Privacy Policy
Last updated: September 22, 2026
1. Introduction
Beacon Track Solution ("BTS", "we", "us", or "our") operates a delivery tracking and logistics management platform accessible at beacontracksolution.com and beacontracksolution.base44.app (collectively, the "Platform"). This Privacy Policy describes how BTS collects, uses, discloses, and safeguards your information when you use our platform, mobile application, and related services (collectively, the "Service").
This Privacy Policy applies to all users of the Service, including administrators, finance personnel, drivers, clients, customers, and contractors. By creating an account or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
This Privacy Policy explains in detail: what personal data we collect, how we collect it, the purposes for which we use it, who we share it with, how long we retain it, what rights you have over your data, and how we protect your information. We are committed to transparency and to complying with applicable data protection laws, including the Singapore Personal Data Protection Act (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect
We collect the following categories of personal and operational data to provide and improve our Service. The specific data we collect depends on your role and how you interact with the platform.
2.1 Account and Registration Information
When you register for an account, we collect your full name, email address, password (encrypted and never stored in plaintext), assigned role (administrator, finance, driver, client, customer, or contractor), and company/tenant affiliation. We also collect your Google account ID and email address if you sign in using Google OAuth. For driver accounts, we also collect your phone number, residential address, NRIC/IC number (last four digits used to generate a unique driver ID), vehicle details (type, brand, model, year, license plate, engine capacity, fuel type, transmission, ownership status), and vehicle ownership documentation (log card or rental proof photo). For client/company accounts, we collect the company name, contact person name, contact phone number, and business description.
2.2 Delivery and Order Data
For each delivery record, we collect and store: order numbers, tracking codes (auto-generated QR identifiers), reference numbers, sender/pickup addresses (block, street, unit, building name, postal code), recipient/drop-off addresses (block, street, unit, building name, postal code), customer names, customer phone numbers (primary and alternate), customer email addresses, attention/attn names, item descriptions (up to 3 items per order), special instructions and remarks (up to 2 remark fields), delivery priority (low, normal, high, urgent), package size (small, medium, large, extra large), payment method (cash on delivery, prepaid, card, bank transfer, none), payment amount to collect from customer, delivery status history (pending, assigned, picked up, in transit, delivered, failed, cancelled), estimated delivery time, actual pickup time, and actual delivery time. We also store district, zone, and outlet trading name information for franchise and corporate deliveries.
2.3 Location and Geolocation Data
We collect precise geolocation data (latitude and longitude coordinates) in the following scenarios: (a) when drivers submit proof-of-delivery photos, pickup photos, and invoice photos through the mobile application — the device's GPS coordinates are captured at the time of photo capture and stored alongside the photo and associated delivery record; (b) live rider location coordinates during active deliveries for real-time tracking on the customer-facing tracking page — these are updated periodically while the delivery is in transit; (c) geocoded pickup and drop-off coordinates derived from postal codes to enable route mapping. For walker-type drivers, live location tracking is subject to explicit PDPA consent captured within the app. Drivers may revoke this consent at any time, which disables live tracking for their deliveries.
2.4 Photos, Media, and Documents
We collect and store the following types of photos and media: proof-of-delivery photos (confirming successful delivery), pickup photos (confirming parcel collection), invoice and receipt photos (for business records), failure documentation photos (showing why a delivery could not be completed), customer signatures (captured on the driver's device at delivery), driver profile photos, vehicle documentation photos (log cards, rental proof, bicycle photos), and expense claim receipt photos. Photos may include embedded GPS metadata at the time of capture. Photos received via Telegram or WhatsApp messenger integrations are also stored with associated delivery records, including any location data shared alongside the photo. All photos are stored in secure cloud storage and are accessible only to authorized roles within the platform.
