Tariff and policies
Data, privacy and security
What QCS holds about you and your customers, who can see it, how long it is kept, and how the platform is secured.
QCS Private Limited holds personal data because a courier cannot work without it: a name, a phone number and an address are the delivery. This page says plainly what is held, who sees it and for how long. It is a working description of the platform, not a substitute for the terms you agreed to.
What is held
Who can see it
- You see your own parcels and nothing else. Every merchant query is scoped to your merchant id in the database layer, not merely hidden in the interface.
- A rider sees only the stops on their own run, and only while the run is live.
- Back-office staff see what their role grants. Access to merchant and customer personal data in the back office is written to the activity log.
- Public tracking shows your customer a partial name, the area rather than the full address, and no phone number.
How long it is kept
How the platform is secured
- Passwords are hashed with Argon2id and a per-user salt. They are never recoverable, by anyone.
- API secrets are hashed with Argon2id and a pepper, shown once at creation and never retrievable.
- Session tokens are stored only as a hash; the raw token exists only in your cookie, which is http-only, secure and host-only.
- Two-factor authentication is required for the super admin and finance roles.
- A rider session is bound to the device it was issued on, and a mismatch revokes it.
- The database and the cache listen only on the server’s loopback interface and are absent from the firewall.
- Stored secrets such as SMTP credentials, OAuth tokens and bank details are encrypted at rest.
- Outbound requests to a URL you supply pass an SSRF guard that refuses private, loopback, link-local and metadata addresses.
- Uploads are validated by extension, declared type and magic bytes, size-capped, and stored under randomised keys. Private evidence is served only through an authorised application route.
Your customers’ rights
A consignee can ask what QCS holds about a parcel addressed to them, and can ask for a correction. Route the request to cs@qcs.com.pk with the tracking number. QCS does not delete a delivery record on request, because it is a financial and legal record of a transaction between you and your customer, but it will correct inaccurate contact details and will stop sending notifications on request.
Your obligations
- Give QCS only the data needed to deliver. Do not put sensitive personal information in the rider instructions field.
- Tell your customers that their name, phone and address are shared with a courier. That notice is yours to give, not ours.
- Keep your portal logins personal. Invite staff as their own users rather than sharing one password, so the audit trail means something.
- Treat an API key or a connection secret as a credential. A leaked key can read your customers’ addresses.