Privacy Policy
Version 6.8 — 17 September 2026. Applies to the EU Delivery ID service, on the Web and in the iOS and Android apps.
This policy describes what EU Delivery ID does with your data. It is written to be read, not to tick a box.
1. Who is responsible
| Entity | Starthrop Dynamics, Unipessoal Lda |
|---|---|
| Company number (NIPC) | 519488261 |
| Registered office | Rua da Sociedade, n.º 4, 2695-567 São João da Talha, Loures, Portugal |
| Privacy contact | support@eudeliveryid.eu |
2. What data we process, and why
We collect what the service needs to work and, separately, whatever you choose to give us — your name is optional, and the table says which is which. Nothing is collected «just in case it turns out to be useful».
| Data | What for | Basis |
|---|---|---|
| identify the account, authenticate and send service messages | performance of the contract | |
| Your name | identifying and personalising your account, if you choose to give it. ⚠️ It is OPTIONAL: the account is created and the service works without it | legitimate interest |
| Password | authentication. Never stored as you typed it: we keep only a cryptographic derivation | performance of the contract |
| Delivery address, and its previous versions | this is what the product is for: keeping the address where you receive parcels. Previous versions remain because a parcel already on its way was sent to the address that existed at the time | performance of the contract |
| Your EU Delivery ID | an identifier the service assigns you. It is not derived from any of your data | performance of the contract |
| Tracking numbers, carrier, sender name and the nickname you give a parcel | following the parcels you add | performance of the contract |
| Tracking events | showing the parcel’s journey: status, place and date as reported by the carrier | performance of the contract |
| Sessions | keeping you signed in and letting you end sessions | performance of the contract |
| Your device’s notification identifier | sending you status-change alerts for the parcels you follow (point 6) | performance of the contract |
| The plan you bought, the subscription status, the period dates and the store’s purchase reference | knowing what service you are entitled to, renewing, cancelling and handling refunds (point 7) | performance of the contract |
| IP address and your account identifier, in the server logs | see point 3 | legitimate interest |
A note about the name. The name is optional: the account is created and the service works entirely without it. We process it on the basis of legitimate interest (Article 6(1)(f) GDPR), and not on performance of the contract — because the service is proven to work without a name, and a field the product chooses to ask for does not create the objective necessity that basis would require. Purpose: to identify and personalise your account, so that the product addresses you by a name rather than by an email address. Necessity: the name is not used to deliver, to track, to charge or to notify — none of those functions touches it and none requires it. Balancing: it is a single field, written by you, which we check against no document, disclose to no shop, carrier, other user or advertiser, and use for no profiling and no advertising — it is handled only by the infrastructure providers listed in section 8, like the rest of your account. The impact on your privacy is minimal, and the benefit is yours. Objection: you may object to this processing at any time by writing to support@eudeliveryid.eu — the name is deleted from your account, which keeps working without it. In the Profile you can correct the name or remove it, without writing to us. The email request stays available for anyone who prefers it.
What we do not collect
We do not collect your phone number. Until 20 August 2026 the profile had an optional field for it. It was taken out of the form: it had no use in the service — it did not sign you in, it received no messages, it was passed to no one. Anyone who had filled it in still has it on their account, and it comes out in the export. We did not delete it on our own initiative: it was your data, and removing it is your call — write to us and it is deleted.
We no longer collect delivery instructions. Until 21 August 2026 the address had an optional field for them. It was removed for the same reason as the phone number: they were used for nothing — they did not go to the carrier, they appeared on no screen and were passed to no one. Any you had already written stay with your address, appear in the export of your data and disappear if you delete your account.
We do not collect your payment details — not the card number, not the cardholder name, not the billing address. See point 7.
We do not collect what you bought from the shops you order from, the price you paid, or the reason for the purchase. None of that is needed to follow a delivery.
We use no advertising identifiers, we do no cross-app tracking, we have no third-party analytics tools and we build no consumption profiles.
This applies to the service — the app and app.eudeliveryid.eu, which this policy covers. Our advertising landing site, eudeliveryid.com, loads Google Analytics only if you accept it there, and has its own privacy notice.
3. Server logs, and what they are for
Like any service on the Internet, our server keeps a log of the requests it receives. That log contains the IP address the request came from, your account identifier when you are signed in, the path requested and the outcome. That log stays with the provider hosting the service and rolls over after about seven days — we do not keep it beyond that, nor use it for anything else.