2.5 Communication and Chat Data
We collect and store chat messages between drivers, customers, and administrators, including text content, media attachments (photos, videos, audio files with inline playback), and message timestamps. Messages are organized by delivery record to provide context for each shipment's communication history. We also collect and store notification logs for automated status updates sent to customers via email or messaging platforms (Telegram, WhatsApp), including the notification content, recipient, and delivery status. Chat attachments retain location metadata where captured. Read/unread status of messages is tracked to display notification badges.
2.6 Financial and Payment Data
For wallet and payment processing, we collect and store: payout amounts per delivery, transaction types (earning, payout, bonus, deduction, withdrawal, top-up), transaction status (pending, paid, failed), payment hold timestamps (24-hour hold policy for withdrawals and payouts), bank account details (bank name, account number, account holder name) for driver payouts, bank statement upload URLs for verification, expense claim amounts with receipt photos and claim type (parking, toll, fuel, other), Stripe payment identifiers for wallet top-ups, and payout reprocessing flags. Stripe processes all card payments — we do not store full card numbers or CVV codes. Financial data is used solely for calculating driver earnings, processing payouts, managing expense claims, and handling wallet top-ups.
2.7 Google Sheets Integration Data
When you connect your Google Sheets account to BTS, we access and process the following data from your authorized spreadsheets: column headers, row values containing delivery information (pickup and dropoff addresses, contact numbers, customer names, item descriptions, remarks, driver assignments), and spreadsheet metadata. We write back to your spreadsheets the following data: delivery status updates, tracking codes, timestamps (pickup time, delivery time), and driver assignment information. This integration uses Google's OAuth 2.0 API with scoped access limited to spreadsheets (scope: https://www.googleapis.com/auth/spreadsheets) and drive file metadata read access (scope: https://www.googleapis.com/auth/drive.metadata.readonly). We do not access, store, or process any Google account data beyond what is strictly necessary to read from and write to the spreadsheets you explicitly authorize.
2.8 Google Sign-In Data
When you sign in using your Google account, we receive your Google account email address, full name, and Google profile picture URL. We use this information solely for authentication and account identification. We do not access your Google Contacts, Google Drive files (beyond authorized Sheets), Gmail messages, Google Calendar, or any other Google services. We do not use your Google sign-in data for advertising or analytics purposes.
2.9 Device and Usage Data
We automatically collect certain technical information including: IP address, browser type and version, device type and identifier, operating system, screen resolution, access times and duration, pages viewed, clicks and interaction events, referring URL, and general usage statistics. We use this information for security monitoring, fraud prevention, analytics, and Service improvement. We may also collect crash reports and error logs to diagnose and fix technical issues.
2.10 Cookies and Tracking Technologies
We use cookies and similar tracking technologies (such as web beacons and local storage) to operate and maintain the Service. Cookies are small data files stored on your device. We use the following types of cookies: (a) Authentication cookies — to maintain your login session and authenticate your requests; (b) Functional cookies — to remember your preferences such as selected role or language; (c) Security cookies — to detect and prevent fraudulent activity and unauthorized access; (d) Analytics cookies — to understand how users interact with the Service and improve its features. You can control cookies through your browser settings, but disabling them may prevent you from using certain features of the Service. We do not use cookies for targeted advertising.
3. How We Use Your Information
We use the collected information for the following purposes, each described in detail:
- Service Delivery and Order Management: To create, assign, track, and manage deliveries from pickup through delivery; generate tracking codes and QR codes for parcel scanning; provide real-time shipment tracking to customers; maintain complete delivery status history; and process delivery updates including pickup, in-transit, delivered, failed, and cancelled statuses.
- Driver Onboarding and Management: To onboard and verify drivers; collect and verify vehicle documentation; assign deliveries to appropriate drivers based on vehicle type and availability; track driver availability and status (available, on delivery, offline); monitor driver location during active deliveries for real-time tracking; calculate and process driver earnings and payouts; and manage sub-driver hierarchies for super-drivers.
