Privacy policy

Effective 2026-08-28

Who we are

Mati Logistics operates www.matilogistics.com and the products on it. For anything in this policy, email moyi@matilogistics.com. We are the controller of the personal data described here. Data is hosted in United States (Microsoft Azure, Central US region).

What each product collects, and why

Website

  • Server and proxy logs: IP address, user agent, pages requested, timestamps — to run and secure the site.
  • Google Analytics: pseudonymous usage events and a truncated IP address — to understand how the site is used.
  • Cookies: a session cookie once you sign in; a bot-management cookie set by our delivery proxy; Google Analytics cookies.

Track and Trace

  • Account data: name, email, company, country, what best describes you, password (stored hashed) — to provide the account and, once, to send a welcome email from our founder.
  • Shipments: the references you track (container, bill of lading, booking numbers), the tracking data carriers return for them, notes, parties and documents you add, and the teammates and share links you create — to provide the service. Tracking references are deduplicated across accounts; the carrier data behind a reference is not personal data about you.
  • Billing: handled by Stripe. We keep the purchase and subscription records; card details never reach us.
  • Guest use: up to three lookups without an account are keyed to your IP address to enforce the limit.
  • Notifications: the email and webhook endpoints you configure, and a log of what was sent.

Supplier directory and AI sourcing agent

  • Directory content is drawn from US ocean import records, a public customs source. It describes companies — names, addresses, shipments — and can include business contact details filed on those records. It is not collected from you; see the methodology for its source and limitations. A company that wants a profile corrected or removed can email us.
  • Sourcing requests: the text you type into the agent, the page it was typed on, whether you were signed in, your IP address, the search plan produced and the results — to run the search, enforce limits, and improve the product. The request text is sent to our model provider (Anthropic); see how the agent works for what that means.
  • Contact-detail reveals and profile page views, with your account (if signed in) and IP address — to prevent bulk harvesting of contact details and to understand which profiles are useful.
  • A short optional poll on profile pages (fixed answers, no free text).

Sourcing inquiry

  • What you submit: what you are sourcing, quantity, timing, country preferences, email, name, company, and the page you came from — to have a person on our sourcing team respond. Submitting sends the inquiry to our team by email and a receipt to you.

API

  • API keys (stored as hashes), the requests you make and their rate-limit counters, and the webhook endpoints you register — to provide and secure API access. Data returned by the API is the same shipment data as in the app.

Who processes data for us

These providers process data on our behalf, under contracts that restrict what they may do with it:

ProviderPurposeDataLocation
Microsoft AzureHosting, database, container registry and logs for every productAll service dataUnited States (Central US)
Ploy (runploy.com)Content delivery and caching proxy in front of www.matilogistics.comRequest metadata (IP address, user agent, URL) for every page view; cached page contentUnited States
AnthropicLanguage model behind the AI sourcing agent (see Methodology → AI sourcing agent)The sourcing request you type and the page it was typed on; no account detailsUnited States
StripePayments and subscriptions for Track and TraceBilling name, email, payment details (never stored by us)United States
ResendTransactional email (sign-up, password reset, notifications, inquiry receipts)Email address, name, message contentUnited States
Google AnalyticsAggregate usage analytics on the websitePseudonymous usage events, truncated IP address, device and browser dataUnited States
FindTEUTracking data aggregator used for one carrier (OOCL) in Track and TraceThe container number being tracked; nothing about youEuropean Union
IPRoyalProxy network through which some carrier tracking pages are fetchedThe request to the carrier, i.e. the tracking reference; nothing about youGlobal network

Beyond these, we share data only with carriers and terminals (the tracking reference, to fetch its status), with teammates and share-link recipients you choose, with our sourcing team for inquiries you submit, and where the law requires. Transfers outside your country rely on standard contractual clauses or an equivalent safeguard.

How long we keep it

DataProductKept for
Account, team and organization dataAllFor the life of the account; deleted within 30 days of a deletion request (backups expire within a further 30 days)
Shipments, tracking events and notesTrack and TraceFor the life of the account. Tracking references are shared across accounts, so the carrier data behind a reference may persist after your copy is deleted; it carries nothing about you
Billing recordsTrack and Trace7 years, as required for tax and accounting
Sourcing agent requests and resultsSupplier directory24 months, then deleted or anonymized (IP address and account link removed)
Profile page views, contact-detail reveals and poll answersSupplier directory24 months, then deleted or anonymized
Sourcing inquiriesSourcing inquiry24 months after our last contact with you about the inquiry
Rate-limit counters (keyed by IP address or account)AllRolling windows of at most 24 hours
Server and access logsAll30 days

Your rights: access, export, deletion

Email moyi@matilogistics.com from the address on your account. We answer within 30 days and may ask you to confirm your identity.

  • Access: a copy of the personal data we hold about you.
  • Export: your account data in a machine-readable format (JSON or CSV).
  • Correction: fix inaccurate data.
  • Deletion: delete your account and personal data (see retention above for what survives and why).
  • Objection and opt-out: object to our use of your sourcing requests for product improvement, and opt out of any marketing email.
  • Restriction and portability where the law that applies to you provides them.

Deleting your account removes your personal data and your copies of shipments, notes and settings; billing records and anything we must keep by law remain for the periods above. You can also download your shipment board as CSV from the app at any time.

AI

The sourcing agent uses a language model (Claude, from Anthropic) to turn your request into a search plan; it never invents suppliers — every result is a row in our database. Mati Logistics does not train models on user data, and Claude is not trained on it either, under Anthropic’s commercial API terms. You can opt out of our product-improvement review of your requests by email. The full description, including output ownership, is in the methodology.

Other things worth knowing

  • The service is for businesses and is not directed at anyone under 18.
  • Security measures are described on the security page, together with how to get a data processing agreement.
  • We will post changes to this policy here and update the effective date; material changes are announced by email to account holders.