PRIVACY POLICY OF THE POSPIH.COM PLATFORM
Last Updated: 12/06/2025
This Privacy Policy (“Policy”) sets out the principles and procedures for the collection, use, transfer, and protection of personal data of users of the Pospih.com Platform (“Platform” or “Website”), in accordance with the General Data Protection Regulation (GDPR), the Law of Ukraine “On Personal Data Protection,” and other applicable legal acts.
The Platform provides an informational online service that allows Users to post and view listings for freight transportation, book carrier services, or offer such services themselves. Pospih.com is not a party to contracts concluded between Users but ensures an appropriate level of data protection in the course of operating the Website.
By using the Platform, the User confirms that they have read this Policy, understand its content, and accept the conditions for processing their personal data as set out below.
We adhere to the principles of fairness, proportionality, and transparency in the processing of personal data. Each User has the right to be informed about how their data is processed, as well as the right to access, rectify, restrict, object to, or delete such data in accordance with the law.
This Policy forms an integral part of the Platform’s Public Offer and applies in conjunction with it. If you do not agree with any provision of this Policy, please refrain from using the Website.
- DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:
- Platform / Pospih.com means an informational online platform located at https://pospih.com that provides technical functionality for publishing freight transportation listings and facilitates communication between Users. Pospih.com is not a party to any legal relationships between Users, does not provide transportation services, and is not an agent or representative of either party. It bears no responsibility for the accuracy, quality, or fulfillment of obligations arising from agreements between Users.
- User (you/your) means a natural person who is at least 18 years old and who has voluntarily registered or uses the functionality of the Platform in accordance with the Terms of Use.
- Personal Data means any information relating to a natural person who is identified or can be directly or indirectly identified, including but not limited to name, email address, phone number, IP address, and data about activity on the Platform.
- Processing of Personal Data means any operation or set of operations performed on Personal Data, including but not limited to collection, storage, systematization, access, transfer, updating, anonymization, or deletion. For the purposes of this Policy, the terms “Processing” and “Handling” are used interchangeably.
- Controller means the entity that determines the purposes and means of Processing Personal Data. For the purposes of this Policy, the Controller is the Administration of Pospih.com.
- Processor means a third party that Processes Personal Data on behalf of the Controller under a confidentiality agreement and solely within the scope of the powers granted (e.g., hosting providers, mailing services, payment processors).
- GDPR means the General Data Protection Regulation (Regulation (EU) 2016/679), which is binding within the European Union and applies extraterritorially to entities that Process Personal Data of EU citizens.
- Terms of Use means the Public Offer that governs the rules for accessing the Platform and using its functionality. This Privacy Policy is an integral part of the Terms of Use.
- DPO (Data Protection Officer) means the person responsible for matters related to the protection of Personal Data, whom you may contact regarding your rights or any data protection concerns. Contact information is provided in Sections 9 and 16 of this Policy.
- CATEGORIES OF PERSONAL DATA WE COLLECT
- The Platform processes only the Personal Data that is necessary to ensure the technical functionality of the service, provide access to the Platform’s features, and facilitate interactions between Users. The data is categorized based on its source and method of use.
- Data voluntarily provided by the User. When creating an account, submitting a listing, requesting transportation, or otherwise interacting with the Platform, you may provide the following information:
- Registration Information: first and last name, email address, phone number, city, and password. This data is required to create an account and authenticate the User.
- Listing Information: content of your published listings, including cargo description, weight, route, contact information, transportation details, and the indicated price. If you offer transportation services, vehicle specifications may also be provided.
- Communication Data: information shared when contacting support or messaging other Users, including the content of messages, attached files, and accompanying technical metadata.
- Data collected automatically. Each time you use the Platform, the following data is automatically processed:
- Technical Data: IP address, device and browser type, interface language, date and time of access, URLs of visited pages, and cookie data.
- Activity Logs: actions performed within the account (posting, viewing, filtering listings, interacting with requests).
- Cookies: small text files stored in your browser that help ensure site stability, preserve preferences, and enhance your user experience. Details on the use of cookies are provided in the relevant section of this Policy.
- Data from integrated services. If you register or log in via third-party services (e.g., Google), we may receive a minimal set of data permitted by those services, such as your name and email address. This data is processed solely to create an account and facilitate login.
- Data generated through User interaction. When a request is confirmed or an agreement is made between Users, a limited amount of personal data may be shared between the parties—such as name, phone number, or route details. This data forms part of the contractual interaction and is provided strictly for the fulfillment of the relevant request.
