Privacy Policy — Torod
Applies to: Torod mobile application (Android package com.torodexpress.torod,
and iOS app named Torod), version 1.0.0 and later.
1. Who We Are
This Privacy Policy explains how the application ("Torod" or "we"), owned by Starship International Shipping Company, collects, uses, stores, and protects your personal information when you use the Torod application ("the App").
| Item | Details |
|---|---|
| Application | Torod |
| Parent Company | Starship International Shipping Company |
| Country of Registration | Republic of Yemen |
| Registered Address | Al-Misbahi, Hadda, Sana'a, Yemen |
| Privacy Contact | contact@torodexpress.com |
| Privacy Policy Link | https://torodexpress.com/privacy-policy |
| Account Deletion Link | https://torodexpress.com/account-deletion |
Torod is a shipping and logistics application that allows you to create and track shipments, manage saved addresses, request e-shopping services, verify your identity, and pay for services via local electronic wallets or in cash.
2. Scope of this Policy
This policy applies to the Torod application on Android and iOS, and to the Torod backend services that the app connects to. It does not apply to third-party applications or websites you may access through the app (such as WhatsApp or our social media pages), as those entities are governed by their own privacy policies.
3. Age Requirement
This application is intended for users aged 18 and older. We do not knowingly collect any personal information from anyone under the age of 18. If we become aware that we have collected personal information from a minor, we will delete it. If you believe a minor has provided us with personal information, please contact us at contact@torodexpress.com.
4. Information We Collect
We only collect the information necessary to operate the shipping service and keep it functional, and we do not collect any data for advertising, marketing, or behavioral profiling purposes.
The app collects a limited amount of diagnostic data—crash reports and names of screens you open—for the sole purpose of detecting and fixing crashes. This is fully explained in Section 4.3.
4.1 Information You Provide to Us
Account Information (Mandatory)
- Mobile Phone Number — Used as the primary identifier for your account, and to send a One-Time Password (OTP) during login and registration
- Full Name
- Account Type (Individual or Business)
- Company Name — For business accounts only
- Email Address — Optional
We do not use passwords; authentication is done entirely via verification codes sent to your phone number.
Addresses (Optional)
When you choose to save an address or attach it to a shipment, we collect:
- Contact name and their phone number for the address
- Email address for the address (optional)
- Country, governorate, city, and a text description of the address
- Geographical coordinates (latitude and longitude) for the address location
- Address code or postal reference, when available
You can enter this information manually, select the location on the map, or—if you grant permission—import a name and phone number from a contact you select from your device's contact list. We do not read or upload your contact list at all; only the single contact you explicitly select is used, and strictly for filling out the address form.
Shipment Information
When creating a shipment, we collect the details you enter, including: sender and recipient addresses, package weight and dimensions, description of contents, options for fragility and identity verification upon delivery, declared value of goods, special instructions, and preferred delivery time window.
For business accounts on domestic shipments, you may also ask us to collect the product's price from the recipient upon delivery. In that case we record that you requested collection and the amount to be collected, so that our delivery staff collect the correct sum and we can settle it with you.
Identity Verification Documents (Mandatory)
These documents are required to verify your account and enable you to create shipments, in compliance with applicable legal terms and conditions governing shipping operations.
- Document type (National ID or Passport)
- Document number and issuance date
- Image of the front of the document, and the back where applicable
- Selfie image
This information is treated as sensitive personal information. See Section 9 for how it is protected, and Section 10 for retention periods.
Files and Images
Images you capture with the camera or select from your photo library, and documents you select from your device storage, when uploaded for identity verification, international shipping documents, product requests, or business product catalogs. We do not access the camera or photo library until the moment you actually choose to attach an image or document.
Payment Information
Torod does not operate a wallet for you and does not hold a balance on your behalf. Payment for your shipments is made either in cash or through one of the local Yemeni electronic wallets—such as Jaib or Floosak—which are the payment methods available in Yemen. The app displays the list of supported wallet providers, and you choose whichever one you want to pay with. Each provider is an independent company that we neither own nor operate.
