Privacy Policy
Shipwize and Circles Privacy Policy
Last Updated: September 9, 2026
1. Introduction
Welcome to Shipwize Services Ltd and Circles Logistics Ltd (“we,” “us,” “our,” or collectively “the Companies”).
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you interact with our services — including the websites shipwize.com and circlesja.com, our customer dashboards and mobile applications, and the systems behind them (collectively, the “Services”).
Our platform has four parts, and this Policy covers all of them:
- The public websites, including the one you are reading now.
- The customer dashboard and mobile applications — on the web at dashboard.circlesja.com — where you sign in to see your suite number, packages, invoices, balances, and rewards.
- The service that connects them — the interface our websites and apps use to read and write your account, package, and billing records.
- The internal desktop application our staff use at our Miami warehouse and Jamaica branches to receive, bill, release, and audit packages.
All four work on the same customer and package records, so information you give to one is visible to the others.
Where something is true of only one of them, we say which. In this Policy this website means the public site at circlesja.com, and the dashboard means the signed-in customer application at dashboard.circlesja.com, which Section 9 describes on its own.
It also outlines your rights under the Data Protection Act 2020 (Jamaica), the General Data Protection Regulation (GDPR – EU 2016/679), the UK Data Protection Act 2018, and the California Consumer Privacy Rights Act (CPRA 2023).
By using our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Scope
This Privacy Policy applies to all digital and offline interactions between you and the Companies, including:
- Shipwize's and Circles' websites, customer dashboards, and mobile apps
- Customer portals, logistics tracking systems, and payment interfaces
- Package handling, billing, and release at our warehouse and branches, including the work our staff do on your record in our internal application
- Customer-service communications, social-media interactions, and offline registrations that reference this Policy
This Policy does not apply to third-party websites, services, or applications that we do not control.
3. Definitions
- Account – a unique profile you create to access our Services.
- Affiliate – an entity that controls, is controlled by, or is under common control with either Company.
- Application – the Shipwize or Circles software application you install or use.
- Companies / we / us / our – Shipwize Services Ltd and Circles Logistics Ltd, both headquartered in Kingston, Jamaica.
- Cookies – small text files stored on your device to remember preferences or session information.
- Dashboard – the signed-in customer application at dashboard.circlesja.com, described in Section 9.
- Device – any hardware that can access our Services (computer, smartphone, tablet, etc.).
- Personal Data – information relating to an identified or identifiable individual (as defined in Section 2 of the Jamaica Data Protection Act 2020).
- Service Provider – any third party that processes data on our behalf under a written contract.
- Suite Number – the mailbox identifier we assign to your Account, which you add to your U.S. shipping address so that arriving packages can be matched to you.
- Tracking Number – the carrier's tracking number for a package, and the internal tracking number we generate for it once we receive it.
- Usage Data – technical data automatically collected when you use the Services (e.g., IP address, browser type, session duration).
- WhatsApp Notifications – the optional package-status messages described in Section 6.
4. What We Collect
A. Personal Data You Provide
When you register, ship with us, or contact us, we may collect:
- Name, email address, and phone number (and a secondary phone number, if you give one)
- Date of birth, and gender, where you choose to provide them
- Taxpayer Registration Number (TRN)
- Shipping, billing, or delivery addresses
- The branch you want to collect from — or, if you would rather we brought your packages to you, the delivery address and any directions you give us for finding it
- Account credentials — a password, or a passkey you register on your own device for the mobile application
- Company name and business type, if you register a business account
- The people you authorize to collect packages on your behalf, and the details needed to identify them at the counter
- Payment or transaction information
- Identity and customs documents you upload or hand in — for example mailbox authorization forms, customs declaration forms, and supplier invoices for a package
- Your WhatsApp number and consent choice, if you opt in to WhatsApp Notifications (Section 6)
- Communications or support messages you send us, and the notes our staff record about your account or a package
B. Data We Create While Providing the Service
In the course of shipping and billing for you, we generate:
- Your suite number
- Package records — carrier and internal tracking numbers, description, weight, declared value, tariff classification, status history, and the manifest and branch a package is routed through
- Billing records — invoices, receipts, freight, duty, GCT, fuel surcharge, insurance and customs-clearance charges, payments, and refunds
- Your account balance, store credit and its history, reward points, and referral credits
- Referral relationships — which account referred you, or which accounts you referred
- Audit trails recording which member of staff changed a record, when, and why
C. Automatically Collected Data
We automatically gather Usage Data such as:
- IP address, browser, and operating system
- Device identifiers, and the sign-in credentials registered to a device
- Pages visited, duration, and actions taken
- Diagnostic, security, and performance logs, including sign-in attempts. A registration that does not go through is recorded with the contact details that were entered — email address, phone numbers, chosen pickup location, and company name — together with the reason it failed, so that we can see what went wrong and help you. The password is never written to a log.
