Privacy Policy
Last updated: 3 September 2026
Pobo automates hyperlocal delivery for Shopify stores in India through three connected apps — Pobo Pod, the storefront experience your customers use to order, choose a delivery time slot and track their rider; Pobo Panel, the merchant dashboard used to dispatch orders across carriers such as Porter, Borzo and Shadowfax; and the Pobo rider app (Pobo Pilot), which a store’s own delivery riders use to run those deliveries. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices and rights you have. It applies when you install or use the App in connection with your Shopify-supported store, to shoppers who interact with Pobo Pod on a merchant’s storefront, and to riders who sign in to the Pobo rider app.
This policy is provided by Pobo E-Commerce Suite Private Limited (“Pobo”, “we”, “us”) and is intended to be read together with our Terms of Service and Refund Policy.
Information We Collect
Merchant & store data (via Shopify)
When you install the App, we access certain information from your Shopify account using the permission scopes below. Each scope maps to a specific delivery-automation function:
read_products— product details (title, price, weight, collections) used for planning, prep time and rate calculation.read_themes/write_themes— detect app-block support and, where app blocks are unavailable, add the storefront code Pobo Pod needs.read_customers— retrieve the customer’s delivery address for serviceability and dispatch.read_orders/read_all_orders— read orders placed through your store (including those older than 60 days) to schedule and fulfil deliveries.write_orders/write_order_edits— create and edit orders, e.g. to attach delivery-slot or tracking metadata.read_locations— read your store locations, which serve as the pickup source of truth.read_merchant_managed_fulfillment_orders— read fulfillment orders for merchant-managed locations.read_shipping/write_shipping— read and register carrier services so live rates appear at checkout.
Information you provide as a merchant
- Carrier API credentials (e.g. Porter, Borzo, Shadowfax, Delhivery) you enter to enable delivery services.
- A Google Maps API key, where you choose to use your own instead of Pobo’s shared key.
- Your contact details, business name and store location, used to evaluate shipping rates and to communicate with you.
- Identity-verification (KYC) information — where required, government-issued identity documents you submit to verify your business before dispatch is enabled.
Customer (end-shopper) information via Pobo Pod
When a shopper uses Pobo Pod on your storefront, we process the information needed to deliver their order:
- Name, phone number and delivery address.
- A precise map location (delivery pin / geolocation) when the shopper drops a pin using Pobo Cart Map, used to compute accurate hyperlocal rates and guide the rider.
- The chosen delivery date and time slot, and order contents.
- The phone number used for Pobo Pod’s verified login, and one-time passwords (OTPs) sent to authenticate it.
Rider information via the Pobo rider app
Riders sign in to the Pobo mobile app (Pobo Pilot) to run a store’s own deliveries. Only a rider a store has added to its fleet can sign in. Through the app we process:
- Name and phone number. The store enters these when it adds the rider to its fleet. The phone number is the rider’s only login — sign-in is a one-time password (OTP) sent to it by SMS. We never ask a rider for an email address.
- Precise location. While a rider is on an active delivery, the app reports their position so the store can see the delivery’s progress and so turn-by-turn navigation works. It is collected only during a delivery and only while the app is open — never in the background — and we keep only the latest position, not a location history.
- Proof-of-delivery photos. At the door, the rider photographs the delivered order with the phone’s camera and the photo is uploaded to Pobo. See Proof-of-delivery photos below.
- Device identifiers. The push-notification token for the rider’s device, so a new delivery offer can reach the right phone, and the device’s model name, which labels that sign-in so a rider can tell their own devices apart.
The app has no advertising, no advertising identifier, and no analytics or crash-reporting component. It does not collect contacts, calendar, messages, call logs, files, audio, health or fitness data, or the list of apps installed on the phone, and it never asks a rider for payment information.
Automatically collected technical data
- Cookies — data files placed on your device, often with an anonymous identifier. Learn more at allaboutcookies.org.
- Log files — actions on the service, including IP address, browser type, ISP, referring/exit pages, and date/time stamps.
- Web beacons, tags and pixels — electronic files used to understand how the service is used.
How We Use Your Information
We use the information we collect to:
- Provide, operate and maintain Pobo Pod, Pobo Panel, the Pobo rider app and the delivery-automation service.
- Compare live carrier rates, check serviceability by distance, and book and track deliveries.
- Send transactional order updates to shoppers by SMS and WhatsApp (e.g. order placed, rider assigned, out for delivery).
