Tumr ("we", "us") operates a commerce and logistics platform: online storefronts (Tumr Stores), merchant tools (Tumr Sell), on-demand dispatch (Tumr Send), carrier fleet management (Tumr Go), a public map (Tumr Maps), rider and field-agent mobile apps, and the APIs behind them. This Privacy Policy explains what information we collect, why, and the choices you have.
1. Information you give us
- Account information. Name, email address, phone number, country, password (stored only as a hash), and the role you register for (merchant, carrier, rider, agent, dispatcher, or customer).
- Business information. Store names, business registration details, payout bank details, and—for merchants who connect one—a WhatsApp Business number.
- Identity verification. Riders, carriers, and agents may be asked for government ID, photos, and vehicle details (KYC) before they can take deliveries or earn payouts.
- Order and delivery information. Delivery addresses, recipient names and phone numbers, package descriptions, order contents, and delivery instructions.
- Communications. Messages you send to support, reviews, and—if you are a customer chatting with a store on WhatsApp—the content of those conversations.
- Payment information. Card details are encrypted and sent to Flutterwave for processing. We receive transaction references and status; we do not store your full card number.
2. Information collected automatically
- Device and usage data. IP address, browser type, pages viewed, API requests, and timestamps, used to secure and operate the platform.
- Location. With your permission, rider and agent apps share GPS position while on active deliveries so dispatch and customers can track progress. Customers may share a location to autocomplete a delivery address.
- Cookies and similar storage. We use a small number of essential cookies (for example, a session cookie that keeps you signed in across Tumr apps) and browser storage for authentication tokens. See the Cookie Policy for details.
3. How we use information
- Create and secure your account and authenticate you across Tumr products
- Process orders, dispatch deliveries, and confirm handovers (including OTP/QR confirmation)
- Operate wallets, escrow holds, payouts, refunds, and the transaction ledger
- Verify identity, prevent fraud, and enforce platform rules
- Send transactional messages: order updates, delivery status, receipts, security alerts (email, SMS, push, WhatsApp)
- Provide AI-assisted features you invoke (for example product-description drafts)
- Resolve disputes, comply with legal obligations, and keep financial records
- Improve reliability and performance of the platform
4. When we share information
- With the people delivering your order. Riders and carriers see the pickup/drop-off address, recipient name, and contact details needed to complete a delivery.
- With merchants. Stores see the customer details attached to their own orders.
- With service providers that process data for us, limited to what they need:
- Flutterwave — payment processing, transfers, and payout recipient validation
- Meta (WhatsApp Cloud API) — optional WhatsApp ordering for stores that enable it
- LocationIQ / OpenStreetMap Nominatim — address autocomplete and geocoding
- Routing engines (e.g., OSRM) — route and ETA calculation for deliveries and maps
- Google Firebase Cloud Messaging — push notifications to mobile apps
- AI providers (Google Gemini, Groq, Mistral) — only when you use an AI feature; prompts are sent to generate the requested output
- Cloud hosting and email/SMS delivery providers that run our infrastructure
- For legal reasons — to comply with law, enforce our terms, or protect rights and safety.
- With your direction — for example when you share a tracking link or a private map link.
We do not sell your personal information.
5. International transfers
Some providers listed above process data outside your country. Where data crosses borders we rely on the provider's own safeguards and process only what the feature requires.
6. Data retention
We keep your information while your account is active. When you delete your account we deactivate it and anonymize your personal details. Some records must be retained afterward where the law or legitimate operations require it—for example, wallet and ledger entries, completed shipment records, and fraud-prevention logs—kept for the periods required of financial and delivery records.
7. Security
We encrypt traffic in transit (TLS), store passwords hashed, sign webhook payloads, and restrict internal access by role. No system is perfectly secure; if we learn of a breach affecting your data we will act in line with applicable law.
8. Your rights and controls
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to withdraw consent for optional processing.
- Account settings. Update profile details, sessions, and notification preferences at any time in Tumr Account.
- Privacy controls. Manage marketing and optional data-sharing preferences under Account → Privacy & data.
- Data export and deletion. Request an export or delete your account under Account → Data. Deleting your account is described in that flow, including what is retained.
- Cookies. Manage non-essential preferences in Account → Privacy & data or via your browser.
You can also email [email protected] to exercise a right. We may need to verify your identity first.
9. Marketing communications
We send transactional messages as part of the service. Optional marketing messages are sent only where you have enabled them, and every marketing email includes an unsubscribe link. Turning off marketing does not affect service messages (receipts, delivery updates, security alerts).
10. Children's privacy
Tumr is a business and commerce platform intended for adults. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
When we make material changes we will update the version and effective date shown above, and where appropriate notify you in-app or by email. Previous versions remain available in the document archive.
12. Contact us
Privacy questions or requests: [email protected] General support: [email protected]
Version history
- v2026-09Effective 21 September 2026Current