Skip to main content
QCSQuick Courier ServiceQCS — Quick Courier Service, home

Tariff and policies

Data, privacy and security

What QCS holds about you and your customers, who can see it, how long it is kept, and how the platform is secured.

Merchants, their customers and auditors5 min readPrintable handbook

QCS Private Limited holds personal data because a courier cannot work without it: a name, a phone number and an address are the delivery. This page says plainly what is held, who sees it and for how long. It is a working description of the platform, not a substitute for the terms you agreed to.

What is held

Data categories
CategoryExamplesWhy
Merchant accountBusiness name, contact name, email, phone, CNIC or NTN, bank account title and IBAN.To open an account, raise invoices and pay out COD.
Consignee dataName, phone numbers, delivery address, area, landmark and coordinates.To deliver the parcel and to tell the customer where it is.
Parcel dataWeight, dimensions, contents description, declared value and the cash to collect.To price, carry and reconcile the parcel.
Operational evidenceScan events, proof of delivery photographs, signatures, refusal photographs and rider cash declarations.To prove what happened, and to settle a dispute on evidence rather than argument.
MessagesThe WhatsApp and email notifications sent about a parcel, with their delivery state.To show that a customer was told, and when.
Audit trailWho changed what, when, from which address.Because every mutation in QCS is audited and the log is append-only.

Who can see it

  • You see your own parcels and nothing else. Every merchant query is scoped to your merchant id in the database layer, not merely hidden in the interface.
  • A rider sees only the stops on their own run, and only while the run is live.
  • Back-office staff see what their role grants. Access to merchant and customer personal data in the back office is written to the activity log.
  • Public tracking shows your customer a partial name, the area rather than the full address, and no phone number.

How long it is kept

Retention
DataKept
Parcel and ledger recordsFor as long as the law requires financial records to be retained.
Notification message bodiesMessage bodies containing personal data are purged after 180 days. The delivery metadata is kept for audit.
Proof of delivery and evidence filesWith the parcel, served only through an authorised route.
Audit log, status history, scan events and journal entriesPermanently. They cannot be updated or deleted.
Session recordsUntil expiry or revocation, then kept as a dated record of the sign-in.

How the platform is secured

  • Passwords are hashed with Argon2id and a per-user salt. They are never recoverable, by anyone.
  • API secrets are hashed with Argon2id and a pepper, shown once at creation and never retrievable.
  • Session tokens are stored only as a hash; the raw token exists only in your cookie, which is http-only, secure and host-only.
  • Two-factor authentication is required for the super admin and finance roles.
  • A rider session is bound to the device it was issued on, and a mismatch revokes it.
  • The database and the cache listen only on the server’s loopback interface and are absent from the firewall.
  • Stored secrets such as SMTP credentials, OAuth tokens and bank details are encrypted at rest.
  • Outbound requests to a URL you supply pass an SSRF guard that refuses private, loopback, link-local and metadata addresses.
  • Uploads are validated by extension, declared type and magic bytes, size-capped, and stored under randomised keys. Private evidence is served only through an authorised application route.

Your customers’ rights

A consignee can ask what QCS holds about a parcel addressed to them, and can ask for a correction. Route the request to cs@qcs.com.pk with the tracking number. QCS does not delete a delivery record on request, because it is a financial and legal record of a transaction between you and your customer, but it will correct inaccurate contact details and will stop sending notifications on request.

Your obligations

  • Give QCS only the data needed to deliver. Do not put sensitive personal information in the rider instructions field.
  • Tell your customers that their name, phone and address are shared with a courier. That notice is yours to give, not ours.
  • Keep your portal logins personal. Invite staff as their own users rather than sharing one password, so the audit trail means something.
  • Treat an API key or a connection secret as a credential. A leaked key can read your customers’ addresses.

Questions we get asked

Does QCS use my customer list for anything else?No. Consignee data is used to deliver the parcel, to notify the customer about that parcel, and to settle a dispute about it. It is not marketed to, sold or shared with another merchant.
Where is the data stored?On QCS infrastructure, in a database that is not reachable from the internet. Backups are encrypted.
Can I get my data out?Yes. Export your parcels and your ledger to CSV from the portal at any time, or pull them over the API.

Next