We use this for two concrete things, and not for others:
- Rate-limiting. Sign-in is throttled by two independent counts: one on the origin of the request, which is the IP address, and one on the email address typed into the form. Five failed attempts within fifteen minutes block that count for another fifteen, and one successful sign-in clears both. The count on the email applies to whatever was typed, whether or not an account exists for it — if it only counted for real accounts, the block itself would reveal which ones exist. The system does not know whose account it is: it counts attempts, it does not tell account holders apart.
- Understanding failures. When something goes wrong, these logs are where you see what happened.
What does not go into these logs, by explicit server configuration: passwords, your email, your name, your address, cookie contents and recovery codes.
We do not use these logs to build profiles, measure audiences or for any commercial purpose.
4. Cookies and what is stored on your device
One cookie: your session, called edid_session. It only keeps you signed in.
| Duration | follows the session’s duration. See point 5 |
|---|---|
| When it stops being valid | when you sign out, when you recover your password, when the session expires, or when you delete your account |
| Protections | HttpOnly (page JavaScript cannot reach it), SameSite=Lax and, over a secure connection, Secure |
The session cookie is necessary for the service to work: without it you cannot be kept signed in.
We also store two preferences on your device, and those are not necessary for the service — they exist only to respect choices you made:
| What we store | Where | What for |
|---|---|---|
edid.tema | the device’s local storage | remembering whether you chose light or dark theme |
edid_idioma | the device’s local storage | remembering the language you chose |
Neither of them is sent to us. They stay on your device and you can remove them by clearing the browser’s or the app’s data.
We use no cookies or any other storage for advertising, audience measurement or profiling.
5. Authentication and sessions
You sign in with your email and your password. There is no other way in.
The session ends after 30 days without use. Every time you use the service that count restarts — anyone using the app regularly does not have to sign in again.
There is a limit that use does not extend: no session lasts more than 180 days from the moment it was created. After that, authentication is requested again, even from someone who uses the service every day.
The session ends immediately when:
- you sign out;
- you change your password — in that case the sessions on the other devices end, and the one you are using continues;
- you recover your password — in that case all end, including the one you are using;
- you delete your account.
The password saved on your device
If your system — iPhone, iPad, Mac or Android — offers to save your password, it is it that saves it, in the system credential manager, because you allowed it to. That copy belongs to the system: it stays under the system's control, it can be deleted in the system's settings, and when it asks for Face ID, Touch ID or the device passcode to fill it in, it is your operating system protecting a password it holds. Our own statement is about us: neither the app nor our servers store your readable password. On the server there is only a cryptographic derivation, which cannot be turned back into it; the app uses the password to sign you in and does not keep it.
6. Notifications
If you allow it, we alert you when a parcel you added changes status. That is the service’s function, which is why the basis is performance of the contract — the same as in the table in point 2.
Every notification we send comes from an event on one of your deliveries. That is the only path in the service that creates an alert: there is no mechanism for promotional notifications.
So that we can send you an alert, your device generates a notification identifier and we store it, linked to your account. That identifier is handed to the platform’s notification service: Apple, on Apple devices; Google, on Android.
The notification carries two things and nothing else: the status of the parcel, already translated by us, and the name you gave it — or “Your parcel”, if you gave it none. It does not carry your name, your email, your address, the tracking number or the text the carrier wrote. That text is still stored and still appears in the delivery's history, inside the app, once you unlock the device — what we do not do is put it on the lock screen, where you are not the one deciding who reads it.
The permission your device asks for to show notifications is a technical control of the system, and can be withdrawn at any time in its settings. Withdrawing it affects neither your rights nor the rest of the service, and it is not the basis for the processing.
7. Plans, payments and the store
Installing the app, creating an account, having your EU Delivery ID, saving your address, exporting your data and deleting your account are free.
What never reaches us
The financial transaction is processed by the store where you buy — today Google Play — or, if you buy on the web, by Stripe. We neither receive nor process your card number, the payment method credentials, the cardholder name or the billing address. Those stay with the store, or with Stripe, and with whoever each of them uses to process them. In a web purchase, Starthrop Dynamics is the merchant of record and Stripe is the payment processor.
