Privacy Policy
Last updated 2026-08-09. Applies from 2026-08-09.
This policy covers dodocket.com (this website) andapp.dodocket.com (the product). Docket is operated byTezi Communications LLP.
The part that matters most: two different roles
Docket handles two kinds of personal data, under two different legal roles, and almost every question below depends on which one applies.
| Data | Our role | What that means |
|---|---|---|
| Website visitors, enquiries, our own customer accounts | Controller | We decide why and how it is used. This policy is the notice for it. |
| Everything inside a customer's account — their mailbox, contracts, documents, and their counterparties' details | Processor | We act on our customer's instructions. They decide what goes in and what comes out; our contract with them governs it, not this page alone. |
If you are a supplier, CHA, bank or forwarder
You may have received an email, WhatsApp message, SMS or call from Docket without ever signing up for anything. That is the product working as intended: an importer who trades with you uses Docket to handle the follow-up that a person on their desk would otherwise do by hand.
Your name, work email address, phone number and the messages exchanged sit insidethat importer's account. They are the controller of it; we process it for them. If you want your details corrected or removed, the fastest route is the company you trade with — but you can write to us atprivacy@dodocket.comand we will pass it on and act on their instruction.
We do not sell this data, we do not build a marketing list from it, and we do not use one customer's counterparties to sell to another.
What this website collects
Little. Nothing at all unless you choose to contact us — there is no sign-up on this site, and nothing below identifies you personally except the form, which only holds what you typed into it.
- What you send us — if you fill in the contact form we keep your name, email, company, rough shipment volume and message, so that we can reply. Alongside it we record your IP address, the country it resolves to, whether you were on a phone or a computer, and the page you were on immediately before: the country tells us which market you are in and what hour it is where you are, the IP is how we tell a real enquiry from an automated one, and the previous page tells us which part of the site was useful enough that you got in touch. Nothing is stored on your device to do this, and none of it is kept once you are no longer a live enquiry. That is the whole of it. It goes to a spreadsheet we control and to our own inbox; it is not sold, and it is not used to build a profile of you. The marketing checkbox is separate, unticked by default, and refusing it changes nothing about whether we answer you.
- Page analytics — we self-host Umami at umami.shipmyapp.in. It records page views, referrer, rough country and device type. It sets no cookie, stores nothing on your device, and the data stays on our own server.
- Company identification — with your consent, Leadfeeder matches the network address of a visit to a business, so we can see that a company read a page. It does not tell us who you are, and we deliberately leave its individual-level form tracking switched off.
- Server logs — standard web server records, including IP address, kept for security and troubleshooting.
Cookies
Two, one of them optional. If it is not in this table, we do not set it.
| Cookie | Set by | What it does | Lasts | Optional? |
|---|---|---|---|---|
| docket_consent | Docket | Remembers whether you accepted or refused the analytics cookie below. | 180 days | No — required |
| _lfa | Leadfeeder (Dealfront) | Identifies the company a visit came from, by matching the network address to a business. It does not tell us who you are. | 2 years | Yes |
The optional one does not load until you accept. Leadfeeder's code sits inside a function that only runs when you press Accept — until then nothing is fetched from it and no cookie is set. You can check with view-source and the network tab.
Change your cookie choice. Refusing after having accepted also deletes the cookie from this browser.
What the app collects
When a customer uses Docket, the product holds:
- Account details — names, work email addresses, and access roles.
- Connected mailbox contents — Docket reads the shipment mailbox a customer connects, so it can find documents, invoices and replies. This is the most sensitive category we handle.
- Contracts and shipment records — purchase and sales contracts, quantities, prices, payment terms, Incoterms and document checklists.
- Counterparty contact details — the people Docket chases, and the messages sent to them across email, WhatsApp, SMS and voice.
- Expenses and payments — duty, port charges, CHA fees and detention, traced back to the email each figure came from.
- Audit trail — every check, reminder, commitment and amount, with the underlying message retained alongside it.
Automated processing, AI and recorded calls
Docket uses AI to read documents and messages, work out what is missing, draft follow-ups, and place calls. Three things you should know, stated plainly:
- We do not train AI models on your data. Documents and messages inside a customer's account are sent to a third-party AI provider to be read and acted on. Docket does not build or train models on customer content. If you need our provider's contractual position on training in writing, ask and we will confirm it for your account.