- Customer Notifications and Tracking: To send automated delivery status updates, tracking links, and estimated time of arrival (ETA) notifications to recipients via email, SMS, or messaging platforms (Telegram, WhatsApp); to provide a public tracking page where customers can view live delivery status and rider location; and to collect customer delivery preferences (home delivery, leave at location, reschedule) and feedback/ratings.
- Google Sheets Two-Way Synchronization: To import delivery data from connected spreadsheets for bulk creation of delivery records; to synchronize delivery statuses, tracking codes, and timestamps back to the user's spreadsheets; and to maintain data consistency between the platform and the user's Google Sheets data.
- Proof of Delivery and Documentation: To capture, store, and display geotagged photos (proof-of-delivery, pickup, and invoice photos) and customer signatures as evidence of successful delivery or documentation of failed delivery attempts; to organize photos by delivery, date, and building for efficient archival and retrieval; and to support photo matching via Telegram and WhatsApp messenger integrations.
- Financial Processing and Wallet Management: To process wallet top-ups via Stripe; calculate driver earnings per delivery; manage expense claims (parking, toll, fuel, other) with receipt verification; process bank transfers for driver payouts with a 24-hour hold policy; manage wallet balances and transaction histories; and generate financial reports for drivers, clients, and finance administrators.
- Real-Time Chat and Communication: To facilitate real-time chat between drivers, customers, and administrators with support for text messages and media attachments (photos, videos, audio); to send in-app and email notifications for new chat messages; and to maintain communication records associated with each delivery for customer support and dispute resolution.
- Role-Based Access Control and Security: To enforce role-based access controls ensuring users can only access data appropriate to their role and tenant; to prevent unauthorized cross-tenant data access; to comply with PDPA requirements for location tracking consent; to maintain audit trails of user actions; and to detect and prevent fraudulent or unauthorized activity.
- Reporting and Analytics: To generate operational reports including delivery counts, success rates, driver performance, financial summaries, and work reports; to analyze usage patterns and platform performance; and to improve our Service features, reliability, and user experience.
- Account Management: To create and manage user accounts; process invitations to join the platform; assign and switch user roles; manage company/tenant registrations and approvals; and handle account deletion requests.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds, in accordance with the Singapore PDPA and, where applicable, the GDPR:
- Contractual Necessity: Processing is necessary to provide the delivery management services you requested when registering for an account. This includes creating delivery records, assigning drivers, processing payments, and providing tracking information.
- Legitimate Interests: We process data to operate and secure our platform, prevent fraud and unauthorized access, maintain delivery records for business operations and audit compliance, and provide customer support. Our legitimate interests include platform security, service reliability, and legal compliance.
- Consent: We collect location data, photos, and media with your explicit consent. Drivers provide consent when enabling device location services, uploading proof-of-delivery photos, or connecting Telegram/WhatsApp accounts. Driver PDPA consent for walker location tracking is explicitly captured within the app and can be revoked at any time. Google Sheets integration requires explicit OAuth 2.0 authorization, which can be revoked through your Google Account settings.
- Legal Obligation: We may process data to comply with applicable laws, regulations, court orders, government requests, or other legal processes. This includes retaining financial records for tax and audit purposes.
- Vital Interests: We may process data to protect the vital interests of any person, including in emergency situations involving delivery drivers or customers.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share information only in the following circumstances:
- Role-Based Access Within the Platform: Data is shared within the platform based on user roles and tenant isolation. Clients see only deliveries belonging to their company (tenant). Drivers see only deliveries assigned to them. Customers see only their own delivery tracking information. Finance personnel see financial and delivery data across their organization. Administrators have full visibility across their organization. Sub-drivers see only deliveries assigned by their parent super-driver. This is enforced through row-level security (RLS) policies.
- Google Sheets Integration: When you connect a Google Sheets account, delivery data is exchanged between the platform and your authorized spreadsheets. Data flows both ways: delivery information is imported from your sheets, and delivery statuses, tracking codes, and timestamps are written back. This access is scoped to spreadsheets you explicitly authorize during the OAuth flow and can be revoked at any time through your Google Account security settings.
