Privacy & Third-Party API Usage Policy
Last Updated: 20/8/2025
1. Introduction
Fare Freight (“we,” “us,” or
“our”) is committed to protecting the privacy and security of our
users’ information. This Privacy & Third-Party API Usage Policy
(“Policy”) explains how we collect, use, protect, and share
information when you use our platform to integrate with third-party carriers
and brokers through their APIs.
By using our services, you agree to the practices described
in this Policy. If you do not agree with this Policy, please do not use our
services.
2. Information We Process
2.1 Types of Information
We process only the minimum information necessary to provide
our shipping integration services:
- Shipment
Information: Pickup and delivery addresses, package dimensions,
weight, contents description, and service preferences
- Technical
Information: API credentials you provide, request/response logs for
troubleshooting pricing discrepancies (retained for 30 days only), and
system performance metrics
- Account
Information: Business name, contact details, and authorized user
information
2.2 Information We Do NOT Collect
- Personal
browsing history
- Payment
or financial information (all payments are handled directly between you
and the carrier/broker)
- Credit
card or banking details
- Unnecessary
personal identifiers
- Information
unrelated to shipping services
3. Third-Party API Integration
3.1 Purpose of Integration
We integrate with third-party shipping providers (including
but not limited to BigPost, KIS, NFM, and Cario) exclusively for:
- Retrieving
real-time shipping rates
- Processing
shipment bookings
- Generating
shipping labels and documentation
- Tracking
consignment status
- Managing
returns and exceptions
- Accessing
carrier-specific services and features
Important Note: Our integration capabilities are
limited to the functionality and endpoints that carriers and brokers make
available through their publicly published APIs. We cannot access or provide
features beyond what these third parties offer through their official API
documentation.
3.2 Security Measures
All API communications are:
- Encrypted
using industry-standard HTTPS/TLS protocols
- Authenticated
using credentials you provide and control
- Subject
to rate limiting and monitoring for unusual activity
- Logged
for troubleshooting purposes only (particularly for pricing discrepancy
resolution)
4. Data Handling Principles
4.1 Data Minimization
We adhere to strict data minimization principles:
- Process
only data necessary for the requested service
- Do
not retain shipment data beyond operational requirements
- Automatically
purge API logs after 30 days
- Never
cache rate responses beyond the active session
4.2 Carrier Data Isolation
- Each
carrier integration operates in complete isolation
- Carrier-specific
data is never shared between different carriers
- API
responses are segregated and access-controlled
- No
cross-carrier data aggregation or analysis occurs
4.3 User Control
You maintain full control over:
- Which
carriers you connect to our platform
- The
API credentials used for each integration
- When
to revoke access to specific carriers
- Deletion
of your account and associated data
5. Data Security
5.1 Technical Safeguards
We implement industry-standard security measures including:
- Encryption
at rest and in transit
- Regular
security audits and vulnerability assessments
- Access
controls and authentication protocols
- Secure
credential storage using encryption and key management systems
- Regular
security updates and patch management
5.2 Operational Security
- Staff
access limited on a need-to-know basis
- Regular
security training for all personnel
- Incident
response procedures in place
- Business
continuity and disaster recovery planning
6. Data Sharing and Disclosure
6.1 No Sale of Data
We never sell, rent, or trade your information to third
parties for marketing purposes.
6.2 No Payment Processing
We do not process, store, or have access to any payment
information. All financial transactions occur directly between you and the
relevant carrier or broker through their own payment systems.
7. Compliance
7.1 Australian Privacy Law
We comply with:
- Privacy
Act 1988 (Cth)
- Australian
Privacy Principles (APPs)
- Notifiable
Data Breach Scheme
- State
and territory privacy laws where applicable
7.2 Industry Standards
We align with:
- ISO
27001 information security standards
- Industry-specific
compliance requirements for logistics and shipping
8. Updates to This Policy
We may update this Policy periodically. We will notify you
of material changes via:
- Email
notification
- Prominent
notice on our platform
- Request
for renewed consent where required
9. Contact Information
For questions, concerns, or complaints about this Policy or
our privacy practices:
Privacy Officer
Fare Freight Pty Ltd
Email: info@farefreight.com.au
10. Definitions
- API:
Application Programming Interface
- Personal
Information: Information that can identify an individual
- Processing:
Any operation performed on data
- Third-Party:
Any entity other than you or Fare Freight
- Publicly
Published API: Official application programming interfaces made
available by carriers and brokers for third-party integration