Data Protection & Privacy Standard

Privacy Policy & Data Protection

Effective Date: September 2026 | Compliant with GDPR, PCI DSS 4.0, and International Maritime Logistics Regulations.

Our Core Privacy Commitment

At Space Ships Logistics, safeguarding your commercial confidentiality and personal data is fundamental to our service delivery. We do not sell, rent, or monetize personal information. Data collected through this platform is used solely to execute freight operations, fulfill customs compliance, manage secure client accounts, and respond to your operational inquiries.

1. Information We Collect

We only collect data strictly necessary for freight forwarding and client portal management:

  • Inquiry & Contact Information: Name, business email, telephone number, company identity, and cargo details submitted via our Contact, Rate Query, or Suggestion forms.
  • Portal Account Credentials: Usernames, encrypted passwords, and associated shipment consignee/shipper references for authorized client tracking.
  • Technical & Audit Telemetry: Anonymized IP addresses, browser User-Agent hashes, and timestamped forensic logs stored strictly for brute-force mitigation and session pinning.

2. Cookie Policy & Tracking Hygiene

Space Ships Logistics adheres to a strict Zero Third-Party Advertising Tracker policy. We do not deploy advertising pixels, third-party profiling cookies, or behavioral trackers.

Strictly Necessary Session Cookies

Encrypted authentication cookies (auth_token, client_session) flagged with HttpOnly, Secure, and SameSite=Lax to prevent cross-site theft.

No Tracking or Marketing Cookies

We do not employ ad networks or tracking scripts. No commercial profiling data is ever transferred to third-party ad brokers.

3. Technical & Organizational Security Measures

We deploy bank-grade technical controls to protect your data:

  • Encryption in Transit: Strict Transport Security (HSTS) enforcing TLS 1.3 encryption across all network exchanges.
  • Encryption at Rest: Sensitive client and vendor contact records encrypted at rest using AES-256 with dynamic initialization vectors.
  • Bot Protection: Cloudflare Turnstile bot challenges deployed to prevent automated harvesting and dictionary attacks.
  • Automated Purging: Stale session tokens, rate-limit counters, and expired tracking tokens are permanently purged every 24 hours by automated maintenance jobs.

4. Your Rights Under GDPR & Data Protection Regulations

Under the General Data Protection Regulation (GDPR) and international privacy frameworks, you have the right to:

  • Right of Access: Request a complete copy of any personal details maintained in our records.
  • Right to Rectification: Request correction of outdated or inaccurate contact or shipment information.
  • Right to Erasure (Right to be Forgotten): Request the permanent deletion of your account and associated contact history (subject to mandatory customs and fiscal audit retention requirements).
  • Right to Restrict Processing: Request suspension of active marketing notifications or communications.

5. Contact our Data Protection Officer

If you have questions regarding this Privacy Policy, wish to exercise any of your statutory data rights, or request data erasure, please contact our compliance desk:

+92 21 32244471-4
Karachi, Pakistan