Legal
Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains how Collicare Logistics collects, uses, shares, protects and retains personal data when you visit our website, request a quote, book or receive a shipment, submit a payment receipt, file a claim, contact support or chat with ColliBot. It is maintained by Collicare Logistics as the data controller.
1. Who We Are
Collicare Logistics (“Collicare”, “we”, “us”) is a freight forwarding and logistics provider based in Kristiansand, Norway. For the processing described in this policy we act as the data controller. Where we transport goods on behalf of a business customer, that customer may be the controller of the consignee data it supplies to us, and we act as processor for that data.
2. What Data We Collect
Data you provide directly
- Contact and identity data: name, company name, email address, phone number, postal and delivery addresses.
- Account data: email address and authentication credentials (passwords are stored only as salted hashes by our authentication provider).
- Shipment data: origin and destination addresses, consignee details, service type, weight, dimensions, declared contents and value, special instructions.
- Payment data: payment reference numbers, payer name, amount, currency and the receipt image or document you upload. We never see or store full card numbers or bank credentials — payments are made outside our systems through the payment provider shown on our payment page.
- Claims and support data: tracking number, description of the issue, photographs and documents you attach, ticket correspondence.
- Chat data: the messages you send to ColliBot and the answers returned.
Data collected automatically
- IP address, approximate location derived from it, browser type and version, device and operating system, screen size and language.
- Pages viewed, referring page, time on page, clicks on key actions (for example “Get a Quote” or “Track Shipment”), and error diagnostics.
- Cookie and local-storage identifiers, including your cookie-consent choice.
Data from third parties
- Status and scan events from subcontracted carriers, airlines, shipping lines and last-mile partners.
- Customs and regulatory information required for clearance.
- Basic profile data (name, email) if you sign in using a third-party identity provider such as Google.
We do not intentionally collect special-category data (such as health data) and we do not knowingly collect data from children under 16. Please do not include sensitive personal information in chat messages or claim descriptions.
3. How We Use Your Data and Our Legal Bases
- To perform our contract with you: creating quotes and bookings, generating tracking numbers, transporting and delivering shipments, issuing invoices, verifying payment receipts, handling claims and tickets, and providing customer support.
- To comply with legal obligations: customs and export declarations, sanctions and anti-money-laundering screening, tax and accounting record-keeping, and responding to lawful requests from authorities.
- For our legitimate interests: operating, securing and improving the website, preventing fraud and abuse (including fraudulent payment receipts), analysing aggregate traffic and conversion, and internal reporting. We balance these interests against your rights and do not use them for intrusive profiling.
- With your consent: non-essential analytics cookies, marketing or newsletter emails where applicable. You may withdraw consent at any time.
We do not sell your personal data, and we do not use your data for automated decision-making that produces legal effects. Operational emails such as tracking updates, invoices and claim responses are part of the service and are not marketing.
4. Data Sharing and Recipients
We share personal data only as needed to deliver the service or comply with the law, with:
- Transport partners: subcontracted carriers, airlines, shipping lines, hauliers, warehouses and last-mile couriers, who receive the addresses and shipment details required to complete delivery.
- Customs authorities, brokers and regulators in the origin, transit and destination countries.
- Technology service providers acting on our instructions under data-processing agreements, including our cloud hosting and database provider, our transactional email provider and our AI assistant provider (which processes chat messages to generate answers).
- Payment providers used to receive and confirm payments.
- Professional advisers, insurers and auditors where necessary to handle a claim or dispute.
- Acquirers or successors in the event of a merger, acquisition or restructuring, subject to this policy.
Some recipients are located outside the EU/EEA. Where that is the case, transfers are made under an adequacy decision or the EU Standard Contractual Clauses together with appropriate technical safeguards such as encryption in transit.
5. Cookies and Similar Technologies
We use cookies, local storage and similar technologies to keep you signed in, remember your preferences and understand how the site is used. On your first visit a consent banner lets you accept all cookies or reject non-essential ones; your choice is stored on your device.
- Strictly necessary: authentication session, security, load balancing, storing your cookie choice. These cannot be disabled.
- Functional: remembering dismissed alerts, form state and interface preferences.
- Analytics: aggregate pageview and interaction measurement so we can improve the site. Set only with your consent.
You can change or withdraw your choice at any time by clearing your browser’s cookies and site data for this domain, after which the banner will appear again. Most browsers also let you block cookies entirely, though strictly necessary cookies are required for sign-in and payment features to work.
6. Data Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit (HTTPS/TLS), encryption at rest for our managed database and file storage, row-level access rules so customers can only reach their own records, private storage buckets with time-limited signed links for uploaded receipts and claim documents, hashed passwords, role-based administrative access restricted to authorised personnel, and logging of administrative actions and notifications.
No system can be guaranteed completely secure. If a personal-data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected individuals without undue delay where required.
7. Data Retention
We keep personal data only as long as necessary for the purpose it was collected, and then delete or anonymise it. Indicatively: shipment, invoice and payment records are retained for up to 5–10 years to meet Norwegian accounting, tax and customs obligations; claims and ticket records for up to 5 years after closure; account data for as long as the account is active and then up to 12 months; website analytics in aggregate form for up to 26 months; and chat transcripts for up to 12 months.
8. Your Rights
Subject to applicable law, and in particular the GDPR for EU/EEA residents, you have the right to:
- Be informed about how your data is processed.
- Access a copy of the personal data we hold about you.
- Have inaccurate or incomplete data corrected.
- Request erasure where we no longer have a lawful basis to keep the data.
- Request restriction of processing while a dispute is resolved.
- Object to processing based on our legitimate interests.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with a supervisory authority — in Norway, Datatilsynet (the Norwegian Data Protection Authority).
To exercise a right, email us at the address below. We will respond within one month and may ask for information to verify your identity. Note that legal retention duties (for example customs and accounting records) may prevent immediate deletion of some shipment data.
9. Third-Party Links and Embedded Content
Our website may link to or embed third-party content, such as videos or payment pages. Those providers may set their own cookies and process data under their own privacy policies. We are not responsible for their practices and encourage you to review them.
10. Changes to This Policy
We may update this policy to reflect changes in our services, technology or legal obligations. The “Last updated” date above always shows the current version, and material changes will be highlighted on the website.
11. Contact for Privacy Concerns
For any privacy question, data-subject request or complaint, contact our privacy team:
Collicare Logistics — Privacy Team · Kristiansand, Norway
Email: collicare.eu@proton.me
Phone: +47 940 12 583
