Privacy Policy
Last Updated: 23rd September 2026
About this Privacy Policy
This Privacy Policy explains how Zimpra ("Zimpra", "we", "us", or "our") collects, uses, stores, protects, and deletes information when you use the Zimpra transport management system and related services.
Zimpra is a transport management system (TMS) for road-transport companies. It helps transport businesses manage trips, customers, invoices, receipts, broker payments, expenses, and reports.
The Zimpra service is available through:
Zimpra is operated by ISUA Solutions Private Limited, a company registered in India.
This Privacy Policy applies to information processed through the Zimpra websites, applications, and services covered by these Terms.
If you have questions about this Privacy Policy or want to request deletion of your data, contact us at:
Email: sales@zimpra.com
What information we collect
We collect information that is necessary to provide and operate the Zimpra service.
2.1 Customer business data
When a transport company uses Zimpra, its authorized users may enter or upload business information such as:
Trip and shipment records
Customer and client information
Invoice information
Payment and receipt records
Broker payment information
Business expenses
Reports and related business records
Delivery-proof photographs and documents
Other information that the customer chooses to store in Zimpra
This information belongs to the customer. Zimpra processes it to provide the service to that customer.
Each Zimpra customer has a separate database for its business data.
2.2 User account information
For people who sign in to Zimpra, we may collect:
Name
Email address
Account and login information
User role or permissions within the customer's Zimpra account
Where Google Sign-In is used, Zimpra requests only the Google OpenID Connect scopes:
openidemailprofile
These scopes are used to authenticate the user and obtain the user's basic Google account identity information, such as their name and email address.
2.3 Technical information
We may collect limited technical information necessary to operate and secure the service, such as:
IP address
Browser and device information
Login and security events
Service usage information
Error and diagnostic information
We use this information to operate, secure, troubleshoot, and improve Zimpra.
3. How we use information
We use information only for legitimate purposes connected with operating and providing Zimpra.
This includes:
Providing the TMS and its features
Authenticating users
Managing customer accounts and permissions
Storing and displaying customer business records
Generating invoices, receipts, reports, and other requested outputs
Processing customer instructions
Providing customer support
Maintaining and securing our systems
Troubleshooting technical problems
Preventing unauthorized access, fraud, abuse, or security incidents
Sending necessary service communications
Complying with applicable legal obligations
Maintaining backups and restoring the service when necessary.
We do not sell customer data or personal information.
4. Google API access and Google user data
Google API access is an optional part of Zimpra. We use Google APIs only when a customer or user chooses to connect their Google account or use a Google-integrated feature. Our Google API use is described below.
4.1 Google Sign-In
Zimpra uses Google Sign-In for authentication.
For Google Sign-In, Zimpra requests only:
openid
email
profile.
We use this information to identify and authenticate the Zimpra user and associate the Google account with the user’s Zimpra account.
We do not request access to the user’s Gmail messages, contacts, calendar, or other Google services merely for Google Sign-In.
4.2 Gmail — gmail.send
Zimpra uses the gmail.send permission only when a customer chooses to send an invoice through their connected Gmail account. The purpose is to allow Zimpra to send the customer’s own invoices from the customer’s own Gmail account to the customer’s own clients.
Zimpra:
Does not read, search, or retrieve Gmail messages
Does not store copies of Gmail messages
Does not use Gmail data for advertising or to train artificial intelligence or machine-learning models.
The permission is used solely to send the email requested by the customer.
4.3 Google Drive — drive.file
Zimpra uses the Google Drive drive.file permission to upload delivery-proof photographs and documents to the customer’s own Google Drive.
When the customer enables this feature, Zimpra creates or uses a folder for the customer’s Zimpra documents and uploads the files selected by the customer.
The application is limited to files that it creates or has been given access to through the drive.file permission. Zimpra does not use this permission to browse or search through the customer's entire Google Drive.
Zimpra does not use Google Drive files for advertising or to train artificial intelligence or machine-learning models.
4.4 Google Sheets
Zimpra can write a read-only mirror of the customer's own Zimpra data into a Google Sheet selected or created for that purpose by the customer.
The purpose of this integration is to allow the customer to access a copy of its own Zimpra business data in Google Sheets.
Zimpra does not use this Google Sheets data for advertising or artificial intelligence or machine-learning training.
5. Google user data — Limited Use
Zimpra's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide the Google-integrated functionality described in this Privacy Policy and as otherwise permitted by Google's applicable policies.
Zimpra does not sell Google user data.
Zimpra does not use Google user data for advertising.
Zimpra does not use Google user data to train, improve, or develop any artificial intelligence or machine-learning model.
Zimpra does not transfer Google user data to third parties except where necessary for infrastructure providers acting on Zimpra's instructions to provide the service, or where disclosure is required by applicable law.
Zimpra does not use Google user data for purposes unrelated to the Google-integrated functionality described above.
6. Google OAuth tokens
When a user connects a Google account, Zimpra may store the OAuth credentials or tokens necessary to maintain the authorized connection.
OAuth tokens are stored in encrypted form.
The encryption key used to protect OAuth tokens is held separately in a secrets-management system and is not stored in the application database.
When a user disconnects their Google account from Zimpra, the associated OAuth tokens are deleted.