- We do not collect special or sensitive categories of personal data (such as health information, political opinions, or religious beliefs). If a User voluntarily includes excessive personal information in open fields (e.g., in a listing description), the Platform bears no responsibility for its content and strongly advises against sharing unnecessary personal details.
- METHODS OF PERSONAL DATA COLLECTION
We collect Personal Data from Users through various methods, depending on how they interact with the Platform:
- Data provided directly by the User. When creating an Account, editing a profile, publishing listings, submitting requests, contacting Support, or using other Platform features, the User voluntarily enters specific information into designated forms. This information is transmitted to the Controller for processing based on the User’s actions (e.g., registration, request submission, inquiry initiation). All such actions are performed voluntarily and at the User’s discretion, and the data is used solely to enable access to the Platform’s features.
- Data collected automatically. When accessing the Platform, our system and integrated Processors may automatically record certain technical and analytical data:
- Cookies and similar technologies: These are created upon visiting the website or app and are used to store settings, maintain authentication sessions, personalize content, and collect statistical information. For more details, see Section 11 of this Policy.
- Server logs: Automatically recorded on the server, these may include the IP address, browser type, operating system parameters, request URLs, date and time of interaction, and device ID. These logs are used to analyze the technical performance of the Platform, detect errors, and monitor security.
- Data obtained from third parties:
- Authentication via external services (e.g., Google or Facebook): If the User opts to log in via an external account, we receive only the minimum required information (name, email, profile photo) through official API channels in accordance with OAuth protocols. This data is accessed only after the User provides explicit consent.
- Partner sources: In certain cases, we may receive technical identifiers (e.g., referral campaign ID, tracking tags) from our partners—for instance, if the User accesses the Platform via an advertisement or referral link.
- Public sources: We may use publicly available information directly related to the User’s actions (e.g., confirmation of business activity or publicly listed contact details in a listing).
- In all cases where Personal Data is obtained from sources other than the User, the Controller will inform the User of the data source at the first point of contact, in accordance with Article 14 of the GDPR.
- Data minimization principle. We do not require excessive Personal Data from Users and do not conduct hidden or automated data collection without the User’s knowledge. All technical processes are configured according to the principle of minimal necessary intrusion, strictly to ensure stable Platform operation, maintain security, and enhance the User experience.
- AGE RESTRICTIONS FOR USERS
- The Pospih.com Platform is intended strictly for individuals who are 18 years of age or older. We do not provide access to the Platform’s features to anyone under this age threshold and do not knowingly collect personal data from minors.
- We reserve the right to implement age verification during the account creation process, including by requesting the user’s date of birth. If we become aware that an account has been created by an individual under the age of 18, or that personal data of a minor has been submitted without proper consent, we will immediately terminate the account and delete all associated data.
- Legal guardians (parents or custodians) who discover that a minor has accessed the Platform or that their personal data has been shared without appropriate consent may contact the Platform Administration via the channels specified in Section 16 of this Policy. We will promptly take action in accordance with applicable legal requirements.
- In cases where an adult User arranges transportation for a minor (e.g., their child), that User assumes full responsibility for the lawful submission of the minor’s personal data, as well as compliance with all applicable laws and the terms of this Policy. In such cases, we will process the submitted data solely for the purpose of facilitating the specific transportation and will not retain it beyond the period necessary for providing the service.
- We do not engage in advertising targeting minors and do not conduct any marketing campaigns directed at individuals under the age of 18.
- If you are under the age of 18, please do not use the Pospih.com.
- PURPOSES OF PROCESSING PERSONAL DATA
- We process Users’ personal data solely for specific, lawful, and transparent purposes. Below are the main reasons for which we may use your personal data:
- Access to Platform features and performance of the Agreement. Your data is necessary to create an account, post listings, view offers, exchange messages, make bookings, and perform other actions governed by the Terms of Use. Processing such data is a condition for entering into and fulfilling our Agreement with you.
- Facilitating interactions between Users.We may disclose a limited amount of personal data (e.g., name and phone number) to another User after a transportation agreement has been reached. This disclosure occurs strictly within the Platform's functionality to enable communication between contracting parties.
- Service-related communications. We may send you messages confirming registration, notifying you of listing status changes, responding to support inquiries, updating terms of service, or sharing important technical notices. These communications are sent under our contractual obligations or based on our legitimate interest in maintaining service quality.
- Marketing and surveys. We may send you news, updates, promotional or partner offers only with your consent or where otherwise permitted by law. You may withdraw your consent at any time.
- Personalization of user experience. We use information about your activity on the Platform to display content relevant to your region and preferences, remember your settings, and improve usability and performance. This processing is based on our legitimate interest in making the service more effective and user-friendly.