The rate estimator on this website is worth naming as an exception: it asks for no personal information. It sends only the commodity, declared value, and weight you type in, and the result is not stored against an account.
The estimate form inside the dashboard is not the same thing. It runs within your account, so the request carries your customer identifier and the figure you are shown is the one that applies to your account.
D. Third-Party Sources
We may receive limited data from logistics partners, carriers, customs brokers, payment processors, marketing affiliates, or social media integrations, in accordance with their privacy policies.
5. How We Use Your Information
We use Personal Data only for lawful purposes, including:
| Purpose | Legal Basis / Justification |
|---|---|
| Provide, maintain, and improve our Services | Contractual necessity (DPA § 22 (1)(b)) |
| Manage your Account and bookings | Legitimate interest / Contract performance |
| Process payments, shipments, and deliveries | Contract performance / Legal obligation |
| Match arriving packages to you using your suite number and account details | Contract performance |
| Prepare customs declarations and verify your identity for customs and mailbox authorization | Legal obligation |
| Operate store credit, reward points, and referrals | Contract performance |
| Send status updates about your packages by email | Contract performance |
| Send package status notifications by WhatsApp | Consent (DPA § 24 (1)) |
| Communicate with you (customer support, updates) | Legitimate interest |
| Send marketing messages (opt-in only) | Consent (DPA § 24 (1)) |
| Comply with tax, customs, and anti-fraud laws | Legal obligation |
| Keep audit records of who changed an account, package, or financial record | Legal obligation / Legitimate interest |
| Analyze usage and improve functionality | Legitimate interest; consent (DPA § 24 (1)) for the website analytics and embedded-map cookies described in Section 10 |
| Manage business transfers or restructuring | Legitimate interest |
| Enforce terms and protect against fraud or misuse | Legitimate interest / Legal obligation |
We do not sell or rent your Personal Data.
6. WhatsApp Package Notifications
You can choose to receive package updates on WhatsApp. This section explains what that choice means for your personal information. If you never opt in, nothing in this section applies to you and we never send a message to your number.
Opting in takes two steps. Ticking the box — on our website, in the mobile application, at our counter, or on the signup form — does not switch notifications on. It records that you have asked to be asked, and it causes exactly one WhatsApp message: a request to confirm. Package notifications begin only after you confirm inside WhatsApp, by pressing the confirmation button or replying with an opt-in keyword. Until you do, you receive nothing further.
Opting in shares your number with Meta. The messages are carried by the WhatsApp Business Platform, operated by Meta Platforms. To send you a message we give Meta your phone number in international format and the content of that message, and Meta tells us whether it was sent, delivered, read, or failed. Message content and delivery state therefore pass through Meta, which handles them as the operator of WhatsApp under its own terms. We do not control WhatsApp itself.
What we send. A notification contains the package status it is about, the tracking numbers of the packages concerned, and your suite number. We never send payment or card details, bank information, or identity-document data over WhatsApp.
When we send. Four package statuses trigger a notification:
- Received In Miami
- Arrived In Jamaica
- Ready for Pickup
- Delivered to Client
That is roughly one message per package per stage. Where several of your packages reach the same stage at about the same time, they are combined into a single message rather than sent one after another. No other status sends a WhatsApp message, and WhatsApp is in addition to — not a replacement for — the status emails you already receive.
