MGR Courier Service Limited ("MGR") is the data controller for personal data we collect about you. We are registered with the Office of the Information Commissioner of Jamaica.
| Category | Examples |
|---|---|
| Identifiers | Name, TRN, passport / driver's licence number, date of birth |
| Contact | Address, phone, email |
| Account | Username, hashed password, 2FA secrets, login timestamps |
| Shipment | Cargo descriptions, invoices, bills of lading, photos, tracking |
| Financial | Payment confirmations (we never store full card numbers) |
| Device | IP address, browser version, approximate location |
| Sensitive | Where required for clearance: health information (medical-device imports), biometric ID copies for KYC, criminal record clearances for FLA/MNS permits |
We rely on the following lawful bases under the Jamaica Data Protection Act 2020 (DPA):
We do not sell your personal data, ever.
Some of our service providers are located outside Jamaica. Where we transfer personal data outside Jamaica we do so under one of the safeguards permitted by the DPA — the data subject's consent, performance of a contract, the recipient's substantially similar protection, or standard contractual clauses approved by the Information Commissioner.
| Data | Retention period |
|---|---|
| Customs entries, brokerage files | 7 years (Customs Act minimum) |
| Tax records, invoices | 6 years (Revenue Administration Act) |
| Account & KYC records | 7 years after closure (POCA) |
| Shipment tracking GPS data | 90 days then aggregated |
| Marketing email subscription | Until withdrawn + 30 days |
| Server logs | 13 months |
Under the DPA you have the right to:
We use a small number of strictly-necessary cookies for authentication and security. Optional analytics cookies are used only with your consent. See our Cookie Policy for details.
We protect personal data with TLS in transit, AES-256-GCM encryption at rest for sensitive document blobs, password hashing with PBKDF2 + salt, role-based access control, audit logging, and 2FA for staff accounts. No system is perfectly secure; we monitor and improve continually.
If we become aware of a personal data breach we will notify the Information Commissioner within 72 hours where there is a risk to data subjects, and notify affected individuals without undue delay. See our Data Breach Response Policy for the full procedure.
Our services are not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Data Protection Officer
MGR Courier Service Limited
Kingston, Jamaica
Email: dpo@mgrcouriers.com
Office of the Information Commissioner (Jamaica) — oic.gov.jm