- Content moderation and fraud prevention. To protect our Users, we may review certain messages or content posted on the Platform, identify fake accounts, detect fraudulent behavior, or prevent abuse. These measures are based on our legitimate interest in maintaining a safe environment.
- Enforcement of sanctions and dispute resolution. In case of a breach of the Terms of Use, we may block accounts, retain relevant information (e.g., messages, listings, complaints), and take measures to prevent the violator from re-registering.
- Legal compliance. We may retain your data for accounting and tax purposes, compliance with personal data protection laws, responses to official government requests, or other legal obligations.
- Additional purposes. If we need to use your personal data for a purpose not outlined in this Policy, we will request your separate consent. No such processing will take place without your permission.
- Data security and third-party sharing. We do not sell your personal data to third parties or share it for the marketing purposes of unrelated companies. Data may be shared only within the limits described above - for example, with our contractors, hosting providers, or payment services - provided an adequate level of protection is ensured.
- DATA RETENTION PERIODS
- We retain Users’ personal data only for as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law. Retention periods depend on the type of data, the nature of your interaction with the Platform, and our legal obligations.
- Account and profile data. We store your identification and contact details (such as name, phone number, email address, and activity history) for as long as your account remains active. If your account is deleted at your request, personal data will be erased or anonymized within a reasonable timeframe, typically no later than 30 days after the request is confirmed. Backup copies containing such data are overwritten automatically as part of the regular backup cycle and are not used for active processing.
- User-generated content. Listings, reviews, messages, requests, and other content published via the Platform are retained for as long as the account exists or until deleted by the User (where such an option is available). Once the profile or content is deleted, this data is also removed or anonymized, except where retained for purposes of investigating violations or resolving disputes.
- Transaction-related information. Data related to confirmed transport services, agreements between Users, or financial transactions is retained for the period required by accounting and tax regulations. Typically, this is no less than 3 years, even after the account is deleted.
- Log files and technical records. Login data, on-site activity records, and other technical logs are stored for up to 12 months unless a longer period is required to investigate security breaches or fraud.
- Backups. Backups are created regularly to ensure the stable operation of the Platform. Data deleted by the User may temporarily remain in such backups until the next scheduled overwrite. We do not restore data from backups except as permitted by law or necessary for information security purposes.
- Data for violation prevention. We may retain a limited amount of personal data after account deletion if necessary to:
- fulfill legal obligations;
- resolve disputes or substantiate actions in the case of complaints or claims;
- prevent the re-registration of individuals who violated the Platform’s rules.
- The retention period in such cases depends on the severity of the violation and may extend up to 10 years.
- Anonymized data. Data that no longer identifies a User (e.g., statistical or aggregated data) may be retained indefinitely for analytical and research purposes.
- Once the applicable retention period expires, we ensure the permanent deletion or irreversible anonymization of the data in accordance with established procedures. If you have additional questions regarding the retention of specific types of personal data, please contact us using the details provided in Section 16 of this Policy.
- NEWSLETTERS AND PROMOTIONAL OFFERS
- We may send Users informational or marketing communications if we have a valid legal basis — either your prior consent or a legitimate interest derived from your use of the Platform.
These communications may include:
- updates about the Platform’s operation, new features, and useful usage tips;
- special offers, promo codes, and loyalty programs;
- time-limited offers from our partners (subject to your consent);
- service quality surveys and feedback requests.
- Channels of communication. Messages may be sent via email, push notifications, messengers, or SMS — depending on your preferences and the permissions you’ve granted. We always clearly indicate that Pospih.com is the sender of the message.
- Opting out. You can unsubscribe from marketing communications at any time by:
- clicking the “Unsubscribe” link at the bottom of the message;
- adjusting your profile settings (if available);
- sending us an email with a relevant request.
- Unsubscribing does not affect the delivery of essential service communications necessary for the operation of the Platform.
- Consent. We do not send marketing materials without your explicit consent. Consent may be obtained by ticking a checkbox during registration or in your account settings. You have the right to withdraw your consent at any time.
- Frequency of communication. We maintain reasonable frequency, sending no more than 1–2 informational emails per month. Personalized offers are sent only when there is a relevant reason.
- Third-party services. We may use external platforms (e.g., Mailchimp, SendPulse, or others) to send communications. These providers process your email address strictly on our behalf and under data processing agreements compliant with the GDPR.
- We do not share your contact details with third parties for their independent marketing campaigns. All messages - including partner content - are sent directly by us and only after your consent.