The app does not support any international payment method: no credit cards, no debit cards, no bank accounts, and no international payment gateways.
To pay with a wallet, you enter:
- The phone number registered with the wallet you are paying from
- Depending on the provider, either a purchase code (PIN) you obtain from that provider, or a one-time confirmation code the provider sends you
These two values serve a single purpose: they are passed through our payment gateway to the wallet provider to authorize that one payment. We do not save them to your account, we do not keep them once the payment attempt concludes, and they are never reused for a later payment. The provider's response back to us contains only a transaction reference and whether the payment succeeded or failed.
We do not read your wallet balance, statement, or transaction history, and we have no access to or control over your account inside the wallet service. We do not request, collect, process, or store credit card numbers, bank account details, or your wallet account password.
Invoices. Our system generates the invoice and transaction record for both cash and wallet payments. What we retain against your shipment is the amount, whether it was paid in cash or by wallet, the name of the wallet provider used, the date, our own transaction reference, and the payment status. See Section 10 for retention periods.
Support Communications
When you contact us via the in-app support option, we may direct you to WhatsApp or our phone line. WhatsApp is used solely to receive feedback and resolve technical issues. Any information you send through that channel is processed strictly to respond to your inquiry.
4.2 Information We Collect with Your Consent
Precise Location
With your consent, the app reads your device's location via GPS for one purpose only: to center the map on your current location, and convert the coordinates into a readable address when adding or selecting an address. The location is only read while you are actively using the map or addresses screen; the app does not track your location in the background.
Push Token
When you enable notifications, we record a device-specific token for Firebase Cloud Messaging, along with the
platform name (android or ios). This token allows us to send shipment status updates
to your device, is not related to advertising, is not used for tracking, and is deleted from our servers when
you log out.
Camera (Scanning QR Codes and Barcodes)
The app can scan shipment tracking codes using the camera. The scanning process takes place on your device; camera images used for scanning are not recorded, stored, or transmitted.
4.3 Diagnostic and Stability Data (Collected Automatically)
The app uses Google Firebase Crashlytics and Google Firebase Analytics to detect and diagnose crashes. Without them, any glitch you experience would be invisible to us and unfixable. This is the only automatic data collection performed by the app.
Crash and Error Reports. When the app crashes or encounters an error, a report is recorded and sent the next time you open the app, including:
- Technical description of the crash — error type, message, and stack trace
- The name of the screen you were on at the moment of the crash
- App version, device model, operating system version, and device language
- Device state at the time of the crash — available memory and storage space, screen orientation, and whether the device is rooted or jailbroken
- A random identifier generated by Crashlytics for your app installation
- Your Torod account ID, so we can link the support request you send us with the crash you experienced
Usage Context Accompanying Those Reports. So that a crash report can be read in context, we also record:
- Names of screens you open, and basic session events like app open or update
- Device model, OS version, and language
- An approximate location (country and city) inferred by Google from your IP address
- A resettable identifier generated for your app installation, and your Torod account ID
Screen names are recorded as route templates, not the actual URL you visited. The shipment details screen,
for example, is recorded as /shipment-details/:id without ever including the shipment number
itself. Nothing you type, no address, no shipment contents, no image, and no identity document is ever
included in any crash report or usage log.
We use this data solely to keep the app working: to alert us to a crash, reproduce and fix it, and ensure the fix is successful. We do not use it for advertising, marketing, profiling, or making any decisions about you, and it is not shared with advertisers.
The app does not even have an advertising ID to collect; the Android advertising ID permission was explicitly removed from the app, and ad personalization is disabled in both Android and iOS versions.
If you prefer not to send any diagnostic data, uninstalling the app will stop it. You can also contact us at contact@torodexpress.com.