Withdrawing consent. You can stop the messages at any time, through any of the routes you could have used to start them: turn the setting off in your account on our website or in the mobile application, ask a member of staff at our counter, or reply STOP to us in WhatsApp. Words such as UNSUBSCRIBE, CANCEL, END, and QUIT are treated the same way, and blocking our number in WhatsApp also stops them. Withdrawal is recorded against your account, not only in WhatsApp, so we stop preparing messages for you rather than merely stopping their delivery.
Changes we record without you asking. If Meta reports that your number is not reachable on WhatsApp — a landline, for example — we mark it unreachable and stop trying, so you are not left waiting for messages that can never arrive. If Meta reports that you have blocked us, we record that as a withdrawal. Both are recorded as changes made in response to the provider rather than as choices you made. Changing your notification number returns your consent to the pending state and we ask you to confirm again, because a new number has confirmed nothing.
The consent trail. We keep an add-only record of every change to this setting: what it became, when it changed, which route it came through (website, mobile application, counter, WhatsApp, or signup), and — where you replied in WhatsApp — the exact word or button you sent. Nothing in that record is edited or removed. It exists so that we can show when and how consent was given or withdrawn if you or Meta ask. It is an internal audit record: it is not displayed in your account, and access to it is limited to senior staff.
What it costs. We do not charge for notifications, but your mobile carrier or data plan may charge you for the data used to receive them. Delivery depends on WhatsApp and on your network; the service-side conditions are in Section 6 of our Terms and Conditions.
Our legal basis for sending these messages is your consent. You can withdraw it at any time without affecting any other part of your account or the service we provide you.
7. Package Records, Customs Documents, and Uploads
A package we receive for you creates a record that stays with your account: its tracking numbers, a description of the goods, weight, declared value, tariff classification, the manifest it travelled on, the branch it was routed to, and the dates it moved between statuses. That record is what our billing, customs, and reporting work is based on.
Some documents come from you. Mailbox authorization forms, customs declaration forms, and supplier invoices that you upload or hand in are held with your account or with the package they relate to. We use them to establish that you are entitled to the mailbox, to declare goods correctly, and to bill the right amount. Where a customs authority, a broker, or a carrier requires a document or a declaration before your goods can move or be released, we provide it — that is a legal obligation rather than a choice, and it is why we ask for a TRN and identity documents in the first place.
Two of those documents are made at sign-up rather than uploaded by you. Before your registration is submitted, the dashboard shows you a mailbox authorization form (United States Postal Service Form 1583) and a customs authorization form addressed to the Jamaica Customs Agency, both filled in from what you typed, with your typed name in place of a signature. You read them and tick to confirm. Your browser then turns those two pages into PDF files, and they are stored on your customer record. They exist because we cannot lawfully receive mail on your behalf, or have goods declared for you, without them.
Package and billing records are edited only through paths that record who made the change, when, and — where a reason is required — why.
8. Store Credit, Rewards, and Referrals
Three balances can sit on your account, and each keeps its own history.
- Store credit is a balance we hold for you and apply against what you owe. Every adjustment is recorded with the amount, the reason, the member of staff who made it, and the time.
- Reward points are earned as your packages are paid for — one point per package — and can be redeemed for store credit at a rate we set. The record of a reward names the package and payment it came from, so the same package cannot be counted twice.
- Referral credit records a relationship between two accounts. If you sign up with someone's referral code, we permanently record that your account was referred by theirs, and the same record exists on their side. The credit is earned when the referred customer's first package arrives in Jamaica, and we record when it was earned and which transaction it was spent on. We do not disclose the identity of a referral code's owner to the person using it.
If you give us your date of birth, we may use it to apply a birthday reward to your account. You are not required to provide it.
9. Your Account on the Customer Dashboard
Almost everything you do with us after you register happens in your account on the customer dashboard at dashboard.circlesja.com. It is a different application from the website you are reading now, and because it is where most of your personal information is actually handled, it is described here on its own.
Signing in. You sign in with your email address and password. Registration, sign-in, and asking for a password-reset code each pass a bot check before we act on them; Section 10 explains what that check sends to Cloudflare. A forgotten password is reset with a code we email to the address on your account. We never display your password back to you, and we cannot read it.
