Skip to content

Privacy Policy

Last updated: 25 September 2026

Expodite ("Expodite", "we", "us" or "our") operates the export operations platform available through our website and web application (together, the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have.

Expodite is a business-to-business platform. Much of the information the Service holds is data our customers — exporters and their teams — enter about their own operations, including about the foreign buyers they trade with. Where we process that data on a customer's behalf, the customer is the controller of it and we act as their processor, under their instructions and the agreement between us.

We are aware of Egypt's Personal Data Protection Law No. 151 of 2020 and, because our customers' buyers and users are frequently outside Egypt, we apply GDPR-aware practices throughout this Policy, even where Egyptian law alone would not require them.

1. Information we collect

We collect the following categories of information:

  • Account and contact details — name, work email, phone number, company name, role and language preference, given when an account is created or when you contact us.
  • Customer business data — the export operations records our customers enter into the Service on their own behalf and on their buyers': buyers and their contacts, export orders, quotes, shipments, documents, letters of credit, cost lines and payments. This is processed as a processor, under the customer's instructions, and may include personal data about a customer's own staff, and about their buyers' contacts abroad, that the customer is responsible for having a lawful basis to give us.
  • Usage and device data — log data such as IP address, browser and device type, pages viewed and timestamps, collected automatically when the Service is used.
  • Cookies and analytics data — see "Cookies and analytics" below.
  • Communications — information you give us when you request a demo, contact sales, or reach support.

2. Our role, and the legal bases we rely on

For account, usage and communications data, Expodite is the controller, and we process it: to perform our contract with you (running the account you hold and the Service you use), for our legitimate interests (keeping the Service secure, understanding how it is used, and improving it), to comply with a legal obligation (such as a request from an authority), and, where you have given it, on your consent (such as a marketing email you can opt out of at any time).

For customer business data, our customer is the controller and we are the processor, acting only on their documented instructions, under the terms of our agreement with them. If you are a buyer, contact or member of staff whose details appear in a customer's account, your relationship for that data is with the customer, and this section explains our own role in processing it on their behalf, not a separate legal basis of our own.

3. Cookies and analytics

We use strictly necessary cookies and local storage to keep you signed in, remember a free document tool's saved identity block (see "Free document tools" below), and operate core features of the Service and this website. These do not require consent and cannot be turned off from this site.

With your consent, this website also uses two analytics tools, each started in a denied, no-cookie state under Google Consent Mode and only beginning to measure once you accept them in the banner shown on your first visit:

  • Google Analytics 4 (Google LLC) — aggregate website usage: pages viewed, navigation paths and engagement, so we can understand how visitors find and use the site.
  • Microsoft Clarity (Microsoft Corporation) — session replay and heatmaps of how visitors interact with the website's pages, so we can find and fix confusing layouts. Clarity masks input fields and other sensitive content by default, and never records what is typed into this site's free document tools or the contact form.
  • Retention: Google Analytics retains this data for up to 14 months; Microsoft Clarity retains it for up to 30 days. Both delete or aggregate it automatically after that period. Both act as our sub-processors, under their own data processing terms, and may process or store data outside Egypt — see "International transfers" below.
  • Your choice is remembered on this device and applied automatically on later visits. Change it anytime using "Cookie settings" in the footer of this website.

4. How we share information

We do not sell personal data. We share information only as described here, with sub-processors bound to protect it under a written agreement:

  • Hosting and infrastructure — cloud hosting and content-delivery providers that store and run the Service.
  • Email and communications — providers that send account, notification and support email on our behalf.
  • File and document storage — providers that store the documents a customer generates or uploads in the Service.
  • Error monitoring and observability — providers that help us detect and diagnose faults in the Service.
  • Within your organisation — customer business data is visible to users in the same customer account, according to the roles and branch permissions that customer configures.
  • Legal and safety — where required by law, regulation or legal process, or to protect the rights, property or safety of Expodite, our customers or the public.
  • Business transfers — in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

5. International transfers

Expodite's customers export internationally, and their buyers, carriers and banks are typically outside Egypt, so information may be processed and stored in a country other than the one you are in. Where we transfer personal data across a border, we take steps designed to keep it protected consistently with this Policy and with applicable law, including, where relevant, standard contractual safeguards with the receiving party.

6. Data retention

We retain account and usage data for as long as your account is active and as needed to provide the Service, meet our legal obligations, resolve disputes and enforce our agreements. Customer business data is retained and deleted according to the customer's instructions and their agreement with us; on termination of that agreement, we make it available for export for a limited period, described in our Terms of Service, after which it may be deleted in the ordinary course.

7. Security

We use technical and organisational measures designed to protect information, including encryption in transit, access controls and role-based, branch-scoped permissions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Depending on your location and Egypt's Personal Data Protection Law No. 151/2020, the GDPR or another applicable law, you may have rights to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us using the details below. Where the personal data relates to customer business data we hold as a processor, please direct your request to that customer, and we will assist them as required by our agreement with them.

9. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 18.

10. Third-party links

The Service and this website may link to third-party websites or services, including government platforms such as Nafeza and GOEIC, that we do not control. This Policy does not apply to those third parties, and we encourage you to review their own privacy notices.

11. Free document tools

Our website offers free document tools that let anyone generate an export document — a proforma invoice, a packing list and similar — without an account. This section explains what happens to what you type into them, and governs the tools where it differs from the sections above.

The live preview stores nothing. While a form is filled in, the document is rendered and shown back as you type; that preview is not written to our database and is cached nowhere along the way. Information is stored only at the moment a finished PDF is requested by email.

When a PDF is requested by email, we store:

  • The email address and contact name given — required because the document is delivered by email and never downloaded from the page.
  • The document data typed in — the form submission exactly as sent, including every line item and the exporter, shipment, banking and buyer details on the document.
  • A hashed IP address — combined with a secret value so only the resulting hash is stored, never the address itself, so we can recognise abuse without tracking anyone.
  • The browser's user-agent string, the page that referred the visitor, the generated PDF, and whether the email was sent successfully.

12. Your buyer's details in the document tools

The tools ask for a buyer's name and address, and optionally their tax ID and similar registration numbers. That person or company has not visited our site and has no relationship with us. The exporter using the tool is responsible for having a lawful basis to give us their buyer's details, and by submitting them confirms that they do. We process them for one purpose only: rendering the document requested. We do not market to a buyer named this way, do not contact them, and do not build a profile of them. They are retained only as part of the submission and are deleted with it.

13. Retention, use and deletion for the document tools

We keep a tool submission for up to 365 days from the day it is made, and do not retain it beyond that period.

We use these submissions to render and email the requested document, to detect and prevent abuse of a free, unauthenticated service, and to understand how the tools are used so we can improve them and the wider Service.

To have a submission deleted before its retention period ends, or to ask what we hold for a given email address, write to [email protected], and we will delete it.

What the browser keeps: to save retyping it on the next document, the tool remembers the user's own identity block — company name, address, contact details, and registration numbers — in local storage on that device, until it is cleared. We deliberately keep nothing else there: a buyer's details are never stored in the browser, and neither are bank details such as an IBAN or SWIFT/BIC. Bank details put on a document are used to render it and, like the rest of the submission, are stored on our servers only when a PDF is requested by email.

14. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the date above and, where appropriate, give additional notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

15. Contact us

Questions about this Policy or our privacy practices can be sent to [email protected].

Questions before you sign up?

Talk to us about your data, your contract, or anything on this page — before you commit to anything.