4.4 Information We Do Not Collect
Specifically, the app does not:
- Use any SDKs for advertising, marketing, or attribution
- Collect an advertising ID, nor does it request the permission that allows it
- Build behavioral profiles, measure your activity for marketing purposes, or track you across other apps and websites
- Use the diagnostic data described in Section 4.3 for any purpose other than maintaining the app's functionality
- Read your contact list, call logs, text messages, or files, except what you explicitly choose
- Collect biometric data, health data, or precise background location
- Collect credit card numbers, debit card numbers, or bank account details, or use any international payment method
- Operate a wallet or hold a balance for you, or access the balance, statement, or transaction history inside your wallet provider
- Store the wallet phone number or the purchase/confirmation code you enter to authorize a payment
- Sell your personal information to any party for any purpose
5. Device Permissions
| Permission | Platform | Reason for Use | Mandatory? |
|---|---|---|---|
| Location (Precise / Approximate) | Android, iOS | Show your current location on the map, and convert coordinates to an address when adding or selecting one | Optional — you can enter addresses manually |
| Camera | Android, iOS | Scan shipment QR codes and barcodes; take photos for identity verification or shipping documents | Optional |
| Photo Library (Read) | Android, iOS | Attach an existing photo for identity verification or to a shipment | Optional |
| Photo Library (Add) | iOS | Save a shipment QR code or label image to your gallery when you choose to do so | Optional |
| Notifications | Android, iOS | Send shipment and account status updates | Optional |
| Internet Access | Android, iOS | Communicate with Torod servers | Mandatory |
| Vibration | Android | Alert upon receiving a notification | Optional |
You can grant or revoke any optional permission at any time from your device's system settings. Revoking a permission may disable the associated feature, but it does not delete previously provided data.
6. How We Use Your Information
We use your information exclusively for the following purposes:
- Creating and operating your account — Registering you, sending verification codes, logging you in, and maintaining your session
- Providing the shipping service — Creating, pricing, routing, dispatching, tracking, and delivering shipments
- Communicating with you regarding your shipments — Via status updates through notifications, and contact from the operations team when necessary to complete delivery
- Processing payments — Passing the wallet phone number and confirmation code you enter to the wallet provider you chose, in order to authorize a single payment, then recording the result and issuing the invoice and transaction record for cash and wallet payments alike
- Verifying your identity — To verify your identity and enable you to use shipping services, in accordance with applicable legal terms and conditions
- Providing technical support — Answering your inquiries and resolving issues
- Fulfilling legal and regulatory obligations — Including maintaining financial records and responding to legal requests, as detailed in Section 8
- Protecting service security and integrity — Detecting abuse, fraud, and prohibited contents in shipments
- Maintaining app functionality — Using crash reports and screen names described in Section 4.3 to detect, reproduce, and fix crashes, and ensure the fix reaches you
We do not use your information for advertising, marketing profiling, making automated decisions with legal effects, or selling it to any party.
7. Legal Basis for Processing
We process your personal information based on the following grounds, in accordance with the laws of the Republic of Yemen:
- Contract Execution — Processing necessary to provide the shipping service you requested, including verifying your identity to enable you to create shipments
- Your Consent — For optional features like access to location, camera, and notifications, which you can withdraw at any time from your device settings
- Compliance with a Legal Obligation — Including verifying user identities in accordance with applicable shipping regulations, maintaining financial records, and cooperating with legal requests from competent authorities
- Legitimate Operational Interest — Securing the service against fraud and prohibited content, and diagnosing crashes and errors to maintain the app's usability
8. Information Sharing and Disclosure
We do not sell your personal information, nor do we share it with any third party for commercial, advertising, or marketing purposes.
Your information may only be disclosed in the following limited circumstances:
A) Within Torod and Starship International Shipping Company. Our operations, delivery, and support staff access shipment and address information to the extent necessary to pick up, transport, and deliver your shipments.
B) Legal, Judicial, and Security Authorities. We reserve the right to disclose personal information, including identity verification documents, exclusively to authorized government or security authorities, and only in exceptional cases, such as:
- Responding to an official legal or judicial request
- Suspecting illegal contents within a shipment
This is done to ensure public safety and comply with applicable laws. Identity documents are never shared with any commercial entity.
