Privacy in the delivery journey.
How the tracking experience handles information used to find and display a shipment. Updated October 2, 2026.
What this policy covers
This policy describes the Shipment Lookup website, public tracking experience, and private business console. A merchant or connected shipment source may have its own privacy terms for the purchase, customer account, and underlying order.
Information used for lookup
Tracking lookup processes the identifier you submit. Supported order lookup also processes the order or carrier reference and checkout email needed to match the correct record. Those details are sent only to the connected services required to complete the lookup.
What a public tracking page can show
Public results can include shipment identifiers, current status, delivery estimates, recorded events, carrier labels, and limited route or destination context when a source provides it. The public response is designed to explain the delivery, not reproduce a customer or order database.
Customer email, phone number, full street address, payment information, reusable authentication credentials, and private operational notes are excluded from the public shipment response.
Shareable tracking links
A public shipment identifier is intended to be shareable with the customer who needs it. Anyone who receives a valid public link may be able to view its limited shipment information, so tracking links should not be published broadly when the delivery is private.
Business accounts and private records
Business accounts use Supabase authentication. While signed in, the console can store and display shipment records owned by that account, including operational references, customer lookup fields, carrier information, destination context, and recorded status history.
Database access policies restrict account-owned records. A publishable project key identifies the application but does not grant privileged access by itself. Privileged credentials are not intended for browser code.
Security and abuse prevention
The backend can use a salted hash of requester network information to count requests over a short rate-limit window. This is used to reduce automated enumeration and abuse. Rate-limit buckets expire and can be cleaned up as the service processes later requests.
Service providers
Supabase provides authentication, database, and backend services. Lovable provides application hosting and deployment services. Google Fonts supplies the site typeface. The application's existing error reporting may send redacted technical error information needed to diagnose failures.
Source accuracy and corrections
Shipment Lookup displays information from the connected record that owns the shipment update. If an order reference, delivery detail, or status is wrong, the merchant handling the purchase is normally the party able to correct the source record.
Retention and availability
Shipment records and account data may remain available for operational, security, and historical purposes according to the connected source and business account configuration. Temporary request logs or rate-limit data may be retained only as needed to operate and protect the service.
Your responsibility when using lookup
Use shipment references and order details only for deliveries you are authorized to view. Avoid sharing checkout emails or tracking links in public places. Businesses should collect only the customer information they need for fulfillment and customer lookup.