- Voice calls are recorded, and the recording is kept with the shipment's audit trail. Whether the person is told at the start of the call is a setting the customer controls — they decide how their own counterparties are contacted, and they are responsible for the notice their configuration gives.
- Chasing is automated; decisions are not. Docket sends the reminders and drafts the documents, but it does not make legal or financial decisions about a person. A human at the customer approves what matters.
If you are a counterparty and you would rather not be called by an automated system, say so on any Docket message or write toprivacy@dodocket.com, and we will pass it to the company you trade with.
Who else sees the data
We do not sell personal data and we do not share it for anyone else's advertising. We use service providers who process it on our behalf, in these categories:
| Category | What it does | Applies to |
|---|---|---|
| Website analytics | Page views on dodocket.com. Self-hosted, no cookie. | This website |
| Company identification | Matches a visit's network address to a business. Consent-gated. | This website |
| Enquiry handling | Stores what you type into the contact form and emails it to us so we can reply. | This website |
| AI processing | Reads documents and messages to find what is missing and draft follow-ups. | The app |
| Messaging and voice | Delivers email, WhatsApp, SMS and calls to counterparties. | The app |
| Cloud hosting | Runs the application and stores its data. | The app |
Customers evaluating Docket can ask for the named list of providers behind these categories, and we will give it. We keep it current privately rather than on this page, so it cannot quietly go out of date here.
Where the data lives
This website and its analytics run on a server we operate ourselves. The app runs on cloud infrastructure operated by our hosting provider.
Trade is cross-border by nature — a Singapore importer, a supplier in Oman, an agent clearing at an Indian port — so data moves between countries as a matter of course. Where a transfer leaves the country you are in, we rely on the protections the applicable law requires for it.
Enterprise customers can avoid this entirely. Docket can run on their own servers or private cloud, in which case their trading data never reaches our infrastructure at all.
How long we keep it
We keep personal data only as long as it is needed for what it was collected for. In practice that means:
- Website analytics and company identification: kept only as long as useful for understanding demand, and deleted when it stops being.
- Contact-form enquiries: kept while we are in touch and for a reasonable period after, so we have the history if you come back. Deleted on request.
- Customer account data: for as long as the account is open, and a short period afterwards for billing and legal records.
- Mailbox contents, documents and the audit trail: for as long as the customer keeps them. Trade records often must be retained for years for customs and tax, so the customer decides, not us. Deleted on request when their account closes.
- Voice-call recordings: kept with the shipment audit trail, so they last as long as that record does.
- Cookie consent: 180 days, then we ask again.
Security
Access to customer data is restricted to the people who need it to run the service. Enterprise customers can run Docket on their own servers or private cloud, in which case their trading data never reaches our infrastructure at all, and they get SSO, role-based access and audit-log exports.
Your rights
Depending on where you are, you can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it, where we are not required to keep it;
- stop using it for a particular purpose, including withdrawing consent;
- complain to your data protection regulator.
The laws we work to:
- Singapore — Personal Data Protection Act 2012 (PDPA)
- United Arab Emirates — Federal Decree-Law No. 45 of 2021 (PDPL)
- India — Digital Personal Data Protection Act 2023 (DPDP)
- European Economic Area and UK — GDPR / UK GDPR, where a visitor or counterparty is located there
Write to privacy@dodocket.comand we will respond within 30 days. If your data sits inside a customer's account, we will forward the request to them, since it is theirs to decide.
Grievance Officer. Mohit Patel, Grievance Officer —privacy@dodocket.com. India's DPDP Act requires a named officer with published contact details; the same route reaches us for PDPA and UAE enquiries.
Children
Docket is a business tool. It is not directed at children and we do not knowingly collect their data.
Changes
We will update this page when what we do changes — including whenever a service provider is added or removed. The date at the top always reflects the current version.
Contact
privacy@dodocket.com, or Balkrishna Agarwal on WhatsApp.
Tezi Communications LLP, Ahmedabad, India.