C) Technical Service Providers Necessary to Operate the App. These providers process limited technical data on our behalf and are not permitted to use it for their own purposes:
| Provider | Data Processed | Purpose |
|---|---|---|
| Google — Firebase Cloud Messaging | Device-specific push token, platform name, and notification content | Delivering notifications to your device |
| Google — Firebase Crashlytics | Crash and error reports as described in Section 4.3: error type and stack trace, screen name, app version, device model and OS version, device state, installation ID, and Torod account ID | Detecting and diagnosing app crashes |
| Google — Firebase Analytics | Screen names, session and app open events, device model and OS version, language, approximate location inferred from IP, installation ID, and Torod account ID | Providing context that makes crash reports diagnosable, and measuring app stability |
| Google — Maps, Places, and Geocoding Services | Map coordinates, and search queries for addresses entered in the map screen | Displaying maps, suggesting addresses, and converting coordinates to readable addresses |
| Hostinger | Hosting Torod servers and stored app data | Running our servers and database |
The use of Google services is subject to Google's Privacy Policy. Documents you upload for international shipments are used internally by Torod and Starship International Shipping Company only and are not shared with any commercial party.
D) The Electronic Wallet Provider You Choose to Pay With. When you pay by wallet, and only for that payment, the following is passed through our payment gateway to the provider you selected:
| Recipient | Data Passed | Purpose |
|---|---|---|
| The local wallet provider you selected (for example Jaib or Floosak) | The wallet phone number you entered, the purchase or confirmation code, and the amount due | Authorizing and confirming the single payment you initiated |
Nothing is sent to any provider you did not select, and no shipment contents, addresses, or identity documents are ever sent to a wallet provider. Each provider handles this data under its own privacy policy and its own terms, as an independent company. Cash payments involve no third party at all.
9. Data Security
We are committed to protecting your personal data and storing it securely:
- All communications between the app and our servers are via encrypted HTTPS connections
- Authentication tokens and your profile data are stored locally on your device in the operating system's secure storage—the encrypted vault backed by Android Keystore on Android, and iOS Keychain on iOS, accessible only after unlocking your device
- Sessions use short-lived access tokens that automatically renew, and are automatically terminated if the token cannot be renewed
- Identity documents and selfies are stored in an encrypted format, accessible only by authorized personnel whose duties require it for verification purposes
- Server configurations and credentials are kept within a protected setup environment, not inside the app itself
No method of transmission or storage is absolutely secure, and while we take these measures to protect your information, we cannot guarantee absolute security. In the event we become aware of a breach affecting your personal information, we will take appropriate action and notify affected users when necessary.
10. Data Retention Period
We retain your data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by applicable legal and regulatory requirements.
| Data Type | Retention Period |
|---|---|
| Account Data | Until you submit an account deletion request |
| Shipment Data and Operational Records | For the period necessary to comply with legal, regulatory, and operational requirements, after which it is deleted or anonymized whenever possible |
| Financial Records (Invoices and Transactions) | At least five years, in accordance with applicable laws. These records contain the amount, payment method, wallet provider name, date, transaction reference, and status — not your wallet credentials |
| Wallet Phone Number and Purchase/Confirmation Code | Not retained — passed to your chosen wallet provider to authorize that one payment, and not stored in your account |
| Identity Verification Documents (KYC) | Until account deletion, or for the period required by law |
| Push Token | Deleted from our servers when you log out or delete your account |
| Crash and Error Reports | Retained by Google Firebase Crashlytics for up to 90 days, then automatically deleted |
| Screen Names and Session Events | Retained for the duration configured in our Firebase project, up to a maximum of 14 months, then automatically deleted |
| Cached Data on Your Device | Deleted when you log out or uninstall the app |
11. Account Deletion and Your Rights
How to Delete Your Account
You can request to delete your account at any time through:
- Inside the App — Open "Profile" → "Delete Account", enter your phone number, and confirm the request with the verification code sent to you
- Via Web — Submit a request via https://torodexpress.com/account-deletion
- Via Email — Email us at contact@torodexpress.com from the phone number or email associated with your account
What Happens When You Delete Your Account
Deletion takes effect immediately upon confirming the verification code. There is no grace period, and the request cannot be undone once submitted.