- Authenticate Pobo Pod logins via OTP and secure merchant access.
- Send push notifications to a rider’s device — a new delivery offer, or an offer that has been withdrawn. The rider app sends no marketing notifications.
- Record proof of delivery (a photograph at the door plus the customer’s delivery OTP) so a store can evidence that an order arrived.
- Verify merchant identity (KYC) where required, and meter usage for billing.
- Communicate with you, provide support, and improve and secure the App.
How We Share Your Information
We share personal information only as needed to run the service:
- Delivery carriers (Porter, Borzo, Shadowfax and other integrated partners) receive the customer name, phone number, pickup and delivery address and order details required to complete a delivery.
- Google Maps Platform processes address and geocoding requests for address collection, mapping and serviceability.
- Messaging providers deliver OTPs and SMS/WhatsApp order notifications.
- Payment providers (e.g. Cashfree Payments for Pobo Credits, and Shopify for subscription billing) process payments; card details are handled by the provider, not stored by Pobo.
- Delivery riders using the Pobo rider app receive the customer name, phone number, delivery address and map pin for the orders their store assigns to them, for as long as they are running that delivery.
- Google Firebase Cloud Messaging delivers push notifications to riders’ devices, and Google Maps Platform provides the rider’s navigation.
- Shopify, which hosts the platform your store runs on.
- Legal & safety — to comply with applicable law, respond to lawful requests (such as a subpoena or warrant), or protect our rights and users.
We do not sell your personal information or your customers’ personal information.
Identity Verification (KYC)
Where a merchant must complete identity verification before dispatch is enabled, any documents you submit are reviewed manually by our team and handled in line with India’s Digital Personal Data Protection Act, 2023. We collect only what is needed to confirm your identity, restrict access to authorised staff, and retain these documents only as long as necessary for verification and our legal obligations.
Proof-of-Delivery Photos
When a store runs deliveries with its own riders, the rider takes a photograph at the point of delivery — the parcel at the customer’s door — using the camera in the Pobo rider app. The photo is taken only at the moment a delivery is completed, alongside the customer’s delivery OTP; the app never opens the camera at any other time and never reads photos already on the rider’s phone.
- Why we take it. It is the store’s evidence that the order arrived, used to settle “it never came” disputes and cash-on-delivery discrepancies. It is not used for any other purpose, and never for advertising or profiling.
- Who can see it. The store the delivery belongs to, and Pobo staff who need it to support that store. Photos are stored privately: there is no public web address for one, and it can only be opened by a signed-in merchant account that owns the delivery.
- How long we keep it. With the delivery record, for as long as the store uses Pobo and as long as needed to resolve disputes and meet the store’s record-keeping obligations. Deleting a rider’s account does not delete the store’s delivery records, but nothing left in them identifies the rider.
- Asking for one to be removed. A customer who does not want a photograph of their doorway retained can contact us, or the store they ordered from, and we will delete it subject to the store’s legal obligations.
Data Retention
We retain order, settings and account information — including proof-of-delivery photographs and the delivery records they belong to — for as long as your store uses Pobo and as needed to provide the service, comply with our legal obligations, resolve disputes and enforce our agreements. A rider’s last known location is kept only until it is replaced by a newer one, and is erased when their account is deleted. You may ask us to delete information we hold about you, subject to those obligations.
Your Rights
If you are an Indian resident, you have the right to access the personal information we hold about you and to ask that it be corrected, updated or deleted, consistent with the Digital Personal Data Protection Act, 2023. To exercise these rights, contact us using the details below. Shoppers should note that the merchant whose store they ordered from is also a controller of their order data.
Riders can delete their own account from inside the Pobo rider app at any time, without asking us or their store — see Delete Your Account, which also explains exactly what is erased and what stays with the store as its own delivery record.
Security
We use reasonable technical and organisational measures to protect personal information, including access controls, encryption of data in transit, and IAM-based database authentication on our infrastructure. Every request the Pobo rider app makes travels over HTTPS, and proof-of-delivery photographs are held in private storage with no public web address. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any incident.
Changes
We may update this Privacy Policy from time to time to reflect changes to our practices or for operational, legal or regulatory reasons. The latest version will always be available on this page.
Contact Us
For any question about this Privacy Policy or your data, contact us at:
- Email: support@pobo.app
- Phone: +91 98167 28172
- Pobo E-Commerce Suite Private Limited, Near SJVN, Shimla — 171006, Himachal Pradesh, India