OAuth tokens are also deleted when the associated Zimpra account is removed, subject to any limited retention required by law or legitimate security purposes.
7. How to revoke Zimpra’s Google access
A user can revoke Zimpra's access to their Google account at any time through Google's account settings:
https://myaccount.google.com/permissions
The user can find Zimpra in the list of applications with access to their Google account and select the option to remove or revoke access.
Revoking Google access prevents Zimpra from continuing to use the relevant Google authorization. Some Zimpra features that depend on that authorization may stop working until the user reconnects the Google account.
8. Requesting deletion of your data
You may request deletion of information associated with your Zimpra account by contacting: sales@zimpra.com.
When making a deletion request, please provide enough information for us to identify the relevant account or customer organization.
If you are an employee or other user of a transport company that uses Zimpra, your request may need to be handled by your employer or the customer organization that controls the relevant business data.
When a customer terminates its Zimpra account, Zimpra will delete or anonymize the customer's data according to the termination and retention rules described in this Privacy Policy, except where we are required to retain particular information by law or need to retain limited information for legitimate legal, security, fraud-prevention, or dispute-resolution purposes.
9. Customer ownership and data export
The customer owns its business data stored in Zimpra.
Zimpra does not claim ownership of a customer's trips, invoices, receipts, payments, expenses, reports, or other business records uploaded to the service.
A customer can request or use the available Zimpra functionality to export its data at any time.
If a customer requests an export and the required export functionality is not available directly within the service, Zimpra will work with the customer to provide a reasonable export of the customer's data in a commonly usable format.
10. Data retention
We retain information for as long as necessary to provide the Zimpra service and for legitimate business, security, legal, accounting, and dispute-resolution purposes.
Customer business data is generally retained while the customer's account is active.
After an account is terminated, customer data is scheduled for deletion subject to:
Any deletion period stated in the customer's agreement with Zimpra
Backup retention
Legal or regulatory requirements
The need to establish, exercise, or defend legal claims
Security and fraud-prevention requirements
Our systems use nightly backups. Data contained in backups may therefore remain for a limited period after deletion from the active production systems before the relevant backup is automatically overwritten or deleted.
We do not retain Google OAuth tokens after the relevant user disconnects their Google account or their account is removed, except where temporary retention is technically or legally necessary.
11. Infrastructure and data location
Zimpra's application infrastructure uses Cloudflare services, including:
Cloudflare Workers
Cloudflare D1
Cloudflare R2
Customer data is stored in the Asia-Pacific region, subject to the technical operation of the services described above.
Zimpra also maintains nightly backups.
Company email is operated using Microsoft 365.
We use infrastructure and service providers only to the extent reasonably necessary to operate, secure, maintain, and support Zimpra.
12. Sharing information
We do not sell customer business data or personal information. We may disclose information in limited circumstances, including those described below.
12.1 Service providers
We may share information with infrastructure and technology providers that process information on our instructions and are necessary to operate Zimpra.
These providers may provide services such as:
Cloud infrastructure
Storage
Security
Authentication
Email and communications
Technical support
These providers are not permitted to use customer data for their own unrelated purposes.
12.2 Legal requirements
We may disclose information where reasonably necessary to:
Comply with applicable law
Respond to a valid legal process
Protect the rights, property, or safety of Zimpra, our customers, users, or others
Detect or prevent fraud, security incidents, or abuse
12.3 Business changes
If Zimpra is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
13. Security
We take reasonable technical and organizational measures to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Our measures include, as applicable:
Encryption of sensitive credentials and OAuth tokens
Separation of encryption keys from application databases
Access controls
Customer database separation
Authentication and authorization controls
Security monitoring and logging
Regular backups
Restricted access to production systems
No internet service can guarantee absolute security. We therefore cannot guarantee that unauthorized access, data loss, or other security incidents will never occur.
If we become aware of a security incident that requires notification under applicable law, we will take the steps required by law.
14. Cookies and similar technologies
Zimpra may use cookies or similar technologies that are necessary for authentication, security, session management, and normal operation of the service.
We may also use limited technical information to understand service performance and diagnose problems.
You can control cookies through your browser settings, although disabling necessary cookies may prevent some parts of Zimpra from working correctly.
15. Children’s privacy
Zimpra is a business software service and is not intended for anyone under 18 years of age.
We do not knowingly provide accounts to people under 18.
If you believe that a person under 18 has provided personal information to Zimpra, please contact us at sales@zimpra.com so that we can investigate and take appropriate action.
16. Your responsibilities
You are responsible for ensuring that information you enter into Zimpra is accurate and that you have the appropriate rights, permissions, notices, and consents required to provide that information to Zimpra for processing.
If you use Zimpra on behalf of a company, you should ensure that your use of the service complies with your company’s privacy and data-protection responsibilities.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make a material change to how we collect, use, or share personal information, we will provide notice through the service, by email, or by another reasonable method.
The updated Privacy Policy will be published on this page with a revised effective or updated date.
You should review this page periodically for changes.
18. Contact us
If you have questions about this Privacy Policy, want to request deletion of your information, or have a privacy-related concern, contact:
Zimpra / ISUA Solutions Private Limited.
Email: sales@zimpra.com.
Website: https://zimpra.com
© 2026 ISUA Solutions Private Limited. All rights reserved.