- If you continue to receive marketing messages after unsubscribing, please notify us, and we will promptly correct the issue.
- INTERNATIONAL TRANSFER OF PERSONAL DATA
- Pospih.com operates primarily within Ukraine; however, in the course of providing services, certain User personal data may be processed or transferred outside of Ukraine. This may occur due to the use of third-party services, the international nature of transport activities, and technical infrastructure distribution.
- Data processing locations. The primary processing and storage of data is carried out in Ukraine or within the European Union (e.g., in EU-based data centers of our hosting partners). We aim to ensure that critical data does not leave jurisdictions with an adequate level of data protection.
- Transfers to third countries. If data is transferred to countries not recognized by the European Commission as offering adequate protection (e.g., the United States), we implement appropriate safeguards in accordance with Articles 44–49 of the GDPR, including:
- Standard Contractual Clauses (SCCs) executed with data recipients to ensure adherence to GDPR standards;
- Additional technical and organizational measures, such as end-to-end encryption, pseudonymization, and access restrictions;
- Explicit User consent, when the transfer is initiated by the User and based on informed agreement regarding potential risks;
- Other legally permitted mechanisms under Article 46 of the GDPR, such as certification schemes or codes of conduct.
- We always inform Users when a specific third-party service involves cross-border data transfers and provide access to relevant terms.
- Examples of possible international data transfers include:
- Use of cloud services (e.g., Amazon Web Services, Google Cloud, Cloudflare), whose data centers may be located in the EU, US, or other jurisdictions;
- Email campaigns sent via dedicated platforms (e.g., Mailchimp, SendPulse) hosted in the United States;
- Processing of anonymized web analytics via Google Analytics or similar services;
- Transmission of contact data to another User in cases involving cross-border transport or bookings, where such transfer is necessary to perform a contract between the parties under Article 49(1)(b) GDPR.
- Important notice. The Platform may include links to third-party websites or embedded elements (widgets, maps, payment forms) that process data according to their own privacy policies. We do not control or assume liability for the practices of such third parties. We recommend that Users review the privacy policies of these external services before submitting any personal data.
- We ensure that your personal data remains protected in accordance with GDPR principles, regardless of the processing country. If you would like more information about our international data transfer mechanisms or copies of contractual safeguards, please contact our support team.
- DATA STORAGE SECURITY AND DPO
- The security of Users' personal data is one of Pospih.com's highest priorities. We have implemented a comprehensive set of technical and organizational measures aligned with current information security standards to prevent unauthorized access, loss, alteration, or disclosure of personal data.
- Key security measures implemented by the Platform include:
- Encryption: All confidential data transferred between the User’s browser and our servers is protected using TLS (HTTPS) encryption. Sensitive data categories, such as passwords, are stored exclusively in cryptographic hash format.
- Access Control: Access to personal data is strictly limited to authorized personnel - employees or contractors who have signed confidentiality agreements and received data protection training. Access is granted based on the principle of least privilege.
- Infrastructure: Our servers are protected by firewalls, intrusion detection systems, and antivirus software. We perform regular data backups and software updates to maintain infrastructure integrity.
- Monitoring: We continuously monitor our infrastructure, conduct regular security audits, including external penetration testing, and promptly respond to any identified risks.
- Pseudonymization: Where feasible, we process data in anonymized or aggregated form to ensure that Users cannot be identified without additional information.
- Incident Response: In the event of a personal data breach that may pose a high risk to User rights, we will notify the relevant supervisory authorities and affected Users within the timeframes established by applicable law.
- While no online service can guarantee absolute security, we are committed to continually reviewing and improving our security policies to address emerging threats.
- User Responsibility. The protection of personal data also depends on the User’s actions. We urge Users to keep their login credentials confidential, use strong passwords, and refrain from sharing them with others. We will never request your password via email or phone. If you receive any suspicious communication, please notify us immediately.
- Data Protection Officer (DPO). The Controller has appointed a Data Protection Officer (DPO) to oversee compliance with GDPR and other privacy regulations. The DPO serves as the primary point of contact for Users regarding any questions or concerns related to personal data processing.
- You may contact our DPO at: support@pospih.com. Please indicate in the subject line that your inquiry concerns personal data protection.
- We review all inquiries as promptly as possible, and no later than 30 calendar days, unless otherwise required by applicable law.
- Confidentiality is a continuous process. We welcome any feedback or suggestions to help us enhance the security of the Platform.
