Privacy Policy
Last updated:
TL;DR: No login is required. Tracking numbers are used for the lookup and temporary cache, but are excluded from analytics and advertising URLs and encrypted in operational logs for up to 30 days. Google storage remains denied; Analytics uses cookieless measurement and AdSense may serve limited ads.
1. Who We Are
TrackParcel (trackparcel.in) is a free, independent parcel tracking platform for India. It is operated by an individual developer and is not affiliated with any courier company. Our contact email is function(){throw Error("Attempted to call CONTACT_EMAIL_DISPLAY() from the server but CONTACT_EMAIL_DISPLAY is on the client. It's not possible to invoke a client function from the server, it can only be rendered as a Component or passed to props of a Client Component.")}.
2. What Data We Collect
TrackParcel is designed to minimise personal data.
Tracking queries: When you enter a tracking number, it is sent in a private POST request to our server, and our server then sends the tracking number to the selected courier, which is necessary to retrieve your tracking result. For one courier (Shree Anjani), the official tracker only supports plain HTTP, not encrypted HTTPS, so that carrier's docket number is sent to its own server without TLS in transit. Only if the operator explicitly enables an optional fallback, used when the official tracker is unreachable, will the tracking number instead be sent to an unaffiliated third-party data source for that carrier; this is separate from, and unrelated to, advertising. For DTDC, certain carrier failures automatically trigger a lookup through ParcelsApp, an unaffiliated tracking provider, which receives the tracking number to retrieve a fallback result. This DTDC fallback does not require a separate user opt-in and is unrelated to advertising. The tracking number may be used as the key for a temporary private cache entry, but it is not attached to a TrackParcel account or placed in analytics or advertising page URLs. For troubleshooting and carrier-health diagnosis, operational scrape logs store the tracking number encrypted at rest for up to 30 days. It can be decrypted only in an authenticated administrator view. See Section 5 for cache duration.
Server and security logs: Infrastructure providers may process ordinary request metadata such as IP address, browser type, requested page and timestamp. TrackParcel's carrier-health logs do not store an IP address beside an encrypted tracking number and are retained for no more than 30 days. A separate security-event log may retain an IP address for up to 90 days when automated abuse is detected; it does not contain tracking numbers.
Contact form: If you contact us via email or the contact form, we store your name, email address, and message solely to respond to your enquiry.
Analytics: Google Analytics uses Consent Mode with analytics storage denied. It sends cookieless basic measurements, and tracking-result identifiers are excluded from analytics URLs.
Advertising: We use Google AdSense to deliver, measure, and optimise advertising. Google and its advertising partners may use cookies, local storage, device identifiers, and similar technologies for ad delivery, frequency control, measurement, fraud prevention, and—where permitted—personalisation. See Section 4 for details.
3. What We Do Not Collect
We do not: - Require you to create an account or log in - Keep a permanent, account-linked tracking history - Sell your tracking numbers or contact-form data - Send tracking numbers to Google Analytics or AdSense
Tracking numbers are shared outside TrackParcel as described in Sections 2 and 5: with the courier you select, with ParcelsApp when the automatic DTDC fallback runs, and with an unaffiliated data source when the operator-enabled Shree Anjani fallback is active. These tracking requests are separate from analytics and advertising.
4. Cookies
TrackParcel uses the following cookies and local storage:
Essential and preference storage: "trackparcel-dark" remembers your colour preference. "tp_browser" is a Secure, HttpOnly, SameSite=Strict cookie that expires after 24 hours and binds anti-automation tokens to one browser. A recent-search list may be stored in sessionStorage for the current tab only and expires when the tab closes; entries older than 24 hours are discarded.
Google AdSense advertising
TrackParcel uses Google AdSense to show advertising and Google Analytics to measure aggregate site usage. Analytics and advertising storage remain denied, so Analytics sends cookieless measurements and Google may serve limited ads. Google may still process IP address, browser and device information, approximate location, referring pages, and interactions for measurement, delivery, security, and fraud prevention.
Google may use and share advertising data with its advertising partners in accordance with Google's Privacy & Terms. TrackParcel does not present a custom consent popup or enable analytics or advertising storage.
You can review or change how Google personalises ads at My Ad Center, opt out of participating companies through the Digital Advertising Alliance, and block or clear cookies through your browser settings.
5. How Tracking Works
When you submit a tracking number, our server makes a request to the relevant courier's public tracking API or website on your behalf and returns the result to you. Your IP address may be visible in the request to the courier.
Result caching: To improve performance and reduce load on carrier systems, tracking results are temporarily cached on the private TrackParcel server using self-hosted Valkey. Cache duration varies by shipment status — from 5 minutes (out for delivery) up to 30 days (delivered) — and an entry may still be served, clearly labelled as stale, for up to 24 hours past its freshness window when the carrier cannot be reached. Cached data contains the tracking number and shipment-status information returned by the courier. Cache entries expire automatically and are never sold.
Result display: Searches remain on the current page and do not put the tracking number in the browser address bar or history. Legacy share links under /t/ are retired and redirect to the homepage without reading or displaying parcel data.
6. Third-Party Services
TrackParcel uses the following third-party services: - Hosting: Our website is hosted on a private server and proxied through Cloudflare for traffic delivery and CDN caching. Cloudflare may process request metadata as per their privacy policy at cloudflare.com/privacypolicy. TrackParcel does not use Cloudflare Turnstile for parcel searches. - Google Analytics and AdSense: Analytics receives cookieless measurements while storage is denied, and AdSense may serve limited ads. Google may process device, usage, approximate-location, and advertising-interaction data for measurement, delivery, security, and fraud prevention. See Google's advertising privacy information and Google's Privacy Policy. - OpenStreetMap: When a tracking result contains enough recognised scan locations to show the optional approximate journey map, the browser requests map tiles from OpenStreetMap. That request reveals the visitor's IP address and the approximate map area being viewed. The map uses city-centre estimates, not live parcel GPS coordinates.
7. Data Retention
Encrypted carrier-health logs are retained for a maximum of 30 days and are available only to an authenticated administrator. Security events created when automated abuse is detected are retained for up to 90 days. Contact form messages are kept for as long as needed to resolve an enquiry. Tracking-result cache entries expire automatically according to Section 5, including the 24-hour stale window; TrackParcel does not keep a permanent, account-linked tracking history.
8. Your Rights
You have the right to: - Request a copy of any personal data we hold about you - Request deletion of any personal data we hold about you - Opt out of personalised advertising through the NAI or DAA links in Section 4
To exercise any of these rights, email us at function(){throw Error("Attempted to call CONTACT_EMAIL_DISPLAY() from the server but CONTACT_EMAIL_DISPLAY is on the client. It's not possible to invoke a client function from the server, it can only be rendered as a Component or passed to props of a Client Component.")}. We will respond within 30 days.
9. Children's Privacy
TrackParcel is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of TrackParcel after changes constitutes your acceptance of the updated policy.
11. Contact
For any privacy-related questions or requests, contact us at:
function(){throw Error("Attempted to call CONTACT_EMAIL_DISPLAY() from the server but CONTACT_EMAIL_DISPLAY is on the client. It's not possible to invoke a client function from the server, it can only be rendered as a Component or passed to props of a Client Component.")}