- Payment Processors (Stripe): We share payment data with Stripe for processing wallet top-ups via credit/debit card. Stripe receives your card details directly through their secure payment form — we never see or store full card numbers. We share transaction metadata (amounts, descriptions) with Stripe to process payments. Bank account details for driver payouts are stored securely and used solely for processing bank transfers.
- Messaging Platforms (Telegram, WhatsApp): Delivery status updates, tracking links, and photos may be sent via Telegram or WhatsApp to drivers and customers who have opted into these communication channels. Drivers who use the Telegram bot integration share their Telegram chat ID and any photos or messages sent to the bot. Location data shared via Telegram's location-sharing feature is stored with the associated photo.
- Cloud Hosting and Infrastructure Providers: We engage cloud hosting providers for application hosting, database storage, and file storage. These providers have access to your data solely to perform services on our behalf and are bound by contractual confidentiality and data protection obligations. Data is stored in secure data centers with appropriate certifications.
- Analytics and Monitoring Services: We may use analytics and error monitoring services to understand platform usage and diagnose technical issues. These services may receive aggregated, de-identified usage data and error reports.
- Legal Compliance and Law Enforcement: We may disclose information when required by law, court order, government regulation, or valid legal process, or to protect the rights, property, or safety of BTS, our users, or others. We will disclose only the minimum information necessary to comply with the request.
- Business Transfers: If BTS is involved in a merger, acquisition, asset sale, financing, or similar transaction, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our platform before your information is transferred and becomes subject to a different privacy policy.
6. Third-Party Services and Links
The Service integrates with or contains links to the following third-party services. Each third-party service has its own privacy policy, and we encourage you to review them:
- Google OAuth / Google Sign-In: Used for authentication. Google's Privacy Policy applies to data collected by Google during the sign-in process. We receive only your email, name, and profile picture from Google.
- Google Sheets API: Used for two-way spreadsheet synchronization. Google's API User Data Policy and Google's Privacy Policy apply. We access only the spreadsheets you explicitly authorize.
- Stripe: Used for payment processing. Stripe's Privacy Policy applies to payment data. We do not store full card details.
- Telegram Bot API: Used for driver communication and photo capture. Telegram's Privacy Policy applies to messages and data processed by Telegram.
- WhatsApp Business API: Used for customer and driver notifications. WhatsApp's Privacy Policy applies to messages processed by WhatsApp.
- Leaflet / OpenStreetMap / Carto: Used for map rendering and geocoding on the tracking page. These services may receive postal codes or addresses for geocoding purposes.
Our Service may contain links to external websites that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. We recommend reviewing the privacy policies of any third-party websites you visit.
7. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter, as described below:
- Account Information: Retained for as long as your account is active. Upon account deletion request, we will delete or anonymize your personal account information within 30 days, subject to legal retention obligations.
- Delivery Records: Retained for the duration of the business relationship and for a minimum of 7 years thereafter to comply with accounting, audit, and legal requirements. Delivery records include order information, addresses, status history, and timestamps.
- Photos and Media: Proof-of-delivery photos, pickup photos, invoice photos, and failure documentation photos are retained alongside the associated delivery record for the same retention period. Customer signatures are retained with the delivery record.
- Location Data: GPS metadata associated with photos is retained alongside the delivery record. Live rider location data is updated in real-time and is replaced with each update; historical location tracking data is not permanently stored beyond the active delivery period.
- Financial and Transaction Data: Wallet transactions, payout records, expense claims, and bank account details are retained for a minimum of 7 years to comply with tax, accounting, and regulatory requirements.
- Chat Messages: Chat messages between users are retained for the duration of the associated delivery record and for a reasonable period thereafter for dispute resolution and customer support purposes.
- Google Sheets Data: Data imported from your Google Sheets is retained as delivery records in the platform. Upon disconnection of the Google Sheets integration, we cease all access to your spreadsheets, but previously imported data remains as business operational data.