What the dashboard shows you. Your suite number and the U.S. address to have purchases sent to; your packages and the stage each one has reached; your invoices and your receipts; what you owe; your store credit, your reward points, and your referral code and link. It also carries the rate estimate form described in Section 4.
What you can change there. Your name and middle initial, your secondary phone number, your company, and your address; the phone number on your account; whether you collect from a branch or want packages delivered, and the delivery address and directions if you do; the list of people you authorize to collect on your behalf; your password; your email address; and whether you receive WhatsApp notifications (Section 6). You can also redeem reward points for store credit. The only thing the dashboard asks you for about an authorized collector is a name.
Changing your email address. The change is confirmed before it takes effect. We email a short code to the new address and apply the change only when you enter that code. The code, and the count of how many times it has been tried, are held on our servers rather than in your browser. While you are typing a new address the dashboard asks us whether it is already in use, so that it can tell you before you submit — which means an address you type there reaches us even if you never save it. The only thing we answer is whether it is available.
How your information travels. Your browser does not contact the system that holds your records. Every request for your data is made by our own server, which holds the key to your session in a cookie your browser will not hand to scripts on the page (Section 10). That is why a page in the dashboard can show your records without the credentials for reaching them ever being present in the page.
When a page fails. If part of the dashboard fails to render, the error and the address of the page it happened on are passed to the diagnostic facility of the platform that hosts the dashboard, where that facility is present, so that the fault can be found. This happens only when something breaks.
What the dashboard does not do. It takes no payment and asks for no card or bank details. Apart from the bot check in Section 10, and the X advertising pixel in Section 10 if you accepted it on either site, it loads nothing from a third party: no analytics, no embedded maps, and no fonts from anyone else's servers. It does not ask for your location and does not use your camera or microphone. It has no button that deletes your account or exports your data — for either of those, write to us using the details in Section 18 and we will handle it as a rights request under Section 14.
10. Cookies & Tracking Technologies
We use cookies and similar tools to operate our websites and to understand how they are used.
Types of cookies used:
- Strictly Necessary – the sign-in session on the dashboard, security, the bot-protection check on registration, sign-in, and password reset, which is provided by Cloudflare, and the cookie that records the answer you give to the question below. The first three are required for the pages that use them to work at all, and the last is required to carry out the answer you gave, so none of them is part of the choice described below.
- Preferences – a setting kept so that a page behaves the way you left it. The only one we keep is which reward you starred in the dashboard, and it is held in your browser's local storage rather than in a cookie. It holds a setting and no identifier, and it is described in full below.
- Analytics – Google Analytics 4, which records the pages visited and session activity on our marketing websites so that we can see which pages are useful.
- Embedded map – the Google Maps view in the locations section of circlesja.com. It is loaded from Google and sets Google’s own cookies, and loading it shares your IP address with Google in the same way that visiting any Google-hosted page would.
- Advertising – the X conversion pixel, operated by X Corp., the company behind the service formerly called Twitter. It loads a script from static.ads-twitter.com, which may set a first-party cookie named _twclid on circlesja.com as well as cookies on X’s own domains. It records that a visitor reached our website and, on the customer dashboard, that an account was created, so that we can measure how the advertisements we run on X perform.
Your choice. The first time you open either circlesja.com or the customer dashboard — whichever of the two you reach first — a banner on that site asks whether you accept the analytics, advertising, and embedded-map cookies. The question is asked once per browser: both sites record your answer in the same place and read it from there, so the site you did not start on already has your answer and does not ask you again. It offers Accept and Reject as two buttons of the same size, side by side, and neither is chosen for you. Google Analytics is not loaded and sets no cookie unless you select Accept. The Google Maps view is not loaded either; the branch address, opening hours, and a link that opens Google Maps in a new tab are shown in its place, and a button lets you load the map for that visit alone without accepting anything. The X advertising pixel is not loaded either, neither here nor on the customer dashboard, and sets no cookie unless you select Accept on one of the two sites. Closing the banner without answering is not consent: nothing optional is loaded, nothing is recorded, and the banner is shown again the next time you open a page.
