Privacy Policy

Last Updated: 23rd September 2026

  1. About this Privacy Policy

This Privacy Policy explains how Zimpra ("Zimpra", "we", "us", or "our") collects, uses, stores, protects, and deletes information when you use the Zimpra transport management system and related services.

Zimpra is a transport management system (TMS) for road-transport companies. It helps transport businesses manage trips, customers, invoices, receipts, broker payments, expenses, and reports.

The Zimpra service is available through:

Zimpra is operated by ISUA Solutions Private Limited, a company registered in India.

This Privacy Policy applies to information processed through the Zimpra websites, applications, and services covered by these Terms.

If you have questions about this Privacy Policy or want to request deletion of your data, contact us at:

Email: sales@zimpra.com

  1. What information we collect

We collect information that is necessary to provide and operate the Zimpra service.

2.1 Customer business data

When a transport company uses Zimpra, its authorized users may enter or upload business information such as:

  • Trip and shipment records

  • Customer and client information

  • Invoice information

  • Payment and receipt records

  • Broker payment information

  • Business expenses

  • Reports and related business records

  • Delivery-proof photographs and documents

  • Other information that the customer chooses to store in Zimpra

This information belongs to the customer. Zimpra processes it to provide the service to that customer.

Each Zimpra customer has a separate database for its business data.

2.2 User account information

For people who sign in to Zimpra, we may collect:

  • Name

  • Email address

  • Account and login information

  • User role or permissions within the customer's Zimpra account

Where Google Sign-In is used, Zimpra requests only the Google OpenID Connect scopes:

  • openid

  • email

  • profile

These scopes are used to authenticate the user and obtain the user's basic Google account identity information, such as their name and email address.

2.3 Technical information

We may collect limited technical information necessary to operate and secure the service, such as:

  • IP address

  • Browser and device information

  • Login and security events

  • Service usage information

  • Error and diagnostic information

We use this information to operate, secure, troubleshoot, and improve Zimpra.

3. How we use information

We use information only for legitimate purposes connected with operating and providing Zimpra.

This includes:

  • Providing the TMS and its features

  • Authenticating users

  • Managing customer accounts and permissions

  • Storing and displaying customer business records

  • Generating invoices, receipts, reports, and other requested outputs

  • Processing customer instructions

  • Providing customer support

  • Maintaining and securing our systems

  • Troubleshooting technical problems

  • Preventing unauthorized access, fraud, abuse, or security incidents

  • Sending necessary service communications

  • Complying with applicable legal obligations

  • Maintaining backups and restoring the service when necessary.

    We do not sell customer data or personal information.

4. Google API access and Google user data

Google API access is an optional part of Zimpra. We use Google APIs only when a customer or user chooses to connect their Google account or use a Google-integrated feature. Our Google API use is described below.

4.1 Google Sign-In

Zimpra uses Google Sign-In for authentication.

For Google Sign-In, Zimpra requests only:

  • openid

  • email

  • profile.

    We use this information to identify and authenticate the Zimpra user and associate the Google account with the user’s Zimpra account.

    We do not request access to the user’s Gmail messages, contacts, calendar, or other Google services merely for Google Sign-In.

4.2 Gmail — gmail.send

Zimpra uses the gmail.send permission only when a customer chooses to send an invoice through their connected Gmail account. The purpose is to allow Zimpra to send the customer’s own invoices from the customer’s own Gmail account to the customer’s own clients.

Zimpra:

  • Does not read, search, or retrieve Gmail messages

  • Does not store copies of Gmail messages

  • Does not use Gmail data for advertising or to train artificial intelligence or machine-learning models.

    The permission is used solely to send the email requested by the customer.

4.3 Google Drive — drive.file

Zimpra uses the Google Drive drive.file permission to upload delivery-proof photographs and documents to the customer’s own Google Drive.

When the customer enables this feature, Zimpra creates or uses a folder for the customer’s Zimpra documents and uploads the files selected by the customer.

The application is limited to files that it creates or has been given access to through the drive.file permission. Zimpra does not use this permission to browse or search through the customer's entire Google Drive.

Zimpra does not use Google Drive files for advertising or to train artificial intelligence or machine-learning models.

4.4 Google Sheets

Zimpra can write a read-only mirror of the customer's own Zimpra data into a Google Sheet selected or created for that purpose by the customer.

The purpose of this integration is to allow the customer to access a copy of its own Zimpra business data in Google Sheets.

Zimpra does not use this Google Sheets data for advertising or artificial intelligence or machine-learning training.

5. Google user data — Limited Use

Zimpra's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is used only to provide the Google-integrated functionality described in this Privacy Policy and as otherwise permitted by Google's applicable policies.

Zimpra does not sell Google user data.

Zimpra does not use Google user data for advertising.

Zimpra does not use Google user data to train, improve, or develop any artificial intelligence or machine-learning model.

Zimpra does not transfer Google user data to third parties except where necessary for infrastructure providers acting on Zimpra's instructions to provide the service, or where disclosure is required by applicable law.

Zimpra does not use Google user data for purposes unrelated to the Google-integrated functionality described above.

6. Google OAuth tokens

When a user connects a Google account, Zimpra may store the OAuth credentials or tokens necessary to maintain the authorized connection.

OAuth tokens are stored in encrypted form.

The encryption key used to protect OAuth tokens is held separately in a secrets-management system and is not stored in the application database.

When a user disconnects their Google account from Zimpra, the associated OAuth tokens are deleted.