- Device and Usage Logs: Technical logs, IP addresses, and usage data are retained for up to 12 months for security monitoring and troubleshooting purposes.
You may request deletion of your account and associated data at any time, subject to legal retention obligations. To request data deletion, please contact us using the information in Section 12.
8. Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
- Row-Level Security (RLS): Role-based access control ensuring users can only access data appropriate to their role and tenant. Clients cannot access other clients' data. Drivers cannot access other drivers' data. Cross-tenant data access is prevented at the database level.
- Encryption in Transit: All data transmission is encrypted using HTTPS/TLS protocols. API communications between the client application and our servers are secured with industry-standard TLS.
- Secure Authentication: We use OAuth 2.0 authentication for all user sessions, including Google Sign-In. Passwords are hashed using industry-standard algorithms and are never stored in plaintext.
- Scoped API Access: Third-party integrations (Google Sheets, Stripe, Telegram) use scoped OAuth 2.0 access with the minimum permissions necessary. We do not request broad or unnecessary scopes.
- Secure File Storage: Uploaded photos and documents are stored in secure cloud storage with access controls. Public file URLs are used only for photos that need to be shared (e.g., proof-of-delivery photos visible to authorized users).
- Service Role Isolation: Backend functions that process sensitive operations (payments, role assignments, tenant management) run with elevated service role permissions that are isolated from end-user access.
- Regular Security Reviews: We conduct periodic security reviews, access audits, and vulnerability assessments to identify and address potential security issues.
- Access Logging: We maintain logs of critical system access and administrative actions for audit and security monitoring purposes.
Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but strive to protect your data using commercially acceptable means. In the event of a data breach, we will notify affected users and relevant authorities in accordance with applicable laws.
9. Your Privacy Rights
Depending on your jurisdiction (Singapore PDPA, EU GDPR, California CCPA, or other applicable laws), you may have the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you, including what data has been collected, how it is being used, and with whom it has been shared.
- Right to Rectification/Correction: You may request correction of inaccurate, incomplete, or outdated personal data. You can update your profile information directly within the app or by contacting us.
- Right to Erasure/Deletion: You may request deletion of your account and associated personal data, subject to legal and regulatory retention requirements. Certain data (e.g., financial records) may need to be retained for compliance purposes.
- Right to Withdraw Consent: You may withdraw consent for location data collection, photo capture, and PDPA walker tracking at any time. Drivers can revoke PDPA consent for live location tracking within the app. Google Sheets access can be revoked through your Google Account settings. Withdrawing consent may limit certain Service features.
- Right to Data Portability: You may request export of your delivery data and personal information in a structured, machine-readable format (such as CSV or JSON).
- Right to Object: You may object to the processing of your personal data for specific purposes, including direct marketing (which we do not engage in) or profiling.
- Right to Restrict Processing: You may request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data or assess a legal objection.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection authority (e.g., the Personal Data Protection Commission of Singapore) if you believe we have violated your data protection rights.
- Do Not Track Signals: Our Service does not currently respond to "Do Not Track" (DNT) browser signals, as there is no industry consensus on how to interpret them. We will update this policy if and when a standard for DNT is established.
To exercise any of these rights, please contact us using the information in Section 12. We will respond to your request within 30 days.
10. Google API Data Usage and Compliance
If you connect your Google account (Google Sheets or Google Sign-In) to BTS, the following terms apply in accordance with Google's API Services User Data Policy, Google OAuth 2.0 limited use requirements, and Google's Privacy Policy:
- Scope of Access: We request only the minimum Google API scopes necessary to provide the requested functionality. For Google Sheets sync, we request
https://www.googleapis.com/auth/spreadsheets(read and write spreadsheet content) andhttps://www.googleapis.com/auth/drive.metadata.readonly(list spreadsheets to select from). For Google Sign-In, we requestopenid,email, andprofilescopes. - Purpose Limitation: We access your Google API data solely to: (a) import delivery information from your spreadsheets, (b) write back delivery statuses, tracking codes, and timestamps to your spreadsheets, and (c) authenticate your identity using your Google email and name. We do not use Google API data for any other purpose.