- INTEGRATED THIRD-PARTY SERVICES
- To ensure the functionality of the Platform and enhance the User experience, we integrate third-party services, including those provided by companies such as Google and Facebook. These services may receive certain data about you in the course of your interaction with the Platform. Below is an overview of the integrated services, their purpose, and their impact on your privacy.
- Google Analytics. This analytical tool is used to collect anonymized statistics about the use of the Platform. Google Analytics may record technical data such as visited pages, session duration, page navigation, and approximate geolocation based on IP address. We configure the service to anonymize User IP addresses whenever technically feasible. Google processes this data as a Processor solely on our behalf and does not use it for its own purposes. You can opt out of data collection via the Google Analytics Opt-out plugin.
- Mapping Services (OpenStreetMap). When the Platform displays interactive maps (e.g., for specifying pickup or delivery locations), it utilizes the open-source mapping service OpenStreetMap. The map is rendered directly in your browser without automatically transmitting personal data to OpenStreetMap. However, like any external web service, technical data (such as IP address) may be processed in accordance with OpenStreetMap's Privacy Policy.
- Google reCAPTCHA. This service may be implemented to protect forms from automated bots. It analyzes User behavior (mouse movements, keystrokes, IP address, and other technical data) to verify human activity. Data is transmitted to Google solely for this verification and is processed according to Google’s privacy policy.
- Facebook Login. If login via Facebook is enabled, the Platform may receive your name, email address, or other information from Facebook, depending on the permissions you grant. This data is used exclusively to create or authorize your account on the Platform. You can revoke access in your Facebook settings under “Apps and Websites.”
- Facebook Pixel and SDK. If the mobile app is used or advertising campaigns are run on Facebook, we may use the Facebook SDK or Facebook Pixel to analyze User activity, evaluate advertising performance, and implement remarketing. Pixel may log events such as page views or registrations and transmit them to Facebook. Email addresses or other data, if shared, are encrypted (hashed) prior to transmission. You can manage personalized advertising in your Facebook profile or via tools like YourAdChoices.
- Other Services. The Platform may integrate additional tools such as “Share” buttons, messenger widgets, YouTube/Vimeo players, etc. These tools may collect technical data about your device and activity in accordance with their own privacy policies.
- Interaction with Third-Party Services. Although we embed these solutions within our Platform, the data processed by such third parties is subject to their own policies. We do not control their practices and assume no responsibility for their actions as independent Controllers. We encourage Users to review the privacy policies of these providers, particularly those of Google and Facebook.
- Consent Banner Functionality. Once a full-featured consent banner is implemented, Users will be able to manage their cookie preferences upon their first visit to the Platform — for example, to allow only essential cookies or withdraw consent for analytical data processing. Until such functionality is in place, we do not use cookies that require prior consent and limit usage to only those strictly necessary to ensure proper Platform operation, in compliance with the data minimization and lawfulness principles of Article 5 GDPR.
- If you would like to know which integrations are currently active on the Platform or wish to request deactivation of a specific service, please contact us using the details in Section 16. We will provide clarification and, where possible, accommodate your request without impairing your access to the Platform.
- ADVERTISING AND ANALYTICAL SERVICES
- To ensure the stable operation of the Platform, optimize User interaction, and promote Pospih.com, we may use third-party analytics tools and advertising services. This section explains how such tools function and how you can control the processing of related data.
- Advertising Services. We may display advertising banners or partner ads on the Platform and promote Pospih.com via advertising campaigns on external platforms such as Google, Facebook, Instagram, or TikTok. In this context, certain technical User data (e.g., device type, IP address, viewed pages) may be processed. However, no personal data is shared with advertisers without your explicit consent.
- Current integrations allow us to display banners either universally or to specific categories of Users (e.g., ads relevant to Carriers). This targeting occurs solely within the Platform and does not involve transferring your personal data to third parties.
- In the future, advertising network services such as Google AdSense may be implemented. In such cases, third-party cookies may collect data on your site activity to build an advertising profile. Prior to launching this functionality, we will implement a cookie consent mechanism that allows you to manage your preferences.
- Analytical Services. In addition to Google Analytics, we may use: internal analytics systems that track key Platform interactions, third-party A/B testing tools to compare interface variants, UX analysis tools (such as heatmaps or session recordings).
- These services help us better understand User behavior and improve the Platform. Data processing in these contexts is based on anonymized identifiers and does not involve identifying specific individuals unless strictly necessary. We sign data processing agreements with all third-party providers in accordance with applicable law.
- Cookies and Similar Technologies. The Platform uses both first-party and third-party cookies. These may collect information such as:
- pages viewed, session duration, and navigation patterns;
- interactions with banners or ads;
- technical parameters of your device (IP address, browser type, etc.);
- chosen interface language or content display preferences.
