ECFY CONSULTING PRIVATE LIMITED

Privacy Policy

This policy explains what data the WebXpress TMS mobile application collects from delivery and field personnel, why, and how it is used, stored, and shared.

App:  WebXpress TMS Package:  com.webx.velocity Effective:  9 September 2026

01Scope & Acceptance

WebXpress TMS ("the App", "we", "us", "our") is a field logistics application operated by ECFY CONSULTING PRIVATE LIMITED, a company incorporated under the Companies Act, 2013.

The App is a multi-tenant platform: it is used by delivery executives, drivers, and warehouse staff across multiple independent client companies (each operating as a separate tenant) to manage docket delivery runs (DRS), capture proof of delivery, print consignment labels and receipts, and report status back to dispatch in real time. It is not limited to a single organisation's internal use — it is distributed publicly so that field personnel at any of our client companies can install and sign in with their own company's credentials. This policy describes what happens to your data when you use it.

By signing in and using the App, you agree to the collection and use of information as described here. If you do not agree, please do not use the App — contact your account administrator instead.

02Information We Collect

We collect only what the App needs to run a delivery route and hand off a docket. This falls into four groups:

Account data

Login credentials (encrypted at rest), employee ID and name, and your assigned company/branch code.

Delivery data

Docket and delivery details for the packages you handle, including consignee information and proof of delivery.

Location data

GPS location while a delivery run is active — see §5.

Device data

Basic device information, used for diagnostics and to connect with paired barcode scanners and printers.

We do not collect data for advertising, and the App does not contain third-party ad SDKs.

03Device Permissions

Android requires the App to declare each sensitive capability it uses. Below is every permission the App requests and the concrete reason for it — nothing is requested "just in case."

Permission
Category
Why we request it
ACCESS_FINE_LOCATION Location Pinpoint your position for live delivery tracking and route/status updates to dispatch.
ACCESS_BACKGROUND_LOCATION Location Keep sending location updates while a delivery run (DRS) is active and the App is closed or backgrounded. Requested only after an in-app explanation, and only while a delivery is in progress.
FOREGROUND_SERVICE_LOCATION Location Runs the location-tracking service with a persistent notification, as Android requires for any app tracking location in the background.
CAMERA Media Capture proof-of-delivery photos and scan barcodes/documents at the point of delivery.
READ_EXTERNAL_STORAGE (≤ Android 12) Media Attach an existing photo to a delivery record on older Android versions. On Android 13+ this is handled by the system Photo Picker, which needs no permission at all.
BLUETOOTH_SCAN / CONNECT / ADVERTISE Device Discover and pair with handheld barcode scanners and portable label/receipt printers used at the delivery point.
POST_NOTIFICATIONS Comms Show the delivery-tracking status notification and other in-app alerts.
WAKE_LOCK / RECEIVE_BOOT_COMPLETED Device Keep the location-tracking service alive during an active run and resume it if the device restarts mid-delivery.
ACCESS_NETWORK_STATE / CHANGE_NETWORK_STATE / CHANGE_WIFI_MULTICAST_STATE Device Detect connectivity to queue delivery updates offline and sync when back online; discover network printers.

The App also requests standard, non-sensitive permissions (INTERNET, VIBRATE, REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, USB accessory access for wired printers) required for normal operation, which Android does not classify as requiring disclosure here.

04How We Use It

  1. Authenticate you and load the modules and permissions assigned to your role and branch.
  2. Build and update your delivery run (DRS), and reflect docket status changes in real time for dispatch and customers.
  3. Record proof of delivery — photo, signature, or barcode scan — against the correct consignment.
  4. Print consignment labels and delivery receipts via paired Bluetooth/USB printers.
  5. Diagnose connectivity and app issues.
  6. Meet legal, audit, and dispute-resolution obligations tied to a delivery (e.g. proving a package was delivered to a given address at a given time).

We do not sell personal data, and we do not use delivery or location data to build advertising profiles.

05Location Data in Detail

Background location is only used while you have an active delivery run in progress — from when you start the run until it is completed or closed. It is not tracked continuously at other times.

You will always see a persistent notification while background location tracking is running, so it's clear when it's active. You can withdraw location permission at any time from your device's App Settings, though this may prevent you from starting or continuing a delivery run.

06Sharing & Disclosure

Delivery and account data is visible within your employer's WebXpress TMS tenant — dispatchers, supervisors, and administrators at your company who are assigned to view your branch or route. We disclose data outside that tenant only:

  • To the consignee or their authorised recipient, strictly as needed to complete and confirm a delivery.
  • To comply with a law, regulation, court order, or lawful government request.
  • To protect the rights, property, or safety of WebXpress, our customers, drivers, or the public.
  • To a successor entity in the event of a merger, acquisition, or asset transfer, with continuity of this policy's protections.

We do not sell or rent personal data to third parties for their own marketing purposes.

07Third-Party & Hosting

App data is transmitted to and stored on WebXpress's own backend services, used solely to operate the App on our behalf.

The App does not integrate any third-party analytics or advertising SDKs.

08Storage & Retention

Account credentials are stored on-device using encrypted secure storage, not plain text.

We retain delivery records (including proof-of-delivery evidence and associated location data) for as long as needed to satisfy operational, audit, tax, and legal-dispute requirements applicable to logistics records, after which they are deleted or anonymised.

09Security

We apply reasonable technical and organisational safeguards — encrypted transport (HTTPS) for all data in transit, encrypted on-device storage for credentials, and role-based access on the backend — to protect your data from loss, misuse, or unauthorised access. No method of transmission or storage is 100% secure, and you also play a part: keep your device lock enabled and your password confidential.

10Your Choices & Rights

You can review or correct your personal information, or ask us to delete it subject to our legal retention obligations, by contacting your account administrator or us directly (§13). You can withdraw location, camera, or Bluetooth permission at any time from your device's Settings, understanding that some App features will then be unavailable.

11Children's Privacy

The App is a workforce tool for employed delivery and logistics personnel and is not directed at, or knowingly used by, children under 18. We do not knowingly collect data from children.

12Changes to This Policy

We may update this policy as the App's features change. Material changes will be reflected by updating the effective date above, and, where required, notified in-app before they take effect. Continued use of the App after a change constitutes acceptance of the revised policy.

13Contact Us

Questions about this policy or your data can be directed to:

ECFY CONSULTING PRIVATE LIMITED
5th Floor, 501/502, Abhar, 5th Road, Khar West, Mumbai Suburban, 400052 India (IN)
Email: support@webxpress.in