What we do process, and it must be said clearly
So that we can give you the service you bought, we know and store: which plan — BASIC or PLUS; the subscription’s status — active, in a grace period, with billing failing, cancelled, ended or refunded; the dates of the paid period; and the reference the store assigns to the purchase, to recognise the messages it later sends us. Without this it is not possible to grant your plan, renew it, honour a cancellation or react to a refund.
The identifier we send to the store
When you buy a plan we send the store a random identifier, generated by us, containing no name, email, address or EU Delivery ID of yours. It links the purchase to your account when the store tells us about a renewal, a cancellation or a refund. We do not send the stores your account’s internal identifier.
That identifier is still personal data: it does not carry your name, but it can be linked to a purchase of yours. That is why it has a retention period and why it is described here. We do not call it anonymous, because it is not.
8. Who the data is shared with
We do not sell data and we do not share it for advertising. For the service to work we rely on the following providers, each with a strict role:
| Provider | What it does | What it receives |
|---|---|---|
| Netlify | hosts the public site you are reading | the IP address and the request for each visit to these pages |
| Render | hosts the service and the database | your account data, at rest and in transit |
| Stripe | processes the card payments made on the web | your email and the payment details you type into its form — the card number never reaches us |
| Google Workspace | delivers the service’s email | your email address and the content of those messages |
| AfterShip | queries parcel status with the carriers | only the tracking number and, when given, the carrier — it receives neither your name, email nor address |
| Apple, notification service | delivers notifications to Apple devices | the device’s notification identifier and the alert’s content |
| Google, notification service | delivers notifications to Android devices | the device’s notification identifier and the alert’s content |
| App Store and Google Play | process the plan purchase and the financial transaction | the payment data, which never passes through us, and the random identifier described in point 7 |
EU Delivery ID does not send your address to AfterShip, to the app stores or to the carriers. Nor is it shown to other users. It is kept in your account, in the service's database — hosted by the provider named in the table above, like the rest of your data. Where that database sits, and what that does not guarantee, is in point 9.
This is a statement about what we do. A carrier delivering a parcel to you naturally knows the delivery address — it got it from whoever sent you the parcel, not from us.
9. Where the data is processed
The infrastructure hosting the service and the database is in the European Union, in the Frankfurt region, Germany. That is where your account, your address and your parcels are kept, and that is where the server logs described in point 3 are kept.
Part of the backups described in section 10 stays with the same provider, in the same region. The rest are encrypted copies kept by the company itself, on its own equipment, outside the provider.
That says where the data is kept, and it is not the same as saying nothing leaves Germany. Three things are worth keeping apart, because they are usually run together: where the data is kept, where the backups are kept, and who can reach it in order to keep the service running. Hosting is provided by a company with international operations: the console and the administration interface we operate the infrastructure through are not confined to this region, and technical maintenance access can be carried out from outside it.
The remaining providers named in point 8 are companies with international operations, and the processing they carry out may involve transferring data outside the European Economic Area — in particular the carrier lookups, the delivery of notifications, the service's email and the purchase of the plan in the stores. Each of them publishes its own data processing terms, which apply to that processing and set out the safeguards it rests on.
If you want to know, for a specific provider, which safeguard applies and where to read it, write to support@eudeliveryid.eu and we will reply with the exact reference.
10. For how long
For as long as your account exists.
When you delete your account, your data is erased — account, addresses and their history, parcels, tracking events, sessions, recovery requests, notification identifiers and the plan record — from the database that runs the service, in a single operation that either runs entirely or does not run. It is immediate, and it is about the live database that we say so. Not everything ends at that instant, and what remains falls into two categories, no more: the residual records, of which there are three and which are listed in the table below, and the technical backups, which are a different thing and are explained at the end of this point.