- The cookie consent banner will be implemented once analytical or marketing cookies are enabled on the Platform. As of now, we use only strictly necessary (technical) cookies, which do not require user consent under applicable law. Users are informed of this in the Privacy Policy.
- Data Processing by Advertising Partners. If we conduct campaigns on social media, we may transmit hashed (encrypted) User identifiers (e.g., hashed email addresses) to our partners for targeted advertising. Such identifiers do not enable partners to directly identify you, and all activities are conducted in accordance with applicable privacy laws. You have the right to object to the use of your data for such purposes by contacting our support team.
- Your Control. You can:
- block cookies in your browser settings;
- enable the "Do Not Track" feature (if supported) - we honor this signal;
- opt out of interest-based advertising;
- submit a request for us to stop using your data for marketing - we will cease all direct marketing processing immediately.
- Additionally, you may manage advertising preferences directly in your profile settings on platforms like Facebook, Google, or Instagram.
- Summary. Advertising and analytics technologies help us maintain the effective operation of the Platform while keeping it freely accessible. We ensure compliance with data protection laws and provide Users with practical tools to control their data. Your privacy inquiries will always be handled with due diligence.
- COOKIE FILES
- Pospih.com uses cookies and other similar technologies to ensure the stable operation of the Platform, enhance functionality, personalize the User experience, and support analytics and marketing optimization.
- A cookie is a small piece of data stored in your browser or on your device during interaction with the Platform. Types of cookies we use:
- Strictly Necessary (Technical). Essential for the website’s functionality, including navigation, authentication, security, and access to secure areas.
- Analytical. Help us understand how Users interact with the website (e.g., Google Analytics). Data is collected in an aggregated form without linking it to individual Users.
- Functional. Used to remember your preferences (e.g., interface language, recent search filters) to make your experience more convenient.
- Marketing. Enable us to display relevant advertisements, measure ad campaign effectiveness, and limit repetitive ad displays. We may integrate third-party services (e.g., Meta Pixel) that also use cookies.
- Consent Banner. When you first visit the Platform, a banner will appear briefly explaining the use of cookies. You can accept all cookies or manage your preferences — for example, allowing only strictly necessary cookies and rejecting others. We do not use analytical or marketing cookies without your prior consent.
- Your choice is stored in a cookie and can be modified at any time via a dedicated tool (e.g., a button or link in the site footer).
- Browser Cookie Management. In addition to Platform tools, you can manage cookies via your browser settings - deleting, blocking, or disabling their use. Note that disabling technical cookies may limit the functionality of the site.
- Legal Basis for Processing. The use of cookies (other than strictly necessary ones) is based on your prior consent in accordance with Article 6(1)(a) GDPR. Technical cookies are processed based on our legitimate interest under Article 6(1)(f) GDPR, as they are required for the proper operation of the website.
- Storage Period. Cookies are stored for varying durations depending on their type:
- Session cookies – stored only during your active browser session.
- Persistent cookies – may be stored from a few days to several months.
- Third Parties. We may use cookies placed by third-party services that act as independent controllers or processors (e.g., Google, Meta, Cloudflare). Detailed information on such services is available in the corresponding section of this Policy.
- USER RIGHTS
- We recognize and respect your rights as a data subject under Regulation (EU) 2016/679 (GDPR), the Law of Ukraine “On Personal Data Protection,” and other applicable regulations. Every User has a set of lawful rights, and we ensure their implementation on transparent terms.
- Right of access to personal data (Article 15 GDPR). You have the right to obtain confirmation of whether we process your personal data and, if so, access all relevant information, including the purposes of processing, data categories, storage periods, data sources (if not provided by you), and recipients to whom the data has been or will be disclosed. You also have the right to receive a copy of your data in a readable format.
- Right to rectification (Article 16 GDPR). If your personal data is inaccurate, incomplete, or outdated, you have the right to request its prompt correction or completion. Some of these changes can be made directly in your user account; others may require contacting us.
- Right to erasure (“right to be forgotten,” Article 17 GDPR). You may request the deletion of your personal data if:
- It is no longer needed for the purposes for which it was collected;
- You have withdrawn your consent and there is no other legal basis for processing;
- You object to processing, and our legitimate interests do not override yours;
- The processing was unlawful;
- There is a legal obligation to delete the data under applicable law.
- If grounds are confirmed, we will delete your data and, where possible, notify third-party recipients. If processing remains necessary (e.g., for legal obligations or the protection of rights), we will provide a justified refusal outlining the reasons.
