Held
What Cargovate stores
Operational records: consignments and their movements, the parties involved, checkpoints
and the evidence attached to them, a fingerprint of each document you record (the file itself stays with you), purchase orders you import, and
— where you license those capabilities — stock, assets and telemetry.
Your own identifiers are kept verbatim. A shipment you call JOB-4417 stays
JOB-4417 throughout, rather than being replaced by a number of ours that your staff then
have to translate. This matters more than it sounds: it is the difference between your
people searching the way they already think and learning a second vocabulary.
Separation
How your records stay yours
Every record carries the organisation it belongs to, and that boundary is enforced by the
database itself rather than by application code remembering to filter. The practical
consequence is that a mistake in a feature cannot expose another customer's data: a query
that forgets to scope returns nothing at all, rather than returning everything.
Where you deliberately grant access — a freight forwarder acting for you — that grant is
explicit, recorded, and revocable by you at any time. It is not a shared login, and every
action taken under it remains attributed to the person who really performed it.
Location
Where it physically lives
In our managed cloud, in the European Union (Finland); a
dedicated instance runs in another region if your records must
be held there. On your own estate,
wherever you put it — including a machine with no route to the internet at all. The
product does not require an outbound connection to function; see
Deployment.
Exit
Getting it all back
Your organisation's owners and administrators can export all of it from within the product,
whenever they like, including while an account is read-only: every record as one JSON file,
any table as CSV, and every uploaded document as one ZIP with a manifest of each file's
SHA-256 fingerprint and what it is attached to. Passwords, access keys and other credentials
are left out. If you cannot export it yourselves, ask us and we will provide a complete copy,
with no proprietary container and no professional-services engagement to read your own history.
On a self-hosted deployment the
database is yours already; the schema is documented and a standard backup restores into a
plain PostgreSQL instance.
We would rather say this plainly than be asked. A platform that makes leaving expensive
earns renewals from friction instead of value, and the customers worth having can tell the
difference.
Deletion
Removal
On request we remove your organisation and the operational records belonging to it.
Records we are separately required to retain — a signed audit trail under a regulation you
operate within — are named at the time rather than quietly kept, so what remains and why
is written down before anything is deleted.