Privacy Policy
Last updated: 14 September 2026 · Effective immediately · Privacy and consent notice
This Privacy Policy explains how Sri Lakshmi Prasanna Enterprises (operating as SLP Express International Couriers, hereafter "SLP", "we", "us" or "our") collects, uses, shares and protects personal data when you use slpcouriers.in or our courier services. We follow applicable Indian privacy and information-security law and are preparing for the phased commencement of the Digital Personal Data Protection Act 2023 and final Digital Personal Data Protection Rules 2025. This page does not describe a provision as currently enforceable before its notified commencement date.
1. Who we are
Data Fiduciary: Sri Lakshmi Prasanna Enterprises (Proprietorship)
Proprietor: Rajkumar Vemulapalli
Registered office: Ground Floor, H No 11/A, Karunasri Apartments, Sanjeev Reddy Nagar X Road, Vengal Rao Nagar, Hyderabad, Telangana 500038, India
GSTIN: 36AFBPV3120L2ZD
Contact: info@slpcouriers.in · +91 99510 83676
2. What personal data we collect
To process your international courier shipment, we collect the following categories of personal data:
From the sender (you)
- Full name, residential or office address in Hyderabad / India
- Mobile number (for WhatsApp coordination, pickup confirmation, AWB delivery)
- Email address (for tracking notifications and invoices)
- Government-issued ID copy (Aadhaar or passport) for KYC at customs export
- PAN or additional KYC only where the payment method, shipment type, carrier or applicable law requires it
- Payment information (UPI ID, last 4 digits of card, bank reference number)
From the recipient
- Full name and destination address
- Recipient phone number and email for delivery coordination by carrier
- Government ID where mandatory (eg. EORI for EU shipments, EIN for US commercial)
About your shipment
- Itemised contents declaration (required for customs invoice)
- Declared value of items in INR / destination currency
- Weight, dimensions and photographs of the parcel taken at pickup
When you allow website analytics
- A random first-party visitor ID and 30-minute session ID used to count visitors and sessions
- A one-way keyed hash of the network address used to estimate unique networks; the v2 analytics collector does not store the raw IP address
- Device category, browser user agent, viewport size, page title and page path
- Pages visited, time engaged, scroll-depth milestones, referring website and campaign attribution parameters
- Links, buttons and contact actions clicked, including WhatsApp, Call, Check Rates and Book Pickup
- Normalised click coordinates used to create an aggregate page click map
The analytics script does not read or record the contents of input, textarea or select fields. We do not create keystroke recordings, screen recordings or replay videos.
3. Why we collect this data (lawful purposes)
- To deliver the courier service you booked — pickup, packing, customs documentation, carrier handover, tracking and delivery
- Mandatory customs compliance — Indian Customs Act 1962 and destination country customs require sender/recipient identification and itemised value declaration
- Tax compliance — Goods and Services Tax (GST) invoicing under CGST Act 2017
- Service communication — booking confirmation, AWB tracking, delivery notifications via WhatsApp / SMS / email
- Marketing communication — only with the applicable consent and opt-out controls
- Fraud prevention — detecting prohibited items, suspicious shipments, KYC verification
- Website analytics and conversion measurement — improving pages, rate journeys, campaign creatives and contact actions, only after you allow analytics
4. Who we share your data with
We share the minimum data necessary with the following categories of recipients:
- Carriers — DHL Express, FedEx, UPS, Aramex and their international networks receive sender + recipient details on the Air Waybill (AWB) so they can deliver your parcel
- Indian Customs (CBIC) — sender KYC, commercial invoice, declared value for export clearance
- Destination country customs authorities — eg. US CBP, UK HMRC, Australian DAFF, EU Customs — receive your customs invoice for import clearance
- Banking and payment processors — to process refunds and reconcile invoices (limited to amount + reference)
- Tax authorities — under valid legal demand only (eg. GST audit, Income Tax notice)
- Law enforcement — only on a written, lawful order from a court or competent authority
- Email delivery service providers (currently Resend) — a qualifying contact action, such as tapping WhatsApp or Call, may trigger an internal notification containing the page, action, device category and a shortened pseudonymous network identifier. The raw IP address and form-field contents are not included.
- Google Ads — only when its optional conversion bridge is enabled and you have allowed analytics. We send configured conversion events for selected contact actions and do not send customer form-field contents.
We do not sell, rent or trade your personal data to any third party for advertising or marketing purposes.