- Right to restriction of processing (Article 18 GDPR). You may temporarily restrict the processing of your personal data if: you contest its accuracy (while we verify it); the processing is unlawful but you oppose deletion; the data is no longer needed by the Platform but required by you to exercise legal claims; or you have objected to processing and we are verifying the legitimacy of processing. During restriction, we only store the data and refrain from using it otherwise (except in situations expressly permitted by law).
- Right to object to processing (Article 21 GDPR). If data is processed based on our legitimate interests or a task carried out in the public interest, you may object to such processing. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. If processing is for direct marketing purposes, your objection is unconditional, and we will immediately cease the processing.
- Right to data portability (Article 20 GDPR). You have the right to receive personal data you provided to us in a machine-readable format (e.g., CSV or JSON) and to transmit it to another Controller. Where feasible, we can also directly transfer the data to another entity at your request.
- Right to withdraw consent (Article 7 GDPR). If data processing is based on your consent, you may withdraw it at any time. This does not affect the legality of processing prior to withdrawal. Upon withdrawal, we will cease the respective processing unless there is another legal basis (e.g., contract performance).
- Right not to be subject to automated decision-making (Article 22 GDPR). At the time of publication of this Policy, we do not use fully automated decision-making that has legal effects on Users. If such algorithms are implemented, you will have the right to receive information on the decision-making logic, request human intervention, express your view, or contest the decision.
- Right to lodge a complaint with a supervisory authority. If you believe your rights have been violated or data is processed unlawfully, you may contact the Ukrainian Parliament Commissioner for Human Rights or the national data protection authority in your jurisdiction (within the EU). We recommend first reaching out to our support team — we are open to resolving any concerns constructively.
- How to exercise your rights? You can exercise your rights via the Platform’s interface or by submitting a written request to the contacts listed in Section 16. We will process your request within one month of receipt. In complex cases, the period may be extended by another two months, with prior notice. If a request is excessive or unfounded, we may deny it or request a reasonable fee to cover administrative costs (Article 12(5) GDPR).
- LIMITATION OF LIABILITY
- We make every reasonable effort to protect Users’ Personal Data and to ensure the uninterrupted operation of the Platform. However, we ask you to take note of the following important limitations of liability:
- Technical limitations and security. Pospih.com implements appropriate organizational and technical security measures. Nevertheless, we cannot guarantee absolute security of data transmission or storage over the Internet. By using the Platform, you acknowledge and accept the inherent risks associated with cyberattacks, data breaches, or temporary service interruptions.
- Use of third-party services. We may rely on Third-Party Services (e.g., hosting providers, analytics, integrations) that operate under their own privacy policies and obligations. While we are not liable for breaches caused by such third parties, we conduct a diligent selection and oversight process in compliance with applicable laws.
- User actions. Users are solely responsible for the accuracy and completeness of the personal data they provide, as well as for submitting information about third parties without a proper legal basis. We do not moderate the content of listings or reviews posted by Users and bear no responsibility for any violations of third-party privacy or data rights resulting from such actions.
- Marketing and communications. We are not liable for any undesired consequences if a User fails to unsubscribe in a timely manner from communications to which they had previously consented. You may withdraw your consent to marketing communications at any time, in accordance with Section 8 of this Policy.
- Force majeure. We are not responsible for security breaches or data loss caused by force majeure events, malicious software, failures in Internet infrastructure or service providers, or any other events objectively beyond our control.
- CHANGES TO THIS POLICY
- We reserve the right to update this Privacy Policy in response to changes in legislation, developments in the functionality of the Platform, or adjustments in our internal data processing procedures.
- Update procedure. All amendments to this Policy take effect upon publication of the updated version at the same URL. The effective date of the current version is indicated at the top of the document. We do not apply new data processing rules retroactively to data collected prior to the update without your explicit consent.
- Material changes. If the changes relate to significant matters (e.g., new purposes for processing, data sharing with new Controllers or Processors, or implementation of new consent-based mechanisms), we will inform Users in advance by one or more of the following methods: a notice on the website; an email notification (if your email is in our database); a banner or message upon login. Where required by law, we will request your consent before applying the changes.
- Your response. By continuing to use the Platform after the effective date of the updated Policy, you are deemed to have accepted its terms. If you disagree with any new provisions, you may stop using the Platform or contact us to raise specific objections.
- Archived versions. Upon request, we can provide access to previous versions of this Policy so that you may review how our approach to data protection has evolved. All versions are retained to ensure transparency.