What your answer stores. Your answer is kept by your own browser, in a cookie named shipwize_cookie_consent. It holds three things: the word “granted” or “denied”, the date and time you answered, and a version number for the question you were asked. It contains no identifier of any kind, and nothing in it tells us apart from one another: two people who answer the same way at the same moment store exactly the same value. The cookie is set for circlesja.com and its subdomains, so a single answer covers this website and the customer dashboard at dashboard.circlesja.com and you are not asked the same question twice. It is marked Secure, so it is sent only over HTTPS, and SameSite=Lax, so it is not sent along with requests started by other websites; because it is a cookie, it does travel to our servers with requests to those addresses, where it is used for nothing but deciding what a page may load. Your browser also keeps a copy of the same three items in its local storage for circlesja.com, under the name shipwize.cookie-consent, so that the site still honours your answer if the cookie is blocked or deleted; that copy is never transmitted. If you answered before we began using the cookie, the answer already in your browser is carried over rather than asked again. Clearing your browsing data for the site removes both. We treat an answer as current for six months, after which the banner asks again.
Changing your mind. Select Cookie Preferences in the footer of any page on circlesja.com to bring the banner back and answer again, or Cookie Preferences in the footer of the customer dashboard, which shows the answer currently recorded and changes it in one step. Both write the same answer, so a change made in either place applies to both. If you withdraw an earlier acceptance, the page immediately switches Google Analytics off, tells it that analytics storage is denied, and deletes the Google Analytics cookies that the page is able to read; the tag is not loaded again on any later page. Two things are beyond what a web page can undo: data Google has already received cannot be recalled from the page, and any Google cookie set for a different site or address cannot be deleted by us. Your browser’s own settings can clear those, and Google’s privacy tools apply to the rest.
Withdrawing also stops the X advertising pixel. It is not loaded on the page you are on or on any later one, on this website or on the customer dashboard, and the _twclid cookie it may have set on circlesja.com is deleted. Cookies that X has set on its own domains are not ours to reach and cannot be deleted by this website; your browser’s own settings, or the settings X provides, are where those are cleared. As with Google, data X has already received cannot be recalled from the page.
On the dashboard. The dashboard asks the same question, in the same terms, but only when your browser holds no current answer to it — that is, only if you have not already answered on circlesja.com. If you answered here first, the dashboard reads that answer and does not ask; if you reached the dashboard first, the answer you gave there is the one this website reads. Both write the identical record, so you are asked once and never asked twice, which is exactly what the shared cookie is there for. The dashboard loads no analytics of its own, runs no profiling tags, and the Google Maps view is not part of it. The one optional thing it does load is the X advertising pixel described above, and only if you selected Accept, on either site: there the pixel also records that an account was created, which is how we tell whether an advertisement we ran on X led to a new account. If you did not accept, or you withdraw an acceptance, it is not loaded on the dashboard at all. It does carry Cookie Preferences in its footer, so you can see and change the recorded answer without leaving the dashboard. What the dashboard does use is this:
Platform measurement by our hosting provider. The dashboard is built and served on Lovable, and the platform runs its own measurement of the service — the kind a hosting provider uses to keep a site running, available, and secure. It is delivered as part of the site itself rather than by an outside company, so you will not see it listed as a third party in your browser, but it is still collection and we would rather say so than let the absence of a familiar name imply otherwise.
Through it, the platform may receive technical information about your visit, such as the pages you open in the dashboard, timing and performance data, your approximate location derived from your IP address, and your browser and device type. If a page in the dashboard fails, the error report sent to the platform includes the address of the page it happened on. We use this to keep the dashboard working, not to build a profile of you, not to advertise to you, and not to follow you across other websites, and we do not sell or share it for advertising.
This measurement comes with the platform the dashboard is built on, so we cannot switch it off for an individual visit. If you would like to know more about it, or you object to it, contact us using the details in Section 18 and we will tell you what we can and consider any request you make. Your rights in Section 14 apply to this information as they do to the rest.
- Your sign-in session — one cookie named shipwize_session. We encrypt and sign it, so what it contains cannot be read or altered by scripts on the page, by you, or by anyone who copies it without our key. It is marked HttpOnly, so page scripts cannot read it at all; Secure, so it is sent only over HTTPS; and SameSite=Lax, so it is not sent along with requests started by other websites. It lasts seven days, signing out clears it, and the dashboard signs you out by itself after thirty minutes without activity.