- Your account data is stripped of anything that identifies you, so it is completely unlinked from you and you can no longer be identified by it
- Your identification documents, selfies, and uploaded files are permanently deleted
- Financial records are retained for the period mandated by law as detailed in Section 10, in a format that satisfies our regulatory obligations
- You will lose access to your shipment history and any information associated with the account, which cannot be recovered thereafter
Your Other Rights
Subject to applicable laws in the Republic of Yemen, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information — your name, email, addresses, and company name can be updated by contacting technical support
- Withdraw your consent for optional processing, including permissions for location, camera, photo library, and notifications, through your device settings
- Request the deletion of your account and associated data, as detailed above
- Object or file a complaint regarding how we handle your information by contacting us at contact@torodexpress.com
We will respond to requests sent to contact@torodexpress.com within a reasonable time. We may ask you to verify your identity before fulfilling the request, to protect your account.
12. Data Stored on Your Device
The app locally stores the following on your device:
- Encrypted Secure Storage — Authentication tokens and your profile data
- Local Cache — Service catalog data only: branch locations, service areas and cities, delivery shift timings, the list of supported wallet providers (their names and logos), and promotional banners. This is stored to make the app faster and usable when connectivity is poor. It contains nothing personal to you — your addresses, shipments, and invoices are not cached, and are fetched from our servers each time you view them
- App Preferences — State of onboarding screens, selected account type, and interface settings
- Pending Crash Reports — When the app crashes, the report described in Section 4.3 is written to your device and sent the next time you open the app
All this data is deleted when you log out or uninstall the app.
13. Information About Other People
When creating a shipment, you may enter another person's name, phone number, and address, for example, as a recipient. By providing this information, you confirm that you have the right to share it with us for the purpose of arranging the shipment. We only use it to complete pickup and delivery, and retain it in accordance with the shipment retention rules in Section 10.
14. Data Location and International Transfer
Torod, a subsidiary of Starship International Shipping Company, operates in the Republic of Yemen, and this policy is governed by the laws of the Republic of Yemen.
Our servers and stored app data are hosted with Hostinger. The technical service providers mentioned in Section 8 operate international infrastructure, meaning limited technical data—such as your device's push token, map and address queries, and crash reports and screen names described in Section 4.3—may be processed on servers outside Yemen. We only use these providers to the extent necessary to operate the map and notification features in the app and to keep it functional.
15. Activity Tracking
The app records the names of screens you open and basic session events for one single purpose: so that a crash report—when it occurs—shows the path you took leading up to it. Without this, the report tells us what broke without telling us what you were doing, which is usually not enough to fix it.
This recording is diagnostic and intentionally limited:
- Screen names are recorded as route templates — the shipment details screen is
/shipment-details/:id, and the shipment number itself is never recorded - We do not record what you type, search for, click on, or the contents of the screen
- We do not measure the time you spend on a screen for marketing purposes, build behavioral profiles, or keep a browsing history
- We do not track you across other apps or websites, and the app has no advertising ID that allows this
- This data is never used for advertising or marketing purposes, and is not shared with advertisers
Section 4.3 details exactly what is recorded, and Section 10 details the retention period. Otherwise, the only records we keep are the operational records necessary to run the service: your account, addresses, shipments, and transactions.
16. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in the app, our practices, or the law. When a material change is made, we will update the "Last Updated" date at the top of this document, publish the revised policy at https://torodexpress.com/privacy-policy, and make it available within the app. If the change materially affects how we handle your personal information, we will notify you via the app or through a notification. Your continued use of the app after the revised policy takes effect constitutes your acceptance of it.
17. Contact Us
For any question, request, or complaint regarding this Privacy Policy or your personal data:
Starship International Shipping Company (Torod App)
Al-Misbahi, Hadda, Sana'a, Yemen
Email: contact@torodexpress.com
Privacy Policy: https://torodexpress.com/privacy-policy
Account Deletion: https://torodexpress.com/account-deletion
Torod App — Starship International Shipping Company | contact@torodexpress.com