Janio

Privacy Policy

Effective Date: January 1, 2025

Last Updated: August 28, 2026

1. Introduction

Taurus One Private Limited (UEN 201810116D) (formerly Janio Technologies Private Limited) ("Janio," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our Fourth-Party Logistics (4PL) platform, services, or visit our website at janio.asia. This policy applies to all users of our services, including shippers, merchants, carriers, and website visitors. By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our services. We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

1.1 Our Role: When We Are a Controller and When We Are a Processor

Janio handles personal data in two distinct capacities, and the rights and routes described in this policy differ depending on which applies. Where we are a controller: For our own account holders — shippers, merchants, carriers and website visitors who register with us or contact us directly — we determine why and how personal data is used. This policy governs that processing in full, and you may exercise your rights directly with us. Where we are a processor (a data intermediary under the PDPA): When a merchant sends us an order to fulfil, the personal data of the recipient — name, delivery address, contact details — is provided to us by that merchant. The merchant remains the controller of that data. We process it only on the merchant's documented instructions, solely to deliver the shipment, and we do not use it for any other purpose. If you are a delivery recipient and wish to exercise your data protection rights, please contact the merchant you ordered from. If you contact us instead, we will acknowledge your request and refer it to that merchant, and we will act on their verified instruction.

2. Information We Collect

We collect information necessary to provide our 4PL logistics services effectively. The types of information we collect depend on how you interact with our platform and services.

2.1 Personal Information

When you create an account or use our services, we may collect personal information including your name, email address, phone number, company name, job title, and billing address. Payment card and bank account details are collected and processed directly by our payment providers; Janio does not store full payment card numbers or bank account credentials. We also collect shipping addresses (both origin and destination) necessary to fulfill logistics services, as well as your account credentials and communication preferences.

2.2 Shipment Data

To process and manage your shipments, we collect package dimensions, weight, and contents descriptions; customs declarations and commercial invoices; tracking information and delivery status updates; carrier selection and routing data; and proof of delivery information including signatures where applicable.

2.3 Technical Data

When you access our platform, we automatically collect certain technical information including your IP address, browser type and version, device information, operating system, usage patterns and feature interactions, API access logs and integration data, and session data and authentication logs. This information helps us maintain security, improve our services, and provide technical support.

2.4 Cookies and Similar Technologies

We use cookies and similar technologies to run our website and, with your consent, to understand usage and support our marketing. Essential cookies (including the cookie that remembers your consent choice) are always active and are required for basic functionality and security. Analytics and advertising cookies from Google Analytics and the LinkedIn Insight Tag load only after you accept them via our cookie banner. You can change or withdraw your choice at any time using the "Cookie settings" link in our footer, or by clearing cookies in your browser. The specific cookies we use are listed below.
Cookie(s)ProviderPurposeRetention
janio_consentJanio (essential)Remembers your cookie consent choice so the banner is not shown repeatedly. Always active.12 months
_ga, _ga_*, _gidGoogle Analytics 4Analytics — measures aggregate site usage and traffic sources. Loads only after you consent.Up to 24 months
bcookie, lidc, UserMatchHistory, li_sugrLinkedIn Insight TagAdvertising and retargeting — helps us reach relevant audiences and measure campaigns. Loads only after you consent.Up to 12 months

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery

We use your information to process and fulfill shipment orders, coordinate with carriers and logistics partners, provide real-time tracking and status updates, manage customs clearance and documentation, generate invoices, and process payments.

3.2 Platform Improvement

We analyze usage patterns to enhance platform features, optimize carrier selection algorithms, improve rate procurement and routing efficiency, and develop new services based on customer needs and feedback.

3.3 Communication

We use your contact information to send shipment notifications and alerts, provide customer support and assistance, share important service updates and announcements, and respond to your inquiries and feedback.

3.4 Legal Compliance

We may use your information to comply with applicable laws, regulations, and legal processes; respond to lawful requests from public authorities; protect our rights, privacy, safety, or property; and enforce our terms of service.

3.5 Legal Bases for Processing

Where the GDPR applies to our processing, we rely on the following legal bases under Article 6:
  • Performance of a contract (Article 6(1)(b)) — to create, route, track and complete shipments, manage customs documentation, generate invoices and process payments, and to provide the platform to account holders.
  • Legitimate interests (Article 6(1)(f)) — to secure and monitor our platform, prevent fraud, analyse usage to improve our services, and manage our business relationships. We balance these interests against your rights and you may object at any time using the contact details in section 11.
  • Legal obligation (Article 6(1)(c)) — to meet customs, tax, accounting and trade compliance requirements, and to respond to lawful requests from public authorities.
  • Consent (Article 6(1)(a)) — for analytics and advertising cookies, and for marketing communications. You may withdraw consent at any time without affecting processing carried out before withdrawal.
Where we act as a processor for a merchant (see section 1.1), that merchant is responsible for establishing the legal basis for the processing it instructs. Under Singapore's PDPA, we rely on consent, deemed consent (including deemed consent by contractual necessity for shipment fulfilment) and the legitimate interests exception, as applicable to each purpose.

4. Information Sharing and Disclosure

As a 4PL orchestrator, we share information with third parties only as necessary to fulfill our services or as required by law. We maintain strict controls over all data sharing.

4.1 Logistics Partners

We share necessary shipment information with carrier networks for shipment fulfillment, including recipient name, address, and package details. We also share information with customs brokers for international clearance, warehouse partners for storage and handling, and last-mile delivery providers. These partners are contractually obligated to protect your information and use it only for the purposes of providing logistics services.

4.2 Service Providers

We engage third-party service providers to assist with our operations, including cloud infrastructure providers (primarily AWS in Singapore), payment processors for transaction handling, analytics tools for platform improvement, and communication services for notifications. These providers are bound by contractual obligations to maintain the confidentiality and security of your information.

