Your operation runs on this data.
Here’s how we protect it.
A courier platform holds your customers, your rates and your revenue. This page sets out — plainly and without marketing gloss — what ParcelOps does to keep that data private, intact and available.
Data residency & POPIA
ParcelOps is hosted in South Africa. Your operational data — waybills, customers, drivers, invoices — is processed and stored in-country and does not leave it.
As required by the Protection of Personal Information Act, ParcelOps acts as an operator processing personal information on behalf of each courier company (the responsible party). Access is limited to what operating the service requires, personal information is never sold or shared for marketing, and data subject requests are supported. Our Privacy Policy sets out the detail.
Encryption
All traffic between your browser, your drivers' devices and the platform is encrypted in transit with TLS. Data is encrypted at rest on the underlying storage.
Passwords are stored only as salted one-way hashes — never in a recoverable form. Payment card details are never stored on ParcelOps at all: online payments are processed by PayFast, a PCI DSS compliant South African payment provider.
Tenant isolation
Every courier company runs in its own isolated environment with its own subdomain, users and data. Every database query is scoped to the requesting tenant at the application layer.
Isolation is not assumed — it is tested. An automated regression suite exercises cross-tenant access attempts on every build, so a change that could leak data between companies fails before it ships.
Access control
Role-based permissions control what each user can see and do — an ops controller, a driver, an accountant and a customer each get exactly their slice of the system and nothing more.
Staff and administrator accounts support multi-factor authentication, and ParcelOps' own internal administrative access is MFA-protected. Sensitive actions are recorded in an audit log: who did what, from where, and when.
Backups & continuity
Databases are backed up automatically every day, with backups retained on separate storage from the production systems.
Backups you cannot restore are theatre, so restores are verified — recovery from backup is tested as a procedure, not assumed. A documented disaster-recovery runbook covers rebuilding the platform from those backups.
Monitoring & incident response
The platform is monitored around the clock by automated systems: uptime and health checks, error tracking on every application, and alerting that pages the team when something needs a human.
When incidents occur, affected customers are informed of what happened and what was done about it. We do not publish theoretical response-time targets we have not proven — we would rather show you the monitoring.
How we build
Every change goes through version control and continuous integration: automated test suites — including the tenant-isolation and billing-accuracy tests — run before code reaches production, and deployments are automated and repeatable.
Dependencies are scanned automatically for known vulnerabilities, and the platform's error budget is reviewed against real production telemetry, not guesswork.
Evaluating ParcelOps?
If your procurement or IT team needs more than this page — a completed security questionnaire, POPIA processing details, or a walkthrough of any control described here — contact us and we’ll work through it with them directly.
Contact usFound a vulnerability?
We appreciate responsible disclosure. If you believe you’ve found a security issue in ParcelOps, email hello@parcelops.co.za with the details. We’ll acknowledge your report, investigate, and keep you informed — and we won’t take action against good-faith research.
Security questions answered before they’re asked
Try the platform your data would live on — free, with no credit card.