5. How long we keep your data
We retain personal data for the following periods:
- Shipment, tax and payment records: for the period required by applicable tax, customs, accounting and claim law
- Customs invoices and AWBs: for the applicable legal, carrier and claim-retention period
- KYC documents: only as long as required for the shipment, legal retention, fraud prevention or a live dispute
- Marketing-consent records: until you withdraw consent
- First-party website analytics and click records: 12 months, then deleted
- First-party visitor ID in your browser: up to 12 months from creation, or until you clear site data or withdraw analytics consent
- Cookie data: see Section 8 for per-cookie expiry
When a retention purpose ends, we delete or de-identify data from active systems through our normal retention process. Backup deletion follows the applicable backup lifecycle; legal holds or live disputes can require longer retention.
6. Data requests we currently accept
You may contact us about the following requests. We will act where applicable law requires and, where practical, voluntarily before future DPDP provisions commence:
- Access — ask what personal data we hold about your booking
- Correction — ask us to correct inaccurate or incomplete data
- Deletion — ask us to delete data that we are not legally or operationally required to retain
- Consent withdrawal — withdraw optional analytics or marketing consent prospectively
- Grievance — raise a privacy concern with the contact in Section 10
Email info@slpcouriers.in or WhatsApp +91 99510 83676 with the subject "Privacy Data Request" and, where relevant, the AWB number. We verify identity, explain any lawful retention need and provide a realistic response estimate.
7. Children's data
SLP Express services are not directed at children under 18. We do not knowingly collect personal data of children. If you believe we have inadvertently collected such data, please contact our Grievance Officer immediately and we will delete it.
8. Cookies and tracking technologies
We use the following categories of cookies:
- Essential cookies (always on, no consent needed) — session management, cart, language preference. Expiry: end of session or 30 days.
- First-party analytics storage — consent-based random visitor and session IDs used for page, funnel, conversion and aggregate click-map measurement. Visitor ID expiry: up to 12 months; session timeout: 30 minutes of inactivity.
- Anonymous counts without consent — if you reject or ignore the banner, we still record each page view and each tap on a contact button (WhatsApp, call, pickup or rates), with the page, button label, device and browser type, the referring site or campaign tag, and a pseudonymous network identifier (a salted hash; the IP address itself is not stored). Nothing is saved in your browser, the identifiers are made up for that single request so separate visits cannot be linked, and no click positions are recorded. Automated traffic such as search-engine crawlers is discarded.
- Optional Google Ads storage — loaded only after consent and only when the conversion bridge is enabled. Google controls its applicable storage duration.
- Consent storage (
slp_consent_v2) — remembers whether you allowed or rejected analytics until you change the choice or clear browser data.
You can allow or reject analytics from the first-visit banner. Rejecting or withdrawing consent stops the consent-based measurement and clears its visitor and session IDs; the anonymous counts described above continue, because nothing is stored on your device and they are not linked across visits. Withdrawal does not affect processing already performed.
9. Data security
We implement reasonable security measures including:
- HTTPS / TLS encryption for all data in transit
- Access controls on customer database — only authorised SLP staff can view sender/recipient details
- Physical document storage in locked cabinets at registered office
- Regular staff training on data handling and confidentiality
- Vendor review and minimum-necessary sharing with the selected carrier or service provider
If a personal-data breach affects you, we will investigate, contain it where possible and notify affected users or authorities when and in the manner required by the law in force at that time. We will not advertise an unsupported universal 72-hour deadline.
10. Privacy contact
Grievance Officer: Mr. Rajkumar Vemulapalli (Proprietor)
Address: Sri Lakshmi Prasanna Enterprises, Ground Floor, H No 11/A, Karunasri Apartments, Sanjeev Reddy Nagar, Hyderabad, Telangana 500038
Email: info@slpcouriers.in (subject line: "Privacy Grievance")
WhatsApp / Phone: +91 99510 83676
Response approach: identity verification, acknowledgement and a realistic resolution estimate based on the request
If an applicable statutory complaint route is available for your issue, you may use that route after giving SLP a reasonable opportunity to respond. We will update this page as the DPDP framework and complaint mechanisms commence.
11. International data transfers
International delivery requires sender, recipient and shipment data to reach the selected carrier network and relevant authorities outside India. We limit sharing to data reasonably needed for booking, delivery and legal compliance and follow applicable transfer restrictions in force at the time.
12. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, services or practices. The "Last updated" date shows the current version. Where practicable and legally required, we will give an appropriate notice of material changes.
13. Governing law and jurisdiction
This Privacy Policy is governed by the laws of India, specifically the Digital Personal Data Protection Act 2023, Information Technology Act 2000 (and Rules), and Consumer Protection Act 2019. Any dispute arising out of or in connection with this policy shall be subject to the exclusive jurisdiction of courts in Hyderabad, Telangana, India.
This Privacy Policy is the complete and exclusive statement of how SLP Express processes your personal data. If anything is unclear, please ask before sharing your data with us — we want you to be fully informed.