- No Advertising: We do not use Google API data, including any personal data or content obtained through the Google APIs, for advertising purposes. We do not share Google API data with advertising networks or use it to serve personalized ads.
- No Transfer to Other Google Services: We do not transfer Google API data to other Google services or Google APIs. Data accessed through one Google API is not combined with data from another Google service.
- No Sharing with Third Parties: We do not share Google API data with third parties, except as necessary to provide the Service (e.g., displaying imported delivery data to authorized users within your organization) or as required by law.
- Limited Use: Our use of Google API data complies with the Google OAuth 2.0 Limited Use requirements. We only access Google API data when necessary to provide the features you have requested, and we do not use it for independent purposes.
- Data Minimization: We access only the specific spreadsheet rows and columns needed to create and update delivery records. We do not access spreadsheets or data that you have not explicitly authorized.
- Revocation of Access: You can revoke BTS's access to your Google account at any time through your Google Account security settings (myaccount.google.com → Security → Third-party apps with account access). Upon revocation, we immediately cease all access to your Google Sheets data. Previously imported delivery records remain in the platform as business operational data, but no further data is accessed from your Google account.
- No Storage of Google Credentials: We do not store your Google password. Authentication tokens are stored securely and are used only to access the Google APIs you have authorized. Tokens are automatically refreshed as needed and revoked upon disconnection.
- Google Privacy Policy: Google's Privacy Policy (available at policies.google.com/privacy) describes how Google collects, uses, and discloses data when you use Google services. We encourage you to review Google's Privacy Policy.
11. International Data Transfers
Your information, including personal data, may be transferred to and maintained on servers located outside of your state, province, country, or jurisdiction where data protection laws may differ. By using the Service, you consent to such transfers. We take reasonable steps to ensure that your data is protected in accordance with this Privacy Policy and applicable law, regardless of where it is stored. We use cloud infrastructure providers that maintain appropriate data protection certifications and comply with international data transfer frameworks.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data in accordance with the GDPR and applicable data transfer mechanisms, including Standard Contractual Clauses (SCCs) where applicable. If you are located in Singapore, we comply with the PDPA and applicable data transfer requirements.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, your personal data, or your privacy rights, please contact our Data Protection Officer:
Beacon Track Solution
Email: beacontracks.app@gmail.com
Website: beacontracksolution.com
Subject Line: "Privacy Policy Inquiry" or "Data Protection Request"
For data access, correction, or deletion requests, please include your account email address and a description of the request. We will verify your identity before processing your request.
13. Children's Privacy
The Service is not intended for use by children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to delete such information and terminate the child's account. By using the Service, you represent that you are at least 13 years old (or the minimum age in your jurisdiction) and that you have the legal capacity to agree to this Privacy Policy.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the features of our Service. We will notify users of material changes by posting the updated policy on this page and updating the "Last updated" date at the top. For significant changes, we may also send an email notification to registered users. We encourage you to review this page periodically to stay informed about how we collect, use, and protect your information.
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the updated Privacy Policy, you may discontinue using the Service and request deletion of your account.
15. Data Controller and Data Processor
For the purposes of applicable data protection laws (including the PDPA and GDPR):
- BTS acts as a Data Controller for the personal data we collect to operate the Service (e.g., account information, delivery data, financial data).
- When clients use the Service to manage their own delivery operations, clients act as Data Controllers for the personal data of their customers (e.g., recipient names, addresses, phone numbers) that they input into the Service. BTS acts as a Data Processor on behalf of these clients, processing customer data only on the client's instructions and in accordance with this Privacy Policy.
- Our third-party service providers (Stripe, Google, cloud hosting) act as Data Processors or Sub-Processors on our behalf, and are bound by data processing agreements that ensure appropriate data protection.