invoices: 7 years (tax and accounting obligations)
- Audit logs: 5 years (immutable compliance trail in PostgreSQL)
- Session tokens: 7 days (Redis TTL, automatically purged)
- Support communications: 3 years from case resolution
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access β request a copy of the personal data we hold about you
- Right to Rectification β request correction of inaccurate or incomplete data
- Right to Erasure β request deletion of your data (subject to legal retention obligations)
- Right to Restrict Processing β ask us to limit how we process your data
- Right to Data Portability β receive your data in a machine-readable format (JSON/CSV)
- Right to Object β object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent β where processing is consent-based, withdraw at any time
- Right to Lodge a Complaint β with your national data protection authority (e.g. ICO, CNIL, NDPC)
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will respond within 30 days (extendable by 60 days for complex requests).
Security Measures
We implement industry-standard technical and organisational security measures to protect your data:
- TLS 1.3 encryption for all data in transit via HTTPS/WSS
- AES-256 encryption for sensitive data at rest
- JWT authentication with 15-minute access token expiry and Redis-managed refresh tokens
- Redis-backed rate limiting (100 req/min per user, 1,000 req/min per organisation)
- Role-Based Access Control (RBAC) enforced at every API route
- Immutable audit logs written to PostgreSQL for every write action
- Zod schema validation on all inbound API requests
- Regular penetration testing and vulnerability assessments
- Multi-factor authentication (TOTP) available for all accounts
Cookies & Tracking
We use cookies and similar technologies to maintain sessions, remember preferences, and understand how our platform is used.
Required for authentication, session management, and core platform functionality. Cannot be disabled.
Help us understand platform usage patterns to improve user experience. You may opt out via your account settings.
Store your language, timezone, display preferences, and dashboard configurations.
You can manage cookie preferences at any time in your account settings or via our Cookie Settings page. Blocking essential cookies may affect platform functionality.
International Transfers
QueChains operates globally. Your data may be transferred to and processed in countries outside your country of residence, including the United States, European Union member states, and other jurisdictions where our service providers operate.
When transferring personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Binding Corporate Rules where applicable
- Adequacy decisions for qualifying countries
- Data Processing Agreements with all sub-processors
A full list of sub-processors and their processing locations is available upon request from our DPO.
Children's Privacy
QueChains is a B2B enterprise platform designed exclusively for use by business professionals. Our services are not directed at, and we do not knowingly collect personal data from, individuals under the age of 18.
If you believe a minor has provided us with personal data, please contact us immediately at [email protected] and we will promptly delete such information.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify you of material changes by:
- Sending an email notification to your registered address at least 30 days before the change takes effect
- Displaying a prominent in-app banner upon next login
- Updating the "Last Updated" date at the top of this policy
Your continued use of QueChains after the effective date of any changes constitutes acceptance of the updated policy.
Contact & DPO
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: [email protected]
- Data Protection Officer: [email protected]
- Mailing address: Quechains LLC, Privacy Team
- Response time: within 30 days of receiving your request
Get in Touch
Our support team is here to help. We respond to all inquiries within 48 hours.