4.3 Legal Requirements

We may disclose your information when required to comply with court orders or legal processes, to customs and regulatory authorities as required by law, to government agencies for trade compliance purposes, or to law enforcement when legally obligated. We will notify you of such disclosures where legally permitted.

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

4.5 Subprocessors

We engage the following categories of subprocessor to deliver our services. A current list of named subprocessors, including the processing they perform and the countries in which they operate, is available on request from dpo@janio.asia.
  • Cloud infrastructure — Amazon Web Services (primary data storage in Singapore).
  • Carrier, last-mile delivery, warehousing and customs brokerage partners in each destination market.
  • Business systems supporting our operations, including Google Workspace, Slack, Atlassian (JIRA), GitLab and XERO.
  • Payment processors and communications providers.
Every subprocessor is assessed before engagement under our Vendor Management Policy and is bound by a written agreement imposing confidentiality, purpose limitation, defined security measures, restrictions on onward transfer, and prompt breach notification. Account holders may subscribe to notifications of changes to our subprocessor list by contacting dpo@janio.asia.

5. Data Security

We implement comprehensive security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. Our security practices include: Technical Safeguards: We employ AES-256 encryption for data at rest and TLS 1.3 encryption for data in transit. We require multi-factor authentication for account access and conduct regular security assessments and penetration testing. Our systems are monitored 24/7 for security threats. Organizational Controls: We implement role-based access control (RBAC) for all systems and require employee security training and awareness programs. Personnel with data access undergo background checks. We maintain documented incident response procedures and conduct regular access reviews with comprehensive audit logging. Independent Assurance: Our Information Security Management System is certified to ISO/IEC 27001:2022 (certificate IC-IS-2607249, issued by InterCert, valid from 17 July 2026). We also undergo an annual SOC 2 Type II examination covering the Security, Availability and Confidentiality Trust Services Criteria for the Janio Platform. Copies of our certificate and report are available to customers and prospective customers on request, subject to a non-disclosure agreement. Breach Notification: We maintain a documented incident response and breach notification plan. If a personal data breach occurs that is likely to result in significant harm, we will notify the relevant supervisory authority — including Singapore's Personal Data Protection Commission — and affected individuals without undue delay and within the timeframes required by applicable law. Where we act as a processor for a merchant, we will notify that merchant without undue delay so that they can meet their own notification obligations. While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, but we continuously work to enhance our security measures.

6. Data Retention

We retain your information only as long as necessary for the purposes outlined in this policy or as required by law. Our retention periods are as follows: Personal data held on behalf of a client, including recipient names, delivery addresses and contact details, is retained for the duration of the client contract plus three (3) months from termination, or for such shorter or longer period as that client contract specifies. Application database backups follow the same period. Financial records, customs declarations and commercial invoices are retained for the period required by applicable tax, customs and accounting law, currently up to seven (7) years. Technical logs are retained for twelve (12) months for security monitoring. Marketing preferences are retained until you withdraw your consent. Where more than one period could apply to the same record, we apply the longest period required by statute, then by contract, then by our internal policy. Upon expiration of the applicable retention period, we securely delete or anonymize your information. Deletion is performed by secure overwriting or cryptographic erasure so that the data is irrecoverable, and the same requirement applies to backup and archived copies. Account deletion requests are processed within thirty (30) days. Backup data is purged according to our retention schedule. Carriers are contractually required to delete the personal data we share with them once it is no longer needed for delivery and any applicable regulatory retention period has expired; because carriers act under their own legal obligations in each destination market, we cannot guarantee deletion within a fixed period.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information under applicable data protection laws, including the General Data Protection Regulation (GDPR) and Singapore's Personal Data Protection Act (PDPA). Right of Access: You may request a copy of the personal information we hold about you. Right to Rectification: You may request that we correct any inaccurate or incomplete personal information. Right to Erasure: You may request that we delete your personal information, subject to certain exceptions. Right to Data Portability: You may request to receive your personal information in a structured, commonly used, and machine-readable format. Right to Object: You may object to certain processing of your personal information. Right to Restrict Processing: You may request that we limit how we use your personal information. Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time. To exercise any of these rights, please contact us at privacy@janio.asia. We will respond to your request within thirty (30) days. We may need to verify your identity before processing your request. There is no fee for reasonable requests, though we may charge a reasonable fee for manifestly unfounded or excessive requests. If you are a delivery recipient: Where we hold your personal data only because a merchant asked us to deliver an order to you, that merchant is the controller of your data and is best placed to answer your request. Please contact them directly. If you contact us, we will acknowledge your request, tell you which merchant instructed the delivery where we are permitted to do so, and refer your request to them.

8. International Data Transfers

As a cross-border logistics provider operating across Southeast Asia, we transfer personal information internationally to fulfill shipments and provide our services. Our primary data storage is located in Singapore. When we transfer personal information outside of your country of residence, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by relevant data protection authorities, Data Processing Agreements with all subprocessors, adequacy assessments for destination countries, and encryption of all cross-border data transfers. We maintain regional compliance with data protection laws in the countries where we operate and can provide regional data residency options where available and required.

9. Children's Privacy

Our services are not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us at privacy@janio.asia. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date at the top of this page. For material changes, we will provide notice via email to account holders at least thirty (30) days before the changes take effect. Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. Previous versions of this policy are available upon request.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: Taurus One Private Limited (UEN 201810116D) 30 Prinsep St, #06-01 Singapore 188647 Email: privacy@janio.asia Data Protection Officer: dpo@janio.asia We will respond to your inquiry within five (5) business days. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority. In Singapore, this is the Personal Data Protection Commission (www.pdpc.gov.sg).

If you have questions about this Privacy Policy, please contact us.