- Which reward you starred — kept by your own browser, in its local storage for the dashboard, under the name shipwize_fav_reward. It holds which of the rewards you marked as your favourite and nothing else, it is not a cookie, it is never sent to us, and clearing your browsing data for the site removes it.
- The bot check — the registration, sign-in, and password-reset pages, and only those three, load Cloudflare Turnstile from challenges.cloudflare.com. Your browser therefore connects to Cloudflare, which receives your IP address and the signals it uses to tell a person apart from an automated script, and which may set its own cookie in the course of the check. Turnstile is what stops those three pages from being attacked with automated attempts, so it is strictly necessary rather than something we ask you to accept, and a browser that blocks it cannot sign in. What Cloudflare returns to us is a pass or a fail, not a profile of you; it acts as our Service Provider for the check.
Blocking or deleting cookies through your browser settings also works at any time, on every site covered by this Policy. Blocking strictly necessary cookies will prevent you from signing in.
The X conversion pixel described above is the only advertising tag on the websites covered by this Policy, it is loaded only if you accept it, and it measures the advertisements we place on X. We run no advertising networks and no other cross-site ad-targeting tags, we do not use it or anything else on these websites to build a profile of you for advertisers, and we do not sell audience data.
11. Sharing & Disclosure of Data
Your information may be shared in the following limited circumstances:
- Between the Companies: Shipwize and Circles share customer, logistics, billing, and support records so that one account and one package history work across both.
- With our staff: our employees see the parts of your record that their role requires. Access is granted by role, checked on our servers each time an action is performed, and recorded for sensitive actions such as financial adjustments and account changes.
- With carriers, customs brokers, and authorities: the information needed to transport, declare, clear, and release your goods, including customs declarations.
- With a person you authorize: someone you name as an authorized collector can be told which of your packages are ready, and can collect them.
- With Service Providers that process data on our behalf under
written data-processing agreements compliant with the Jamaica DPA and GDPR Article 28:
- Meta Platforms – delivery of WhatsApp Notifications, and only if you have opted in (Section 6).
- MongoDB Atlas – the managed database service that stores our customer, package, and billing records.
- Amazon Web Services – hosting, and secure storage of credentials, for the service behind our websites and applications.
- Vercel – hosting for our marketing websites.
- Lovable – hosting for the customer dashboard. It also collects its own operational analytics about that service, described in Section 10.
- Google – website analytics and the embedded maps described in Section 10.
- X Corp. – the advertising conversion pixel described in Section 10, which measures the advertisements we run on X. Its privacy policy is at x.com/en/privacy.
- Cloudflare – the bot-protection check on the dashboard's registration, sign-in, and password-reset pages.
- Our email provider – delivery of account, status, invoice, and campaign email.
- Legal Requirements: if disclosure is required by a court order, regulator, or law-enforcement authority.
- Business Transfers: during mergers, acquisitions, or similar restructuring, subject to confidentiality.
- With Your Consent: when you explicitly authorize sharing.
We will never sell your data to advertisers or data brokers.
12. International Data Transfers
We operate from Jamaica, your packages pass through the United States, and the providers listed in Section 11 operate internationally. Your Personal Data is therefore transferred to and processed outside Jamaica, including in the United States.
Whenever data is transferred internationally, we ensure:
- Adequate protection consistent with the Jamaica Data Protection Act 2020 (Part III, Sections 27-29); and
- Standard Contractual Clauses (SCCs) or other recognised safeguards under GDPR Chapter V.
By using our Services, you consent to such lawful transfers.
13. Data Retention & Deletion
We retain Personal Data only as long as necessary for the purposes stated in this Policy or as required by law. Some categories are kept longer than others by their nature:
- Financial and customs records — invoices, receipts, payments, refunds, and declarations — are kept for as long as tax and customs law requires, which is longer than the life of an account.
- Audit and consent records — including the WhatsApp consent trail described in Section 6 and the history of changes to packages, balances, and accounts — are add-only by design. They are kept as evidence of what was done and when, and are not edited or pruned in the ordinary course of business.
- Account and package records are kept while your account is open, and afterwards for as long as they are needed to answer a query, resolve a dispute, or meet a legal obligation.