Category one — the three residual records:
| What stays | How long | What it is, and why |
|---|---|---|
| A record that the deletion happened | 30 days | It contains the internal identifier of the deleted account and the date. It contains no name, email, address or parcels — but it is still pseudonymised personal data, because it refers to you. It exists to ensure your account is not restored if a system backup has to be recovered |
| Already revoked notification identifiers | seven days | When a device stops receiving alerts, the identifier stops serving. It stays seven days to allow diagnosing delivery failures, and is erased afterwards |
| Random payment identifier, if you had a paid plan | see below | The identifier from point 7. Also pseudonymised |
About the payment identifier: we keep it for as long as your account exists — including after the subscription ends, because without it an earlier purchase would stop being recognisable — and we delete it 180 days after you delete the account. That period is not arbitrary: it covers the windows in which the store can still write to us about your purchase — Apple retries billing for up to 60 days, and a refund or a dispute can arrive after that. Once the 180 days pass, it is erased. We do not keep it for accounting purposes: the store processes the charge and the transaction’s financial records stay with it — all that reaches us is this identifier and the state of the subscription.
The backups
The database has backups that exist for a single purpose: rebuilding the service if something goes badly wrong. They are not used for routine lookups or to selectively recover one person’s data. There are four kinds:
| Copy | Where it is kept | How long |
|---|---|---|
| Continuous copy, which allows rebuilding the database at a moment in the past | with the provider that hosts the service, in the same region | about three days — the provider decides the exact size; we measure it and it has been hovering around that figure |
| Full daily copy of the database | with the same provider, in the same region | seven days |
| Encrypted daily copy | on the company’s equipment, outside the provider | about 30 days |
| Encrypted archive | on the company’s physical storage | about 30 days, like the encrypted daily copy; used only if the other copies fail |
The copies kept by the company are encrypted when they reach its equipment, and can only be opened with a key the hosting provider does not have. When you delete your account, your data leaves the live database immediately, but remains in these copies until each one expires. If the service ever has to be rebuilt from a copy, we delete again the accounts whose deletion appears in the record described above, which we keep for 30 days. For that reason, no copy kept by the company lasts longer than that record: a copy older than it could no longer be restored without bringing deleted accounts back into the service, so it is deleted — on the physical storage, the next time it is connected.
One-off copies may also exist, taken before a maintenance operation — before a change to the database structure, for instance — so that we can go back if the operation goes wrong. They stay with the provider or, encrypted, with the company, and they have the same purpose, the same protection and the same retention period as the other copies kept where they are.
Password recovery requests expire after one hour and are invalidated as soon as they are used, or when you make a new request.
11. Deleting your account
You can delete the account from your Profile, with double confirmation. It is final.
Having a paid plan does not prevent deletion. Your right to erase your data does not depend on any commercial matter.
But deleting the account does not cancel the subscription. The plan is bought on Google Play or on the web, and it is cancelled where it was bought: in Google Play, or in the customer portal from your account. A store subscription is not something we can cancel for you.
If you delete the account without cancelling, you will continue to be charged by whoever charges you. The app warns you about this before you confirm, and shows the link to where you bought.
12. Your rights
As the data subject, you have the rights of access, rectification, erasure, restriction, objection and portability. Part of them you exercise in the product, without writing to us, and it is this:
- Export — download your data as a file, from your profile. That is the right of access and the right to portability.
- Delete the account — in the profile, with double confirmation. It is final.
- Correct or remove your name — in the profile. That is rectification, on the part we can hand you directly.
- Correct your address — in the profile. The previous version stays stored, as stated in point 2.
What still depends on writing to us: changing the account's email address, which identifies the account and is not yet editable in the product; objecting to the processing of your name on the legitimate interest basis, if you prefer that route to the button; and restriction of processing. For those, write to support@eudeliveryid.eu. You also have the right to lodge a complaint with the supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD).
13. Security
Connections to the service are encrypted in transit.
Passwords are stored only as a cryptographic derivation — never as you typed them. Recovery requests and sessions are stored as a cryptographic digest: the value in your cookie does not exist in our database, and a recovery request cannot be reconstructed from what we keep.
The email we send is cryptographically signed (DKIM) and the domain is protected by SPF and DMARC, to make it harder for anyone to impersonate us.
Server logs are configured to omit passwords, email, name, address, cookies and recovery codes. Provider access credentials do not live in the service’s code.
14. Minors
The service is intended for people aged 18 or over.
We do not knowingly collect data from minors.
15. Changes
This policy carries a version and date at the top, and the version in force is always published on this page.
When there are material changes — ones that significantly alter what we do with your data — we inform users before they take effect, by means appropriate to the nature of the change and whenever the law requires it.
16. Contact
Any question about this policy or about your data: support@eudeliveryid.eu.