OAuth tokens are also deleted when the associated Zimpra account is removed, subject to any limited retention required by law or legitimate security purposes.

7. How to revoke Zimpra’s Google access

A user can revoke Zimpra's access to their Google account at any time through Google's account settings:

https://myaccount.google.com/permissions

The user can find Zimpra in the list of applications with access to their Google account and select the option to remove or revoke access.

Revoking Google access prevents Zimpra from continuing to use the relevant Google authorization. Some Zimpra features that depend on that authorization may stop working until the user reconnects the Google account.

8. Requesting deletion of your data

You may request deletion of information associated with your Zimpra account by contacting: sales@zimpra.com.

When making a deletion request, please provide enough information for us to identify the relevant account or customer organization.

If you are an employee or other user of a transport company that uses Zimpra, your request may need to be handled by your employer or the customer organization that controls the relevant business data.

When a customer terminates its Zimpra account, Zimpra will delete or anonymize the customer's data according to the termination and retention rules described in this Privacy Policy, except where we are required to retain particular information by law or need to retain limited information for legitimate legal, security, fraud-prevention, or dispute-resolution purposes.

9. Customer ownership and data export

The customer owns its business data stored in Zimpra.

Zimpra does not claim ownership of a customer's trips, invoices, receipts, payments, expenses, reports, or other business records uploaded to the service.

A customer can request or use the available Zimpra functionality to export its data at any time.

If a customer requests an export and the required export functionality is not available directly within the service, Zimpra will work with the customer to provide a reasonable export of the customer's data in a commonly usable format.

10. Data retention

We retain information for as long as necessary to provide the Zimpra service and for legitimate business, security, legal, accounting, and dispute-resolution purposes.

Customer business data is generally retained while the customer's account is active.

After an account is terminated, customer data is scheduled for deletion subject to:

  • Any deletion period stated in the customer's agreement with Zimpra

  • Backup retention

  • Legal or regulatory requirements

  • The need to establish, exercise, or defend legal claims

  • Security and fraud-prevention requirements

Our systems use nightly backups. Data contained in backups may therefore remain for a limited period after deletion from the active production systems before the relevant backup is automatically overwritten or deleted.

We do not retain Google OAuth tokens after the relevant user disconnects their Google account or their account is removed, except where temporary retention is technically or legally necessary.

11. Infrastructure and data location

Zimpra's application infrastructure uses Cloudflare services, including:

  • Cloudflare Workers

  • Cloudflare D1

  • Cloudflare R2

Customer data is stored in the Asia-Pacific region, subject to the technical operation of the services described above.

Zimpra also maintains nightly backups.

Company email is operated using Microsoft 365.

We use infrastructure and service providers only to the extent reasonably necessary to operate, secure, maintain, and support Zimpra.

12. Sharing information

We do not sell customer business data or personal information. We may disclose information in limited circumstances, including those described below.

12.1 Service providers

We may share information with infrastructure and technology providers that process information on our instructions and are necessary to operate Zimpra.

These providers may provide services such as:

  • Cloud infrastructure

  • Storage

  • Security

  • Authentication

  • Email and communications

  • Technical support

These providers are not permitted to use customer data for their own unrelated purposes.

12.2 Legal requirements

We may disclose information where reasonably necessary to:

  • Comply with applicable law

  • Respond to a valid legal process

  • Protect the rights, property, or safety of Zimpra, our customers, users, or others

  • Detect or prevent fraud, security incidents, or abuse

12.3 Business changes

If Zimpra is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.

13. Security

We take reasonable technical and organizational measures to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

Our measures include, as applicable:

  • Encryption of sensitive credentials and OAuth tokens

  • Separation of encryption keys from application databases

  • Access controls

  • Customer database separation

  • Authentication and authorization controls

  • Security monitoring and logging

  • Regular backups

  • Restricted access to production systems

No internet service can guarantee absolute security. We therefore cannot guarantee that unauthorized access, data loss, or other security incidents will never occur.

If we become aware of a security incident that requires notification under applicable law, we will take the steps required by law.

14. Cookies and similar technologies

Zimpra may use cookies or similar technologies that are necessary for authentication, security, session management, and normal operation of the service.

We may also use limited technical information to understand service performance and diagnose problems.

You can control cookies through your browser settings, although disabling necessary cookies may prevent some parts of Zimpra from working correctly.

15. Children’s privacy

Zimpra is a business software service and is not intended for anyone under 18 years of age.

We do not knowingly provide accounts to people under 18.

If you believe that a person under 18 has provided personal information to Zimpra, please contact us at sales@zimpra.com so that we can investigate and take appropriate action.

16. Your responsibilities

You are responsible for ensuring that information you enter into Zimpra is accurate and that you have the appropriate rights, permissions, notices, and consents required to provide that information to Zimpra for processing.

If you use Zimpra on behalf of a company, you should ensure that your use of the service complies with your company’s privacy and data-protection responsibilities.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If we make a material change to how we collect, use, or share personal information, we will provide notice through the service, by email, or by another reasonable method.

The updated Privacy Policy will be published on this page with a revised effective or updated date.

You should review this page periodically for changes.

18. Contact us

If you have questions about this Privacy Policy, want to request deletion of your information, or have a privacy-related concern, contact:

Zimpra / ISUA Solutions Private Limited.

Email: sales@zimpra.com.

Website: https://zimpra.com

© 2026  ISUA Solutions Private Limited. All rights reserved.