We do not currently publish a fixed retention period for each category of record. If you want to know how long a particular record about you is kept, or you want it deleted, contact us using the details in Section 18 and we will tell you what we hold, how long we intend to keep it, and what we are required by law to keep.
When data is no longer needed, we securely delete or anonymize it in accordance with Schedule 1, Part II of the Jamaica DPA and GDPR Article 5(1)(e).
14. Your Rights
Under the Jamaica Data Protection Act, GDPR, and CPRA, you may exercise the following rights:
- Access: Request a copy of your data.
- Rectification: Correct inaccurate or incomplete information.
- Erasure: Request deletion where no lawful basis exists to retain it.
- Restriction: Limit processing in certain cases.
- Data Portability: Receive your data in machine-readable format.
- Objection: Object to marketing or profiling.
- Withdraw Consent: Revoke permissions you have given. Two of these you can withdraw yourself at any time: WhatsApp Notifications, using the routes in Section 6, and your cookie choice, using Cookie Preferences on circlesja.com or on the customer dashboard as described in Section 10 — both change the one shared answer.
To exercise these rights, email privacy@shipwize.com or privacy@circlesja.com.
We will verify your identity and respond within the statutory timeframe:
- 30 days (Jamaica DPA § 21(1)) or
- One month (GDPR Art. 12(3)), whichever applies.
If unsatisfied, you may lodge a complaint with the Information Commissioner (Jamaica) or your local supervisory authority.
15. Security of Your Information
We apply technical and organizational measures appropriate to the data we hold, including:
- Encrypted connections, with HTTPS required across our production services;
- Passwords stored only as salted one-way hashes, never in a readable form, and passkey sign-in for the mobile application, where the private key never leaves your device;
- Role-based access, checked on our servers for every request, so that a signed-in customer can reach only their own records and a member of staff only what their role allows;
- Rate limiting and bot protection on signup, sign-in, and password reset, and session tokens that stop working as soon as you change or reset your password;
- Sign-in sessions carried in a cookie that we encrypt and sign, that scripts on the page cannot read, that travels only over HTTPS, that is not sent alongside requests started by other websites, and that expires after seven days;
- The credentials used to reach your records kept on our servers and never in the page: the dashboard's browser code does not call the system holding your records at all, so those credentials are never delivered to your device;
- Protections sent to your browser with every page — HTTPS held in place by Strict Transport Security, a rule forbidding other websites from framing our pages, and a rule switching off the camera, microphone, and location interfaces;
- Credentials and keys held in a managed secret store rather than in application code or configuration files;
- Logging of staff actions on customer, package, and financial records, with the actor and timestamp retained;
- Masking of phone numbers to their last four digits in the internal notification logs staff use to check delivery;
- Automated dependency, vulnerability, and secret scanning of our code on every change and on a weekly schedule;
- Employee confidentiality and data-protection training.
While we strive for industry-standard security, no method of transmission over the Internet is completely secure; we therefore cannot guarantee absolute security.
If a data breach occurs, we will notify affected individuals and the Information Commissioner (Jamaica) within the statutory period under Section 31 of the DPA and GDPR Articles 33-34.
16. Children’s Privacy
Our Services are not directed to persons under 16 years.
We do not knowingly collect Personal Data from minors.
If we learn that a minor’s information was collected without verifiable parental consent, we will delete it promptly and notify the guardian and relevant authorities as required by law.
17. Links to Other Websites
Our Services may contain links to third-party websites not operated by us.
We are not responsible for their content or privacy practices.
Please review the privacy policies of any external sites you visit.
18. Contact Us
For questions, requests, or to exercise your data-protection rights, please contact:
- Shipwize Services Ltd
- Kingston, Jamaica
- info@shipwize.com
- +1-876-619-SHIP
- Circles Logistics Ltd
- Kingston, Jamaica
- info@circlesja.com
- circlesja.com
- +1-876-619-7447
19. Changes to This Policy
We may revise this Privacy Policy periodically to reflect operational, legal, or regulatory updates.
The latest version will always appear on our websites.
If we make material changes, we will notify users by email or in-app notice before the new terms take effect.