- No retroactive effect. Policy updates are not retroactive. We will not apply new rules to data collected in the past if doing so would contradict the original purpose of collection or your consent at the time of submission.
- CONTACT AND FEEDBACK
- We welcome any inquiries, requests, or suggestions regarding the processing of Personal Data and fully support Users in exercising their rights in accordance with this Policy and applicable legislation. If you have questions, wish to exercise your rights, or would like to file a complaint, please contact us via your preferred method:
- Email (preferred method): Send your message to support@pospih.com – this is the official inbox of our Support Team and the Data Protection Officer. Please include a brief subject line describing your request (e.g., "Data deletion request", "Access request") to help us process it efficiently. We will acknowledge receipt and respond within a reasonable timeframe, typically no later than 7 business days.
- Platform features: If the website or mobile app offers a chat or feedback form, you may use it to submit your message. It will be automatically directed to the privacy officer or responsible specialist.
- Postal address: If you need to send a formal written request (such as a legal claim, complaint, or data subject request), you may use our legal address listed in the Terms of Use. Please mark the envelope: "Attn: Data Protection Officer".
- Platform Contact Information:
Serhii Anatoliiovych Isaienko
Address: Ukraine, 03150 Kyiv, Vasyl Tyutyunnyk Street 53, Office 1133
Email: mail@pospih.com
Phone: If a support phone number is provided on the site, you may call us. However, for legally significant requests, we may ask you to verify your identity in writing.
- Your inquiry will be handled with the utmost care and attention. In the case of a complaint, we will thoroughly investigate and, if possible, propose a resolution. For rights-related requests, we will perform identity verification and fulfill the request within legally mandated timeframes.
- We are committed to transparency and open communication with every User. Don’t hesitate to reach out- your feedback helps us improve our data protection practices and maintain the highest standards of trust.
- REVIEWS AND RECOMMENDATIONS
- On the Pospih.com Platform, Users may leave public reviews and recommendations about their interactions with other Users, including their experience with transport services or order fulfillment. This functionality is a core component of the Platform’s transparency and fosters mutual trust.
- Public nature of reviews. Reviews and recommendations you submit or receive are publicly visible to other Users of the Platform. In some cases, they may also be visible to non-logged-in visitors depending on your profile’s visibility settings. A review may include your name, profile image, Platform role (e.g., Customer or Carrier), and the written comment. By submitting a review, you acknowledge and accept its public character.
- Legal basis for processing. The processing of reviews and public recommendations is based on our legitimate interest in promoting safety, integrity, and mutual accountability within the Platform.
- Purposes of processing. We collect and process reviews to enhance service quality, support community development, and create a reputation system based on real experiences. Each User can read others' feedback before deciding to engage in collaboration.
- Content moderation. We reserve the right to moderate or remove reviews that: contain offensive language, defamation, or discriminatory remarks; disclose personal or contact information of third parties; are promotional, fraudulent, or spam-like; or otherwise violate the Terms of Use. In some cases, moderation may involve partial redaction (e.g., hiding phone numbers) without altering the core message. Repeated or serious violations may result in account suspension.
- Data you should avoid including. We advise against posting in reviews any: phone numbers, physical addresses, email addresses or other contact details; confidential information (including routes, payment amounts, etc.); or names of third parties who are not Users of the Platform. Privacy is a shared responsibility, and we count on your discretion.
- Retention and deletion of reviews. Reviews remain on the Platform for the lifetime of the associated accounts. If a User deletes their account, the reviews they submitted may be anonymized but retained in the reputation history of others. If you wish to edit or delete a review you’ve submitted, contact Support. Edits are typically permitted within 48 hours of posting. After that, changes are allowed only upon request and with valid justification.
- Right of reply and dispute resolution. If you receive a review you disagree with, you have the right to reply or file a complaint. We do not remove content solely for being negative unless it violates our Policy or the law. However, if a review contains false, abusive, or prohibited content, we are obligated to investigate and, if warranted, remove it.
- Use in marketing. Selected reviews may be featured in our marketing materials (e.g., homepage or promotional presentations), but only in anonymized form or with your explicit consent. If you wish to prohibit such use, please inform us, and we will respect your choice.
- Abuse of the review system. Attempts to manipulate reputation — including fake reviews, coordinated review schemes, or retaliatory posting - are strictly prohibited. Detection of such behavior may result in sanctions, including account suspension. We are committed to maintaining honesty and balance in the review system at Pospih.com.
- Questions and support. If you have questions or disputes regarding reviews or recommendations, please contact our support team. We will handle inquiries within the scope of our role as a neutral platform.